# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=346

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 347

---

## [JSON parse error, original data now in message field {:message=\>"Could not set field 'original' on object '' to value '{\\"event\\": \\"\\"}'](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-message-could-not-set-field-original-on-object-to-value-event/337740)

<div class="topic-metadata">

**Author:** [@cosmosir](https://discuss.elastic.co/u/cosmosir)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 4:09am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-message-could-not-set-field-original-on-object-to-value-event/337740 "2023-07-06T04:09:53Z")

</div>

logstash8.8.1 JSON parse error, original data now in message field {:message=\>"Could not set field 'original' on object '' to value '{"event": ""}'.This is probably due to trying to set a field like \[foo\]\[bar\] = someVal…

---

## [Elastic Agent - Remove Unused Beats](https://discuss.elastic.co/t/elastic-agent-remove-unused-beats/337726)

<div class="topic-metadata">

**Author:** [@RichardH1](https://discuss.elastic.co/u/RichardH1)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:36pm UTC](https://discuss.elastic.co/t/elastic-agent-remove-unused-beats/337726 "2023-07-05T22:36:44Z")

</div>

Hi, We want to use Elastic Agent for our server deployments but the package size is larger than competing technologies. 90% of our servers just need Metricbeat installed so I'm wondering if we can strip out the other be…

---

## [Search UI - custom checkbox styling issue](https://discuss.elastic.co/t/search-ui-custom-checkbox-styling-issue/337725)

<div class="topic-metadata">

**Author:** [@JeroenAdam](https://discuss.elastic.co/u/JeroenAdam)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:28pm UTC](https://discuss.elastic.co/t/search-ui-custom-checkbox-styling-issue/337725 "2023-07-05T22:28:05Z")

</div>

Hi there, I'm developing an app using search UI and Elasticsearch, great experience so far. I 'm lacking in advanced React skills, I have no idea why my custom styled checkboxes won't reflect the correct state in the UI…

---

## [Adding Uptime Monitors to a Dashboard](https://discuss.elastic.co/t/adding-uptime-monitors-to-a-dashboard/336454)

<div class="topic-metadata">

**Author:** [@mpinto](https://discuss.elastic.co/u/mpinto)\
**Replies:** 5\
**Last updated:** [July 5, 2023, 9:36pm UTC](https://discuss.elastic.co/t/adding-uptime-monitors-to-a-dashboard/336454 "2023-07-05T21:36:19Z")

</div>

Hello, I am creating a few dashboards to monitor our solutions' logs and we have a separate "dashboard" with all our Uptime Monitors. Is there a way to incorporate these uptime monitors in the dashboards we're building? …

---

## [Wildcard search for a word](https://discuss.elastic.co/t/wildcard-search-for-a-word/337718)

<div class="topic-metadata">

**Author:** [@umesh\_choudary](https://discuss.elastic.co/u/umesh_choudary)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 9:03pm UTC](https://discuss.elastic.co/t/wildcard-search-for-a-word/337718 "2023-07-05T21:03:02Z")

</div>

How can i search for a word as contains while searching index. eg: if i search the index using books, i need to get the results which should contain book and books in the response..

---

## [Change Timestamp to event.ingested](https://discuss.elastic.co/t/change-timestamp-to-event-ingested/337498)

<div class="topic-metadata">

**Author:** [@Xenial](https://discuss.elastic.co/u/Xenial)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 8:44pm UTC](https://discuss.elastic.co/t/change-timestamp-to-event-ingested/337498 "2023-07-05T20:44:29Z")

</div>

Hello Elastic Team, Can you help me , i want to change timestamp field to event.ingested on Kibana 8.8 and elasticsearch 8 Thankyou

---

## [Deserializing Avro Records with different schemas](https://discuss.elastic.co/t/deserializing-avro-records-with-different-schemas/337701)

<div class="topic-metadata">

**Author:** [@fine\_porcupine](https://discuss.elastic.co/u/fine_porcupine)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 7:43pm UTC](https://discuss.elastic.co/t/deserializing-avro-records-with-different-schemas/337701 "2023-07-05T19:43:12Z")

</div>

I'm doing the due diligence on the Avro Codec Plugin and I'm wondering if it's possible to use this if there are different types of events in the same SQS queue? For example - SQS Queue contains serialized events with s…

---

## [Kibana: export option for table visualisations](https://discuss.elastic.co/t/kibana-export-option-for-table-visualisations/337592)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 7:38pm UTC](https://discuss.elastic.co/t/kibana-export-option-for-table-visualisations/337592 "2023-07-05T19:38:39Z")

</div>

ES/Kibana version 7.17.1 I want to be able to export data from aggregation table visualisations. I have some existing ones that have an export option: so far as I can tell these are not Lense but the original "Aggre…

---

## [Enrolling elastic-agent, the production-ready way?](https://discuss.elastic.co/t/enrolling-elastic-agent-the-production-ready-way/337697)

<div class="topic-metadata">

**Author:** [@UPPERCASE](https://discuss.elastic.co/u/UPPERCASE)\
**Replies:** 5\
**Last updated:** [July 5, 2023, 7:07pm UTC](https://discuss.elastic.co/t/enrolling-elastic-agent-the-production-ready-way/337697 "2023-07-05T19:07:39Z")

</div>

I want to use Fleet, but I have some doubts about the documented deployment method. I think it would've been better if it was possible to just install the elastic-agent as an RPM/DEB and then configure a yaml file, then …

---

## [Logs are getting parsed in messages field for M365 Defender Logs](https://discuss.elastic.co/t/logs-are-getting-parsed-in-messages-field-for-m365-defender-logs/337698)

<div class="topic-metadata">

**Author:** [@elastic12](https://discuss.elastic.co/u/elastic12)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 4:27pm UTC](https://discuss.elastic.co/t/logs-are-getting-parsed-in-messages-field-for-m365-defender-logs/337698 "2023-07-05T16:27:11Z")

</div>

The issue is with the logs in Microsoft 365 Defender. All of the logs are being stored in a single message field, instead of being stored in individual fields as shown in Elasticsearch documentation. Previously, the logs…

---

## [Stacktrace logged by several lines in kibana](https://discuss.elastic.co/t/stacktrace-logged-by-several-lines-in-kibana/337539)

<div class="topic-metadata">

**Author:** [@ANARAN](https://discuss.elastic.co/u/ANARAN)\
**Replies:** 3\
**Last updated:** [July 5, 2023, 3:59pm UTC](https://discuss.elastic.co/t/stacktrace-logged-by-several-lines-in-kibana/337539 "2023-07-05T15:59:45Z")

</div>

Hello, I'm trying to improve the display of stacktraces for an application I'm working on. Now, the stacktrace look like this : I work with log4j (I know, it's deprecated) and logstash, but not filebeat. How can I…

---

## [Api Search in Python - how to get bad return code](https://discuss.elastic.co/t/api-search-in-python-how-to-get-bad-return-code/337686)

<div class="topic-metadata">

**Author:** [@RickT](https://discuss.elastic.co/u/RickT)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 2:43pm UTC](https://discuss.elastic.co/t/api-search-in-python-how-to-get-bad-return-code/337686 "2023-07-05T14:43:47Z")

</div>

Hi, I'm using the search API running from Python to collect some documents. The request goes well as long as the connection is OK. However, when the connection is timeout, the Python script crashes and i can't used any…

---

## [Installation document for ELK 8.7](https://discuss.elastic.co/t/installation-document-for-elk-8-7/337635)

<div class="topic-metadata">

**Author:** [@SivaPrasadELK](https://discuss.elastic.co/u/SivaPrasadELK)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 1:59pm UTC](https://discuss.elastic.co/t/installation-document-for-elk-8-7/337635 "2023-07-05T13:59:40Z")

</div>

While trying to install the ELK 8.7 and its components such as file beat logstash kibana and Elasticsearch and trying to setup the ELK as below Filebeat =====\> Logstash ======\> elastic =======\>kibana keeping this workf…

---

## [Is it possible to use encrypted elascticsearch instead of direct username, password in Output plugin of logstash?](https://discuss.elastic.co/t/is-it-possible-to-use-encrypted-elascticsearch-instead-of-direct-username-password-in-output-plugin-of-logstash/337647)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 1:24pm UTC](https://discuss.elastic.co/t/is-it-possible-to-use-encrypted-elascticsearch-instead-of-direct-username-password-in-output-plugin-of-logstash/337647 "2023-07-05T13:24:57Z")

</div>

I want to use encrypted elasticsearch, So I don't want to use directly username ,password of elasticsearch in logstash. Please provide the any answers.

---

## [Logstash build from Source failing](https://discuss.elastic.co/t/logstash-build-from-source-failing/337611)

<div class="topic-metadata">

**Author:** [@tejas7](https://discuss.elastic.co/u/tejas7)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 12:58pm UTC](https://discuss.elastic.co/t/logstash-build-from-source-failing/337611 "2023-07-05T12:58:49Z")

</div>

Hello Team , I am trying to build logstash from source code from the main branch. It is failing with the following error: \* Exception is: org.gradle.api.tasks.TaskExecutionException: Execution failed for task ':install…

---

## [Login Elasticsearch and Kibana](https://discuss.elastic.co/t/login-elasticsearch-and-kibana/337661)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 11:14am UTC](https://discuss.elastic.co/t/login-elasticsearch-and-kibana/337661 "2023-07-05T11:14:09Z")

</div>

Hi, Is it possible to generate a token on the elasticsearch API? A sort of login (username/password) and the same on kibana? Currently, there's no such thing on my elasticsearch and kibana instance, and anyone can make…

---

## [Cluster overshard issue](https://discuss.elastic.co/t/cluster-overshard-issue/337603)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 10:22am UTC](https://discuss.elastic.co/t/cluster-overshard-issue/337603 "2023-07-05T10:22:20Z")

</div>

Hi, I have question about how to solve the cluster overshard issue sot that things can get back to normal/ Currently, I am renting 2 node in 2 different zone. And, I've encountered oversharding issue, show in the b…

---

## [Cannot connect to elasticsearch, via functionbeat(using AWS Lambda)](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-via-functionbeat-using-aws-lambda/337657)

<div class="topic-metadata">

**Author:** [@Kavan\_Dalwadi](https://discuss.elastic.co/u/Kavan_Dalwadi)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:42am UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-via-functionbeat-using-aws-lambda/337657 "2023-07-05T10:42:39Z")

</div>

Currently I have deployed Elasticstack (ELK) on AWS EKS and Im using NodePort service for all the application My elasticsearch is running at- 54.2xx.xxx.xxx:30092/ (Which is the public IP address of EC2). I have lamb…

---

## [How to not use Keyword type when importing csv?](https://discuss.elastic.co/t/how-to-not-use-keyword-type-when-importing-csv/337601)

<div class="topic-metadata">

**Author:** [@tavd-projects](https://discuss.elastic.co/u/tavd-projects)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 10:10am UTC](https://discuss.elastic.co/t/how-to-not-use-keyword-type-when-importing-csv/337601 "2023-07-05T10:10:37Z")

</div>

Hello. How to make columns not indexed as Keyword when importing CSV? (I'm using the standard integration, not Logstash). The problem is that I can't seem to change the Keyword to a specific data type in any way. I will …

---

## [When the master node publishes the cluster state, if a certain slave node fails to respond consistently and no timeout is set, does it mean that it will keep waiting and cannot complete?](https://discuss.elastic.co/t/when-the-master-node-publishes-the-cluster-state-if-a-certain-slave-node-fails-to-respond-consistently-and-no-timeout-is-set-does-it-mean-that-it-will-keep-waiting-and-cannot-complete/337595)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 9:47am UTC](https://discuss.elastic.co/t/when-the-master-node-publishes-the-cluster-state-if-a-certain-slave-node-fails-to-respond-consistently-and-no-timeout-is-set-does-it-mean-that-it-will-keep-waiting-and-cannot-complete/337595 "2023-07-05T09:47:35Z")

</div>

I found that when the master node publishes the cluster state, in the second phase, it will wait for all slave nodes to respond (successfully or unsuccessfully) before proceeding with the subsequent process. If a request…

---

## [Change path of data file](https://discuss.elastic.co/t/change-path-of-data-file/337633)

<div class="topic-metadata">

**Author:** [@Hi\_u\_Thu\_n](https://discuss.elastic.co/u/Hi_u_Thu_n)\
**Replies:** 4\
**Last updated:** [July 5, 2023, 9:39am UTC](https://discuss.elastic.co/t/change-path-of-data-file/337633 "2023-07-05T09:39:22Z")

</div>

I change path in file elasticsearch.yml but it not working! # ----------------------------------- Paths ------------------------------------ # # Path to directory where to store the data (separate multiple locations by …

---

## [Can not create update index pipeline without unique identifier in database](https://discuss.elastic.co/t/can-not-create-update-index-pipeline-without-unique-identifier-in-database/337494)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 3\
**Last updated:** [July 5, 2023, 9:31am UTC](https://discuss.elastic.co/t/can-not-create-update-index-pipeline-without-unique-identifier-in-database/337494 "2023-07-05T09:31:05Z")

</div>

Hi all. I want to create an update index using jdbc input and elasticsearch output. I have a left joined table consists of 4 tables in database. But I do not have a unique identifier in db. Therefore I can not create …

---

## [I want to implement automatic user login to a Kibana dashboard from a web application](https://discuss.elastic.co/t/i-want-to-implement-automatic-user-login-to-a-kibana-dashboard-from-a-web-application/337233)

<div class="topic-metadata">

**Author:** [@dilshadpaleri](https://discuss.elastic.co/u/dilshadpaleri)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 9:05am UTC](https://discuss.elastic.co/t/i-want-to-implement-automatic-user-login-to-a-kibana-dashboard-from-a-web-application/337233 "2023-07-05T09:05:55Z")

</div>

I want to implement automatic user login to a Kibana dashboard from a web application. I have successfully enabled x-pack security and attempted to authenticate users through the HTTP header. However, I am facing an issu…

---

## [MongoDB to Elasticsearch?](https://discuss.elastic.co/t/mongodb-to-elasticsearch/336767)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 4\
**Last updated:** [July 5, 2023, 6:40am UTC](https://discuss.elastic.co/t/mongodb-to-elasticsearch/336767 "2023-07-05T06:40:52Z")

</div>

Is there a way to index data from mongoDB to elasticsearch? I've searched a bit but I haven't found any mongodb input on logstash i.e. part of the mongoDB collection by making an aggregation query and then storing the r…

---

## [How to use curl command to input data into logstash](https://discuss.elastic.co/t/how-to-use-curl-command-to-input-data-into-logstash/337615)

<div class="topic-metadata">

**Author:** [@vijeibarthi](https://discuss.elastic.co/u/vijeibarthi)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 6:21am UTC](https://discuss.elastic.co/t/how-to-use-curl-command-to-input-data-into-logstash/337615 "2023-07-05T06:21:16Z")

</div>

Hi All, I have a curl command which works fine but I have trouble using that curl command in the json format. Please guide on how to correct this script to output the data. =============================================…

---

## [Regular expressions in kibana filters](https://discuss.elastic.co/t/regular-expressions-in-kibana-filters/337548)

<div class="topic-metadata">

**Author:** [@SajjanKumarPatea](https://discuss.elastic.co/u/SajjanKumarPatea)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 6:11am UTC](https://discuss.elastic.co/t/regular-expressions-in-kibana-filters/337548 "2023-07-05T06:11:55Z")

</div>

Can you tell me how to filter messages in indexes correctly? I am filtering messages by a specific field. And I want to see messages only with this value in the field: id-nmap100-tapic-prod But I also get messages wit…

---

## [Can I use "from/size", "timeout", "track\_total\_hits", "format", etc. for free?](https://discuss.elastic.co/t/can-i-use-from-size-timeout-track-total-hits-format-etc-for-free/337523)

<div class="topic-metadata">

**Author:** [@kimjinyoung](https://discuss.elastic.co/u/kimjinyoung)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 11:46pm UTC](https://discuss.elastic.co/t/can-i-use-from-size-timeout-track-total-hits-format-etc-for-free/337523 "2023-07-04T23:46:30Z")

</div>

hi thank for watching Can I use "from/size", "timeout", "track\_total\_hits", "format", etc. for free? "When I looked it up on the following site, I found that "from/size", "timeout"," "track\_total\_hits" and "format" be…

---

## [Strategy for matching unstructured text to phrases in index](https://discuss.elastic.co/t/strategy-for-matching-unstructured-text-to-phrases-in-index/337583)

<div class="topic-metadata">

**Author:** [@rustunooldu](https://discuss.elastic.co/u/rustunooldu)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 7:39pm UTC](https://discuss.elastic.co/t/strategy-for-matching-unstructured-text-to-phrases-in-index/337583 "2023-07-04T19:39:59Z")

</div>

I'm trying to extract data from product descriptions, and I have the catalog data indexed and categorized. For example, I have a color name index (that contains all possible colors for the product), and I want to be able…

---

## [Bitdefender GravityZone and Logstash Integration](https://discuss.elastic.co/t/bitdefender-gravityzone-and-logstash-integration/337582)

<div class="topic-metadata">

**Author:** [@Paulo\_Martins\_de\_Sen](https://discuss.elastic.co/u/Paulo_Martins_de_Sen)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 5:24pm UTC](https://discuss.elastic.co/t/bitdefender-gravityzone-and-logstash-integration/337582 "2023-07-04T17:24:48Z")

</div>

Hey guys, has anyone done Bitdefender GravityZone and Elastic Security integration? I'm trying to do it through agent elastic, but without success so far.

---

## [Logstash @timestamp not including milliseconds](https://discuss.elastic.co/t/logstash-timestamp-not-including-milliseconds/337579)

<div class="topic-metadata">

**Author:** [@Anthony\_Zottola](https://discuss.elastic.co/u/Anthony_Zottola)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 4:17pm UTC](https://discuss.elastic.co/t/logstash-timestamp-not-including-milliseconds/337579 "2023-07-04T16:17:08Z")

</div>

All of my logs have this format "@timestamp" =\> 2023-07-04T15:40:19.000Z where the milliseconds are missing, is there any way to make it included the milliseconds. I tried manually adding it but it is read only. My con…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=345)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=347)
