# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=297

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 298

---

## [Filter the Nth serial numbers with highest count](https://discuss.elastic.co/t/filter-the-nth-serial-numbers-with-highest-count/354002)

<div class="topic-metadata">

**Author:** [@robertomzc](https://discuss.elastic.co/u/robertomzc)\
**Replies:** 2\
**Last updated:** [February 26, 2024, 12:30pm UTC](https://discuss.elastic.co/t/filter-the-nth-serial-numbers-with-highest-count/354002 "2024-02-26T12:30:57Z")

</div>

Hi all! I am trying to do a scatter plot with Vega-Lite that shows the evolution of capacity of some batteries with time. The colors in the plot should correspond to the different batteries (serial number). Find below a…

---

## [Elastic stack change from GCP to AWS](https://discuss.elastic.co/t/elastic-stack-change-from-gcp-to-aws/354098)

<div class="topic-metadata">

**Author:** [@Vilius\_Dudenas](https://discuss.elastic.co/u/Vilius_Dudenas)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 11:52am UTC](https://discuss.elastic.co/t/elastic-stack-change-from-gcp-to-aws/354098 "2024-02-26T11:52:09Z")

</div>

Hey, I am currently investigating what would be the best approach to migrate current deployment from GCP to AWS. As I see snapshots are tied to the provider and it does not allow me to restore on another provider (prob…

---

## [Alerts configuration via mail through KIBANA](https://discuss.elastic.co/t/alerts-configuration-via-mail-through-kibana/354118)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 11:41am UTC](https://discuss.elastic.co/t/alerts-configuration-via-mail-through-kibana/354118 "2024-02-26T11:41:00Z")

</div>

We are using Free Install of KIBANA. Is it possible to create email alert for logs in elasticsearch and how can i configure it in KIBANA UI .

---

## [Snapshot name from original index name as a suffix](https://discuss.elastic.co/t/snapshot-name-from-original-index-name-as-a-suffix/353353)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [February 26, 2024, 11:08am UTC](https://discuss.elastic.co/t/snapshot-name-from-original-index-name-as-a-suffix/353353 "2024-02-26T11:08:00Z")

</div>

Hi Is it possible to make configuration for shift the name from original index to snapshot name? I need such config because many of index are generate with name in date order so I want to know which one index has snapsh…

---

## [Elastic Search curator not working](https://discuss.elastic.co/t/elastic-search-curator-not-working/354114)

<div class="topic-metadata">

**Author:** [@Akash\_Rai](https://discuss.elastic.co/u/Akash_Rai)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 10:42am UTC](https://discuss.elastic.co/t/elastic-search-curator-not-working/354114 "2024-02-26T10:42:34Z")

</div>

Hi , I am trying to install elastisearch -curator but its not working. kind: CronJob metadata: name: curator labels: app: curator spec: schedule: "\* \* \* \* \*" successfulJobsHistoryLimit: 1 failedJobsHistoryLimit…

---

## [Datastream under a policy behaving unstable](https://discuss.elastic.co/t/datastream-under-a-policy-behaving-unstable/353144)

<div class="topic-metadata">

**Author:** [@Mubolio](https://discuss.elastic.co/u/Mubolio)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 10:35am UTC](https://discuss.elastic.co/t/datastream-under-a-policy-behaving-unstable/353144 "2024-02-26T10:35:55Z")

</div>

Hello, I have a datastream that should keep data only for the latest 15 days, documents that are older than 15 days will be deleted(based on the @timestamp field). This is the index template attached to the datastream: …

---

## [Python client multisearch with different fields weights](https://discuss.elastic.co/t/python-client-multisearch-with-different-fields-weights/354064)

<div class="topic-metadata">

**Author:** [@Marco\_Solari](https://discuss.elastic.co/u/Marco_Solari)\
**Replies:** 5\
**Last updated:** [February 26, 2024, 10:13am UTC](https://discuss.elastic.co/t/python-client-multisearch-with-different-fields-weights/354064 "2024-02-26T10:13:05Z")

</div>

I'm quite new to elasticsearch... I created my first index (to be used for italian language), and basic search functionality, for my cooking recipes database. I now am trying to implement some more advanced search feat…

---

## [ECK : can't have green elasticsearch cluster](https://discuss.elastic.co/t/eck-cant-have-green-elasticsearch-cluster/354106)

<div class="topic-metadata">

**Author:** [@Bobflyer](https://discuss.elastic.co/u/Bobflyer)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 9:55am UTC](https://discuss.elastic.co/t/eck-cant-have-green-elasticsearch-cluster/354106 "2024-02-26T09:55:40Z")

</div>

Hello, I try to deploy an elasticsearch cluster on my docker-desktop kubernetes test cluster. The final goal is to deploy it in a k3s cluster on my raspberry pies. Here my kubernetes manifest : apiVersion: elasticsear…

---

## [Elastic Search UI - Adding filter returns all results](https://discuss.elastic.co/t/elastic-search-ui-adding-filter-returns-all-results/354095)

<div class="topic-metadata">

**Author:** [@jackfrost](https://discuss.elastic.co/u/jackfrost)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 8:11am UTC](https://discuss.elastic.co/t/elastic-search-ui-adding-filter-returns-all-results/354095 "2024-02-26T08:11:21Z")

</div>

Hey All. I am use Elasticsearch ui with the @elastic/search-ui-elasticsearch-connector. I currently have the search up and running. I am able to do a search for something like a name, and get one exact result back. All …

---

## [Connect Git to ELK](https://discuss.elastic.co/t/connect-git-to-elk/353954)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 4\
**Last updated:** [February 26, 2024, 7:11am UTC](https://discuss.elastic.co/t/connect-git-to-elk/353954 "2024-02-26T07:11:47Z")

</div>

Hi, im trying to export all the saved object to insert all object inside a repository. Someone know if is possible connect kibana and git in easier way? Thanks in advance

---

## [\[mysql\]queries cannot be logged](https://discuss.elastic.co/t/mysql-queries-cannot-be-logged/354087)

<div class="topic-metadata">

**Author:** [@h32309](https://discuss.elastic.co/u/h32309)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 6:55am UTC](https://discuss.elastic.co/t/mysql-queries-cannot-be-logged/354087 "2024-02-26T06:55:52Z")

</div>

When the query field contains a type of DOUBLE, the query cannot be logged.

---

## [The number of my es's file descriptor keep growing,I need help](https://discuss.elastic.co/t/the-number-of-my-ess-file-descriptor-keep-growing-i-need-help/354080)

<div class="topic-metadata">

**Author:** [@SKYWALKER-STAR](https://discuss.elastic.co/u/SKYWALKER-STAR)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 5:55am UTC](https://discuss.elastic.co/t/the-number-of-my-ess-file-descriptor-keep-growing-i-need-help/354080 "2024-02-26T05:55:50Z")

</div>

The number of my es's file descriptor keep growing.How can i reduce the my file descriptor number used by my es cluster.

---

## [Trying to visulaize the working of a dead letter queue but getting error while creating index](https://discuss.elastic.co/t/trying-to-visulaize-the-working-of-a-dead-letter-queue-but-getting-error-while-creating-index/354078)

<div class="topic-metadata">

**Author:** [@Karan37](https://discuss.elastic.co/u/Karan37)\
**Replies:** 2\
**Last updated:** [February 26, 2024, 5:46am UTC](https://discuss.elastic.co/t/trying-to-visulaize-the-working-of-a-dead-letter-queue-but-getting-error-while-creating-index/354078 "2024-02-26T05:46:23Z")

</div>

This is my logstash configuration input { file{ path =\> "C:\\Elastic Stack\\logstash-8.12.0\\config\\sample-data-dlq.json" start\_position =\> "beginning" sincedb\_path =\> "NUL" codec =\> "json" } } filter{ …

---

## [Elastic Search is getting restarted by few second time period -- Sowing Kibana server is not ready yet](https://discuss.elastic.co/t/elastic-search-is-getting-restarted-by-few-second-time-period-sowing-kibana-server-is-not-ready-yet/353863)

<div class="topic-metadata">

**Author:** [@dinakar](https://discuss.elastic.co/u/dinakar)\
**Replies:** 2\
**Last updated:** [February 26, 2024, 5:07am UTC](https://discuss.elastic.co/t/elastic-search-is-getting-restarted-by-few-second-time-period-sowing-kibana-server-is-not-ready-yet/353863 "2024-02-26T05:07:54Z")

</div>

I tried to resatrt the Kibana and the elasticsearch for renewing the certificate of server, after I'm facing the following error. Appreciate if anyone provide the solution for the same ASAP. \* Kibana logs, Caused by: ki…

---

## [ILM Policy on No alias](https://discuss.elastic.co/t/ilm-policy-on-no-alias/354077)

<div class="topic-metadata">

**Author:** [@Suresh\_Ghatuwa](https://discuss.elastic.co/u/Suresh_Ghatuwa)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 4:11am UTC](https://discuss.elastic.co/t/ilm-policy-on-no-alias/354077 "2024-02-26T04:11:34Z")

</div>

Hello, I am trying to implement the ILM policy on index not having an alias. ILM policy need to be trigger on removing an alias from index immediately. Could you please suggest if that is possible ? Thanks in advance. …

---

## [Dynamic way of building aggregation query using java api client](https://discuss.elastic.co/t/dynamic-way-of-building-aggregation-query-using-java-api-client/353946)

<div class="topic-metadata">

**Author:** [@prasad.ram1431](https://discuss.elastic.co/u/prasad.ram1431)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 3:48am UTC](https://discuss.elastic.co/t/dynamic-way-of-building-aggregation-query-using-java-api-client/353946 "2024-02-26T03:48:23Z")

</div>

Hi Team, Can someone please help with sample code to create aggregate query dynamically based on the given list of fields using Elasticsearch Java API Client. Unfortunately I couldn't get much documentation help on this…

---

## [Issue with Elasticsearch Cluster](https://discuss.elastic.co/t/issue-with-elasticsearch-cluster/354075)

<div class="topic-metadata">

**Author:** [@Jimmy\_Wang](https://discuss.elastic.co/u/Jimmy_Wang)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 3:28am UTC](https://discuss.elastic.co/t/issue-with-elasticsearch-cluster/354075 "2024-02-26T03:28:43Z")

</div>

Hello, I am currently setting up an Elasticsearch cluster with three nodes and encountering an issue with cluster formation. Here's the setup: elastic01: 10G network interface with VLAN configured, able to join the clu…

---

## [Dynamic template copy\_to does not work with flattened type](https://discuss.elastic.co/t/dynamic-template-copy-to-does-not-work-with-flattened-type/354026)

<div class="topic-metadata">

**Author:** [@s.moran](https://discuss.elastic.co/u/s.moran)\
**Replies:** 1\
**Last updated:** [February 25, 2024, 11:36pm UTC](https://discuss.elastic.co/t/dynamic-template-copy-to-does-not-work-with-flattened-type/354026 "2024-02-25T23:36:16Z")

</div>

I have a field of flattened type that contains a subfield that I want to do numeric range searches on. I am trying to use a dynamic template to copy the field's value to a top level field that I can use for range queries…

---

## [Kibana inaccessible](https://discuss.elastic.co/t/kibana-inaccessible/354056)

<div class="topic-metadata">

**Author:** [@eloi-gn](https://discuss.elastic.co/u/eloi-gn)\
**Replies:** 5\
**Last updated:** [February 25, 2024, 9:30pm UTC](https://discuss.elastic.co/t/kibana-inaccessible/354056 "2024-02-25T21:30:42Z")

</div>

Hello, I set up a k3s cluster using ubuntu. I want to install ELK on my cluster. So I installed elasticsearch and Kibana with the Debian package in version 7.6.1. I left the elastic and Kibana configuration as default. f…

---

## [ES|QL CIDR\_MATCH not working (or more likely I'm doing something wrong)?](https://discuss.elastic.co/t/es-ql-cidr-match-not-working-or-more-likely-im-doing-something-wrong/350035)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 1\
**Last updated:** [February 25, 2024, 8:05pm UTC](https://discuss.elastic.co/t/es-ql-cidr-match-not-working-or-more-likely-im-doing-something-wrong/350035 "2024-02-25T20:05:55Z")

</div>

Hi All, I've been messing around with ES|QL a bit, but I'm having an issue with the CIDR\_MATCH function, I'm hoping someone can help with. At a minimum, I have a document that looks like: { "host": { "name": "ip…

---

## [Regarding issues related to the ES SSPL protocol](https://discuss.elastic.co/t/regarding-issues-related-to-the-es-sspl-protocol/354058)

<div class="topic-metadata">

**Author:** [@liruileay](https://discuss.elastic.co/u/liruileay)\
**Replies:** 2\
**Last updated:** [February 25, 2024, 7:47pm UTC](https://discuss.elastic.co/t/regarding-issues-related-to-the-es-sspl-protocol/354058 "2024-02-25T19:47:02Z")

</div>

The customer service within the company based on ES encapsulation belongs to the provision of products as services to the outside world. Do we need commercial authorization or open source code

---

## [How to gain insight into what management tasks are running?](https://discuss.elastic.co/t/how-to-gain-insight-into-what-management-tasks-are-running/354067)

<div class="topic-metadata">

**Author:** [@bruce289](https://discuss.elastic.co/u/bruce289)\
**Replies:** 0\
**Last updated:** [February 25, 2024, 7:22pm UTC](https://discuss.elastic.co/t/how-to-gain-insight-into-what-management-tasks-are-running/354067 "2024-02-25T19:22:02Z")

</div>

Hey, We can see that some of the nodes in our cluster have many more completed tasks in the management thread pool than others. Is there anyway to find out what exactly these management tasks are/were? Whenever I run \_c…

---

## [How to catch a null\_pointer\_exception?](https://discuss.elastic.co/t/how-to-catch-a-null-pointer-exception/353921)

<div class="topic-metadata">

**Author:** [@catalin8](https://discuss.elastic.co/u/catalin8)\
**Replies:** 2\
**Last updated:** [February 25, 2024, 5:44pm UTC](https://discuss.elastic.co/t/how-to-catch-a-null-pointer-exception/353921 "2024-02-25T17:44:59Z")

</div>

On a reindex operation I'm using if(ctx.\_source.containsKey("author")) { ctx.\_source.title = ctx.\_source.title + ctx.\_source.author\[0\]; ctx.\_source.remove("author"); } Which throws a null pointer exception erro…

---

## [GeoIP issue on logstash conf file](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/354047)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 19\
**Last updated:** [February 25, 2024, 2:49pm UTC](https://discuss.elastic.co/t/geoip-issue-on-logstash-conf-file/354047 "2024-02-25T14:49:04Z")

</div>

\[ERROR\]\[logstash.filters.geoip \] Invalid setting for geoip filter plugin: filter { geoip { # This setting must be a path # File does not exist or cannot be opened ./usr/share/logstash/GeoLite2-City.m…

---

## [Percentage in each group](https://discuss.elastic.co/t/percentage-in-each-group/353882)

<div class="topic-metadata">

**Author:** [@Senol\_Kurt](https://discuss.elastic.co/u/Senol_Kurt)\
**Replies:** 2\
**Last updated:** [February 25, 2024, 6:13am UTC](https://discuss.elastic.co/t/percentage-in-each-group/353882 "2024-02-25T06:13:12Z")

</div>

i have an index that holds monthly product sales data for several cities. i want to display in a table the monthly percentage of each product sales in each city. how can i do that?

---

## [Logs are not visible in Kibana](https://discuss.elastic.co/t/logs-are-not-visible-in-kibana/353789)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 3\
**Last updated:** [February 24, 2024, 8:35pm UTC](https://discuss.elastic.co/t/logs-are-not-visible-in-kibana/353789 "2024-02-24T20:35:42Z")

</div>

Hello, do test some logs Logstash configurations I want to use this docker-compose.yml and I'm running Debian 12 . Docker version 25.0.3, build 4debf41 docker-compose version 1.29.2 my user is in the docker group, to …

---

## [Wildcard query on keyword vs N-gram analyzer + multi-match](https://discuss.elastic.co/t/wildcard-query-on-keyword-vs-n-gram-analyzer-multi-match/354038)

<div class="topic-metadata">

**Author:** [@you-last-did](https://discuss.elastic.co/u/you-last-did)\
**Replies:** 0\
**Last updated:** [February 24, 2024, 6:06pm UTC](https://discuss.elastic.co/t/wildcard-query-on-keyword-vs-n-gram-analyzer-multi-match/354038 "2024-02-24T18:06:54Z")

</div>

Hi everyone. I have benefited a lot from the forum and now it's my first post :slight\_smile: So I have some fields which look like these: orderId: ABC-DEF-1234 date: 2024-02-24 lastUpdatedTime: 2024-02-24T12:09:48.7…

---

## [Logstash input imap plugin 3.2.1 No server greeting](https://discuss.elastic.co/t/logstash-input-imap-plugin-3-2-1-no-server-greeting/354027)

<div class="topic-metadata">

**Author:** [@fatdragon](https://discuss.elastic.co/u/fatdragon)\
**Replies:** 1\
**Last updated:** [February 24, 2024, 3:33pm UTC](https://discuss.elastic.co/t/logstash-input-imap-plugin-3-2-1-no-server-greeting/354027 "2024-02-24T15:33:07Z")

</div>

Installed version 3.2.1 logstash-input-imap on Elastic/logstash 8.11.1 and I get this error: ERROR\]\[logstash.inputs.imap \]\[main\]\[b9cf826e6bcb4a03aae915640362d7e31ff45aa3980afc12c3cca2a437c6e280\] Encountered error Ne…

---

## [Elasticsaerch Query Exact match](https://discuss.elastic.co/t/elasticsaerch-query-exact-match/353696)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 6\
**Last updated:** [February 21, 2024, 2:38pm UTC](https://discuss.elastic.co/t/elasticsaerch-query-exact-match/353696 "2024-02-21T14:38:25Z")

</div>

to find the exact match mappings "keywords": { "type": "object", "enabled": True, "properties": { "keyword\_values": { "type": "text", "analyzer": "synonym\_stemmer\_bad\_words\_a…

---

## [Csv download ERROR from Discover Visualization](https://discuss.elastic.co/t/csv-download-error-from-discover-visualization/353824)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 1\
**Last updated:** [February 24, 2024, 1:33am UTC](https://discuss.elastic.co/t/csv-download-error-from-discover-visualization/353824 "2024-02-24T01:33:23Z")

</div>

I'm using Kibana v.8.6.2 . I get the error from Kibana Dashboard when I try to download csv from Discover Visualization. The Dev Tools Console gives me a error message like below. Does anyone know why? To solve this, …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=296)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=298)
