# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=305

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 306

---

## [Bind9 elastic agent integration](https://discuss.elastic.co/t/bind9-elastic-agent-integration/353412)

<div class="topic-metadata">

**Author:** [@Brennen\_Rose](https://discuss.elastic.co/u/Brennen_Rose)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 9:16pm UTC](https://discuss.elastic.co/t/bind9-elastic-agent-integration/353412 "2024-02-15T21:16:31Z")

</div>

Hi there - we have setup a custom log ingestion pipeline from our DNS server running Bind. We had have an existing fleet agent running on that server, so we opted to add a custom pipeline with a grok for Bind9 logs. I am…

---

## [Exclude field from request if it is empty](https://discuss.elastic.co/t/exclude-field-from-request-if-it-is-empty/353410)

<div class="topic-metadata">

**Author:** [@rijexe9501](https://discuss.elastic.co/u/rijexe9501)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 8:57pm UTC](https://discuss.elastic.co/t/exclude-field-from-request-if-it-is-empty/353410 "2024-02-15T20:57:21Z")

</div>

Hi all. Please tell me, I have a request like this (request 1) and if field2 in it is empty, then I want to exclude it from the selection so that a request like this will be executed (request 2). How can I do this? Requ…

---

## [Logstash S3 output plugin fails to upload txt files in S3](https://discuss.elastic.co/t/logstash-s3-output-plugin-fails-to-upload-txt-files-in-s3/353352)

<div class="topic-metadata">

**Author:** [@Aniket\_Chakrabarty](https://discuss.elastic.co/u/Aniket_Chakrabarty)\
**Replies:** 6\
**Last updated:** [February 15, 2024, 5:38pm UTC](https://discuss.elastic.co/t/logstash-s3-output-plugin-fails-to-upload-txt-files-in-s3/353352 "2024-02-15T17:38:25Z")

</div>

Hi, We have tried to upload a txt file through logstash s3 output plugin but having issues it says: Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which l…

---

## [100% io utilization after migrating to XFS from EXT4](https://discuss.elastic.co/t/100-io-utilization-after-migrating-to-xfs-from-ext4/353404)

<div class="topic-metadata">

**Author:** [@Brandon\_Kauffman](https://discuss.elastic.co/u/Brandon_Kauffman)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 5:36pm UTC](https://discuss.elastic.co/t/100-io-utilization-after-migrating-to-xfs-from-ext4/353404 "2024-02-15T17:36:36Z")

</div>

We recently switched from EXT4 to XFS in an upgrade from rhel7 to 9. Both were using LVM and RAID-0. We noticed that IO utilization stays near 100% Before it was near 30% That being said, disk performance seems to …

---

## [How to split one line document into several documents using logstash?](https://discuss.elastic.co/t/how-to-split-one-line-document-into-several-documents-using-logstash/353394)

<div class="topic-metadata">

**Author:** [@jimmyb](https://discuss.elastic.co/u/jimmyb)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 5:04pm UTC](https://discuss.elastic.co/t/how-to-split-one-line-document-into-several-documents-using-logstash/353394 "2024-02-15T17:04:35Z")

</div>

Hello All, First time poster here. I have a document coming into logstash which is just one field that references different logs however it has come into elastic as just one line. For example the string within the "me…

---

## [How to handle special characters (hex encoded) in logstash mutate or grok](https://discuss.elastic.co/t/how-to-handle-special-characters-hex-encoded-in-logstash-mutate-or-grok/352437)

<div class="topic-metadata">

**Author:** [@Johnson\_will](https://discuss.elastic.co/u/Johnson_will)\
**Replies:** 6\
**Last updated:** [February 15, 2024, 4:59pm UTC](https://discuss.elastic.co/t/how-to-handle-special-characters-hex-encoded-in-logstash-mutate-or-grok/352437 "2024-02-15T16:59:11Z")

</div>

� This is the special character, I am on logstash7.17.10, It seems like it is able to parse on the greater version of logstash I am using mutate to remove the special character from message filter{ # mutate { gsub…

---

## [Elasticsearch Alerts Timing Edge Case](https://discuss.elastic.co/t/elasticsearch-alerts-timing-edge-case/353400)

<div class="topic-metadata">

**Author:** [@spatel68](https://discuss.elastic.co/u/spatel68)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 4:45pm UTC](https://discuss.elastic.co/t/elasticsearch-alerts-timing-edge-case/353400 "2024-02-15T16:45:10Z")

</div>

We’re currently using Elasticsearch Alerts to get notified for the number of documents that were ingested each minute. The alert runs on an interval of 1m. We were concerned about timing edge cases since this could lead …

---

## [Filestream Autodiscover Kubernetes duplication error logs being generated](https://discuss.elastic.co/t/filestream-autodiscover-kubernetes-duplication-error-logs-being-generated/353313)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 5\
**Last updated:** [February 15, 2024, 4:30pm UTC](https://discuss.elastic.co/t/filestream-autodiscover-kubernetes-duplication-error-logs-being-generated/353313 "2024-02-15T16:30:50Z")

</div>

Hi We are using ELK 8.11.1 we are seeing these types of errors logs being generated from filebeat. filestream input with ID \<\> already exists, this will lead to data duplication, please use a different ID. Metrics coll…

---

## [Problems with a table in Dashboard](https://discuss.elastic.co/t/problems-with-a-table-in-dashboard/353376)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 4:15pm UTC](https://discuss.elastic.co/t/problems-with-a-table-in-dashboard/353376 "2024-02-15T16:15:32Z")

</div>

I have a dashboard which will be used as a way to extract some data via CSV. But I've reached a problem in which there are too many buckets to load and so it reaches an error making impossible to work. I would like to…

---

## [How to plot over time the sum of iot values using last value rather than the cumulative sum](https://discuss.elastic.co/t/how-to-plot-over-time-the-sum-of-iot-values-using-last-value-rather-than-the-cumulative-sum/353286)

<div class="topic-metadata">

**Author:** [@Julien\_Revol](https://discuss.elastic.co/u/Julien_Revol)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 4:01pm UTC](https://discuss.elastic.co/t/how-to-plot-over-time-the-sum-of-iot-values-using-last-value-rather-than-the-cumulative-sum/353286 "2024-02-15T16:01:36Z")

</div>

I have a simple CSV sample like that and i want to see the evolution of the sum, breaked down by de last value date evse power 2024-02-12T10:00:00 evse\_1 2 2024-02-12T11:00:00 evse\_1 4 2024-02-12T12:00:00 evse\_1 6 2024-…

---

## [Proxy based authentication documentation](https://discuss.elastic.co/t/proxy-based-authentication-documentation/352969)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 7:20pm UTC](https://discuss.elastic.co/t/proxy-based-authentication-documentation/352969 "2024-02-09T19:20:55Z")

</div>

Where can I find documentation on setting up proxy based authentication? I didn't see anything here:

---

## [Transposing Rows to Columns in Kibana Data Table Visualization](https://discuss.elastic.co/t/transposing-rows-to-columns-in-kibana-data-table-visualization/352918)

<div class="topic-metadata">

**Author:** [@abhinay\_nalla](https://discuss.elastic.co/u/abhinay_nalla)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 3:48pm UTC](https://discuss.elastic.co/t/transposing-rows-to-columns-in-kibana-data-table-visualization/352918 "2024-02-15T15:48:17Z")

</div>

Hello Kibana community, I am currently working on visualizing data from my MS Defender AV logs in Kibana, and I'm facing a challenge in presenting the data in the desired format. I have data in the following structure: …

---

## [ElasticSearch creating new index is unassigned even though it says that it can allocate](https://discuss.elastic.co/t/elasticsearch-creating-new-index-is-unassigned-even-though-it-says-that-it-can-allocate/353374)

<div class="topic-metadata">

**Author:** [@ChrisWohlert](https://discuss.elastic.co/u/ChrisWohlert)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 1:16pm UTC](https://discuss.elastic.co/t/elasticsearch-creating-new-index-is-unassigned-even-though-it-says-that-it-can-allocate/353374 "2024-02-15T13:16:26Z")

</div>

We have a setup running ECK in AWS running version 8.10.2. Any attempt to create an index results in the shards not being assigned. I can manually assign them, but that is not a solution. GET \_cat/shards?v=true&h=index,…

---

## [Update by query in ES with option conflicts=proceed](https://discuss.elastic.co/t/update-by-query-in-es-with-option-conflicts-proceed/353169)

<div class="topic-metadata">

**Author:** [@sdv](https://discuss.elastic.co/u/sdv)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 12:58pm UTC](https://discuss.elastic.co/t/update-by-query-in-es-with-option-conflicts-proceed/353169 "2024-02-15T12:58:54Z")

</div>

Hi Team, I have below two questions for 'update\_by\_query' API with option 'conflicts=proceed'. Basically if we allow processing documents with 'conflicts=proceed' option and still have a retry based on 'VersionConfli…

---

## [Can I create a URL link for each data view on the Discover page?](https://discuss.elastic.co/t/can-i-create-a-url-link-for-each-data-view-on-the-discover-page/353222)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 8\
**Last updated:** [February 15, 2024, 12:52pm UTC](https://discuss.elastic.co/t/can-i-create-a-url-link-for-each-data-view-on-the-discover-page/353222 "2024-02-15T12:52:08Z")

</div>

I have multiple data views maintained in Kibana's Discover. I am happy to switch between data views from the UI on Discover and see the contents of each data view, but I noticed that the URL does not contain any informa…

---

## [Netflow beats not completing index'ing resulting in ILM not deleting last data indice of the day](https://discuss.elastic.co/t/netflow-beats-not-completing-indexing-resulting-in-ilm-not-deleting-last-data-indice-of-the-day/352851)

<div class="topic-metadata">

**Author:** [@eddie4](https://discuss.elastic.co/u/eddie4)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 12:49pm UTC](https://discuss.elastic.co/t/netflow-beats-not-completing-indexing-resulting-in-ilm-not-deleting-last-data-indice-of-the-day/352851 "2024-02-15T12:49:42Z")

</div>

Hello, We are running filebeat's with netflow extention to keep track of data. We are running into the issue that the last incomplete indice is not completed/finished and there for never deleted by ILM. This results in…

---

## [Kibana and React](https://discuss.elastic.co/t/kibana-and-react/353342)

<div class="topic-metadata">

**Author:** [@Anteneh\_Mulu](https://discuss.elastic.co/u/Anteneh_Mulu)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 12:38pm UTC](https://discuss.elastic.co/t/kibana-and-react/353342 "2024-02-15T12:38:30Z")

</div>

Hey,is it possible to add react UI(eg.Registration form or button) to kibana visualization?

---

## [Kibana won't up](https://discuss.elastic.co/t/kibana-wont-up/352648)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 4\
**Last updated:** [February 15, 2024, 12:19pm UTC](https://discuss.elastic.co/t/kibana-wont-up/352648 "2024-02-15T12:19:49Z")

</div>

Hi, few month back I was configured the elk stack on aws ubuntu instance and it's works fine without any issue. But due to some VPC related reason, I was taken the AMI from that elk stack instance and launched the new i…

---

## [Elastic Agent installation on the window server 2012 r2](https://discuss.elastic.co/t/elastic-agent-installation-on-the-window-server-2012-r2/353364)

<div class="topic-metadata">

**Author:** [@Yogesh\_AS](https://discuss.elastic.co/u/Yogesh_AS)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 12:15pm UTC](https://discuss.elastic.co/t/elastic-agent-installation-on-the-window-server-2012-r2/353364 "2024-02-15T12:15:12Z")

</div>

Hi All, I am installing the elastic agent in windows server r2 2012 edition where I am facing issue is I am unable to see the CPU and memory metrices in fleet management. please help me out to resolve issues but when I…

---

## [Moving avg counts](https://discuss.elastic.co/t/moving-avg-counts/353367)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 12:13pm UTC](https://discuss.elastic.co/t/moving-avg-counts/353367 "2024-02-15T12:13:39Z")

</div>

we have created visualization to fetch counts average count but as attached in screenshot for in place of highlighted field we want previous timeframes average count so,...is it possible to find count lik this?

---

## [Array in Response](https://discuss.elastic.co/t/array-in-response/353334)

<div class="topic-metadata">

**Author:** [@Shreya\_Chandak](https://discuss.elastic.co/u/Shreya_Chandak)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 11:04am UTC](https://discuss.elastic.co/t/array-in-response/353334 "2024-02-15T11:04:06Z")

</div>

Hello Community , I am new to querying elastic , there is a requirement -\> I have logs on elk with field names request(string) and average response time (Number) , I want to first specify a date\_range in query and find …

---

## [To solve an error](https://discuss.elastic.co/t/to-solve-an-error/353339)

<div class="topic-metadata">

**Author:** [@With\_Ayush](https://discuss.elastic.co/u/With_Ayush)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 10:58am UTC](https://discuss.elastic.co/t/to-solve-an-error/353339 "2024-02-15T10:58:58Z")

</div>

Facing this error. Please help me resolve, Error updating document with EventID ': AuthorizationException(403, security exception", "action \[Indices:data/read/get\] is unauthorized for user \[user\] with roles \[viewer, su…

---

## [Heartbeat on Docker not receiving logs in Kibana](https://discuss.elastic.co/t/heartbeat-on-docker-not-receiving-logs-in-kibana/353130)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 5\
**Last updated:** [February 15, 2024, 10:57am UTC](https://discuss.elastic.co/t/heartbeat-on-docker-not-receiving-logs-in-kibana/353130 "2024-02-15T10:57:43Z")

</div>

This is my config: heartbeat.monitors: - type: http enabled: true schedule: '@every 10s' urls: \["http://localhost:9200"\] # Elasticsearch - type: tcp enabled: true schedule: '@every 10s' hosts: \["localhost:5…

---

## [NOT ABLE TO INDEX DATA USING HTTP POLLER](https://discuss.elastic.co/t/not-able-to-index-data-using-http-poller/353251)

<div class="topic-metadata">

**Author:** [@rajatbhardwaj1393](https://discuss.elastic.co/u/rajatbhardwaj1393)\
**Replies:** 12\
**Last updated:** [February 15, 2024, 10:37am UTC](https://discuss.elastic.co/t/not-able-to-index-data-using-http-poller/353251 "2024-02-15T10:37:10Z")

</div>

want to index data from the third party api. trying to index data from response but the data is coming as array of results and ruby code below is not storing it as individual event. Can someone suggest what i am doing w…

---

## [S3 compatible with repository\_verification\_exception](https://discuss.elastic.co/t/s3-compatible-with-repository-verification-exception/353360)

<div class="topic-metadata">

**Author:** [@Omizollo](https://discuss.elastic.co/u/Omizollo)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 10:31am UTC](https://discuss.elastic.co/t/s3-compatible-with-repository-verification-exception/353360 "2024-02-15T10:31:32Z")

</div>

I have a custom s3 storage which I can communicate with using AWS sdk. I have configured the repository with Elasticsearch v7.17 and it is working fine, but after upgrade to the version v8.11 the verification to the repo…

---

## [Shard routing while active indexing](https://discuss.elastic.co/t/shard-routing-while-active-indexing/353326)

<div class="topic-metadata">

**Author:** [@Prashant\_Rana](https://discuss.elastic.co/u/Prashant_Rana)\
**Replies:** 3\
**Last updated:** [February 15, 2024, 10:27am UTC](https://discuss.elastic.co/t/shard-routing-while-active-indexing/353326 "2024-02-15T10:27:06Z")

</div>

What happens if I explicitly route a shard to a different node while the indexing happens to that shard in the original shard? Should I stop indexing in that shard?

---

## [EUI ":first-child" warning help](https://discuss.elastic.co/t/eui-first-child-warning-help/353083)

<div class="topic-metadata">

**Author:** [@David10](https://discuss.elastic.co/u/David10)\
**Replies:** 3\
**Last updated:** [February 15, 2024, 10:02am UTC](https://discuss.elastic.co/t/eui-first-child-warning-help/353083 "2024-02-15T10:02:28Z")

</div>

Hello, I've been receiving the following warning everytime I insert an tag within my plugin: "The pseudo class ":first-child" is potentially unsafe when doing server-side rendering. Try changing it to ":first-of-type".…

---

## [Elastic dashboard in Kiosk mode](https://discuss.elastic.co/t/elastic-dashboard-in-kiosk-mode/353093)

<div class="topic-metadata">

**Author:** [@gnatola](https://discuss.elastic.co/u/gnatola)\
**Replies:** 3\
**Last updated:** [February 15, 2024, 9:53am UTC](https://discuss.elastic.co/t/elastic-dashboard-in-kiosk-mode/353093 "2024-02-15T09:53:55Z")

</div>

I have a dashboard read-only user. Is there a way to configure this dashboard in kiosk mode so the user gets automatically logged in? Thanks.

---

## [How to get list of installed software/products from windows Server?](https://discuss.elastic.co/t/how-to-get-list-of-installed-software-products-from-windows-server/353088)

<div class="topic-metadata">

**Author:** [@Padam](https://discuss.elastic.co/u/Padam)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 9:38am UTC](https://discuss.elastic.co/t/how-to-get-list-of-installed-software-products-from-windows-server/353088 "2024-02-15T09:38:51Z")

</div>

Hi All, Greetings!!! Could you please help me to get all list products/ software, version and their EOL details?

---

## [Is LSCL documented?](https://discuss.elastic.co/t/is-lscl-documented/353178)

<div class="topic-metadata">

**Author:** [@joostdecock](https://discuss.elastic.co/u/joostdecock)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 8:36am UTC](https://discuss.elastic.co/t/is-lscl-documented/353178 "2024-02-15T08:36:53Z")

</div>

Hi all, I am looking for documentation on LSCL, the logstash configuration language. The one that inputs and pipelines are written in and looks like this: input { kafka { id =\> "whatever" } } I'm in a situatio…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=304)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=306)
