# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [About the Elastic Stack category](https://discuss.elastic.co/t/about-the-elastic-stack-category/235254)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [June 1, 2020, 11:57pm UTC](https://discuss.elastic.co/t/about-the-elastic-stack-category/235254 "2020-06-01T23:57:55Z")

</div>

Meet the core products — all free and open Elasticsearch, Kibana, Beats, and Logstash - also known as the ELK Stack. Reliably and securely take data from any source, in any format, then search, analyze, and visualize it …

---

## [Elasticsearch Sometimes Returns Incomplete Search Results From My Website Even Though the Documents Are Indexed](https://discuss.elastic.co/t/elasticsearch-sometimes-returns-incomplete-search-results-from-my-website-even-though-the-documents-are-indexed/390803)

<div class="topic-metadata">

**Author:** [@joeroot](https://discuss.elastic.co/u/joeroot)\
**Replies:** 1\
**Last updated:** [October 2, 2026, 9:33am UTC](https://discuss.elastic.co/t/elasticsearch-sometimes-returns-incomplete-search-results-from-my-website-even-though-the-documents-are-indexed/390803 "2026-10-02T09:33:10Z")

</div>

Hi All, I am having an issue with Elasticsearch on my website where search requests sometimes return incomplete results even though the relevant documents are already present in the Elasticsearch index. The website uses…

---

## [Elasticsearch Netflow Top-N dashboard showing data in bytes instead of MB.GB etc](https://discuss.elastic.co/t/elasticsearch-netflow-top-n-dashboard-showing-data-in-bytes-instead-of-mb-gb-etc/390772)

<div class="topic-metadata">

**Author:** [@ahsan0331](https://discuss.elastic.co/u/ahsan0331)\
**Replies:** 2\
**Last updated:** [October 2, 2026, 7:59am UTC](https://discuss.elastic.co/t/elasticsearch-netflow-top-n-dashboard-showing-data-in-bytes-instead-of-mb-gb-etc/390772 "2026-10-02T07:59:56Z")

</div>

Hi i have upgraded "or so to speak" from filebeat netflow module to elastic netflow fleet based. And while i see its dashboards are somewhat good compared to the filebeat ones. but one dashboard that i used a lot in fil…

---

## [Kibana Alert Email - URL broken in SMTP email notifications](https://discuss.elastic.co/t/kibana-alert-email-url-broken-in-smtp-email-notifications/390797)

<div class="topic-metadata">

**Author:** [@Omar2](https://discuss.elastic.co/u/Omar2)\
**Replies:** 2\
**Last updated:** [October 2, 2026, 7:56am UTC](https://discuss.elastic.co/t/kibana-alert-email-url-broken-in-smtp-email-notifications/390797 "2026-10-02T07:56:01Z")

</div>

Hello, I'm experiencing an issue with Kibana alert emails sent through an SMTP connector. Kibana version: 9.4.3 Alert message: La règle Kibana {{rule.name}} s'est déclenchée: Nombre d'erreurs : {{context.value}} …

---

## [How do you verify that an eland-imported tree model matches the original?](https://discuss.elastic.co/t/how-do-you-verify-that-an-eland-imported-tree-model-matches-the-original/390787)

<div class="topic-metadata">

**Author:** [@Milivoje\_Simonovic](https://discuss.elastic.co/u/Milivoje_Simonovic)\
**Replies:** 1\
**Last updated:** [October 1, 2026, 1:34am UTC](https://discuss.elastic.co/t/how-do-you-verify-that-an-eland-imported-tree-model-matches-the-original/390787 "2026-10-01T01:34:37Z")

</div>

Hi, Laura Trotta at Elastic suggested I post this here. When eland imports an XGBoost, LightGBM or scikit-learn model into Elasticsearch, what Elasticsearch runs is a converted copy of the trained model. I am curious h…

---

## [Missing Export button for custom role despite enabling "Generate PDF or PNG report" privilege (v8.19.11)](https://discuss.elastic.co/t/missing-export-button-for-custom-role-despite-enabling-generate-pdf-or-png-report-privilege-v8-19-11/390775)

<div class="topic-metadata">

**Author:** [@WANASANAN815](https://discuss.elastic.co/u/WANASANAN815)\
**Replies:** 1\
**Last updated:** [October 1, 2026, 12:02am UTC](https://discuss.elastic.co/t/missing-export-button-for-custom-role-despite-enabling-generate-pdf-or-png-report-privilege-v8-19-11/390775 "2026-10-01T00:02:38Z")

</div>

Hi everyone, I’m currently having an issue creating a custom role in Elastic SIEM. I am trying to create a role that allows users to export dashboards as PDFs. Environment: Elastic Version: 8.19.11 License: Enter…

---

## [Missing Export button for custom role despite enabling "Generate PDF or PNG report" privilege (v8.19.11)](https://discuss.elastic.co/t/missing-export-button-for-custom-role-despite-enabling-generate-pdf-or-png-report-privilege-v8-19-11/390774)

<div class="topic-metadata">

**Author:** [@WANASANAN815](https://discuss.elastic.co/u/WANASANAN815)\
**Replies:** 1\
**Last updated:** [September 30, 2026, 2:25pm UTC](https://discuss.elastic.co/t/missing-export-button-for-custom-role-despite-enabling-generate-pdf-or-png-report-privilege-v8-19-11/390774 "2026-09-30T14:25:19Z")

</div>

Hi everyone, I’m currently having an issue creating a custom role in Elastic SIEM. I am trying to create a role that allows users to export dashboards as PDFs. Environment: Elastic Version: 8.19.11 License: Enter…

---

## [Downsampling non-dimension labels to last value is misleading](https://discuss.elastic.co/t/downsampling-non-dimension-labels-to-last-value-is-misleading/390779)

<div class="topic-metadata">

**Author:** [@pmcc](https://discuss.elastic.co/u/pmcc)\
**Replies:** 0\
**Last updated:** [September 30, 2026, 11:36am UTC](https://discuss.elastic.co/t/downsampling-non-dimension-labels-to-last-value-is-misleading/390779 "2026-09-30T11:36:22Z")

</div>

I'm upgrading from v7 to 9.5 - lots of great new features! For my application, TSDS look ideal, and downsampling will be a major improvement. There appears to be one flaw with downsampling for my use cases. Keyword fiel…

---

## [Support for metrics for kafka consumer group using new Consumer Rebalance Protocol](https://discuss.elastic.co/t/support-for-metrics-for-kafka-consumer-group-using-new-consumer-rebalance-protocol/390766)

<div class="topic-metadata">

**Author:** [@rakesh.iitism95](https://discuss.elastic.co/u/rakesh.iitism95)\
**Replies:** 0\
**Last updated:** [September 29, 2026, 8:29pm UTC](https://discuss.elastic.co/t/support-for-metrics-for-kafka-consumer-group-using-new-consumer-rebalance-protocol/390766 "2026-09-29T20:29:36Z")

</div>

We are currently using elastic agent to collect kafka consumer group metric. After a consumer group was configured to use the new consumer rebalance protocol available in Kafka 4.0 , the agent was not collecting the metr…

---

## [CISA KEV integration upgrade to 1.10](https://discuss.elastic.co/t/cisa-kev-integration-upgrade-to-1-10/388850)

<div class="topic-metadata">

**Author:** [@rklee](https://discuss.elastic.co/u/rklee)\
**Replies:** 1\
**Last updated:** [September 29, 2026, 7:59pm UTC](https://discuss.elastic.co/t/cisa-kev-integration-upgrade-to-1-10/388850 "2026-09-29T19:59:16Z")

</div>

So I was on a CISA KEV integration before version 1.7. I upgraded it to 1.10 and vulnerability reports are not coming in anymore. The integration says to re-enter configuration details and re-enable the package. However …

---

## [Filebeat postgresql log module produces timestamp fields that are not indexable when using ECS](https://discuss.elastic.co/t/filebeat-postgresql-log-module-produces-timestamp-fields-that-are-not-indexable-when-using-ecs/390640)

<div class="topic-metadata">

**Author:** [@kriller](https://discuss.elastic.co/u/kriller)\
**Replies:** 3\
**Last updated:** [September 29, 2026, 1:41pm UTC](https://discuss.elastic.co/t/filebeat-postgresql-log-module-produces-timestamp-fields-that-are-not-indexable-when-using-ecs/390640 "2026-09-29T13:41:32Z")

</div>

When using the ingest-pipeline that filebeat creates for postgresql logs, the resulting event contains the field postgresql.log.timestamp which conflicts with the ecs@mappings component template. The filebeat-9.5.4-post…

---

## [The impact of /etc/timezone on the ES cluster](https://discuss.elastic.co/t/the-impact-of-etc-timezone-on-the-es-cluster/390756)

<div class="topic-metadata">

**Author:** [@mloine](https://discuss.elastic.co/u/mloine)\
**Replies:** 1\
**Last updated:** [September 29, 2026, 12:25pm UTC](https://discuss.elastic.co/t/the-impact-of-etc-timezone-on-the-es-cluster/390756 "2026-09-29T12:25:39Z")

</div>

I'm facing a situation now: There are two batches of nodes in an ES cluster. One batch loads 'user.timezone=Asia/Bangkok' from etc/timezone at startup, while the other batch loads 'user.timezone=America/Bogota'. Even tho…

---

## [Capture Elasticsearch diagnostics](https://discuss.elastic.co/t/capture-elasticsearch-diagnostics/390628)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 2\
**Last updated:** [September 28, 2026, 7:19am UTC](https://discuss.elastic.co/t/capture-elasticsearch-diagnostics/390628 "2026-09-28T07:19:28Z")

</div>

Hi there, very soon I am going to purchase elastic licence. In a prior company I had also elastic licences and was used to use the Elasticsearch diagnostics script by the support to collect cluster health parameters. M…

---

## [Logstash at Tenant end or server end?](https://discuss.elastic.co/t/logstash-at-tenant-end-or-server-end/390608)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [September 25, 2026, 10:59pm UTC](https://discuss.elastic.co/t/logstash-at-tenant-end-or-server-end/390608 "2026-09-25T22:59:52Z")

</div>

I’m trying to design an architecture where multiple tenants ingest their logs into Elastic. My understanding is that if the requirement is primarily log collection, I can use Elastic Agent, and if additional enrichment,…

---

## [Time picker in ES|QL query - esql](https://discuss.elastic.co/t/time-picker-in-es-ql-query-esql/390631)

<div class="topic-metadata">

**Author:** [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Replies:** 2\
**Last updated:** [September 25, 2026, 1:55pm UTC](https://discuss.elastic.co/t/time-picker-in-es-ql-query-esql/390631 "2026-09-25T13:55:30Z")

</div>

Hi community, I was wondering about a weird behaviour that might catch some people off-guard. How does the time picker affect ES|QL searches? For example the following query implies a 24-hour search, but yet the data d…

---

## [Filebeat performance, 430 containers](https://discuss.elastic.co/t/filebeat-performance-430-containers/390622)

<div class="topic-metadata">

**Author:** [@zerkms](https://discuss.elastic.co/u/zerkms)\
**Replies:** 0\
**Last updated:** [September 24, 2026, 5:18am UTC](https://discuss.elastic.co/t/filebeat-performance-430-containers/390622 "2026-09-24T05:18:13Z")

</div>

I'm migrating from quite an old ES+fluentbit configuration (logging solution for a small kubernetes cluster). And this is quite simple yet inefficient (?) config I came up with (this file is generated by ECK using the B…

---

## [ILM unable to delete old index since upgrade to 8.19.20](https://discuss.elastic.co/t/ilm-unable-to-delete-old-index-since-upgrade-to-8-19-20/390601)

<div class="topic-metadata">

**Author:** [@numpty-boy](https://discuss.elastic.co/u/numpty-boy)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 8:58am UTC](https://discuss.elastic.co/t/ilm-unable-to-delete-old-index-since-upgrade-to-8-19-20/390601 "2026-09-23T08:58:47Z")

</div>

Morning Team, Since upgrading to 8.19.20, I've started getting these errors: policy \[.fleet-actions-results-ilm-policy\] for index \[.ds-.fleet-actions-results-2026.05.02-000014\] on an error step due to a transient error…

---

## [Field formatters in ES|QL table panels](https://discuss.elastic.co/t/field-formatters-in-es-ql-table-panels/390418)

<div class="topic-metadata">

**Author:** [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Replies:** 1\
**Last updated:** [September 23, 2026, 8:07am UTC](https://discuss.elastic.co/t/field-formatters-in-es-ql-table-panels/390418 "2026-09-23T08:07:19Z")

</div>

Hi! We have started to use ES|QL a lot in our Kibana dashboards, and I love the flexibility it brings! One of the few missing features compared to Lens table panels is to set formatting on a text/keyword field. F ex a l…

---

## [Integration-level Outputs](https://discuss.elastic.co/t/integration-level-outputs/390582)

<div class="topic-metadata">

**Author:** [@jameswiggins](https://discuss.elastic.co/u/jameswiggins)\
**Replies:** 3\
**Last updated:** [September 22, 2026, 8:17pm UTC](https://discuss.elastic.co/t/integration-level-outputs/390582 "2026-09-22T20:17:35Z")

</div>

I'm trying to determine how to configure integration-level outputs: Set integration-level outputs | Elastic Docs I followed the instructions for configuring, but do not see the option. Can someone share a screenshot of…

---

## [Kibana 9 - Detail pane is a bad replacement for Expandable row for my use cases](https://discuss.elastic.co/t/kibana-9-detail-pane-is-a-bad-replacement-for-expandable-row-for-my-use-cases/390555)

<div class="topic-metadata">

**Author:** [@poifir](https://discuss.elastic.co/u/poifir)\
**Replies:** 0\
**Last updated:** [September 21, 2026, 12:00pm UTC](https://discuss.elastic.co/t/kibana-9-detail-pane-is-a-bad-replacement-for-expandable-row-for-my-use-cases/390555 "2026-09-21T12:00:16Z")

</div>

In Kibana 8 we continued to use the "old" UI that offered to expand each row individually to show it's detail values. This works good as the full width of the windows is also available to the detailed attributes and so …

---

## [Kibana 9 - Detail dialog also shows "Truncated string" as configured for the overview](https://discuss.elastic.co/t/kibana-9-detail-dialog-also-shows-truncated-string-as-configured-for-the-overview/390551)

<div class="topic-metadata">

**Author:** [@poifir](https://discuss.elastic.co/u/poifir)\
**Replies:** 0\
**Last updated:** [September 21, 2026, 11:49am UTC](https://discuss.elastic.co/t/kibana-9-detail-dialog-also-shows-truncated-string-as-configured-for-the-overview/390551 "2026-09-21T11:49:22Z")

</div>

In the new Kibana 9 UI it's possible to customize the column visualization with "Edit data view field". This allows to e.g. enable to truncate a field to the first x characters so it only needs a reasonable size i…

---

## [Kibana Dark Theme Now Blue?](https://discuss.elastic.co/t/kibana-dark-theme-now-blue/377919)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 4\
**Last updated:** [September 21, 2026, 9:26am UTC](https://discuss.elastic.co/t/kibana-dark-theme-now-blue/377919 "2026-09-21T09:26:32Z")

</div>

In Kibana versions up to 8.18.1, the dark theme was black, just as with almost all other software I have used that offers a dark theme. I just upgraded my company's DEV cluster, as well as my home cluster, to 9.0.1, and …

---

## [SAN required in cert?](https://discuss.elastic.co/t/san-required-in-cert/390541)

<div class="topic-metadata">

**Author:** [@rik](https://discuss.elastic.co/u/rik)\
**Replies:** 2\
**Last updated:** [September 20, 2026, 7:06pm UTC](https://discuss.elastic.co/t/san-required-in-cert/390541 "2026-09-20T19:06:49Z")

</div>

I am trying to use an ES service from a remote machine, using the cert copied from the container: podman cp app:/usr/share/elasticsearch/config/certs But simply doing a client.info() I am getting a elastic\_transport.Co…

---

## [java.nio.file.NoSuchFileException: /usr/share/elasticsearch/data/\_state/\_pu2t.cfs](https://discuss.elastic.co/t/java-nio-file-nosuchfileexception-usr-share-elasticsearch-data-state-pu2t-cfs/390250)

<div class="topic-metadata">

**Author:** [@TheJ](https://discuss.elastic.co/u/TheJ)\
**Replies:** 15\
**Last updated:** [September 19, 2026, 6:07pm UTC](https://discuss.elastic.co/t/java-nio-file-nosuchfileexception-usr-share-elasticsearch-data-state-pu2t-cfs/390250 "2026-09-19T18:07:12Z")

</div>

Hi, I have a problem with one of my elasticsearch node. For some reason node was shutdown due to some error. When I look into the log, I get the error java.nio.file.NoSuchFileException: /usr/share/elasticsearch/data/\_st…

---

## [Kibana error](https://discuss.elastic.co/t/kibana-error/390521)

<div class="topic-metadata">

**Author:** [@vanhung0709](https://discuss.elastic.co/u/vanhung0709)\
**Replies:** 1\
**Last updated:** [September 18, 2026, 4:17am UTC](https://discuss.elastic.co/t/kibana-error/390521 "2026-09-18T04:17:51Z")

</div>

I have set up elasticsearch and kibana. All steps have been done. Although i can curl es from kibana pod, kibana doesn’t put request to create index .kibana. When searching logs in pod kibana, it loop curl get nodes, but…

---

## [Upgrade from 7.17.9 to 8.19.18 to 9.4.3](https://discuss.elastic.co/t/upgrade-from-7-17-9-to-8-19-18-to-9-4-3/390473)

<div class="topic-metadata">

**Author:** [@sundar.s](https://discuss.elastic.co/u/sundar.s)\
**Replies:** 4\
**Last updated:** [September 17, 2026, 10:17am UTC](https://discuss.elastic.co/t/upgrade-from-7-17-9-to-8-19-18-to-9-4-3/390473 "2026-09-17T10:17:24Z")

</div>

Hi Team, I am trying to run upgrades on a dockerized ES environment. With indices created in 7.17.9, I am able to successfuly migrate to 8.19.18, by just bringing up a new container of ES 8.19.18 pointing to the same v…

---

## [Kibana 8.17.3 – Malware Detection of security\_labs Knowledge Base File (TROJ\_FRS.VSNTIA26)](https://discuss.elastic.co/t/kibana-8-17-3-malware-detection-of-security-labs-knowledge-base-file-troj-frs-vsntia26/390482)

<div class="topic-metadata">

**Author:** [@shiva3](https://discuss.elastic.co/u/shiva3)\
**Replies:** 0\
**Last updated:** [September 16, 2026, 10:21pm UTC](https://discuss.elastic.co/t/kibana-8-17-3-malware-detection-of-security-labs-knowledge-base-file-troj-frs-vsntia26/390482 "2026-09-16T22:21:06Z")

</div>

Hello Elastic Team, We are investigating a security alert involving the Kibana 8.17.3 Docker image deployed in our OpenShift environment. Our endpoint security product detected the following file as: Detection: TROJ\_F…

---

## [Filebeat with Salesforce input and batch](https://discuss.elastic.co/t/filebeat-with-salesforce-input-and-batch/390433)

<div class="topic-metadata">

**Author:** [@stephaniearce](https://discuss.elastic.co/u/stephaniearce)\
**Replies:** 1\
**Last updated:** [September 16, 2026, 5:59pm UTC](https://discuss.elastic.co/t/filebeat-with-salesforce-input-and-batch/390433 "2026-09-16T17:59:51Z")

</div>

Can anyone explain why I'm running into this issue? I copied the exact config from the docs here: Salesforce input | Beats Salesforce input: object.batch.enabled: true fails with "map has no entry for key batch\_start\_ti…

---

## [POSTFIX Ingest and the future of Logstash](https://discuss.elastic.co/t/postfix-ingest-and-the-future-of-logstash/390279)

<div class="topic-metadata">

**Author:** [@RalphDibney](https://discuss.elastic.co/u/RalphDibney)\
**Replies:** 6\
**Last updated:** [September 16, 2026, 12:40pm UTC](https://discuss.elastic.co/t/postfix-ingest-and-the-future-of-logstash/390279 "2026-09-16T12:40:22Z")

</div>

We have a mail gateway based on Postfix, and we want to get these logs into Elastic. For our product, our MSP that helps us with it has a logstash based integration that is also merges the mutliline log of postfix to on…

---

## [Unhealthy EDOT/OTEL Collector in Agent 9.4.x](https://discuss.elastic.co/t/unhealthy-edot-otel-collector-in-agent-9-4-x/388928)

<div class="topic-metadata">

**Author:** [@DavidA](https://discuss.elastic.co/u/DavidA)\
**Replies:** 1\
**Last updated:** [September 15, 2026, 7:09pm UTC](https://discuss.elastic.co/t/unhealthy-edot-otel-collector-in-agent-9-4-x/388928 "2026-09-15T19:09:34Z")

</div>

Environment: Elastic Agent / EDOT: 9.4.4 (build baed89504b1a1c0a7642d60dc0b6c1b0eb34f100, elastic-otel-collector service.version 9.4.4) OS: Ubuntu 24.04 (HP thin client) Fleet-managed, policy "Thin Client" Agent runtim…

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=1)
