# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=666

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 667

---

## [Watcher - send runtime field in a Slack message](https://discuss.elastic.co/t/watcher-send-runtime-field-in-a-slack-message/323235)

<div class="topic-metadata">

**Author:** [@Darko\_Krstevski](https://discuss.elastic.co/u/Darko_Krstevski)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 10:36am UTC](https://discuss.elastic.co/t/watcher-send-runtime-field-in-a-slack-message/323235 "2023-01-16T10:36:12Z")

</div>

Hi All. I've created runtime mapping (field), transaction.duration.sec, which contains converted (in seconds) value of the "original" transaction duration (expressed in microseconds), with the following watcher configur…

---

## [Using wildcard and must\_not to search](https://discuss.elastic.co/t/using-wildcard-and-must-not-to-search/323236)

<div class="topic-metadata">

**Author:** [@geeky\_human](https://discuss.elastic.co/u/geeky_human)\
**Replies:** 1\
**Last updated:** [January 16, 2023, 11:12am UTC](https://discuss.elastic.co/t/using-wildcard-and-must-not-to-search/323236 "2023-01-16T11:12:27Z")

</div>

Hi, I’m new to ELK. For searching, I’m using dev tools in kibana. I want to find all the results that do not match a wildcard term. "must\_not": \[ {"wildcard": { "agent.keyword": {"value":"python\*"} }}\] I…

---

## [Elastic Logging Plugin for Docker: "error creating client config: A hosts flag is required"](https://discuss.elastic.co/t/elastic-logging-plugin-for-docker-error-creating-client-config-a-hosts-flag-is-required/323202)

<div class="topic-metadata">

**Author:** [@kthy](https://discuss.elastic.co/u/kthy)\
**Replies:** 1\
**Last updated:** [January 16, 2023, 11:12am UTC](https://discuss.elastic.co/t/elastic-logging-plugin-for-docker-error-creating-client-config-a-hosts-flag-is-required/323202 "2023-01-16T11:12:18Z")

</div>

This question is about the Elastic Logging Plugin for Docker , which doesn't have it's own category on the Elastic forums. Sad. I have tried creating a docker container with the Elastic logging plugin, but I get an erro…

---

## [Please keep the old expand document, the new "pop-out" makes everything slow](https://discuss.elastic.co/t/please-keep-the-old-expand-document-the-new-pop-out-makes-everything-slow/322941)

<div class="topic-metadata">

**Author:** [@blommis](https://discuss.elastic.co/u/blommis)\
**Replies:** 6\
**Last updated:** [January 16, 2023, 10:54am UTC](https://discuss.elastic.co/t/please-keep-the-old-expand-document-the-new-pop-out-makes-everything-slow/322941 "2023-01-16T10:54:30Z")

</div>

We just upgraded version and expanding a document in the table is now in a popup covering halv the screen. Before this change it was shown as more details below every row, making it possible to view details on multiple …

---

## [Elasticsearch DSL Query - Field is not null or not empty](https://discuss.elastic.co/t/elasticsearch-dsl-query-field-is-not-null-or-not-empty/323005)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 8\
**Last updated:** [January 16, 2023, 10:49am UTC](https://discuss.elastic.co/t/elasticsearch-dsl-query-field-is-not-null-or-not-empty/323005 "2023-01-16T10:49:18Z")

</div>

I have an existing DSL query that needs to modify such that the id "12345" should be not null or not empty: { "bool":{ "must":\[ { "bool":{ "should":\[ { …

---

## [Cache tunning for cardinality](https://discuss.elastic.co/t/cache-tunning-for-cardinality/323015)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 5\
**Last updated:** [January 16, 2023, 10:41am UTC](https://discuss.elastic.co/t/cache-tunning-for-cardinality/323015 "2023-01-16T10:41:25Z")

</div>

Hi I'm troubleshooting some wired case related to maybe cache ... so when I'm using simple query by curl for the first shoot I got something like below {"detail":"3,000 milliseconds timeout on connection http-outgoing-…

---

## [This node is locked](https://discuss.elastic.co/t/this-node-is-locked/323040)

<div class="topic-metadata">

**Author:** [@Randomize](https://discuss.elastic.co/u/Randomize)\
**Replies:** 11\
**Last updated:** [January 16, 2023, 10:25am UTC](https://discuss.elastic.co/t/this-node-is-locked/323040 "2023-01-16T10:25:02Z")

</div>

Hello I updated elasticsearch to version 8.4.1 Now im trying to start elasticsearch using discovery.type: single-node in config file. But its does not starting. I can see status activating in systemctl status. In elast…

---

## [Gsub processor in ingest pipeline cannot substitute a pattern into newline](https://discuss.elastic.co/t/gsub-processor-in-ingest-pipeline-cannot-substitute-a-pattern-into-newline/323151)

<div class="topic-metadata">

**Author:** [@andreatera](https://discuss.elastic.co/u/andreatera)\
**Replies:** 4\
**Last updated:** [January 16, 2023, 9:39am UTC](https://discuss.elastic.co/t/gsub-processor-in-ingest-pipeline-cannot-substitute-a-pattern-into-newline/323151 "2023-01-16T09:39:17Z")

</div>

Hello there, since we are moving from logstash pipeline into ingest pipeline we had to rewrite our gsub pattern from logstash into ingest processors. Our use case is simple, replace the unicode \\u2028 into a newline ch…

---

## [How to apply search on special characters when search is limited to specific fields?](https://discuss.elastic.co/t/how-to-apply-search-on-special-characters-when-search-is-limited-to-specific-fields/323220)

<div class="topic-metadata">

**Author:** [@Moazzam\_Saleem](https://discuss.elastic.co/u/Moazzam_Saleem)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 6:58am UTC](https://discuss.elastic.co/t/how-to-apply-search-on-special-characters-when-search-is-limited-to-specific-fields/323220 "2023-01-16T06:58:49Z")

</div>

I'm new to elasticsearch, I'm trying to give global search but when I limited my search to apply of specific fields by giving fields param in query, search doesn't apply on special characters Here is my JSON query: { …

---

## [How to mask card number of xml message](https://discuss.elastic.co/t/how-to-mask-card-number-of-xml-message/322925)

<div class="topic-metadata">

**Author:** [@Anil0110](https://discuss.elastic.co/u/Anil0110)\
**Replies:** 5\
**Last updated:** [January 16, 2023, 7:19am UTC](https://discuss.elastic.co/t/how-to-mask-card-number-of-xml-message/322925 "2023-01-16T07:19:27Z")

</div>

Hello the requirement is we need to mask the cardnumber of xml message our input message looks like : message : output message expected

---

## [How to Get Control Filter in my custom plugin](https://discuss.elastic.co/t/how-to-get-control-filter-in-my-custom-plugin/323221)

<div class="topic-metadata">

**Author:** [@monusharma](https://discuss.elastic.co/u/monusharma)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 6:59am UTC](https://discuss.elastic.co/t/how-to-get-control-filter-in-my-custom-plugin/323221 "2023-01-16T06:59:28Z")

</div>

In this regards, I have searched on internet and found deprecated below mentioned code: import FilterBarQueryFilterProvider from 'ui/filter\_bar/query\_filter'; // Somewhere in your directive, service, or controller con…

---

## [Cluter removed timeout Coordinating node](https://discuss.elastic.co/t/cluter-removed-timeout-coordinating-node/323208)

<div class="topic-metadata">

**Author:** [@chengdihua](https://discuss.elastic.co/u/chengdihua)\
**Replies:** 1\
**Last updated:** [January 16, 2023, 6:45am UTC](https://discuss.elastic.co/t/cluter-removed-timeout-coordinating-node/323208 "2023-01-16T06:45:25Z")

</div>

Hello, everyone! We have 15 nodes in our ES cluster, including 3 master nodes, 9 data nodes, and 3 coordinate/client nodes. There are 3 physical hosts in the cluster, and 5 ES nodes are deployed on each host. (1 master…

---

## [Regarding daily active users count formula](https://discuss.elastic.co/t/regarding-daily-active-users-count-formula/323188)

<div class="topic-metadata">

**Author:** [@bhavin.shah](https://discuss.elastic.co/u/bhavin.shah)\
**Replies:** 3\
**Last updated:** [January 16, 2023, 5:52am UTC](https://discuss.elastic.co/t/regarding-daily-active-users-count-formula/323188 "2023-01-16T05:52:57Z")

</div>

Hello team, I am trying to calculate one number output as , how many customers have placed daily atleast one order in last one day. My index formation is like following Ord\_order\_no - unique record / document ID Clien…

---

## [Unable to reset default password](https://discuss.elastic.co/t/unable-to-reset-default-password/323210)

<div class="topic-metadata">

**Author:** [@yuvrajbset](https://discuss.elastic.co/u/yuvrajbset)\
**Replies:** 1\
**Last updated:** [January 16, 2023, 3:58am UTC](https://discuss.elastic.co/t/unable-to-reset-default-password/323210 "2023-01-16T03:58:15Z")

</div>

Hello ES Team, I am unable to reset my Elasticsearch password. Please find the screenshot below. Please help me out with this.

---

## [Path does not chain with any of the trust anchors](https://discuss.elastic.co/t/path-does-not-chain-with-any-of-the-trust-anchors/322688)

<div class="topic-metadata">

**Author:** [@chris3](https://discuss.elastic.co/u/chris3)\
**Replies:** 3\
**Last updated:** [January 15, 2023, 11:37pm UTC](https://discuss.elastic.co/t/path-does-not-chain-with-any-of-the-trust-anchors/322688 "2023-01-15T23:37:00Z")

</div>

Hi All, Appreciate if you could help. I have tried to follow the elastic documentation here to setup internode communication using certificates: https://www.elastic.co/guide/en/elasticsearch/reference/current/security-…

---

## [I want contribute to kibana](https://discuss.elastic.co/t/i-want-contribute-to-kibana/322845)

<div class="topic-metadata">

**Author:** [@dawn023349](https://discuss.elastic.co/u/dawn023349)\
**Replies:** 7\
**Last updated:** [January 15, 2023, 4:41pm UTC](https://discuss.elastic.co/t/i-want-contribute-to-kibana/322845 "2023-01-15T16:41:02Z")

</div>

I finished installing and testing the Linux version of Kibana. And I forked git repo. But "kibana\\src\\plugins\\data\\target\\public\\data.plugin.js" file did not exist. What should I do?

---

## [CompositeAggregation.aggregateAfter usage](https://discuss.elastic.co/t/compositeaggregation-aggregateafter-usage/323196)

<div class="topic-metadata">

**Author:** [@hmkhitaryan](https://discuss.elastic.co/u/hmkhitaryan)\
**Replies:** 0\
**Last updated:** [January 15, 2023, 11:56am UTC](https://discuss.elastic.co/t/compositeaggregation-aggregateafter-usage/323196 "2023-01-15T11:56:33Z")

</div>

Hello everyone. this is my code, where I want to gain pagination ability, for not getting the whole bucket list and not to overload RAM memory. But anyway, it's unclear to me: what is this actually 'afterKey' for, an…

---

## [Filebeat support required](https://discuss.elastic.co/t/filebeat-support-required/323181)

<div class="topic-metadata">

**Author:** [@Sagar\_Naik](https://discuss.elastic.co/u/Sagar_Naik)\
**Replies:** 13\
**Last updated:** [January 15, 2023, 4:35am UTC](https://discuss.elastic.co/t/filebeat-support-required/323181 "2023-01-15T04:35:53Z")

</div>

getting error : Jan 14 21:30:07 ndc3vmappelk05 filebeat\[2374\]: 2023-01-14T21:30:07.888+0530 ERROR pipeline/output.go:100 Failed to connect to backoff(async(tcp://10.94.241.145:5043)): dial tcp 10.94…

---

## [Help me with logstash config (Feature Request)](https://discuss.elastic.co/t/help-me-with-logstash-config-feature-request/322992)

<div class="topic-metadata">

**Author:** [@Md\_Shariful\_Islam](https://discuss.elastic.co/u/Md_Shariful_Islam)\
**Replies:** 4\
**Last updated:** [January 15, 2023, 5:30am UTC](https://discuss.elastic.co/t/help-me-with-logstash-config-feature-request/322992 "2023-01-15T05:30:36Z")

</div>

I am using logstash aggregate filter and I want timeout value for infinite time. How to do that? Current config for aggregate filter given below if \[src\_ip\] { aggregate { task\_id =\> "%{src\_ip}" …

---

## [Unable to trigger a watcher alert when multiple conditions are met](https://discuss.elastic.co/t/unable-to-trigger-a-watcher-alert-when-multiple-conditions-are-met/319361)

<div class="topic-metadata">

**Author:** [@as-sre](https://discuss.elastic.co/u/as-sre)\
**Replies:** 0\
**Last updated:** [November 20, 2022, 9:40am UTC](https://discuss.elastic.co/t/unable-to-trigger-a-watcher-alert-when-multiple-conditions-are-met/319361 "2022-11-20T09:40:53Z")

</div>

I am trying to implement a logic in watcher to trigger an alert when multiple conditions are met. I have seen a couple of examples where it talks about checking the field ctx.payload.alert.hits.total, but I am sure it is…

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/322433)

<div class="topic-metadata">

**Author:** [@alam02](https://discuss.elastic.co/u/alam02)\
**Replies:** 1\
**Last updated:** [January 15, 2023, 3:09am UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/322433 "2023-01-15T03:09:50Z")

</div>

Hello i have kibana, logstash started but impossible to start elastic.service and i got this error code when i run systemctl start elastic.service. Also on the website i receive this message " kibana is not ready yet". …

---

## [Adding score to SearchHit via REST Template](https://discuss.elastic.co/t/adding-score-to-searchhit-via-rest-template/323154)

<div class="topic-metadata">

**Author:** [@timothystone](https://discuss.elastic.co/u/timothystone)\
**Replies:** 3\
**Last updated:** [January 15, 2023, 3:07am UTC](https://discuss.elastic.co/t/adding-score-to-searchhit-via-rest-template/323154 "2023-01-15T03:07:04Z")

</div>

I'm using a NativeSearchQuery with setTrackScores(true). This query is passed to the ElasticsearchRestTemplate#search(Query, Clazz) (inherited from AbstractElasticsearchTemplate#(Query, Clazz) The Clazz here is a typica…

---

## [Merging fields of two index pattern](https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564)

<div class="topic-metadata">

**Author:** [@random\_dash](https://discuss.elastic.co/u/random_dash)\
**Replies:** 1\
**Last updated:** [October 24, 2022, 2:19pm UTC](https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564 "2022-10-24T14:19:49Z")

</div>

Hi, I have two data streams in Kibana with similar information. I am trying to aggregate them by creating a new index pattern. Each of them has a field "state". For one of them, the state can be \[passed, failed\], and f…

---

## [Field value not found in aggregatable field](https://discuss.elastic.co/t/field-value-not-found-in-aggregatable-field/323182)

<div class="topic-metadata">

**Author:** [@nnet](https://discuss.elastic.co/u/nnet)\
**Replies:** 2\
**Last updated:** [January 14, 2023, 8:40pm UTC](https://discuss.elastic.co/t/field-value-not-found-in-aggregatable-field/323182 "2023-01-14T20:40:16Z")

</div>

Hi folks, I'm at a loss to understand this. ELK stack 5.6. Using filebeat i send json logs of nginx to logstash where they're parsed and fed into elasticsearch. No errors, all seems good. In kibana I have a visualizat…

---

## [Logstash Elasticsearch filter Bad URI Exception](https://discuss.elastic.co/t/logstash-elasticsearch-filter-bad-uri-exception/323176)

<div class="topic-metadata">

**Author:** [@eraste](https://discuss.elastic.co/u/eraste)\
**Replies:** 9\
**Last updated:** [January 14, 2023, 7:02pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-bad-uri-exception/323176 "2023-01-14T19:02:12Z")

</div>

Hello Everyone. I have an exception in Logstash with Elasticsearch filter in the hosts parameter. When i give manually the hosts parameter like this, all thing is good, i don't get error : filter { elasticsearch {…

---

## [Kibana Cavas empty datatable](https://discuss.elastic.co/t/kibana-cavas-empty-datatable/317001)

<div class="topic-metadata">

**Author:** [@Zdeno\_Liska](https://discuss.elastic.co/u/Zdeno_Liska)\
**Replies:** 4\
**Last updated:** [October 24, 2022, 1:46pm UTC](https://discuss.elastic.co/t/kibana-cavas-empty-datatable/317001 "2022-10-24T13:46:48Z")

</div>

Hi, I am facing strange issue. I have created canvas report like below. Anyway, I am getting random icons with exclamation marks, but when I reload data with Alt+R, they randomly disapear and reapear on different metric…

---

## [Print logs into a file before parsing with GROK](https://discuss.elastic.co/t/print-logs-into-a-file-before-parsing-with-grok/323145)

<div class="topic-metadata">

**Author:** [@danishbit09](https://discuss.elastic.co/u/danishbit09)\
**Replies:** 3\
**Last updated:** [January 14, 2023, 5:52pm UTC](https://discuss.elastic.co/t/print-logs-into-a-file-before-parsing-with-grok/323145 "2023-01-14T17:52:15Z")

</div>

Is there any option to store logs into a file before parsing it in GROK. Please suggest. Can I use logger.info() in Filter plugin.

---

## [Elastic Logging Plugin for Docker: is the connection encrypted?](https://discuss.elastic.co/t/elastic-logging-plugin-for-docker-is-the-connection-encrypted/323177)

<div class="topic-metadata">

**Author:** [@kthy](https://discuss.elastic.co/u/kthy)\
**Replies:** 1\
**Last updated:** [January 14, 2023, 4:54pm UTC](https://discuss.elastic.co/t/elastic-logging-plugin-for-docker-is-the-connection-encrypted/323177 "2023-01-14T16:54:51Z")

</div>

This question is about the Elastic Logging Plugin for Docker, which doesn't have it's own category on the Elastic forums as far as I can see, but since it is based on Beats I'm posting here. Apologies if misplaced. My q…

---

## [Load Eland dataframe partially by query](https://discuss.elastic.co/t/load-eland-dataframe-partially-by-query/323180)

<div class="topic-metadata">

**Author:** [@mruiter](https://discuss.elastic.co/u/mruiter)\
**Replies:** 0\
**Last updated:** [January 14, 2023, 2:15pm UTC](https://discuss.elastic.co/t/load-eland-dataframe-partially-by-query/323180 "2023-01-14T14:15:13Z")

</div>

I'm trying to fetch data from Elasticsearch into an Eland dataframe partially, because it takes too much time to load the entire index. The following works, except for the \_query\_compiler. The official Eland docs contai…

---

## [Kibana Iframe Share Issue with Xframe and SameSite Cookie](https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824)

<div class="topic-metadata">

**Author:** [@hidanny](https://discuss.elastic.co/u/hidanny)\
**Replies:** 1\
**Last updated:** [October 24, 2022, 12:49pm UTC](https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824 "2022-10-24T12:49:34Z")

</div>

Hello all, This may be a super dumb question. For reference, I am using latest React and Google Chrome. Also, to note, this is working completely fine in Firefox. Just not in Google Chrome. Essentially, I am trying to …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=665)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=667)
