# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=311

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 312

---

## [Shrink do not proceed because of number of shard filter](https://discuss.elastic.co/t/shrink-do-not-proceed-because-of-number-of-shard-filter/352861)

<div class="topic-metadata">

**Author:** [@Teoman\_Sevinc](https://discuss.elastic.co/u/Teoman_Sevinc)\
**Replies:** 3\
**Last updated:** [February 8, 2024, 3:27pm UTC](https://discuss.elastic.co/t/shrink-do-not-proceed-because-of-number-of-shard-filter/352861 "2024-02-08T15:27:37Z")

</div>

Hi Community, I'm trying to shrink my indices with a curator. This is my action.yml content: actions: 1: action: shrink description: "Shrink indices starting with mylog older than two days" options: …

---

## [Lifecycle is not workin - no errors](https://discuss.elastic.co/t/lifecycle-is-not-workin-no-errors/352875)

<div class="topic-metadata">

**Author:** [@Nathan\_Borik1](https://discuss.elastic.co/u/Nathan_Borik1)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 3:25pm UTC](https://discuss.elastic.co/t/lifecycle-is-not-workin-no-errors/352875 "2024-02-08T15:25:51Z")

</div>

Elastic version 7.17.1 Looks like all the settings are ok, no errors but the lifecycle is not running. Not moving to warm or cold and no deletion as specified in the Index Lifecycle Policies. { "lx-logs-be-01" : { …

---

## [Generate multi resolution dashboard/visualize just by url](https://discuss.elastic.co/t/generate-multi-resolution-dashboard-visualize-just-by-url/352455)

<div class="topic-metadata">

**Author:** [@lstoneir](https://discuss.elastic.co/u/lstoneir)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 2:47pm UTC](https://discuss.elastic.co/t/generate-multi-resolution-dashboard-visualize-just-by-url/352455 "2024-02-08T14:47:34Z")

</div>

Hi friends, How are you? I want to say a story for you! in these days, when i want to create minutely, hourly, daily visualizations. I create 3 visualize. one for minutely resolution, one for hourly and the last one fo…

---

## [Shard allocated / total](https://discuss.elastic.co/t/shard-allocated-total/352868)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 2:02pm UTC](https://discuss.elastic.co/t/shard-allocated-total/352868 "2024-02-08T14:02:30Z")

</div>

Hi everyone, im doing some check on my system and im analyzing the number of shard on my deployment. Im using two "command" to check how many shard im using. With the command GET /\_stats?level=cluster&filter\_path=\_sh…

---

## [Can we create kibana dashboards as code?](https://discuss.elastic.co/t/can-we-create-kibana-dashboards-as-code/352783)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 1:57pm UTC](https://discuss.elastic.co/t/can-we-create-kibana-dashboards-as-code/352783 "2024-02-08T13:57:53Z")

</div>

Is there a way we can automate kibana dashboard creation? It would be great if we could create via version controlled source for better tracking and easy maintenance. Thanks

---

## [Using Elastic Search Latest Version Throw Exception](https://discuss.elastic.co/t/using-elastic-search-latest-version-throw-exception/352739)

<div class="topic-metadata">

**Author:** [@GANESHAN\_RAMAN](https://discuss.elastic.co/u/GANESHAN_RAMAN)\
**Replies:** 3\
**Last updated:** [February 8, 2024, 1:54pm UTC](https://discuss.elastic.co/t/using-elastic-search-latest-version-throw-exception/352739 "2024-02-08T13:54:50Z")

</div>

Hi, My application with Elasticsearch was working fine until Elasticsearch version 7.17.9, As there is a vulnerability issue with this version as reported by black duck i changed to the recent version 8.12.0, Once i c…

---

## [Add volume for each strimzi kafka broker](https://discuss.elastic.co/t/add-volume-for-each-strimzi-kafka-broker/352864)

<div class="topic-metadata">

**Author:** [@jerin](https://discuss.elastic.co/u/jerin)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 1:44pm UTC](https://discuss.elastic.co/t/add-volume-for-each-strimzi-kafka-broker/352864 "2024-02-08T13:44:44Z")

</div>

I am sending logs to Elasticsearch like below beats -- logstash entry -- Kafka -- logstash indexing -- Elasticsearch . We want to remove Kafka in the data flow by replacing with logstash persistent queue .. currently …

---

## [How Can I generate Root-ca.pem for Elasticsearch for integrating with wazuh](https://discuss.elastic.co/t/how-can-i-generate-root-ca-pem-for-elasticsearch-for-integrating-with-wazuh/352835)

<div class="topic-metadata">

**Author:** [@fahim2024](https://discuss.elastic.co/u/fahim2024)\
**Replies:** 3\
**Last updated:** [February 8, 2024, 1:28pm UTC](https://discuss.elastic.co/t/how-can-i-generate-root-ca-pem-for-elasticsearch-for-integrating-with-wazuh/352835 "2024-02-08T13:28:00Z")

</div>

It would be great if someone help me with step by step guidance with explanation

---

## [Slowness in Kibana and high CPU utilization usage](https://discuss.elastic.co/t/slowness-in-kibana-and-high-cpu-utilization-usage/352824)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 8\
**Last updated:** [February 8, 2024, 1:26pm UTC](https://discuss.elastic.co/t/slowness-in-kibana-and-high-cpu-utilization-usage/352824 "2024-02-08T13:26:55Z")

</div>

Hi, I am facing slowness in Kibana Production. Discover and dashboard is taking too much time to load and sometimes getting the error as shown in the first screenshot. I checked the cluster status from the stack mon…

---

## [Multiple Inner\_hit on knn](https://discuss.elastic.co/t/multiple-inner-hit-on-knn/351893)

<div class="topic-metadata">

**Author:** [@Tommaso\_FAVARON](https://discuss.elastic.co/u/Tommaso_FAVARON)\
**Replies:** 4\
**Last updated:** [February 8, 2024, 1:11pm UTC](https://discuss.elastic.co/t/multiple-inner-hit-on-knn/351893 "2024-02-08T13:11:35Z")

</div>

here my index mapping: { "chunker2": { "aliases": {}, "mappings": { "properties": { "creation\_time": { "type": "date" }, "full\_text": { "type": "text" …

---

## [How to setup a multi-node elasticsearch cluster in separate machines with ip specified in docker-compose.yml](https://discuss.elastic.co/t/how-to-setup-a-multi-node-elasticsearch-cluster-in-separate-machines-with-ip-specified-in-docker-compose-yml/352854)

<div class="topic-metadata">

**Author:** [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 12:12pm UTC](https://discuss.elastic.co/t/how-to-setup-a-multi-node-elasticsearch-cluster-in-separate-machines-with-ip-specified-in-docker-compose-yml/352854 "2024-02-08T12:12:15Z")

</div>

Hi guys, I would like to setup a multi-node elasticsearch v8.11.4 cluster using docker compose, "not in a single machine / host". I have 3 machines with IP 192.168.0.101, 192.168.0.102 and 192.168.0.103, and I want my …

---

## [Kibana alerts under stack management](https://discuss.elastic.co/t/kibana-alerts-under-stack-management/352597)

<div class="topic-metadata">

**Author:** [@anushasweety](https://discuss.elastic.co/u/anushasweety)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 11:57am UTC](https://discuss.elastic.co/t/kibana-alerts-under-stack-management/352597 "2024-02-08T11:57:38Z")

</div>

Hi, I'm trying to create alert in kibana for the device\_id creating highest number of logs and trigger a mail( we have number of edge device connected and file beat is installed to collect the logs and it will send it t…

---

## [Index not showing current metric data](https://discuss.elastic.co/t/index-not-showing-current-metric-data/352643)

<div class="topic-metadata">

**Author:** [@sajmeister](https://discuss.elastic.co/u/sajmeister)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 11:24am UTC](https://discuss.elastic.co/t/index-not-showing-current-metric-data/352643 "2024-02-08T11:24:02Z")

</div>

Hi, Our newly created Index named 'alerts\_to\_snow' used to show us the latest metric data when in Kibana \> Discover and then select data view named 'alerts\_to\_snow'. The data we get presented is up to Jan 29th 2024 on…

---

## [Cannot build logstash-output-elasticsearch plugin locally](https://discuss.elastic.co/t/cannot-build-logstash-output-elasticsearch-plugin-locally/352845)

<div class="topic-metadata">

**Author:** [@amaciejk](https://discuss.elastic.co/u/amaciejk)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 9:57am UTC](https://discuss.elastic.co/t/cannot-build-logstash-output-elasticsearch-plugin-locally/352845 "2024-02-08T09:57:03Z")

</div>

I'm attempting to build this plugin locally: However it fails seemingly due to a gemspec dependency issue: logstash-output-elasticsearch % jruby -S bundle install Fetching gem metadata from https://rubygems.org/.....…

---

## [Reindex vs Split Speed and Storage Requirements](https://discuss.elastic.co/t/reindex-vs-split-speed-and-storage-requirements/352719)

<div class="topic-metadata">

**Author:** [@zalseryani](https://discuss.elastic.co/u/zalseryani)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 9:43am UTC](https://discuss.elastic.co/t/reindex-vs-split-speed-and-storage-requirements/352719 "2024-02-08T09:43:06Z")

</div>

I have seen a previous topic discussing the difference in speed between reindexing and splitting for an index Reindex vs Split index speeds if splitting is much faster than reindexing since it is hard-linking the under…

---

## [Apparent bug in logstash-output-mongodb plugin v 3.1.7 for logstash logstash-7.17.17](https://discuss.elastic.co/t/apparent-bug-in-logstash-output-mongodb-plugin-v-3-1-7-for-logstash-logstash-7-17-17/352819)

<div class="topic-metadata">

**Author:** [@shaigaut](https://discuss.elastic.co/u/shaigaut)\
**Replies:** 2\
**Last updated:** [February 8, 2024, 9:38am UTC](https://discuss.elastic.co/t/apparent-bug-in-logstash-output-mongodb-plugin-v-3-1-7-for-logstash-logstash-7-17-17/352819 "2024-02-08T09:38:17Z")

</div>

I recently migrated from mongodb 3.0 to mongodb 6.0 and logstash plugin 3.1.5 was no longer working, I upgraded the plugin to 3.1.7 and I keep getting this error in logstash logs: n\] MONGODB | Error checking 127.0.0.1:2…

---

## [Aggregation with script code with previous result](https://discuss.elastic.co/t/aggregation-with-script-code-with-previous-result/352836)

<div class="topic-metadata">

**Author:** [@Fnizou](https://discuss.elastic.co/u/Fnizou)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 9:11am UTC](https://discuss.elastic.co/t/aggregation-with-script-code-with-previous-result/352836 "2024-02-08T09:11:51Z")

</div>

Hello everyone I would like to know if it is possible in 1 single request, in the aggregations, to make a script which calculates an aggs based on the previous results: I need to dynamically calculate the interval th…

---

## [Metricbeat error](https://discuss.elastic.co/t/metricbeat-error/352828)

<div class="topic-metadata">

**Author:** [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 8:58am UTC](https://discuss.elastic.co/t/metricbeat-error/352828 "2024-02-08T08:58:11Z")

</div>

Hello, Could anyone please tell me what kind of error is this : It is in my elasticsearch log /var/log/elasticsearch/elktest01.log. \[2024-02-08T09:03:07,475\]\[WARN \]\[o.e.x.m.MonitoringService\] \[testdata01\] monitoring …

---

## [Can minimum\_should\_match be 'boxed'](https://discuss.elastic.co/t/can-minimum-should-match-be-boxed/352417)

<div class="topic-metadata">

**Author:** [@bbaronas](https://discuss.elastic.co/u/bbaronas)\
**Replies:** 3\
**Last updated:** [February 7, 2024, 4:53pm UTC](https://discuss.elastic.co/t/can-minimum-should-match-be-boxed/352417 "2024-02-07T16:53:00Z")

</div>

Is it possible to use minimum\_should\_match to control an overabundance of should clauses in a boolean query? For context: I made a query builder that allows a user to add multiple texts that get translated into individ…

---

## [What is the meaning of \[YES... and \[NO... in kibana displayed error messages?](https://discuss.elastic.co/t/what-is-the-meaning-of-yes-and-no-in-kibana-displayed-error-messages/352555)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 2\
**Last updated:** [February 8, 2024, 6:51am UTC](https://discuss.elastic.co/t/what-is-the-meaning-of-yes-and-no-in-kibana-displayed-error-messages/352555 "2024-02-08T06:51:19Z")

</div>

What is the meaning of \[YES... and \[NO... in kibana displayed error messages?

---

## [Real time alert in Elasticsearch](https://discuss.elastic.co/t/real-time-alert-in-elasticsearch/352816)

<div class="topic-metadata">

**Author:** [@akashmaharana93](https://discuss.elastic.co/u/akashmaharana93)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 6:49am UTC](https://discuss.elastic.co/t/real-time-alert-in-elasticsearch/352816 "2024-02-08T06:49:17Z")

</div>

Hi Team I want to configure an alert in KIbana in such a way that it will be triggered for every specific error message comes to Elasticsearch. Ex : Suppose for a JWT validation failure my error code is ERROR1. So i wa…

---

## [Logstash : parse json input from http poller failing](https://discuss.elastic.co/t/logstash-parse-json-input-from-http-poller-failing/352787)

<div class="topic-metadata">

**Author:** [@Rasheed](https://discuss.elastic.co/u/Rasheed)\
**Replies:** 8\
**Last updated:** [February 8, 2024, 5:46am UTC](https://discuss.elastic.co/t/logstash-parse-json-input-from-http-poller-failing/352787 "2024-02-08T05:46:53Z")

</div>

I have a logstash configuration of http poller input, and elastic output, but i am struggling to store the json input from poller to index as documents. it stores the entire json as a single field but i need to store eac…

---

## [Realtime aggregations per application transaction](https://discuss.elastic.co/t/realtime-aggregations-per-application-transaction/352708)

<div class="topic-metadata">

**Author:** [@abduimrn](https://discuss.elastic.co/u/abduimrn)\
**Replies:** 6\
**Last updated:** [February 8, 2024, 5:01am UTC](https://discuss.elastic.co/t/realtime-aggregations-per-application-transaction/352708 "2024-02-08T05:01:40Z")

</div>

Hello all, I was wondering about whether Elasticsearch is the meant to be used for real time aggregations PER application transaction request? Is this one of use cases? application transaction request = incoming reques…

---

## [Filebeat on Mac - How to get unlocked workstation log?](https://discuss.elastic.co/t/filebeat-on-mac-how-to-get-unlocked-workstation-log/352814)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 1:55am UTC](https://discuss.elastic.co/t/filebeat-on-mac-how-to-get-unlocked-workstation-log/352814 "2024-02-08T01:55:59Z")

</div>

I recently installed filebeat on a Mac and have enabled the auditd and system modules. I am wondering what log represents an unlocked screen or login success. Thanks.

---

## [Allocate all unassigned shards at once!](https://discuss.elastic.co/t/allocate-all-unassigned-shards-at-once/352614)

<div class="topic-metadata">

**Author:** [@Johannes\_Haufila](https://discuss.elastic.co/u/Johannes_Haufila)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 10:32pm UTC](https://discuss.elastic.co/t/allocate-all-unassigned-shards-at-once/352614 "2024-02-07T22:32:16Z")

</div>

how to allocate all unassigned shards at once. In my case I have 2897 missing replicas on my cluster

---

## [Running Pipeline Manually](https://discuss.elastic.co/t/running-pipeline-manually/352777)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 10\
**Last updated:** [February 7, 2024, 10:14pm UTC](https://discuss.elastic.co/t/running-pipeline-manually/352777 "2024-02-07T22:14:34Z")

</div>

Quick Question for all: When I am trying to run my pipeline for logstash do I execute pipelines.yml, or just start up logstash? Based on this Documentation I believe I should be starting up logstash " This file is for…

---

## [Patterns defined under patterns\_dir are not valid](https://discuss.elastic.co/t/patterns-defined-under-patterns-dir-are-not-valid/352498)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 23\
**Last updated:** [February 7, 2024, 8:29pm UTC](https://discuss.elastic.co/t/patterns-defined-under-patterns-dir-are-not-valid/352498 "2024-02-07T20:29:39Z")

</div>

I would like to write a grok pattern for logstash using patterns\_dir for maillog based on the following document. There is a postfix-grok-patterns file in patterns\_dir with all the following patterns. I have added th…

---

## [Migrating Kibana Plugins from Angular.js](https://discuss.elastic.co/t/migrating-kibana-plugins-from-angular-js/352546)

<div class="topic-metadata">

**Author:** [@Neeecu](https://discuss.elastic.co/u/Neeecu)\
**Replies:** 6\
**Last updated:** [February 7, 2024, 8:15pm UTC](https://discuss.elastic.co/t/migrating-kibana-plugins-from-angular-js/352546 "2024-02-07T20:15:49Z")

</div>

Hello! I have an application with Elasticsearch 7.9.3 and Kibana 7.9.3 with some plugins which are written in plain Angular.js (directives, controllers, templates etc.) and no React code. I plan on migrating and upgrad…

---

## [Multiple aggregation in single query or single single aggregation in multiple query which will perform better](https://discuss.elastic.co/t/multiple-aggregation-in-single-query-or-single-single-aggregation-in-multiple-query-which-will-perform-better/352799)

<div class="topic-metadata">

**Author:** [@kuldeep\_gupta](https://discuss.elastic.co/u/kuldeep_gupta)\
**Replies:** 0\
**Last updated:** [February 7, 2024, 8:05pm UTC](https://discuss.elastic.co/t/multiple-aggregation-in-single-query-or-single-single-aggregation-in-multiple-query-which-will-perform-better/352799 "2024-02-07T20:05:09Z")

</div>

I Have to perform two aggregation let's say query1 = { "aggs": { "traffic": { "date\_histogram": { "field": "@timestamp", "fixed\_interval": "30s", …

---

## [Fortigate 30E not sending any logs to ubuntu/logstash](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270)

<div class="topic-metadata">

**Author:** [@dadafaf](https://discuss.elastic.co/u/dadafaf)\
**Replies:** 14\
**Last updated:** [February 7, 2024, 7:49pm UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270 "2024-02-07T19:49:14Z")

</div>

Hi! I have a problem that I need help with. I am using a Fortigate 30e firewall and a log server on a virtual machine with ELK stack and Logstash installed. The goal is to send logs from the Fortigate 30e to the log ser…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=310)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=312)
