# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=312

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 313

---

## [‏is there a shortcut instead of click to send request in kibana dev tools?](https://discuss.elastic.co/t/is-there-a-shortcut-instead-of-click-to-send-request-in-kibana-dev-tools/352740)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 5\
**Last updated:** [February 7, 2024, 7:40pm UTC](https://discuss.elastic.co/t/is-there-a-shortcut-instead-of-click-to-send-request-in-kibana-dev-tools/352740 "2024-02-07T19:40:24Z")

</div>

Is there a shortcut instead of click to send request in kibana dev tools?

---

## [AWS CloudFront Ingest Pipeline Failing](https://discuss.elastic.co/t/aws-cloudfront-ingest-pipeline-failing/352678)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 3\
**Last updated:** [February 7, 2024, 6:50pm UTC](https://discuss.elastic.co/t/aws-cloudfront-ingest-pipeline-failing/352678 "2024-02-07T18:50:13Z")

</div>

I am having an issue with logs ingesting into logs-aws.cloudfront\_logs-\* from a specific account, using Elastic Serverless Forwarder. In one specific account and this account only, I am receiving the following error in …

---

## [Error writing to Elastic search from Databricks](https://discuss.elastic.co/t/error-writing-to-elastic-search-from-databricks/352696)

<div class="topic-metadata">

**Author:** [@kichcha](https://discuss.elastic.co/u/kichcha)\
**Replies:** 5\
**Last updated:** [February 7, 2024, 6:34pm UTC](https://discuss.elastic.co/t/error-writing-to-elastic-search-from-databricks/352696 "2024-02-07T18:34:06Z")

</div>

Hello, I am an Elasticsearch newbie trying to connect to Elasticsearch on GCP from databricks on AWS. I tried following instructions provided by databricks (unable to post link here). However, I am now running into th…

---

## [Help requested to iterate and join sub-arrays](https://discuss.elastic.co/t/help-requested-to-iterate-and-join-sub-arrays/352408)

<div class="topic-metadata">

**Author:** [@lmw](https://discuss.elastic.co/u/lmw)\
**Replies:** 4\
**Last updated:** [February 7, 2024, 6:25pm UTC](https://discuss.elastic.co/t/help-requested-to-iterate-and-join-sub-arrays/352408 "2024-02-07T18:25:09Z")

</div>

Hi everyone, Please forgive me for my noob question, of it it has already been answered, but I have not been able to find it by myself. Let's consider that I have this datasource, with an arrays of vars, which may cont…

---

## [Error with datetime field in Kibana](https://discuss.elastic.co/t/error-with-datetime-field-in-kibana/352759)

<div class="topic-metadata">

**Author:** [@ehmontesinos](https://discuss.elastic.co/u/ehmontesinos)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 6:10pm UTC](https://discuss.elastic.co/t/error-with-datetime-field-in-kibana/352759 "2024-02-07T18:10:14Z")

</div>

Hi to everyone I have the following problem. I am exporting from a csv file to generate a dashboard with data that is read daily from that file, which is also generated daily. One of the fields that I include in the csv…

---

## [I need to get store.size in GB from \_cat/indices for all indices](https://discuss.elastic.co/t/i-need-to-get-store-size-in-gb-from-cat-indices-for-all-indices/352566)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 9\
**Last updated:** [February 7, 2024, 5:30pm UTC](https://discuss.elastic.co/t/i-need-to-get-store-size-in-gb-from-cat-indices-for-all-indices/352566 "2024-02-07T17:30:55Z")

</div>

I need to get store.size in GB from \_cat/indices for all indices in order to load the command results in excel and process the results in excel. That's what I need the store.size column to be all rows in the same measur…

---

## [Migrating Kibana Plugins from Angular.js](https://discuss.elastic.co/t/migrating-kibana-plugins-from-angular-js/352720)

<div class="topic-metadata">

**Author:** [@Neeecu](https://discuss.elastic.co/u/Neeecu)\
**Replies:** 2\
**Last updated:** [February 7, 2024, 4:55pm UTC](https://discuss.elastic.co/t/migrating-kibana-plugins-from-angular-js/352720 "2024-02-07T16:55:08Z")

</div>

Hello! I have an application with Elasticsearch 7.9.3 and Kibana 7.9.3 with some plugins which are written in plain Angular.js (directives, controllers, templates etc.) and no React code. I plan on migrating and upgrad…

---

## [Elastic Lucene Qeuery](https://discuss.elastic.co/t/elastic-lucene-qeuery/352784)

<div class="topic-metadata">

**Author:** [@RavaliJ](https://discuss.elastic.co/u/RavaliJ)\
**Replies:** 0\
**Last updated:** [February 7, 2024, 4:50pm UTC](https://discuss.elastic.co/t/elastic-lucene-qeuery/352784 "2024-02-07T16:50:58Z")

</div>

Hi I have Elasticsearch integrated as a datasource for my Grafana dashboard. I can see my raw data as below laong with few other feilds: Name Time\_Taken(in ms) abc 245 def 6 erg 58 How do i get …

---

## [Dashborad shows Internal Server error message about every change in Dashboard](https://discuss.elastic.co/t/dashborad-shows-internal-server-error-message-about-every-change-in-dashboard/352478)

<div class="topic-metadata">

**Author:** [@Mulee](https://discuss.elastic.co/u/Mulee)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 4:25pm UTC](https://discuss.elastic.co/t/dashborad-shows-internal-server-error-message-about-every-change-in-dashboard/352478 "2024-02-07T16:25:50Z")

</div>

When I make even very small change (for example, changing size), it should this error message and I cannot save my changes. What is the reason and what should I do? Is there any limits of numer of Graph in one dashboa…

---

## [Replace @timestamp with SYSLOGTIMESTAMP](https://discuss.elastic.co/t/replace-timestamp-with-syslogtimestamp/352725)

<div class="topic-metadata">

**Author:** [@vuvu](https://discuss.elastic.co/u/vuvu)\
**Replies:** 8\
**Last updated:** [February 7, 2024, 3:52pm UTC](https://discuss.elastic.co/t/replace-timestamp-with-syslogtimestamp/352725 "2024-02-07T15:52:26Z")

</div>

hi! I want to replace the @timestamp from the Dashboard with the timestamp from the logs that I get from some servers. The thing is that these logs have the SYSLOGTIMESTAMP format and just by using the date filter, it di…

---

## [How to reference Elasticsearch variable remotely](https://discuss.elastic.co/t/how-to-reference-elasticsearch-variable-remotely/352773)

<div class="topic-metadata">

**Author:** [@Stan\_Kendzior](https://discuss.elastic.co/u/Stan_Kendzior)\
**Replies:** 0\
**Last updated:** [February 7, 2024, 3:00pm UTC](https://discuss.elastic.co/t/how-to-reference-elasticsearch-variable-remotely/352773 "2024-02-07T15:00:52Z")

</div>

I am trying to include a reference to a variable that I have defined on the Elasticsearch side within a query. Running this query in the Dev Tools within Kibana works correctly. However, when I try to execute it through …

---

## [Help - Logstash multiple logs in single output](https://discuss.elastic.co/t/help-logstash-multiple-logs-in-single-output/352746)

<div class="topic-metadata">

**Author:** [@CDY1911](https://discuss.elastic.co/u/CDY1911)\
**Replies:** 2\
**Last updated:** [February 7, 2024, 1:39pm UTC](https://discuss.elastic.co/t/help-logstash-multiple-logs-in-single-output/352746 "2024-02-07T13:39:41Z")

</div>

Hi, Im currently stuck surrounding why my testfile is not outputting both types of logs (flow\_logs and URL\_logs). I've ran these both separately and they work fine However once i run the following code below. Im only o…

---

## [Error while running PUT https://\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*.us-central1.gcp.cloud.es.io//home/rahul/Downloads/epfile\_documents](https://discuss.elastic.co/t/error-while-running-put-https-us-central1-gcp-cloud-es-io-home-rahul-downloads-epfile-documents/352713)

<div class="topic-metadata">

**Author:** [@Rahul\_Patel1](https://discuss.elastic.co/u/Rahul_Patel1)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 1:21pm UTC](https://discuss.elastic.co/t/error-while-running-put-https-us-central1-gcp-cloud-es-io-home-rahul-downloads-epfile-documents/352713 "2024-02-07T13:21:38Z")

</div>

Hello, I am getting following error on starting the FSCrawler. 13:53:09,247 DEBUG \[f.p.e.c.f.c.ElasticsearchClient\] get version 13:53:10,062 DEBUG \[f.p.e.c.f.c.ElasticsearchClient\] get version returns 8.12.1 and 8 as t…

---

## [Help you need to configure log files via filebeat and not logstash](https://discuss.elastic.co/t/help-you-need-to-configure-log-files-via-filebeat-and-not-logstash/352742)

<div class="topic-metadata">

**Author:** [@v.popov](https://discuss.elastic.co/u/v.popov)\
**Replies:** 6\
**Last updated:** [February 7, 2024, 12:59pm UTC](https://discuss.elastic.co/t/help-you-need-to-configure-log-files-via-filebeat-and-not-logstash/352742 "2024-02-07T12:59:43Z")

</div>

Now everything is configured through logstash, but I need to use filebeat, how can I do this? Here is the logstash conf file input { beats { port =\> 5044 } } filter { if \[type\] == "nginx\_logs" { grok { …

---

## [Stack\_trace is coming under ignore\_fields section](https://discuss.elastic.co/t/stack-trace-is-coming-under-ignore-fields-section/352755)

<div class="topic-metadata">

**Author:** [@peterreji94](https://discuss.elastic.co/u/peterreji94)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 12:57pm UTC](https://discuss.elastic.co/t/stack-trace-is-coming-under-ignore-fields-section/352755 "2024-02-07T12:57:02Z")

</div>

since stack\_trace is marked as an ignored\_field, I'm unable to search for stack traces "\_ignored": \[ "stack\_trace" \], how can i move it out of the ignored\_field?

---

## [Is it elasticsearch going to be licensed](https://discuss.elastic.co/t/is-it-elasticsearch-going-to-be-licensed/352718)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 11:45am UTC](https://discuss.elastic.co/t/is-it-elasticsearch-going-to-be-licensed/352718 "2024-02-07T11:45:31Z")

</div>

Hi Team, Is Elasticsearch going to be paid version going forward, currently we are using elasticsearch 8.5.3 . Could you provide more on this. Thanks, Sarala K

---

## [What ingest pipeline will be used?](https://discuss.elastic.co/t/what-ingest-pipeline-will-be-used/352535)

<div class="topic-metadata">

**Author:** [@andy\_j](https://discuss.elastic.co/u/andy_j)\
**Replies:** 3\
**Last updated:** [February 7, 2024, 11:35am UTC](https://discuss.elastic.co/t/what-ingest-pipeline-will-be-used/352535 "2024-02-07T11:35:06Z")

</div>

In a Logstash -\> Elastic setup, how do we know which ingest pipeline will be used to process the data? As an example, in this guide we have the following Logstash config. What pipeline will be used in the else condition…

---

## [Guaranteed higher scores from one should query over another](https://discuss.elastic.co/t/guaranteed-higher-scores-from-one-should-query-over-another/352728)

<div class="topic-metadata">

**Author:** [@andy\_j](https://discuss.elastic.co/u/andy_j)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 11:07am UTC](https://discuss.elastic.co/t/guaranteed-higher-scores-from-one-should-query-over-another/352728 "2024-02-07T11:07:43Z")

</div>

I have a Elasticsearch query with three should queries of declining importance. How can I assert that documents returned from each should query has higher score than those of less importance? Maybe this could be solved …

---

## [DataStream does not roll over on primary shard max size](https://discuss.elastic.co/t/datastream-does-not-roll-over-on-primary-shard-max-size/352732)

<div class="topic-metadata">

**Author:** [@Roura\_Antoine](https://discuss.elastic.co/u/Roura_Antoine)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 10:57am UTC](https://discuss.elastic.co/t/datastream-does-not-roll-over-on-primary-shard-max-size/352732 "2024-02-07T10:57:35Z")

</div>

Hello, I'm new to Elastic. I am trying to configure a DataStream that must roll over when the primary shard size reach 1MB (it is a functional test), but it does not. Here is my ILM : PUT \_ilm/policy/short\_life\_policy…

---

## [Geoip in logstash filter makes filebeat pods stop running (0/1: running) after approximately 24 hours](https://discuss.elastic.co/t/geoip-in-logstash-filter-makes-filebeat-pods-stop-running-0-1-running-after-approximately-24-hours/352736)

<div class="topic-metadata">

**Author:** [@Kareem\_Afaneh](https://discuss.elastic.co/u/Kareem_Afaneh)\
**Replies:** 0\
**Last updated:** [February 7, 2024, 10:37am UTC](https://discuss.elastic.co/t/geoip-in-logstash-filter-makes-filebeat-pods-stop-running-0-1-running-after-approximately-24-hours/352736 "2024-02-07T10:37:48Z")

</div>

Hello everyone, I am using filebeat and send the logs to logstash, and in logstash i am using plugin 'geoip' like this: geoip { source =\> "source.ip" target =\> "\[source\]\[geo\]" } geoip { default\_database\_type =\> "…

---

## [\[lpseg2p\] \[spc\]\[0\], node\[r1Sz\_DsNSZ-wbxR35IPMpg\], \[P\], v\[20\], s\[STARTED\], a\[id=DEhEGi5WRZG5DiEHg7uvUw\]: failed to execute \[org.elasticsearch.action.percolate.PercolateRequest@350ed365\] RemoteTransportException\[\[lpseg2p\]\[11.22.23.19:9300\]\[indices:data/read](https://discuss.elastic.co/t/lpseg2p-spc-0-node-r1sz-dsnsz-wbxr35ipmpg-p-v-20-s-started-a-id-dehegi5wrzg5diehg7uvuw-failed-to-execute-org-elasticsearch-action-percolate-percolaterequest-350ed365-remotetransportexception-lpseg2p-11-22-23-19-9300-indices-data-read/352702)

<div class="topic-metadata">

**Author:** [@mobistar](https://discuss.elastic.co/u/mobistar)\
**Replies:** 4\
**Last updated:** [February 7, 2024, 9:02am UTC](https://discuss.elastic.co/t/lpseg2p-spc-0-node-r1sz-dsnsz-wbxr35ipmpg-p-v-20-s-started-a-id-dehegi5wrzg5diehg7uvuw-failed-to-execute-org-elasticsearch-action-percolate-percolaterequest-350ed365-remotetransportexception-lpseg2p-11-22-23-19-9300-indices-data-read/352702 "2024-02-07T09:02:40Z")

</div>

Hi Friend, I am getting given erron on elasticsearch can some one help to resove it. It have a big data on shared and we just recover shard \[0\] after renaming translog directory \\BR Manoj Kumar

---

## [Parsing logs with logstash](https://discuss.elastic.co/t/parsing-logs-with-logstash/352655)

<div class="topic-metadata">

**Author:** [@Nejmeddine\_Saidane](https://discuss.elastic.co/u/Nejmeddine_Saidane)\
**Replies:** 5\
**Last updated:** [February 7, 2024, 8:01am UTC](https://discuss.elastic.co/t/parsing-logs-with-logstash/352655 "2024-02-07T08:01:50Z")

</div>

I have this log {"data" =\> "\<Event xmlns='link'\>\<System\>\<Provider Name='Service Control Manager' Guid='{555908d1-a6d7-4695-8e1e-26931d2012f4}' EventSourceName='Service Control Manager'/\>\<EventID Qualifiers='16384'\>7036\</…

---

## [ILM and curator](https://discuss.elastic.co/t/ilm-and-curator/352706)

<div class="topic-metadata">

**Author:** [@Youssef\_Shehadeh](https://discuss.elastic.co/u/Youssef_Shehadeh)\
**Replies:** 0\
**Last updated:** [February 7, 2024, 7:55am UTC](https://discuss.elastic.co/t/ilm-and-curator/352706 "2024-02-07T07:55:03Z")

</div>

Hello All, I have a few questions about snapshots and restoring snapshots. Please consider this scenario: if I have an elastic cluster deployed in a production environment and to reduce storage, I take snapshots for ind…

---

## [Calculate differences between documents in a query](https://discuss.elastic.co/t/calculate-differences-between-documents-in-a-query/351519)

<div class="topic-metadata">

**Author:** [@mbby](https://discuss.elastic.co/u/mbby)\
**Replies:** 4\
**Last updated:** [February 7, 2024, 7:23am UTC](https://discuss.elastic.co/t/calculate-differences-between-documents-in-a-query/351519 "2024-02-07T07:23:55Z")

</div>

I need to calculate the MTBF of our systems which are monitored using the observatiblity uptime feature of Elasticsearch. Let's say that I've an index with the following values: time, system-name, state 10:00, system1…

---

## [Nginx ingress controller integration is not working](https://discuss.elastic.co/t/nginx-ingress-controller-integration-is-not-working/352592)

<div class="topic-metadata">

**Author:** [@Subrahmanyam\_Veerank](https://discuss.elastic.co/u/Subrahmanyam_Veerank)\
**Replies:** 5\
**Last updated:** [February 7, 2024, 6:11am UTC](https://discuss.elastic.co/t/nginx-ingress-controller-integration-is-not-working/352592 "2024-02-07T06:11:10Z")

</div>

Hi, we have enabled the kubernetes and nginx ingress controller integration on the elastic agent \[managed with fleet\] but the access & error logs are not coming and getting the below errors. 04:19.949 elastic\_agent \[…

---

## [HSTS Missing From HTTPS Server for elasticsearch](https://discuss.elastic.co/t/hsts-missing-from-https-server-for-elasticsearch/352694)

<div class="topic-metadata">

**Author:** [@kam89](https://discuss.elastic.co/u/kam89)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 4:47am UTC](https://discuss.elastic.co/t/hsts-missing-from-https-server-for-elasticsearch/352694 "2024-02-07T04:47:20Z")

</div>

Hi everyone, Good day and hope all of you are doing great! I am setting up an ELKStack server (version 8.12.0), mainly to do for testing purpose for data ingestion and our IT security team had run an assessment test be…

---

## [Grok Filter](https://discuss.elastic.co/t/grok-filter/352525)

<div class="topic-metadata">

**Author:** [@Emilie\_Carlier](https://discuss.elastic.co/u/Emilie_Carlier)\
**Replies:** 3\
**Last updated:** [February 6, 2024, 10:19pm UTC](https://discuss.elastic.co/t/grok-filter/352525 "2024-02-06T22:19:29Z")

</div>

Hello, I have event from Acces Point Dlink. I can parse some events but for this type I need your help: \<6\>1707130951,Src\_MAC="9E:98:48:98:8E:81",Dst\_MAC="EC:AD:E0:7D:5A:98",Src\_IP="10.229.64.250",Dst\_IP="17.57.146.17…

---

## [To use the full set of free features in this distribution of Kibana, please update Elasticsearch to the default distribution](https://discuss.elastic.co/t/to-use-the-full-set-of-free-features-in-this-distribution-of-kibana-please-update-elasticsearch-to-the-default-distribution/352572)

<div class="topic-metadata">

**Author:** [@e-ferrari](https://discuss.elastic.co/u/e-ferrari)\
**Replies:** 8\
**Last updated:** [February 6, 2024, 10:05pm UTC](https://discuss.elastic.co/t/to-use-the-full-set-of-free-features-in-this-distribution-of-kibana-please-update-elasticsearch-to-the-default-distribution/352572 "2024-02-06T22:05:13Z")

</div>

Hi, from what i understand it seems i have the OSS version of elasticsearch installed, but not the OSS version of Kibana. So i need now this "default distribution". Where do i get it ? And now trying to connect to Kib…

---

## [Can Logstash detect updates to TLS certificates?](https://discuss.elastic.co/t/can-logstash-detect-updates-to-tls-certificates/352684)

<div class="topic-metadata">

**Author:** [@jpelletier](https://discuss.elastic.co/u/jpelletier)\
**Replies:** 0\
**Last updated:** [February 6, 2024, 9:46pm UTC](https://discuss.elastic.co/t/can-logstash-detect-updates-to-tls-certificates/352684 "2024-02-06T21:46:10Z")

</div>

We run Logstash in a Kubernetes environment using Docker containers. We are looking to integrate cert-manager service to handle automatic updates to TLS certificates within the environment. Is Logstash setup in a way t…

---

## [Setting number\_of\_replicas on existing template](https://discuss.elastic.co/t/setting-number-of-replicas-on-existing-template/352672)

<div class="topic-metadata">

**Author:** [@parisila](https://discuss.elastic.co/u/parisila)\
**Replies:** 3\
**Last updated:** [February 6, 2024, 8:09pm UTC](https://discuss.elastic.co/t/setting-number-of-replicas-on-existing-template/352672 "2024-02-06T20:09:31Z")

</div>

Apologize for the screenshot but my elasticsearch instance is in a secure environment with only a jumphost browser that cannot copy anything out. Elastic Stack version 7.17.4 single node I am trying to update an index …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=311)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=313)
