# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=302

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 303

---

## [Specific Kibana filter in iframe URL and filter bar](https://discuss.elastic.co/t/specific-kibana-filter-in-iframe-url-and-filter-bar/353672)

<div class="topic-metadata">

**Author:** [@skouf](https://discuss.elastic.co/u/skouf)\
**Replies:** 2\
**Last updated:** [February 20, 2024, 1:45pm UTC](https://discuss.elastic.co/t/specific-kibana-filter-in-iframe-url-and-filter-bar/353672 "2024-02-20T13:45:56Z")

</div>

Hello I saw many topic regarding this subject. But I need to add mine because maybe there are some solutions that exists since. I am using Elastic and Kibana 7 I need to pass some specific filters to my iframe from my…

---

## [On restarting filebeat, every filestream paths input is deemed to be truncated](https://discuss.elastic.co/t/on-restarting-filebeat-every-filestream-paths-input-is-deemed-to-be-truncated/353337)

<div class="topic-metadata">

**Author:** [@Dheeraj\_Gupta](https://discuss.elastic.co/u/Dheeraj_Gupta)\
**Replies:** 6\
**Last updated:** [February 20, 2024, 1:32pm UTC](https://discuss.elastic.co/t/on-restarting-filebeat-every-filestream-paths-input-is-deemed-to-be-truncated/353337 "2024-02-20T13:32:05Z")

</div>

Hi, We are using filebeat to ship Zeek logs to logstash. We do this by defining a different filestream input for each type of log and in the input we define the path filebeat.yml path.home: /usr/share/filebeat path.da…

---

## [Logstash - The default timestamp field does not match my log field](https://discuss.elastic.co/t/logstash-the-default-timestamp-field-does-not-match-my-log-field/353622)

<div class="topic-metadata">

**Author:** [@ozonshak](https://discuss.elastic.co/u/ozonshak)\
**Replies:** 5\
**Last updated:** [February 20, 2024, 1:16pm UTC](https://discuss.elastic.co/t/logstash-the-default-timestamp-field-does-not-match-my-log-field/353622 "2024-02-20T13:16:36Z")

</div>

Hello. I have an existing Elastic stack that is pulling in app and web server logs. For the web site, I have 2 software stacks - 1 is using an older apache format (comma separated values) and 1 is using a newer JSON form…

---

## [ElasticSearch failed to apply default image tag in OpenShift deployment](https://discuss.elastic.co/t/elasticsearch-failed-to-apply-default-image-tag-in-openshift-deployment/353630)

<div class="topic-metadata">

**Author:** [@Mike\_Kirby](https://discuss.elastic.co/u/Mike_Kirby)\
**Replies:** 2\
**Last updated:** [February 20, 2024, 12:54pm UTC](https://discuss.elastic.co/t/elasticsearch-failed-to-apply-default-image-tag-in-openshift-deployment/353630 "2024-02-20T12:54:20Z")

</div>

Good Afternoon my Elastic Guru's. I am in the process of using the Docker image of 8.11.4 to deploy Elasticsearch in an OpenShift envirorment. I am using the OpenShift User interface and it should be a simple enough ta…

---

## [Year to date visualization](https://discuss.elastic.co/t/year-to-date-visualization/353539)

<div class="topic-metadata">

**Author:** [@Senol\_Kurt](https://discuss.elastic.co/u/Senol_Kurt)\
**Replies:** 3\
**Last updated:** [February 20, 2024, 12:41pm UTC](https://discuss.elastic.co/t/year-to-date-visualization/353539 "2024-02-20T12:41:15Z")

</div>

i have an index that holds monthly aggregated sales data. i want to visualize year to date sales for each month. can i do it without creating a new field and what is the best way to do it?

---

## [ECK on GKE with local SSDs](https://discuss.elastic.co/t/eck-on-gke-with-local-ssds/353689)

<div class="topic-metadata">

**Author:** [@rh\_at](https://discuss.elastic.co/u/rh_at)\
**Replies:** 0\
**Last updated:** [February 20, 2024, 12:39pm UTC](https://discuss.elastic.co/t/eck-on-gke-with-local-ssds/353689 "2024-02-20T12:39:00Z")

</div>

Hi all, We've set a new elasticsearch cluster to store skywalking data. Settings are as following: 6 data nodes, each 16GB RAM (around 50% heap size), 16 cores, 4\*375G local SSDs disks (thats about 1.5TB each) 3 maste…

---

## [Block results for search terms](https://discuss.elastic.co/t/block-results-for-search-terms/353615)

<div class="topic-metadata">

**Author:** [@syrupman](https://discuss.elastic.co/u/syrupman)\
**Replies:** 1\
**Last updated:** [February 20, 2024, 12:37pm UTC](https://discuss.elastic.co/t/block-results-for-search-terms/353615 "2024-02-20T12:37:50Z")

</div>

We are using elastic.co to search images in our ecommerce with ELSER. Knowing that AI/ML will eventually commit a faux-paus, we need to be able to add negative words to each item so they won't show up on searches with t…

---

## [Kibana returns 404](https://discuss.elastic.co/t/kibana-returns-404/352342)

<div class="topic-metadata">

**Author:** [@Reclocco](https://discuss.elastic.co/u/Reclocco)\
**Replies:** 9\
**Last updated:** [February 20, 2024, 11:49am UTC](https://discuss.elastic.co/t/kibana-returns-404/352342 "2024-02-20T11:49:05Z")

</div>

Hi everyone i have a problem where kibana stopped working at some point without any tinkering with config. I checked the nginx routing etc and that seems to be fine 'security' is not enabled elasticsearch is green \[r…

---

## [Logstash.service unable to access Keystore](https://discuss.elastic.co/t/logstash-service-unable-to-access-keystore/353628)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 7\
**Last updated:** [February 20, 2024, 11:48am UTC](https://discuss.elastic.co/t/logstash-service-unable-to-access-keystore/353628 "2024-02-20T11:48:06Z")

</div>

Hello everyone, while trying to setup a test Logstash instance, i struggle to get it running. The following error appears, viewable via journalctl: ERROR: Failed to load settings file from "path.settings". Aborting...…

---

## [Failed to restore an incremental snapshot](https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657)

<div class="topic-metadata">

**Author:** [@praval\_singhal](https://discuss.elastic.co/u/praval_singhal)\
**Replies:** 6\
**Last updated:** [February 20, 2024, 11:42am UTC](https://discuss.elastic.co/t/failed-to-restore-an-incremental-snapshot/353657 "2024-02-20T11:42:38Z")

</div>

I have been trying to restore an incremental snapshot for my ES cluster stored in azure storage account. I am getting this error {"error":{"root\_cause":\[{"type":"snapshot\_restore\_exception","reason":"\[elasticsearch\_sna…

---

## [Get only one fileld that is common accoss different indices, like SQL join on tables](https://discuss.elastic.co/t/get-only-one-fileld-that-is-common-accoss-different-indices-like-sql-join-on-tables/353677)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [February 20, 2024, 11:08am UTC](https://discuss.elastic.co/t/get-only-one-fileld-that-is-common-accoss-different-indices-like-sql-join-on-tables/353677 "2024-02-20T11:08:14Z")

</div>

Hello All, Can someone please let me know I have a requirement to make dashboard which shows which usecases/ index are critical to be shown with status Heathy in green color and Red Critical. Below is image I have achi…

---

## [Not able to get all RDS metrics to Elasticsearch](https://discuss.elastic.co/t/not-able-to-get-all-rds-metrics-to-elasticsearch/353676)

<div class="topic-metadata">

**Author:** [@arvind297](https://discuss.elastic.co/u/arvind297)\
**Replies:** 0\
**Last updated:** [February 20, 2024, 11:04am UTC](https://discuss.elastic.co/t/not-able-to-get-all-rds-metrics-to-elasticsearch/353676 "2024-02-20T11:04:12Z")

</div>

Hi, We are trying to configure elasticagent to send RDS metrics to Elasticsearch. Able to configure using AWS RDS integration and we are getting the metrics. But not getting all the metrics.From the documentation i unde…

---

## [Elasticsaerch Query with exact match with stemmer apply](https://discuss.elastic.co/t/elasticsaerch-query-with-exact-match-with-stemmer-apply/353675)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 0\
**Last updated:** [February 20, 2024, 11:03am UTC](https://discuss.elastic.co/t/elasticsaerch-query-with-exact-match-with-stemmer-apply/353675 "2024-02-20T11:03:40Z")

</div>

To fetch the exact match I have applied Ex: keywords.keyword\_values.keyword mappings: "keywords": { "type": "object", "enabled": True, "properties": { "keyword\_values": { "type": "text"…

---

## [How to refer doc\_count in MovingFunctions.ewma aggregation bucket path?](https://discuss.elastic.co/t/how-to-refer-doc-count-in-movingfunctions-ewma-aggregation-bucket-path/353602)

<div class="topic-metadata">

**Author:** [@Abinash\_Raja](https://discuss.elastic.co/u/Abinash_Raja)\
**Replies:** 1\
**Last updated:** [February 20, 2024, 10:47am UTC](https://discuss.elastic.co/t/how-to-refer-doc-count-in-movingfunctions-ewma-aggregation-bucket-path/353602 "2024-02-20T10:47:32Z")

</div>

Hi, Is there a way to directly refer the doc\_count of date histogram(over time\_millis field) bucket(s) in MovingFunctions.ewma bucket path, instead of creating a separate value\_count aggregation (for the same field time…

---

## [Illegal\_state\_exception: no rollover info found for \[logstash-2024.02.16\] with rollover target \[logstash-\], the index has not yet rolled over with that target](https://discuss.elastic.co/t/illegal-state-exception-no-rollover-info-found-for-logstash-2024-02-16-with-rollover-target-logstash-the-index-has-not-yet-rolled-over-with-that-target/353667)

<div class="topic-metadata">

**Author:** [@martianzz](https://discuss.elastic.co/u/martianzz)\
**Replies:** 0\
**Last updated:** [February 20, 2024, 9:46am UTC](https://discuss.elastic.co/t/illegal-state-exception-no-rollover-info-found-for-logstash-2024-02-16-with-rollover-target-logstash-the-index-has-not-yet-rolled-over-with-that-target/353667 "2024-02-20T09:46:00Z")

</div>

illegal\_state\_exception: no rollover info found for \[logstash-2024.02.16\] with rollover target \[logstash-\], the index has not yet rolled over with that target. Why is this error always coming. How to solve it

---

## [Hardware profiles for Hot/Warm tiers](https://discuss.elastic.co/t/hardware-profiles-for-hot-warm-tiers/353582)

<div class="topic-metadata">

**Author:** [@intrepid1](https://discuss.elastic.co/u/intrepid1)\
**Replies:** 2\
**Last updated:** [February 20, 2024, 9:01am UTC](https://discuss.elastic.co/t/hardware-profiles-for-hot-warm-tiers/353582 "2024-02-20T09:01:40Z")

</div>

Hi there, We are in the process of moving our on-premise logging cluster to AWS on EC2 and would like to use a hot/warm architecture. The aim is to place the data on the hardware that is most suited to, allowing multipl…

---

## [Agents periodically disconnecting from Fleets](https://discuss.elastic.co/t/agents-periodically-disconnecting-from-fleets/353397)

<div class="topic-metadata">

**Author:** [@squatchulator](https://discuss.elastic.co/u/squatchulator)\
**Replies:** 1\
**Last updated:** [February 20, 2024, 7:40am UTC](https://discuss.elastic.co/t/agents-periodically-disconnecting-from-fleets/353397 "2024-02-20T07:40:47Z")

</div>

Version: 8.9.0 Hi there! Working on a SOC team where we manage agents for lots of local endpoints within our network. I'm pretty new to working with the stack, so I am hoping someone with more experience with agent issu…

---

## [Issue with Character Encoding When Receiving Data from RSYSLOG in Logstash 8.4.3](https://discuss.elastic.co/t/issue-with-character-encoding-when-receiving-data-from-rsyslog-in-logstash-8-4-3/353609)

<div class="topic-metadata">

**Author:** [@nw-engineer](https://discuss.elastic.co/u/nw-engineer)\
**Replies:** 4\
**Last updated:** [February 20, 2024, 5:41am UTC](https://discuss.elastic.co/t/issue-with-character-encoding-when-receiving-data-from-rsyslog-in-logstash-8-4-3/353609 "2024-02-20T05:41:19Z")

</div>

Hello, I'm currently using Logstash version 8.4.3 and encountering an issue when processing data received from RSYSLOG. The error message I'm seeing is as follows: \[WARN \]\[logstash.codecs.plain\]\[main\]\[b162f9e29529bc018…

---

## [Send logs From Filebeat to 2 different group logstash servers simultaneously](https://discuss.elastic.co/t/send-logs-from-filebeat-to-2-different-group-logstash-servers-simultaneously/353548)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 4\
**Last updated:** [February 20, 2024, 3:54am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-2-different-group-logstash-servers-simultaneously/353548 "2024-02-20T03:54:36Z")

</div>

I need to send logs From Filebeat to 2 different group logstash servers simultaneously Group A: Single logstash server with certificate\_A and CA\_A Group B: 3 logstash servers run in loadbalance mode. with certificate\_B…

---

## [Kibana failed to fetch event log KPI](https://discuss.elastic.co/t/kibana-failed-to-fetch-event-log-kpi/353640)

<div class="topic-metadata">

**Author:** [@greenhand](https://discuss.elastic.co/u/greenhand)\
**Replies:** 0\
**Last updated:** [February 20, 2024, 2:35am UTC](https://discuss.elastic.co/t/kibana-failed-to-fetch-event-log-kpi/353640 "2024-02-20T02:35:49Z")

</div>

Hello! I am an elasticsearch user from China and I thought I might need some help, I can't find the information to solve this problem in my own country.When I tried to use the alert function, I found that the log TAB did…

---

## [Failed to load SSL configuration \[xpack.security.transport.ssl\] - cannot read configured \[PKCS12\]](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-read-configured-pkcs12/352840)

<div class="topic-metadata">

**Author:** [@Jerry-yz](https://discuss.elastic.co/u/Jerry-yz)\
**Replies:** 3\
**Last updated:** [February 20, 2024, 1:54am UTC](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-read-configured-pkcs12/352840 "2024-02-20T01:54:49Z")

</div>

wehn i run es with docker; my docker run cmd is: docker run -itd -p 9200:9200 -m 2GB --privileged=true -v $PWD/config/elasticsearch.yml:/usr/share/elasticsearch/config/elasticsearch.yml -v $PWD/data:/usr/share/elasticse…

---

## [What log Windows security rules require into a winlogbeat](https://discuss.elastic.co/t/what-log-windows-security-rules-require-into-a-winlogbeat/353632)

<div class="topic-metadata">

**Author:** [@dominic.savaria](https://discuss.elastic.co/u/dominic.savaria)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 8:06pm UTC](https://discuss.elastic.co/t/what-log-windows-security-rules-require-into-a-winlogbeat/353632 "2024-02-19T20:06:36Z")

</div>

I want to enable most of the Windows security rules in Kibana, but I am missing a lot of fields from my winlogbeat. We are fowarding our logs into a windows event collector but I don't know what log are missing for the s…

---

## [Issue with setting \`\_tier\_preference\` in index template](https://discuss.elastic.co/t/issue-with-setting-tier-preference-in-index-template/353631)

<div class="topic-metadata">

**Author:** [@Sebastian\_Veliz\_MQ](https://discuss.elastic.co/u/Sebastian_Veliz_MQ)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 8:02pm UTC](https://discuss.elastic.co/t/issue-with-setting-tier-preference-in-index-template/353631 "2024-02-19T20:02:10Z")

</div>

Hello We are encountering an issue while trying to set the \_tier\_preference in an index template. Despite updating the setting in the index template edit page, the preview shows that \_tier\_preference is set to null inst…

---

## [Allow requests to elastic deployment only from AWS EC2 instances in VPN](https://discuss.elastic.co/t/allow-requests-to-elastic-deployment-only-from-aws-ec2-instances-in-vpn/353618)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [February 19, 2024, 6:02pm UTC](https://discuss.elastic.co/t/allow-requests-to-elastic-deployment-only-from-aws-ec2-instances-in-vpn/353618 "2024-02-19T18:02:39Z")

</div>

Is it possible to restrict access to elastic deployment only from AWS EC2 instances that are part of a particular VPN?

---

## [Slow Navigation in Kibana](https://discuss.elastic.co/t/slow-navigation-in-kibana/349279)

<div class="topic-metadata">

**Author:** [@tepus](https://discuss.elastic.co/u/tepus)\
**Replies:** 5\
**Last updated:** [February 19, 2024, 5:13pm UTC](https://discuss.elastic.co/t/slow-navigation-in-kibana/349279 "2024-02-19T17:13:33Z")

</div>

Dear Community, we use the following configuration of ELK: Version: 8.5.3 OS: RHEL 8 Number of master nodes: 1 Number of master and warm nodes: 2 Hot nodes: 2 Kibana instances: 2 Our issue is that the navigation …

---

## [Multiline does not append the lines](https://discuss.elastic.co/t/multiline-does-not-append-the-lines/353625)

<div class="topic-metadata">

**Author:** [@Pedro\_Lopez\_Gonzalez](https://discuss.elastic.co/u/Pedro_Lopez_Gonzalez)\
**Replies:** 2\
**Last updated:** [February 19, 2024, 4:55pm UTC](https://discuss.elastic.co/t/multiline-does-not-append-the-lines/353625 "2024-02-19T16:55:33Z")

</div>

Hi all, I have configured a parser to join the lines into one but it doesn´t work. This is the configuration code: filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can use d…

---

## [Security minimal setup 7.9.0](https://discuss.elastic.co/t/security-minimal-setup-7-9-0/353304)

<div class="topic-metadata">

**Author:** [@mwitsas](https://discuss.elastic.co/u/mwitsas)\
**Replies:** 2\
**Last updated:** [February 19, 2024, 3:32pm UTC](https://discuss.elastic.co/t/security-minimal-setup-7-9-0/353304 "2024-02-19T15:32:12Z")

</div>

Can anyone confirm this procedure is valid for 7.9.0 and should work? Or can anyone highlight any issues with trying this on 7.9.0? I see the page only exists in documentation from 7.12.0 onwards - "This page is not a…

---

## [Having trouble parsing my JSON apache log using Logstash](https://discuss.elastic.co/t/having-trouble-parsing-my-json-apache-log-using-logstash/353488)

<div class="topic-metadata">

**Author:** [@ozonshak](https://discuss.elastic.co/u/ozonshak)\
**Replies:** 4\
**Last updated:** [February 19, 2024, 3:17pm UTC](https://discuss.elastic.co/t/having-trouble-parsing-my-json-apache-log-using-logstash/353488 "2024-02-19T15:17:28Z")

</div>

Hello. I have an existing Elastic stack that is pulling in app and web server logs. For the web site, I have 2 software stacks - 1 is using an older apache format (comma separated values) and 1 is using a newer JSON fo…

---

## [fatal exception while booting Elasticsearch](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/353620)

<div class="topic-metadata">

**Author:** [@carrot016](https://discuss.elastic.co/u/carrot016)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 3:15pm UTC](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/353620 "2024-02-19T15:15:24Z")

</div>

elasticsearch-1 | {"@timestamp":"2024-02-19T12:02:08.108Z", "log.level":"ERROR", "message":"fatal exception while booting Elasticsearch", "ecs.version": "1.2.0","service.name":"ES\_ECS","event.dataset":"elasticsearch.serv…

---

## [Data tiers vs searchable snapshot \[platinum license elastic onprem\]](https://discuss.elastic.co/t/data-tiers-vs-searchable-snapshot-platinum-license-elastic-onprem/353541)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 14\
**Last updated:** [February 19, 2024, 3:07pm UTC](https://discuss.elastic.co/t/data-tiers-vs-searchable-snapshot-platinum-license-elastic-onprem/353541 "2024-02-19T15:07:58Z")

</div>

Hello team! I want to make use of the hot, warm, cold, frozen tiers for my onprem elastic deployment. I can see from this link that data tier is possible with platinum licensing. However I see 'searchable snapshots' ca…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=301)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=303)
