# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=298

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 299

---

## [Data display for Hour which has maximum value for a variable](https://discuss.elastic.co/t/data-display-for-hour-which-has-maximum-value-for-a-variable/352906)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 3\
**Last updated:** [February 24, 2024, 1:20am UTC](https://discuss.elastic.co/t/data-display-for-hour-which-has-maximum-value-for-a-variable/352906 "2024-02-24T01:20:58Z")

</div>

Hello Team, I will explain my query with below example. I have below data timestamp, Date, hour, Column A, Column B, Column C, Column D, Column E For last day (from 00:00 to 23:59 Hour), I need only that hour …

---

## [Pass canvas workpad filter to dashboard url in markdown menu](https://discuss.elastic.co/t/pass-canvas-workpad-filter-to-dashboard-url-in-markdown-menu/353849)

<div class="topic-metadata">

**Author:** [@jyoti\_panse](https://discuss.elastic.co/u/jyoti_panse)\
**Replies:** 1\
**Last updated:** [February 24, 2024, 1:19am UTC](https://discuss.elastic.co/t/pass-canvas-workpad-filter-to-dashboard-url-in-markdown-menu/353849 "2024-02-24T01:19:24Z")

</div>

I want to pass canvas workpad filters to a markdown url so once user click on it, they will redirect to kibana dashboard with filter applied on workpad.

---

## [Restore from found-snapshots across clusters](https://discuss.elastic.co/t/restore-from-found-snapshots-across-clusters/353903)

<div class="topic-metadata">

**Author:** [@dan-cbm](https://discuss.elastic.co/u/dan-cbm)\
**Replies:** 1\
**Last updated:** [February 24, 2024, 1:10am UTC](https://discuss.elastic.co/t/restore-from-found-snapshots-across-clusters/353903 "2024-02-24T01:10:46Z")

</div>

Is it possible to use the default "found-snapshots" S3 repository to restore from one cluster into another (e.g. prod -\> test)? For context I'm using elastic cloud to host our deployment environments (managed on top of …

---

## [Can't find ruby gem of api (7.17)](https://discuss.elastic.co/t/cant-find-ruby-gem-of-api-7-17/353935)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [February 24, 2024, 1:01am UTC](https://discuss.elastic.co/t/cant-find-ruby-gem-of-api-7-17/353935 "2024-02-24T01:01:55Z")

</div>

IT412392:~ rful011$ sudo gem install elasticsearch=7.17.12 ERROR: Could not find a valid gem 'elasticsearch=7.17.12' (\>= 0) in any repository ERROR: Possible alternatives: elasticsearch-rails2, elasticsearch\_record, el…

---

## [Can't create histogram for summed values](https://discuss.elastic.co/t/cant-create-histogram-for-summed-values/353929)

<div class="topic-metadata">

**Author:** [@tomek\_z](https://discuss.elastic.co/u/tomek_z)\
**Replies:** 2\
**Last updated:** [February 23, 2024, 8:08pm UTC](https://discuss.elastic.co/t/cant-create-histogram-for-summed-values/353929 "2024-02-23T20:08:22Z")

</div>

Can't create histogram for summed values I'cant figure out how to create histogram for sumemd values. This query gives me sum of events time per user: GET /events/\_search { "size": 0, "aggregations": { "by\_use…

---

## [Problems with dynamic mapping](https://discuss.elastic.co/t/problems-with-dynamic-mapping/353940)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 7:38pm UTC](https://discuss.elastic.co/t/problems-with-dynamic-mapping/353940 "2024-02-23T19:38:49Z")

</div>

I have some ECS formatted data that I want to put into a new data stream. I created an index template with default parameters: (no setting, mappings or aliases) but when I try and put data into it using the ruby api I g…

---

## [How to send heartbeats to Elasticsearch in a secured network?](https://discuss.elastic.co/t/how-to-send-heartbeats-to-elasticsearch-in-a-secured-network/353484)

<div class="topic-metadata">

**Author:** [@jschreud](https://discuss.elastic.co/u/jschreud)\
**Replies:** 13\
**Last updated:** [February 23, 2024, 7:16pm UTC](https://discuss.elastic.co/t/how-to-send-heartbeats-to-elasticsearch-in-a-secured-network/353484 "2024-02-23T19:16:56Z")

</div>

Hey there everyone,.. really hoping I can find some help here. I am working in an environment where Elasticsearch, Kibana and Logstash is running on machine A. Machine B has a Heartbeat installed and is collecting heart…

---

## [Nested bool querie](https://discuss.elastic.co/t/nested-bool-querie/354015)

<div class="topic-metadata">

**Author:** [@eirik](https://discuss.elastic.co/u/eirik)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 6:36pm UTC](https://discuss.elastic.co/t/nested-bool-querie/354015 "2024-02-23T18:36:44Z")

</div>

Hi, I'm pretty new to queries in elastic and need some help to understand how the post\_filter below is executed for both when a document has the \_id field and when it doesn't have it :slight\_smile: "post\_filter": { …

---

## ["certificate" verification mode for Logstash's output plugin for Elasticsearch](https://discuss.elastic.co/t/certificate-verification-mode-for-logstashs-output-plugin-for-elasticsearch/353956)

<div class="topic-metadata">

**Author:** [@Dhiwakar\_Ravikumar](https://discuss.elastic.co/u/Dhiwakar_Ravikumar)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 6:35pm UTC](https://discuss.elastic.co/t/certificate-verification-mode-for-logstashs-output-plugin-for-elasticsearch/353956 "2024-02-23T18:35:25Z")

</div>

In the following page valid values for SSL verification mode are "full" , "none" I want Logstash to only verify the certificate provided by Elasticsearch is from a trusted authority and not the hostname itself , is th…

---

## [Collect router-specific syslog data](https://discuss.elastic.co/t/collect-router-specific-syslog-data/354013)

<div class="topic-metadata">

**Author:** [@Saullus](https://discuss.elastic.co/u/Saullus)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 6:29pm UTC](https://discuss.elastic.co/t/collect-router-specific-syslog-data/354013 "2024-02-23T18:29:05Z")

</div>

Hello community. I activated Syslog on a Cisco 3725 router and need to connect to Elasticsearch/Logstash to collect the logs. I need to collect memory, CPU and UP/DOWN events from the router. How can I filter this infor…

---

## [Azure Billing](https://discuss.elastic.co/t/azure-billing/354010)

<div class="topic-metadata">

**Author:** [@aquintananieves2](https://discuss.elastic.co/u/aquintananieves2)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 5:54pm UTC](https://discuss.elastic.co/t/azure-billing/354010 "2024-02-23T17:54:48Z")

</div>

When using the Azure Billing integrations, it works only using a single subscription. When adding a Billing Account ID or Department ID, it stops working. Has anyone run into this issue, or does this need to be reported …

---

## [Logstash error "logstash.codecs.json"](https://discuss.elastic.co/t/logstash-error-logstash-codecs-json/354001)

<div class="topic-metadata">

**Author:** [@Antonio\_Lopez](https://discuss.elastic.co/u/Antonio_Lopez)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 4:09pm UTC](https://discuss.elastic.co/t/logstash-error-logstash-codecs-json/354001 "2024-02-23T16:09:15Z")

</div>

Hi everybody, I'm using Logstash version 7.12.0, and I'm experiencing issues processing the input data. The logs are stored in an NFS, and Logstash has access to them. The data is formatted in JSON, and I'm using the c…

---

## [Issue with the example from the ES blog](https://discuss.elastic.co/t/issue-with-the-example-from-the-es-blog/354000)

<div class="topic-metadata">

**Author:** [@profuel](https://discuss.elastic.co/u/profuel)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 3:57pm UTC](https://discuss.elastic.co/t/issue-with-the-example-from-the-es-blog/354000 "2024-02-23T15:57:20Z")

</div>

Hi there! I'm trying to setup a proper search for the Japanese audience. I found this blog post - How to implement Japanese full-text search in Elasticsearch | Elastic Blog, though the example here is not accepted neit…

---

## [How to implement a custom pipeline to a index](https://discuss.elastic.co/t/how-to-implement-a-custom-pipeline-to-a-index/353129)

<div class="topic-metadata">

**Author:** [@Subrahmanyam\_Veerank](https://discuss.elastic.co/u/Subrahmanyam_Veerank)\
**Replies:** 5\
**Last updated:** [February 23, 2024, 3:17pm UTC](https://discuss.elastic.co/t/how-to-implement-a-custom-pipeline-to-a-index/353129 "2024-02-23T15:17:18Z")

</div>

Sir, I have created a custom pipeline for converting the UTC time (field name : time in my log entry) to IST & created a new field ist\_time. How to apply this custom pipeline to the filebeat index?

---

## [How to get dashobards based on ID](https://discuss.elastic.co/t/how-to-get-dashobards-based-on-id/353723)

<div class="topic-metadata">

**Author:** [@griffer98](https://discuss.elastic.co/u/griffer98)\
**Replies:** 3\
**Last updated:** [February 23, 2024, 2:26pm UTC](https://discuss.elastic.co/t/how-to-get-dashobards-based-on-id/353723 "2024-02-23T14:26:58Z")

</div>

I am using elastic cloud and I am trying to use a saved object ID to tie it to a dashboard name. Ive tried everything and cant get the query to work. Im trying to use devtools to find a dashboard name based on a given sa…

---

## [How to create Client while registering GCS as repository?](https://discuss.elastic.co/t/how-to-create-client-while-registering-gcs-as-repository/353987)

<div class="topic-metadata">

**Author:** [@aditya\_rewari](https://discuss.elastic.co/u/aditya_rewari)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 2:12pm UTC](https://discuss.elastic.co/t/how-to-create-client-while-registering-gcs-as-repository/353987 "2024-02-23T14:12:37Z")

</div>

I am trying to setup GCS (Google Client Storage) for archiving my logs through kibana-logstash I am facing issue while registering repository I am unable to crate a client which is required while creating repository, o…

---

## [Metric won't setup because of bad certificates](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891)

<div class="topic-metadata">

**Author:** [@Klheik](https://discuss.elastic.co/u/Klheik)\
**Replies:** 14\
**Last updated:** [February 23, 2024, 2:01pm UTC](https://discuss.elastic.co/t/metric-wont-setup-because-of-bad-certificates/353891 "2024-02-23T14:01:43Z")

</div>

Hi, I have a debian 11 install on a server, i am using the ELK satck with the 7.17 version and Elasticsearch, Logstash, Filebeat and kibana are installa and configure and works perfectly when it's about monitoring log f…

---

## [Elasticsearch in Windows with gMSA](https://discuss.elastic.co/t/elasticsearch-in-windows-with-gmsa/353990)

<div class="topic-metadata">

**Author:** [@Palla](https://discuss.elastic.co/u/Palla)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 1:34pm UTC](https://discuss.elastic.co/t/elasticsearch-in-windows-with-gmsa/353990 "2024-02-23T13:34:23Z")

</div>

Hi all, I have a quick question: is it possible to use Elasticsearch in Windows with a service account gMSA? I'm not sure if it needs a Local System account. Thanks.

---

## [How can I increase maximum allowed value of "max\_matches" option for enrich processor](https://discuss.elastic.co/t/how-can-i-increase-maximum-allowed-value-of-max-matches-option-for-enrich-processor/353985)

<div class="topic-metadata">

**Author:** [@pataposha](https://discuss.elastic.co/u/pataposha)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 12:57pm UTC](https://discuss.elastic.co/t/how-can-i-increase-maximum-allowed-value-of-max-matches-option-for-enrich-processor/353985 "2024-02-23T12:57:40Z")

</div>

I use enrich pipeline for matching docs from "source" index to "destination" index. For my data there are "many" docs from "source" index matched into "single" doc from "destination" index. Often, number of "source" docs…

---

## [Ingest data from a relational database - STDOUT Duplicates](https://discuss.elastic.co/t/ingest-data-from-a-relational-database-stdout-duplicates/353984)

<div class="topic-metadata">

**Author:** [@MaikLinnemann](https://discuss.elastic.co/u/MaikLinnemann)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 12:50pm UTC](https://discuss.elastic.co/t/ingest-data-from-a-relational-database-stdout-duplicates/353984 "2024-02-23T12:50:29Z")

</div>

Dear all, when i follow the article to ingest data from a relational database (MSSQL), which is that one: Klick and i stdout the results to console, i receive duplicates. Exactly i use: stdout { codec =\> json } for th…

---

## [Is it possible to modify Managed Pipelines, Component Templates, and Index Templates?](https://discuss.elastic.co/t/is-it-possible-to-modify-managed-pipelines-component-templates-and-index-templates/353901)

<div class="topic-metadata">

**Author:** [@fredyfredburger1](https://discuss.elastic.co/u/fredyfredburger1)\
**Replies:** 17\
**Last updated:** [February 23, 2024, 12:40pm UTC](https://discuss.elastic.co/t/is-it-possible-to-modify-managed-pipelines-component-templates-and-index-templates/353901 "2024-02-23T12:40:44Z")

</div>

Good morning. I'm on a project using OpenTelementry to collect system health and status metrics for servers, and we are integrated with Elasticsearch through APM. There is a field we are setting in the data which I nee…

---

## [Loading data from elasticsearch to hadoop](https://discuss.elastic.co/t/loading-data-from-elasticsearch-to-hadoop/353817)

<div class="topic-metadata">

**Author:** [@Hussain\_Sain](https://discuss.elastic.co/u/Hussain_Sain)\
**Replies:** 2\
**Last updated:** [February 23, 2024, 11:48am UTC](https://discuss.elastic.co/t/loading-data-from-elasticsearch-to-hadoop/353817 "2024-02-23T11:48:36Z")

</div>

Hi, we are using Elasticsearch 7.6.1 and CDH 6.2. we need to get data from elasticsearch to hive in CSV format but we dont know the way. any document which i go through have steps for loading data from hive to elaticse…

---

## [Get dataset into Elastic](https://discuss.elastic.co/t/get-dataset-into-elastic/353710)

<div class="topic-metadata">

**Author:** [@CD9820](https://discuss.elastic.co/u/CD9820)\
**Replies:** 4\
**Last updated:** [February 23, 2024, 11:43am UTC](https://discuss.elastic.co/t/get-dataset-into-elastic/353710 "2024-02-23T11:43:26Z")

</div>

Hello, I developed a script that gathers information from a range of physical servers (hardware health state, firmware versions, security settings, ...). The gathered dataset is written to a json file. As a test I 've …

---

## [Unrecognized signal name: "\_source" when using calculate in Vega-Lite](https://discuss.elastic.co/t/unrecognized-signal-name-source-when-using-calculate-in-vega-lite/353976)

<div class="topic-metadata">

**Author:** [@robertomzc](https://discuss.elastic.co/u/robertomzc)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 10:48am UTC](https://discuss.elastic.co/t/unrecognized-signal-name-source-when-using-calculate-in-vega-lite/353976 "2024-02-23T10:48:19Z")

</div>

Hi all, I am trying to compute the sum of the absolute value of three fields in a dataset but I am getting an 'Unrecognized signal name: "\_source" ' error in the calculate clause. I tried substituting the '\_source' for…

---

## [Timestamp field mismatching with server time](https://discuss.elastic.co/t/timestamp-field-mismatching-with-server-time/353975)

<div class="topic-metadata">

**Author:** [@Fahdel\_Achmad](https://discuss.elastic.co/u/Fahdel_Achmad)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 10:43am UTC](https://discuss.elastic.co/t/timestamp-field-mismatching-with-server-time/353975 "2024-02-23T10:43:25Z")

</div>

I have a problem, where the timestamp on Kibana and on the server is different. I have changed the advanced settings to GMT-7 but there is no change. Apart from that, the time on the server is correct. Thank You

---

## [Rovided Grok patterns do not match data in the input, create array for each field while it's a string](https://discuss.elastic.co/t/rovided-grok-patterns-do-not-match-data-in-the-input-create-array-for-each-field-while-its-a-string/353963)

<div class="topic-metadata">

**Author:** [@hsam](https://discuss.elastic.co/u/hsam)\
**Replies:** 1\
**Last updated:** [February 23, 2024, 10:29am UTC](https://discuss.elastic.co/t/rovided-grok-patterns-do-not-match-data-in-the-input-create-array-for-each-field-while-its-a-string/353963 "2024-02-23T10:29:46Z")

</div>

\-csv exemple: A;B;C as991m;tr;lbr-expl/trd/jcl/as991m as991mb;tr;lbr-expl/trd/jcl/as991mb as991t;tr;lbr-expl/trd/jcl/as991t as991tb;tr;lbr-expl/trd/jcl/as991tb as991w;tr;lbr-expl/trd/jcl/as991w as991wb;tr;lbr-expl/trd/j…

---

## [Rally benchmark results have much smaller latency than real](https://discuss.elastic.co/t/rally-benchmark-results-have-much-smaller-latency-than-real/353943)

<div class="topic-metadata">

**Author:** [@fatcloud](https://discuss.elastic.co/u/fatcloud)\
**Replies:** 2\
**Last updated:** [February 23, 2024, 10:05am UTC](https://discuss.elastic.co/t/rally-benchmark-results-have-much-smaller-latency-than-real/353943 "2024-02-23T10:05:17Z")

</div>

I wrote a Rally benchmark with a single search query operation. The Rally benchmark result shows a much smaller p50 latency(~200ms) compared to the latency I observe when i just use curl command to send same query(severa…

---

## [KIBANA UI is not coming up even all services are UP Without any error in Logs](https://discuss.elastic.co/t/kibana-ui-is-not-coming-up-even-all-services-are-up-without-any-error-in-logs/352763)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 5\
**Last updated:** [February 23, 2024, 10:02am UTC](https://discuss.elastic.co/t/kibana-ui-is-not-coming-up-even-all-services-are-up-without-any-error-in-logs/352763 "2024-02-23T10:02:03Z")

</div>

Dear Team We are newly installing KIBANA Setup on new server, After configuration of services all services are up From Backend also no any error observed in Elasticsearch/kibana logs ,but UI URL is not coming up we are…

---

## [Need Help with Multi-Index Search and Boosting for Petstore Project](https://discuss.elastic.co/t/need-help-with-multi-index-search-and-boosting-for-petstore-project/353651)

<div class="topic-metadata">

**Author:** [@SwathiAngaluru](https://discuss.elastic.co/u/SwathiAngaluru)\
**Replies:** 2\
**Last updated:** [February 23, 2024, 9:34am UTC](https://discuss.elastic.co/t/need-help-with-multi-index-search-and-boosting-for-petstore-project/353651 "2024-02-23T09:34:44Z")

</div>

Hi Elastic community, I'm currently working on a petstore project where we have three different pet providers (a, b, c), and their data is stored in three separate indices (provider-a, provider-b, provider-c). All three…

---

## [Native memory pressure in deployemnts](https://discuss.elastic.co/t/native-memory-pressure-in-deployemnts/353962)

<div class="topic-metadata">

**Author:** [@Die\_Viera](https://discuss.elastic.co/u/Die_Viera)\
**Replies:** 0\
**Last updated:** [February 23, 2024, 9:13am UTC](https://discuss.elastic.co/t/native-memory-pressure-in-deployemnts/353962 "2024-02-23T09:13:18Z")

</div>

Hi. I want to know what process use the antive memory pressure of an node in elasticsearch, what can cause i high elasticsearch native memory pressure and what implications has a high native memory pressure in elasticse…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=297)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=299)
