# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=310

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 311

---

## [Display a home page other than the default](https://discuss.elastic.co/t/display-a-home-page-other-than-the-default/352954)

<div class="topic-metadata">

**Author:** [@gnatola](https://discuss.elastic.co/u/gnatola)\
**Replies:** 1\
**Last updated:** [February 9, 2024, 3:37pm UTC](https://discuss.elastic.co/t/display-a-home-page-other-than-the-default/352954 "2024-02-09T15:37:59Z")

</div>

I would like to the Elastic home page to display a particular dashboard on login, rather than the default home page. How do I accomplish that? At the bottom of the default home page there is a link, "Display a different …

---

## [Shipping of logs](https://discuss.elastic.co/t/shipping-of-logs/352955)

<div class="topic-metadata">

**Author:** [@Arsalan\_Muhammad](https://discuss.elastic.co/u/Arsalan_Muhammad)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 3:10pm UTC](https://discuss.elastic.co/t/shipping-of-logs/352955 "2024-02-09T15:10:43Z")

</div>

Hi I need to ship my logs from my application pod which is running in some abc namespace to Elasticsearch cluster I am trying to resolve the issue but I am not able to resolve it. How to resolve this ? also from dev cons…

---

## [Gettting error migrating data stream](https://discuss.elastic.co/t/gettting-error-migrating-data-stream/352947)

<div class="topic-metadata">

**Author:** [@James83](https://discuss.elastic.co/u/James83)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 2:31pm UTC](https://discuss.elastic.co/t/gettting-error-migrating-data-stream/352947 "2024-02-09T14:31:43Z")

</div>

Hello, I'm in the process of migrating ELK (both servers on same version 7.17). I'm trying to restore an index wich has the ilm-history datastream. The index is restored but I'm getting this error in log : java.lang.Il…

---

## [Update ELK version](https://discuss.elastic.co/t/update-elk-version/352573)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 7\
**Last updated:** [February 9, 2024, 2:04pm UTC](https://discuss.elastic.co/t/update-elk-version/352573 "2024-02-09T14:04:16Z")

</div>

Hi, I'm planning to update ELK version 8.2 to 8.12 version. Does ELK version 8.12 require additional CPU, RAM to deploy the new version of ELK or it's not required additional resources to upgrade the ELK version. Than…

---

## [How to improve ELSERv2 ingest throughput?](https://discuss.elastic.co/t/how-to-improve-elserv2-ingest-throughput/352636)

<div class="topic-metadata">

**Author:** [@Rakesh\_Nayak](https://discuss.elastic.co/u/Rakesh_Nayak)\
**Replies:** 3\
**Last updated:** [February 9, 2024, 1:16pm UTC](https://discuss.elastic.co/t/how-to-improve-elserv2-ingest-throughput/352636 "2024-02-09T13:16:06Z")

</div>

Hello Team, We need your guidance on "Improving ELSERv2 optimized model ingest throughput". As per the link we can't ingest more than 26docs per sec no matter what the allocations are. A little background on our inges…

---

## [How to remove text from variable. Alerts](https://discuss.elastic.co/t/how-to-remove-text-from-variable-alerts/352937)

<div class="topic-metadata">

**Author:** [@Nidro96](https://discuss.elastic.co/u/Nidro96)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 1:13pm UTC](https://discuss.elastic.co/t/how-to-remove-text-from-variable-alerts/352937 "2024-02-09T13:13:31Z")

</div>

Hi. First post, so I am sorry if this is in the wrong categorie. I am trying to set up an alert for my system. I got everything working but having problems with formating the message sent to the users. I have the follow…

---

## [Identifying Duplicate Records Based on Multiple Fields in Elasticsearch](https://discuss.elastic.co/t/identifying-duplicate-records-based-on-multiple-fields-in-elasticsearch/352115)

<div class="topic-metadata">

**Author:** [@Bikash\_Hutait](https://discuss.elastic.co/u/Bikash_Hutait)\
**Replies:** 7\
**Last updated:** [February 9, 2024, 12:13pm UTC](https://discuss.elastic.co/t/identifying-duplicate-records-based-on-multiple-fields-in-elasticsearch/352115 "2024-02-09T12:13:36Z")

</div>

I have a dataset in Elasticsearch containing records related to users and their assistants. I need to identify duplicate records for a specific file\_id. A record should be considered a duplicate if the fields FirstName, L…

---

## [Http input is not letting beat input to run](https://discuss.elastic.co/t/http-input-is-not-letting-beat-input-to-run/352912)

<div class="topic-metadata">

**Author:** [@JITENDER\_NEGI](https://discuss.elastic.co/u/JITENDER_NEGI)\
**Replies:** 1\
**Last updated:** [February 9, 2024, 11:11am UTC](https://discuss.elastic.co/t/http-input-is-not-letting-beat-input-to-run/352912 "2024-02-09T11:11:17Z")

</div>

I running in a strange situation where i have 2 seperate pipeline running on a same instance. When I run the beats pipeline alone it works properly but as soon as I create the http-input.conf in the different directory …

---

## [Correct way to have different databases connected to different elasticsearches](https://discuss.elastic.co/t/correct-way-to-have-different-databases-connected-to-different-elasticsearches/352856)

<div class="topic-metadata">

**Author:** [@mike\_mike](https://discuss.elastic.co/u/mike_mike)\
**Replies:** 2\
**Last updated:** [February 9, 2024, 9:57am UTC](https://discuss.elastic.co/t/correct-way-to-have-different-databases-connected-to-different-elasticsearches/352856 "2024-02-09T09:57:12Z")

</div>

Hello all, I am new here and kinda new to the way Elasticsearch should work (cause I am already working with it, but I miss lots of documentation principles). We mainly use ES as a faster way to retrieve important data…

---

## [Metric and multi-option controls](https://discuss.elastic.co/t/metric-and-multi-option-controls/352807)

<div class="topic-metadata">

**Author:** [@rastro](https://discuss.elastic.co/u/rastro)\
**Replies:** 3\
**Last updated:** [February 9, 2024, 9:51am UTC](https://discuss.elastic.co/t/metric-and-multi-option-controls/352807 "2024-02-09T09:51:58Z")

</div>

Here's a simplified example. I run a business with 2 locations. I have a daily document in an index that stores the number of employees in that location. Now, I'd like to have a dashboard that shows a legacy metric fo…

---

## [StackConfigPolicy ECK Index template fails to create](https://discuss.elastic.co/t/stackconfigpolicy-eck-index-template-fails-to-create/352909)

<div class="topic-metadata">

**Author:** [@PLR-KMD](https://discuss.elastic.co/u/PLR-KMD)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 7:20am UTC](https://discuss.elastic.co/t/stackconfigpolicy-eck-index-template-fails-to-create/352909 "2024-02-09T07:20:45Z")

</div>

Hi, According to docs on Elastic Stack configuration policies | Elastic Cloud on Kubernetes \[2.11\] | Elastic I'm trying to deploy simple ILM and index template. Everything works fine when I deploy ILM only but I can't g…

---

## [AccessDeniedException for path.repo while starting Elasticsearch](https://discuss.elastic.co/t/accessdeniedexception-for-path-repo-while-starting-elasticsearch/322428)

<div class="topic-metadata">

**Author:** [@cr\_168328](https://discuss.elastic.co/u/cr_168328)\
**Replies:** 3\
**Last updated:** [February 9, 2024, 5:49am UTC](https://discuss.elastic.co/t/accessdeniedexception-for-path-repo-while-starting-elasticsearch/322428 "2024-02-09T05:49:19Z")

</div>

I have installed elasticsearch Debian package. In /etc/elasticsearch/elasticsearch.yml file, I have this added: path.repo: \["/home/admin/backup\_extracted/var/lib/elasticsearch/es\_bkp"\]. The ownership of backup\_exctracted …

---

## [Simple\_query\_string and query\_string not working as expected](https://discuss.elastic.co/t/simple-query-string-and-query-string-not-working-as-expected/352905)

<div class="topic-metadata">

**Author:** [@Sankar\_S](https://discuss.elastic.co/u/Sankar_S)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 5:05am UTC](https://discuss.elastic.co/t/simple-query-string-and-query-string-not-working-as-expected/352905 "2024-02-09T05:05:27Z")

</div>

I have a title field in document 1 document has $kitkat as value and another has "title" : "Testing Special\_character Elastic Search in $reference entry search" { "query": { "bool": { "must": \[ …

---

## [Failed to load SSL configuration \[xpack.security.transport.ssl\] - cannot specify both \[keystore.secure\_password\] and \[keystore.password\]](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-specify-both-keystore-secure-password-and-keystore-password/352748)

<div class="topic-metadata">

**Author:** [@Karan37](https://discuss.elastic.co/u/Karan37)\
**Replies:** 2\
**Last updated:** [February 9, 2024, 4:55am UTC](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-specify-both-keystore-secure-password-and-keystore-password/352748 "2024-02-09T04:55:24Z")

</div>

when running the elasticsearch.bat command after generating the certificates with the password it is showing only this error "fatal exception while booting Elasticsearchorg.elasticsearch.ElasticsearchSecurityException: f…

---

## [Logstash Pipeline Error: JSON ParseError](https://discuss.elastic.co/t/logstash-pipeline-error-json-parseerror/352808)

<div class="topic-metadata">

**Author:** [@samuelstephens](https://discuss.elastic.co/u/samuelstephens)\
**Replies:** 7\
**Last updated:** [February 8, 2024, 10:09pm UTC](https://discuss.elastic.co/t/logstash-pipeline-error-json-parseerror/352808 "2024-02-08T22:09:58Z")

</div>

Summary I am collecting asset data for Jira using automations to generate a HTTP POST request to Logstash, the following code then takes the input from the request and filters it and sends it to OpenSearch. I have one y…

---

## [Single logstash config file should send data to mutiple indices](https://discuss.elastic.co/t/single-logstash-config-file-should-send-data-to-mutiple-indices/352506)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 6\
**Last updated:** [February 8, 2024, 7:08pm UTC](https://discuss.elastic.co/t/single-logstash-config-file-should-send-data-to-mutiple-indices/352506 "2024-02-08T19:08:59Z")

</div>

Hello All, Kindly suggest if something wrong I'm doing here. Logstash: 8.8.2 I have two indices: mis-monitoring-webserver and mis-monitoring-webui. I want some additional fileds to be created based on some condition…

---

## [Can't write to logstash (ELK)](https://discuss.elastic.co/t/cant-write-to-logstash-elk/352887)

<div class="topic-metadata">

**Author:** [@Rotem\_Orbach](https://discuss.elastic.co/u/Rotem_Orbach)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 6:13pm UTC](https://discuss.elastic.co/t/cant-write-to-logstash-elk/352887 "2024-02-08T18:13:15Z")

</div>

Hi, I'm trying to write to ELK. (using Docker) Elastic is already installed and working properly. I've installed Logstash on docker as well. Problem is I can't see any logs being generated on kibana, I thought tha…

---

## [Logs not being sent if multiple fields in grok pattern](https://discuss.elastic.co/t/logs-not-being-sent-if-multiple-fields-in-grok-pattern/352881)

<div class="topic-metadata">

**Author:** [@vuvu](https://discuss.elastic.co/u/vuvu)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 5:26pm UTC](https://discuss.elastic.co/t/logs-not-being-sent-if-multiple-fields-in-grok-pattern/352881 "2024-02-08T17:26:17Z")

</div>

hi! I have the following filter which works fine: filter { grok { match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp}" } } date { match =\> \[ "syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:…

---

## [Filebeat o365 module field type inconsistency](https://discuss.elastic.co/t/filebeat-o365-module-field-type-inconsistency/352884)

<div class="topic-metadata">

**Author:** [@Daniel314](https://discuss.elastic.co/u/Daniel314)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 5:41pm UTC](https://discuss.elastic.co/t/filebeat-o365-module-field-type-inconsistency/352884 "2024-02-08T17:41:49Z")

</div>

Hi, I've been using the O365 module in FileBeat for a while now, and I've noticed that when the O365 module outputs the o365.audit.AdditionalInfo field, sometimes it's as a JSON string, and sometimes it's as an object. …

---

## [Event Correlation - Can Elastic do this?](https://discuss.elastic.co/t/event-correlation-can-elastic-do-this/352880)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 4:49pm UTC](https://discuss.elastic.co/t/event-correlation-can-elastic-do-this/352880 "2024-02-08T16:49:38Z")

</div>

Hello, With the introduction of AIOPs, I was wondering if Elastic can do event correlation among different systems and different apps more easily? I know currently we can display variety of systems data in one dashboar…

---

## [Load Null values to Index Key column](https://discuss.elastic.co/t/load-null-values-to-index-key-column/352879)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 4:38pm UTC](https://discuss.elastic.co/t/load-null-values-to-index-key-column/352879 "2024-02-08T16:38:29Z")

</div>

Hi Team, we had created index with location\_timestamp as key of type date and format "epoch\_millis" as below. "location\_timestamp":{ "type": "date", "format": "epoch\_millis" }, But while loading data from…

---

## [Terms aggregation split by coma](https://discuss.elastic.co/t/terms-aggregation-split-by-coma/352798)

<div class="topic-metadata">

**Author:** [@Imad\_Ourak](https://discuss.elastic.co/u/Imad_Ourak)\
**Replies:** 5\
**Last updated:** [February 8, 2024, 4:32pm UTC](https://discuss.elastic.co/t/terms-aggregation-split-by-coma/352798 "2024-02-08T16:32:51Z")

</div>

I have a bunch of Elasticsearch documents that contain information about study fields. I'm trying to aggregate the studyfields field to extract the number of "study fields" instances from the job posting. e.g. data scien…

---

## [Question on DHCP Scope Utilization on Windows for Used IP's, Available IP's, and Total IP's](https://discuss.elastic.co/t/question-on-dhcp-scope-utilization-on-windows-for-used-ips-available-ips-and-total-ips/352878)

<div class="topic-metadata">

**Author:** [@Tortuga](https://discuss.elastic.co/u/Tortuga)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 4:30pm UTC](https://discuss.elastic.co/t/question-on-dhcp-scope-utilization-on-windows-for-used-ips-available-ips-and-total-ips/352878 "2024-02-08T16:30:01Z")

</div>

Does anyone know of a way to collect the DHCP stats on a non-domain joined Windows system for the number of used IP's, available IP's, and total IP's?

---

## [\[ERROR\]\[discovery.ec2 \] \[host\] unexpected error while joining cluster, trying again org.elasticsearch.ElasticsearchException: Ping execution failed](https://discuss.elastic.co/t/error-discovery-ec2-host-unexpected-error-while-joining-cluster-trying-again-org-elasticsearch-elasticsearchexception-ping-execution-failed/352690)

<div class="topic-metadata">

**Author:** [@jnunez87](https://discuss.elastic.co/u/jnunez87)\
**Replies:** 7\
**Last updated:** [February 8, 2024, 4:22pm UTC](https://discuss.elastic.co/t/error-discovery-ec2-host-unexpected-error-while-joining-cluster-trying-again-org-elasticsearch-elasticsearchexception-ping-execution-failed/352690 "2024-02-08T16:22:45Z")

</div>

Hello all Today we had a very strange error appear today in our cluster that is preventing the node from connecting. Below is our errors \[2024-02-06 23:18:11,590\]\[ERROR\]\[discovery.ec2 \] \[Windeagle\] unexpect…

---

## [Kibana restarting in a loop](https://discuss.elastic.co/t/kibana-restarting-in-a-loop/352877)

<div class="topic-metadata">

**Author:** [@ramiwashere](https://discuss.elastic.co/u/ramiwashere)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 4:10pm UTC](https://discuss.elastic.co/t/kibana-restarting-in-a-loop/352877 "2024-02-08T16:10:00Z")

</div>

Hi, After an upgrade , kibana is restarting in a loop. On kibana.logs, I can see: "message":"\[{\\"type\\":\\"unavailable\_shards\_exception\\",\\"reason\\":\\"\[.kibana\_security\_solution\_8.9.2\_001\]\[0\] Not enough active copies t…

---

## [Process monitor](https://discuss.elastic.co/t/process-monitor/352026)

<div class="topic-metadata">

**Author:** [@Gadapa\_Vasundhara](https://discuss.elastic.co/u/Gadapa_Vasundhara)\
**Replies:** 13\
**Last updated:** [February 8, 2024, 3:59pm UTC](https://discuss.elastic.co/t/process-monitor/352026 "2024-02-08T15:59:25Z")

</div>

Hi Team, I need some help on process monitor ex: datamonitor.exe process from logstash which plugin i need to use. wmi plugin is not working. and more over we are getting the status of process.state as running only.…

---

## [Migrating from RestClient to ElasticsearchClient](https://discuss.elastic.co/t/migrating-from-restclient-to-elasticsearchclient/352575)

<div class="topic-metadata">

**Author:** [@Tony\_Clarke](https://discuss.elastic.co/u/Tony_Clarke)\
**Replies:** 6\
**Last updated:** [February 8, 2024, 3:54pm UTC](https://discuss.elastic.co/t/migrating-from-restclient-to-elasticsearchclient/352575 "2024-02-08T15:54:36Z")

</div>

Hi, I'm trying to migrate from using the org.elasticsearch.client.RestClient to co.elastic.clients.elasticsearch.ElasticsearchClient. However, I'm noticing one difference in behavior. The ElasticsearchClient has bespoke…

---

## [Alert for multiple indices without summing them up](https://discuss.elastic.co/t/alert-for-multiple-indices-without-summing-them-up/352721)

<div class="topic-metadata">

**Author:** [@vymk](https://discuss.elastic.co/u/vymk)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 3:46pm UTC](https://discuss.elastic.co/t/alert-for-multiple-indices-without-summing-them-up/352721 "2024-02-08T15:46:15Z")

</div>

Hi, I'd like to have alerts if indices don't receive any new documents for a few minutes, therefore I have a rule like this: Now if I add another index to the rule, they get summarized, so as long as one index receiv…

---

## [Disable Stack Monitoring access in Kibana spaces](https://discuss.elastic.co/t/disable-stack-monitoring-access-in-kibana-spaces/352870)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 3:38pm UTC](https://discuss.elastic.co/t/disable-stack-monitoring-access-in-kibana-spaces/352870 "2024-02-08T15:38:55Z")

</div>

I want to create spaces in Kibana with some limited privileges, and I also want to disable "Stack Management" within those spaces. I want to know what privileges to give to those users so they can only manage their indi…

---

## [API calls taking more than 10s](https://discuss.elastic.co/t/api-calls-taking-more-than-10s/352769)

<div class="topic-metadata">

**Author:** [@kvmuralidhar](https://discuss.elastic.co/u/kvmuralidhar)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 3:28pm UTC](https://discuss.elastic.co/t/api-calls-taking-more-than-10s/352769 "2024-02-08T15:28:35Z")

</div>

Hi There, We are running Elasticsearch version 8.8.1 (on prem) and have the following configuration. 3 coordinator nodes 3 dedicated master nodes 17 hot nodes 20 cold nodes 6 frozen nodes (Each frozen node has abou…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=309)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=311)
