# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=303

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 304

---

## [Autoscaling](https://discuss.elastic.co/t/autoscaling/353616)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 2:59pm UTC](https://discuss.elastic.co/t/autoscaling/353616 "2024-02-19T14:59:40Z")

</div>

I see from documentation that elastic autoscaling works based on storage and there is no scaling available based on cpu. has anyone done scripting to automate scaling based on cpu?

---

## [Exiting: error connecting to Kibana: fail to get the Kibana version: fail to parse kibana version (): passed version is not semver:](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-fail-to-parse-kibana-version-passed-version-is-not-semver/353450)

<div class="topic-metadata">

**Author:** [@alsoGAMER](https://discuss.elastic.co/u/alsoGAMER)\
**Replies:** 20\
**Last updated:** [February 19, 2024, 2:35pm UTC](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-fail-to-parse-kibana-version-passed-version-is-not-semver/353450 "2024-02-19T14:35:15Z")

</div>

I'm trying to setup an ELK instance to use as a winlogbeat output, and even though both the ELK stack and winlogbeat versions are the exact same, I'm getting this cryptic error: Exiting: error connecting to Kibana: fail…

---

## [Is there a way I can store recent data on partitions?](https://discuss.elastic.co/t/is-there-a-way-i-can-store-recent-data-on-partitions/353581)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 3\
**Last updated:** [February 19, 2024, 2:02pm UTC](https://discuss.elastic.co/t/is-there-a-way-i-can-store-recent-data-on-partitions/353581 "2024-02-19T14:02:12Z")

</div>

Hello, Is there a way so that I can have ELK keep say the last 50 or more GB on one partition and everything else on a different partition? In general I was thinking of putting all recent logs on SSD and after X age/tim…

---

## ['took' time fast, curl sometimes slow](https://discuss.elastic.co/t/took-time-fast-curl-sometimes-slow/353422)

<div class="topic-metadata">

**Author:** [@ryans](https://discuss.elastic.co/u/ryans)\
**Replies:** 6\
**Last updated:** [February 19, 2024, 1:59pm UTC](https://discuss.elastic.co/t/took-time-fast-curl-sometimes-slow/353422 "2024-02-19T13:59:04Z")

</div>

I am using Elastic Cloud for my Elasticsearch instance. My issue is that sometimes (rarely) I'm seeing strange behavior where the curl time (round trip from my web server to Elastic Cloud) is taking 8+ seconds but the '…

---

## [Hey, i have some problems about elasticsearch and kibana! i want to create different space for my clients and i wouldn't that client had acces at the graph others! also, i want send many traffic netflow in my filebeat, but i don't know how we make!](https://discuss.elastic.co/t/hey-i-have-some-problems-about-elasticsearch-and-kibana-i-want-to-create-different-space-for-my-clients-and-i-wouldnt-that-client-had-acces-at-the-graph-others-also-i-want-send-many-traffic-netflow-in-my-filebeat-but-i-dont-know-how-we-make/353576)

<div class="topic-metadata">

**Author:** [@Pierre\_Yoboue](https://discuss.elastic.co/u/Pierre_Yoboue)\
**Replies:** 1\
**Last updated:** [February 19, 2024, 12:38pm UTC](https://discuss.elastic.co/t/hey-i-have-some-problems-about-elasticsearch-and-kibana-i-want-to-create-different-space-for-my-clients-and-i-wouldnt-that-client-had-acces-at-the-graph-others-also-i-want-send-many-traffic-netflow-in-my-filebeat-but-i-dont-know-how-we-make/353576 "2024-02-19T12:38:07Z")

</div>

Module: netflow Docs: https://www.elastic.co/guide/en/beats/filebeat/main/filebeat-module-netflow.html module: netflow log: enabled: true var: netflow\_host: 10.74.192.64 netflow\_port: 2055 tags: \["INQ"\] # intern…

---

## [Histogram query over calculated field](https://discuss.elastic.co/t/histogram-query-over-calculated-field/353586)

<div class="topic-metadata">

**Author:** [@marinavictoria](https://discuss.elastic.co/u/marinavictoria)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 12:22pm UTC](https://discuss.elastic.co/t/histogram-query-over-calculated-field/353586 "2024-02-19T12:22:42Z")

</div>

My case is the following: doc1: event.type (keyword): a doc2: event.type: aa doc3: event.type: aa doc4: event.type: aaaa I want to create a query that gives me in the Y axis the count of event.type and in the X …

---

## [Updating the documents through the Ingest Pipeline](https://discuss.elastic.co/t/updating-the-documents-through-the-ingest-pipeline/353583)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 11:45am UTC](https://discuss.elastic.co/t/updating-the-documents-through-the-ingest-pipeline/353583 "2024-02-19T11:45:10Z")

</div>

Is there any way to update documents using the ingest pipeline? We are trying to ingest documents using a custom API through the Ingest pipeline. We are looking to identify the duplicate records. We used the "fingerprin…

---

## [Filebeat 7.7 not working in rocky OS 9.2, Kindly help on this](https://discuss.elastic.co/t/filebeat-7-7-not-working-in-rocky-os-9-2-kindly-help-on-this/353580)

<div class="topic-metadata">

**Author:** [@Munir\_Sayyad](https://discuss.elastic.co/u/Munir_Sayyad)\
**Replies:** 1\
**Last updated:** [February 19, 2024, 11:40am UTC](https://discuss.elastic.co/t/filebeat-7-7-not-working-in-rocky-os-9-2-kindly-help-on-this/353580 "2024-02-19T11:40:12Z")

</div>

Filebeat 7.7 not working in rocky OS 9.2

---

## [CaptureBody invalid format](https://discuss.elastic.co/t/capturebody-invalid-format/353579)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 11:36am UTC](https://discuss.elastic.co/t/capturebody-invalid-format/353579 "2024-02-19T11:36:32Z")

</div>

Good morning, I have updated the version of elasticstack to the version 8.12.0 and I capture the body in the APM transactions. But now the field http.request.body is different and appears the body inside the field "ori…

---

## [Transfer log events as files between Logstash instances](https://discuss.elastic.co/t/transfer-log-events-as-files-between-logstash-instances/353503)

<div class="topic-metadata">

**Author:** [@olavur](https://discuss.elastic.co/u/olavur)\
**Replies:** 4\
**Last updated:** [February 19, 2024, 11:34am UTC](https://discuss.elastic.co/t/transfer-log-events-as-files-between-logstash-instances/353503 "2024-02-19T11:34:15Z")

</div>

Hi, I have two logstash instances. One instance A receives events from elastic agents. The second, instance B, inputs the events and outputs them further downstream. But my only option is to transfer files from instanc…

---

## [Структура индекса для поиска в интернетмагазине](https://discuss.elastic.co/t/topic/353567)

<div class="topic-metadata">

**Author:** [@denis.lapa](https://discuss.elastic.co/u/denis.lapa)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 10:40am UTC](https://discuss.elastic.co/t/topic/353567 "2024-02-19T10:40:40Z")

</div>

Добрый день. У нас интернет-магазин 560 000 товаров. Контент на 6-ти языках. Сейчас контент на всех языках индексируется в один индекс: поле pname = Мобильный телефон xiaomi, Mobile phone xiaomi и тд. поле сat\_name …

---

## [Elastic Agent shouldn't log httpjson pagination completion as an error](https://discuss.elastic.co/t/elastic-agent-shouldnt-log-httpjson-pagination-completion-as-an-error/353565)

<div class="topic-metadata">

**Author:** [@agmic](https://discuss.elastic.co/u/agmic)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 10:37am UTC](https://discuss.elastic.co/t/elastic-agent-shouldnt-log-httpjson-pagination-completion-as-an-error/353565 "2024-02-19T10:37:08Z")

</div>

I think this is a bug, but seeking confirmation here before I raise it on github. I am also not sure if this should be raised against Elastic Agent or the integration. The Cisco Secure Endpoint integration collects eve…

---

## [How to Handle Large Indices when non-time series data](https://discuss.elastic.co/t/how-to-handle-large-indices-when-non-time-series-data/353535)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 4\
**Last updated:** [February 19, 2024, 10:30am UTC](https://discuss.elastic.co/t/how-to-handle-large-indices-when-non-time-series-data/353535 "2024-02-19T10:30:27Z")

</div>

Hello Everyone: We are using Elasticsearch v7.8.0 and some clusters of version 8.10.4. We are having Indices storing 40 millions of records in each , having shards -5 primary shards at the time of each index creation. …

---

## [\["org.apache.lucene.index.CorruptIndexException: checksum failed (hardware problem?)](https://discuss.elastic.co/t/org-apache-lucene-index-corruptindexexception-checksum-failed-hardware-problem/353558)

<div class="topic-metadata">

**Author:** [@Kesavan](https://discuss.elastic.co/u/Kesavan)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 10:13am UTC](https://discuss.elastic.co/t/org-apache-lucene-index-corruptindexexception-checksum-failed-hardware-problem/353558 "2024-02-19T10:13:59Z")

</div>

We are facing the CorruptIndexException and also UnavailableShardsException in elastic log. In our system for all index the number of shards is 5. While QA testing we are facing the index elated exception below are the …

---

## [Missing log file](https://discuss.elastic.co/t/missing-log-file/353554)

<div class="topic-metadata">

**Author:** [@Pooort](https://discuss.elastic.co/u/Pooort)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 9:46am UTC](https://discuss.elastic.co/t/missing-log-file/353554 "2024-02-19T09:46:38Z")

</div>

Hello. I start logstash with in official container logstash:8.12.1: logstash -f logstash.conf --path.logs /var/log/logstash/ I see logs in the console but path is empty. How can I get logs in the file? Thanks in adva…

---

## [Small tsvb in dashboard - same as in synthetics](https://discuss.elastic.co/t/small-tsvb-in-dashboard-same-as-in-synthetics/352936)

<div class="topic-metadata">

**Author:** [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Replies:** 2\
**Last updated:** [February 19, 2024, 8:30am UTC](https://discuss.elastic.co/t/small-tsvb-in-dashboard-same-as-in-synthetics/352936 "2024-02-19T08:30:23Z")

</div>

Hi, how to create small graphs in dashboards, visually similar with those in "synthetics"? OR How to create nice and clean indicator of the last value in an index? The purpose is to visualize in green if the service i…

---

## [Reindex multiple downsampled indexes into one cause invalid start/end\_time](https://discuss.elastic.co/t/reindex-multiple-downsampled-indexes-into-one-cause-invalid-start-end-time/353546)

<div class="topic-metadata">

**Author:** [@VietDuc](https://discuss.elastic.co/u/VietDuc)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 7:01am UTC](https://discuss.elastic.co/t/reindex-multiple-downsampled-indexes-into-one-cause-invalid-start-end-time/353546 "2024-02-19T07:01:41Z")

</div>

Hi Everyone, I have a TSDS index and already downsample many backing indexes. Now, i want to reindex some of my downsampled indexes into 1 index (to reduce number of backing index). While it is possible by using POST \_r…

---

## [Nginx reverse proxy for elastic cloud kibana page](https://discuss.elastic.co/t/nginx-reverse-proxy-for-elastic-cloud-kibana-page/353543)

<div class="topic-metadata">

**Author:** [@hanase](https://discuss.elastic.co/u/hanase)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 6:46am UTC](https://discuss.elastic.co/t/nginx-reverse-proxy-for-elastic-cloud-kibana-page/353543 "2024-02-19T06:46:50Z")

</div>

Hi, I'd like to use nginx to proxy\_pass a custom domain to elastic cloud kibana page. I tried some configurations from the discussion as well as this article. https://xeraa.net/blog/2020\_custom-domains-and-anonymous-a…

---

## [Semantic search on help documents](https://discuss.elastic.co/t/semantic-search-on-help-documents/353468)

<div class="topic-metadata">

**Author:** [@9d224d4833094bd482cf](https://discuss.elastic.co/u/9d224d4833094bd482cf)\
**Replies:** 2\
**Last updated:** [February 19, 2024, 6:46am UTC](https://discuss.elastic.co/t/semantic-search-on-help-documents/353468 "2024-02-19T06:46:30Z")

</div>

Hello, We have a help documents on our website for our web application. This help documents on our websites are well documented (with text and images). It has a list of Topics and each topic has its own url with sub to…

---

## [Can the Snapshot Restore restores all my data just once](https://discuss.elastic.co/t/can-the-snapshot-restore-restores-all-my-data-just-once/353538)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 2\
**Last updated:** [February 19, 2024, 6:31am UTC](https://discuss.elastic.co/t/can-the-snapshot-restore-restores-all-my-data-just-once/353538 "2024-02-19T06:31:43Z")

</div>

Hi I have a question about the snapshot restore mechanism, Senerio, I create an index, and it has data keep indexing in it and I have set the Elasticsearch to take snapshot once per night specficly for this index, let …

---

## [Why is segment not merged when deleted over 33%?](https://discuss.elastic.co/t/why-is-segment-not-merged-when-deleted-over-33/353537)

<div class="topic-metadata">

**Author:** [@missingcat92](https://discuss.elastic.co/u/missingcat92)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 4:17am UTC](https://discuss.elastic.co/t/why-is-segment-not-merged-when-deleted-over-33/353537 "2024-02-19T04:17:38Z")

</div>

We have an ES v7.10 instance, and every config about merge is default. Now we have a segment, which include 37% deleted doc (docs.count=6513192,docs.deleted=3902050), the segment is now 4.8gb, and it's not merged for ab…

---

## [Understanding the Impacts of Manual Operations on Elasticsearch Indices Controlled by ILM](https://discuss.elastic.co/t/understanding-the-impacts-of-manual-operations-on-elasticsearch-indices-controlled-by-ilm/353531)

<div class="topic-metadata">

**Author:** [@gwapoo92](https://discuss.elastic.co/u/gwapoo92)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 1:01am UTC](https://discuss.elastic.co/t/understanding-the-impacts-of-manual-operations-on-elasticsearch-indices-controlled-by-ilm/353531 "2024-02-19T01:01:40Z")

</div>

Hey Elasticsearch enthusiasts! I'm currently exploring the possibilities of implementing Index Lifecycle Management (ILM) in Elasticsearch. As I delve into this feature, a question has been lingering in my mind: What ha…

---

## [Pagination using Filebeat httpjson how to reference the 'next' link in results](https://discuss.elastic.co/t/pagination-using-filebeat-httpjson-how-to-reference-the-next-link-in-results/353528)

<div class="topic-metadata">

**Author:** [@Jez1](https://discuss.elastic.co/u/Jez1)\
**Replies:** 0\
**Last updated:** [February 18, 2024, 11:23pm UTC](https://discuss.elastic.co/t/pagination-using-filebeat-httpjson-how-to-reference-the-next-link-in-results/353528 "2024-02-18T23:23:23Z")

</div>

Hello, I'm pretty new to using filebeat and currently working out how to use the httpjson input to pull data from a REST API. I've worked out how to pull the response based on the time period I need and in the correct t…

---

## [Create new side menu category in Kibana](https://discuss.elastic.co/t/create-new-side-menu-category-in-kibana/353525)

<div class="topic-metadata">

**Author:** [@Sanskar\_Panchal](https://discuss.elastic.co/u/Sanskar_Panchal)\
**Replies:** 0\
**Last updated:** [February 18, 2024, 8:03pm UTC](https://discuss.elastic.co/t/create-new-side-menu-category-in-kibana/353525 "2024-02-18T20:03:04Z")

</div>

Hi, I wanted to create a new side menu category for Kibana. The actual requirement is to build something similar to "Recently viewed" section on the side menu. Is it possible with a custom plugin ? Thank you.

---

## [Kibana UI does not work when kibana.yml file is mounted into docker container, but does work when config is set via env vars](https://discuss.elastic.co/t/kibana-ui-does-not-work-when-kibana-yml-file-is-mounted-into-docker-container-but-does-work-when-config-is-set-via-env-vars/353522)

<div class="topic-metadata">

**Author:** [@pred135](https://discuss.elastic.co/u/pred135)\
**Replies:** 3\
**Last updated:** [February 18, 2024, 7:18pm UTC](https://discuss.elastic.co/t/kibana-ui-does-not-work-when-kibana-yml-file-is-mounted-into-docker-container-but-does-work-when-config-is-set-via-env-vars/353522 "2024-02-18T19:18:15Z")

</div>

I am having a very weird and frustrating issue with kibana. I am running the dockerhub elasticsearch and kibana containers on my kubernetes cluster. Here is the issue: I can run elasticsearch just fine, and also port for…

---

## [Definition of plugin "urlForwarding" not found and may have failed to load](https://discuss.elastic.co/t/definition-of-plugin-urlforwarding-not-found-and-may-have-failed-to-load/349921)

<div class="topic-metadata">

**Author:** [@yoss\_fazwaz](https://discuss.elastic.co/u/yoss_fazwaz)\
**Replies:** 7\
**Last updated:** [February 18, 2024, 5:36pm UTC](https://discuss.elastic.co/t/definition-of-plugin-urlforwarding-not-found-and-may-have-failed-to-load/349921 "2024-02-18T17:36:39Z")

</div>

Hi guys, after installing Elasticsearch on Kubernetes, I can access Elasticsearch, but when I tried to access Kibana, I encountered this error. Version: 8.11.1 Build: 68203 Error: Definition of plugin "urlForwarding" no…

---

## [Add field in table of Kibana dashboard](https://discuss.elastic.co/t/add-field-in-table-of-kibana-dashboard/353506)

<div class="topic-metadata">

**Author:** [@yashar.ansari76](https://discuss.elastic.co/u/yashar.ansari76)\
**Replies:** 8\
**Last updated:** [February 18, 2024, 5:29pm UTC](https://discuss.elastic.co/t/add-field-in-table-of-kibana-dashboard/353506 "2024-02-18T17:29:14Z")

</div>

Hi I have Kibana that visualize my data and I want to add column that exist in my log but I don't know how to add that filed in column. Thanks for your attention.

---

## [Sparse vector embeddings](https://discuss.elastic.co/t/sparse-vector-embeddings/353498)

<div class="topic-metadata">

**Author:** [@mwon](https://discuss.elastic.co/u/mwon)\
**Replies:** 4\
**Last updated:** [February 18, 2024, 3:40pm UTC](https://discuss.elastic.co/t/sparse-vector-embeddings/353498 "2024-02-18T15:40:50Z")

</div>

Hi, Is there any plan to re-introduce sparse vector fields? It was depreciated and there is this discussion about it. I would like to use sparse vectors to search by sparse vector embeddings. For example, I would like…

---

## [SQL data upload using JDBC-logstash](https://discuss.elastic.co/t/sql-data-upload-using-jdbc-logstash/353435)

<div class="topic-metadata">

**Author:** [@Ritikapawar](https://discuss.elastic.co/u/Ritikapawar)\
**Replies:** 8\
**Last updated:** [February 18, 2024, 10:04am UTC](https://discuss.elastic.co/t/sql-data-upload-using-jdbc-logstash/353435 "2024-02-18T10:04:22Z")

</div>

Hi, I'm uploading data using jdbc-logstash script but when i run ths script it adds allover data again and again so index is showing count of duplicate data too. This is the script which i am using input { jdbc { …

---

## [Kibana formula "reducedTimeRange" not working](https://discuss.elastic.co/t/kibana-formula-reducedtimerange-not-working/353243)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 3\
**Last updated:** [February 18, 2024, 7:13am UTC](https://discuss.elastic.co/t/kibana-formula-reducedtimerange-not-working/353243 "2024-02-18T07:13:36Z")

</div>

I'm facing an issue while creating a visualization, whenever i use "reducedTimeRange" the result value becomes 0.

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=302)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=304)
