# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=317

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 318

---

## [Metricbeat can not connect to elasticsearch](https://discuss.elastic.co/t/metricbeat-can-not-connect-to-elasticsearch/352301)

<div class="topic-metadata">

**Author:** [@Beeblbroy](https://discuss.elastic.co/u/Beeblbroy)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 2:07pm UTC](https://discuss.elastic.co/t/metricbeat-can-not-connect-to-elasticsearch/352301 "2024-02-01T14:07:34Z")

</div>

Hi! I have a VPS running ELK in docker, ports are lisening, and I cannot connect to it from another machine where i've installed metricbeat. ( tried it from two different machine, same issue) I got a following error aft…

---

## [Unable to retrieve version information from Elasticsearch nodes](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/352299)

<div class="topic-metadata">

**Author:** [@Twobuy1](https://discuss.elastic.co/u/Twobuy1)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 2:03pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/352299 "2024-02-01T14:03:56Z")

</div>

Elasticsearch starts up good then when i open up kibana i start gettting this issue. Please keep aware this is my first time doing this and new to any type of code. \[2024-02-01T05:55:42.170-08:00\]\[INFO \]\[plugins.alertin…

---

## [Help with my Query :)](https://discuss.elastic.co/t/help-with-my-query/351975)

<div class="topic-metadata">

**Author:** [@Kiwisaki](https://discuss.elastic.co/u/Kiwisaki)\
**Replies:** 2\
**Last updated:** [February 1, 2024, 1:46pm UTC](https://discuss.elastic.co/t/help-with-my-query/351975 "2024-02-01T13:46:28Z")

</div>

Can anyone advise where im going wrong with my query ? I am trying to achieve the following: Generate an Alert whenever event.code 4648 is seen - with the only exception being to not alert if the winlog.event\_data.Subj…

---

## [How to set precision\_threshold in Kibana 8.10 version](https://discuss.elastic.co/t/how-to-set-precision-threshold-in-kibana-8-10-version/350904)

<div class="topic-metadata">

**Author:** [@Sagesh](https://discuss.elastic.co/u/Sagesh)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 1:45pm UTC](https://discuss.elastic.co/t/how-to-set-precision-threshold-in-kibana-8-10-version/350904 "2024-02-01T13:45:04Z")

</div>

Precision\_threshold is not working in Kibana 8.10.2 version. I tried providing it in Advance Json like "{ "precision\_threshold":4000} but it throws an error. Thanks, Sagesh

---

## [Meaning of packages/methods with underscore prefix in java-api library](https://discuss.elastic.co/t/meaning-of-packages-methods-with-underscore-prefix-in-java-api-library/352295)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 1:44pm UTC](https://discuss.elastic.co/t/meaning-of-packages-methods-with-underscore-prefix-in-java-api-library/352295 "2024-02-01T13:44:44Z")

</div>

Just wondering why some of method calls like the following \_toQuery(), which was found in public docs, have underscore prefixes. I also saw this in some packages like \_types. Typically I see this done for internal usage,…

---

## [Snapshot creation failed](https://discuss.elastic.co/t/snapshot-creation-failed/352243)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 4:51am UTC](https://discuss.elastic.co/t/snapshot-creation-failed/352243 "2024-02-01T04:51:12Z")

</div>

HI Team, I was taken snapshot of Elasticsearch version 8.8.1, Then restored that snapshot into Elasticsearch version of 8.12.0. Now Tried to take snapshot from Elasticsearch version of 8.12.0 Getting an error as {"@ti…

---

## [How can a Threshold line be provided on a Vertical bar graph in Kibana?](https://discuss.elastic.co/t/how-can-a-threshold-line-be-provided-on-a-vertical-bar-graph-in-kibana/352259)

<div class="topic-metadata">

**Author:** [@Pushpender\_Singh](https://discuss.elastic.co/u/Pushpender_Singh)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 1:33pm UTC](https://discuss.elastic.co/t/how-can-a-threshold-line-be-provided-on-a-vertical-bar-graph-in-kibana/352259 "2024-02-01T13:33:07Z")

</div>

Hi Elastic Community, I am not able to get a threshold line on my Vertical bar graph, after selecting "Show Threshold Line" and configuring Panel Settings as shown below. Even after I update all the details as shown bel…

---

## [Elasticsearch and Kibana 8.11.3 running issue in WSL](https://discuss.elastic.co/t/elasticsearch-and-kibana-8-11-3-running-issue-in-wsl/352289)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 2\
**Last updated:** [February 1, 2024, 1:24pm UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-8-11-3-running-issue-in-wsl/352289 "2024-02-01T13:24:51Z")

</div>

Hi I am trying to run Elasticsearch and Kibana version 8.11.3 on Windows WSL version to build custom theme. I am able to run the yarn kbn bootstrap sucessfully. I have used below commands in separate windows to start …

---

## [\[Help\] Help about Winogbeat service failure](https://discuss.elastic.co/t/help-help-about-winogbeat-service-failure/352283)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 12:56pm UTC](https://discuss.elastic.co/t/help-help-about-winogbeat-service-failure/352283 "2024-02-01T12:56:57Z")

</div>

Hello From Japan Dear Elastic Engineers, I would like you to check a small problem that occurred in my environment. My environment is winlogbeat8.11 and I want to send Windows event viewer logs to Elaticsearch. The co…

---

## [Remote Cluster node 9300 port cannot connect](https://discuss.elastic.co/t/remote-cluster-node-9300-port-cannot-connect/352031)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 12:40pm UTC](https://discuss.elastic.co/t/remote-cluster-node-9300-port-cannot-connect/352031 "2024-02-01T12:40:56Z")

</div>

I am connecting a remote cluster from the local cluster. I got a connection time out error. Then I tried to curl the 9200 and 9300 port from the local cluster note to the remote cluster node. This is the response: curl …

---

## [Horizontal scaling of Elasticsearch cluster](https://discuss.elastic.co/t/horizontal-scaling-of-elasticsearch-cluster/352147)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 5\
**Last updated:** [February 1, 2024, 12:33pm UTC](https://discuss.elastic.co/t/horizontal-scaling-of-elasticsearch-cluster/352147 "2024-02-01T12:33:19Z")

</div>

if I have index size of 2tb and node size is 1tb , In that case how index will split on another nodes and if i add new data nodes so how this data can be distribute, it will do automatically? Or I can do it manually. I w…

---

## [Snapshot policy snapshot name as uniq ID](https://discuss.elastic.co/t/snapshot-policy-snapshot-name-as-uniq-id/352279)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 12:29pm UTC](https://discuss.elastic.co/t/snapshot-policy-snapshot-name-as-uniq-id/352279 "2024-02-01T12:29:50Z")

</div>

Hi Team, here is my snapshot policy snapshot name math expression \<test-snap-{now{MM-dd-yyyy\_HH-mm|Asia/Kolkata}}\> so the result should be test-snap-02-01-2024\_17-09 but in kibana UI the snapshot name showing as test-s…

---

## [Get the result of split two values into alert or another value](https://discuss.elastic.co/t/get-the-result-of-split-two-values-into-alert-or-another-value/351645)

<div class="topic-metadata">

**Author:** [@cperzrt10](https://discuss.elastic.co/u/cperzrt10)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 12:01pm UTC](https://discuss.elastic.co/t/get-the-result-of-split-two-values-into-alert-or-another-value/351645 "2024-02-01T12:01:13Z")

</div>

I have data with 2 variables, one is the total number of http response code and another is only the total of http response code with the value of "200". the structure is the result of transform the result is like this …

---

## [Stylizing TSVB or Lens in Canvas](https://discuss.elastic.co/t/stylizing-tsvb-or-lens-in-canvas/351459)

<div class="topic-metadata">

**Author:** [@Tom-Gorup](https://discuss.elastic.co/u/Tom-Gorup)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 11:54am UTC](https://discuss.elastic.co/t/stylizing-tsvb-or-lens-in-canvas/351459 "2024-02-01T11:54:43Z")

</div>

Running into a few challenges as I attempt to tackle this problem in myriad ways. First, my desired outcome is a (1) stylized horizontal bar chart using percentage (2) as the value for each aggregated row while includin…

---

## [I have created ubuntu server for receiving logs from fortigate30e using logstash](https://discuss.elastic.co/t/i-have-created-ubuntu-server-for-receiving-logs-from-fortigate30e-using-logstash/352278)

<div class="topic-metadata">

**Author:** [@Eepe123](https://discuss.elastic.co/u/Eepe123)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 11:29am UTC](https://discuss.elastic.co/t/i-have-created-ubuntu-server-for-receiving-logs-from-fortigate30e-using-logstash/352278 "2024-02-01T11:29:43Z")

</div>

Its not working and everything points to a network error, fortigate30e cant ping our ubuntu server but ubuntu server can ping fortigate firewall. Does anyone know anything we could try to fix network issue or could this …

---

## [Metricbeat package failure (mitchellh/osext not found)](https://discuss.elastic.co/t/metricbeat-package-failure-mitchellh-osext-not-found/352275)

<div class="topic-metadata">

**Author:** [@holodomi](https://discuss.elastic.co/u/holodomi)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 11:12am UTC](https://discuss.elastic.co/t/metricbeat-package-failure-mitchellh-osext-not-found/352275 "2024-02-01T11:12:35Z")

</div>

I am trying to build metricbeat from scratch but am getting hung up on 'https://github.com/mitchellh/osext/' apparently not existing anymore. I am building with: $ git clone https://github.com/elastic/beats.git $ cd be…

---

## [Secure Connection Between Filebeat & Logstash using Basic Auth](https://discuss.elastic.co/t/secure-connection-between-filebeat-logstash-using-basic-auth/352269)

<div class="topic-metadata">

**Author:** [@Dhiwakar\_Ravikumar](https://discuss.elastic.co/u/Dhiwakar_Ravikumar)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 10:22am UTC](https://discuss.elastic.co/t/secure-connection-between-filebeat-logstash-using-basic-auth/352269 "2024-02-01T10:22:05Z")

</div>

I want to secure the connection between filebeat & logstash using basic authentication. For logstash, I figured out that we can enable authentication for the logstash http input plugin BUT neither is such an option avai…

---

## [log whoever connects to the kibana web interface](https://discuss.elastic.co/t/log-whoever-connects-to-the-kibana-web-interface/352222)

<div class="topic-metadata">

**Author:** [@clocker87](https://discuss.elastic.co/u/clocker87)\
**Replies:** 5\
**Last updated:** [February 1, 2024, 9:44am UTC](https://discuss.elastic.co/t/log-whoever-connects-to-the-kibana-web-interface/352222 "2024-02-01T09:44:58Z")

</div>

Hi everyone, I need to have logs of who connects to the kibana web interface, I have several accounts and I would like to be able to monitor these accesses. I have kibana version 8.3.2, what can I do? Thank you

---

## [Generates self-signed client certificates (not server certificates) for Elasticsearch clients](https://discuss.elastic.co/t/generates-self-signed-client-certificates-not-server-certificates-for-elasticsearch-clients/352182)

<div class="topic-metadata">

**Author:** [@patpanda](https://discuss.elastic.co/u/patpanda)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 6:58am UTC](https://discuss.elastic.co/t/generates-self-signed-client-certificates-not-server-certificates-for-elasticsearch-clients/352182 "2024-02-01T06:58:04Z")

</div>

What I am trying to achieve Generates self-signed client certificate (not server certificates) for clients trying to connect to Elasticsearch server. What did I try: I ran this command elasticsearch/bin elasticsearc…

---

## [Filebeats doesn't send logs to Elasticsearch](https://discuss.elastic.co/t/filebeats-doesnt-send-logs-to-elasticsearch/352255)

<div class="topic-metadata">

**Author:** [@Vladimir\_Fomin1](https://discuss.elastic.co/u/Vladimir_Fomin1)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 6:45am UTC](https://discuss.elastic.co/t/filebeats-doesnt-send-logs-to-elasticsearch/352255 "2024-02-01T06:45:23Z")

</div>

I have some problems with Filebeats 8.12.0. in the Kubernetes cluster. My filebeat.yml: filebeat.inputs: - type: filestream paths: - /var/log/pods/\*\*/\*.log parsers: - container: ~ prospector: scanner…

---

## [How to bulk migrate users and roles with native realms authentication](https://discuss.elastic.co/t/how-to-bulk-migrate-users-and-roles-with-native-realms-authentication/350476)

<div class="topic-metadata">

**Author:** [@fim](https://discuss.elastic.co/u/fim)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 6:31am UTC](https://discuss.elastic.co/t/how-to-bulk-migrate-users-and-roles-with-native-realms-authentication/350476 "2024-02-01T06:31:08Z")

</div>

I'm looking for an advice how to migrate users (if possible including passwords) and roles from an old cluster to a new cluster. (Elasticsearch v8.x) I wanna perform this with Kibana DevTools. I populate users and role…

---

## [\[Filebeat\] How to read "special text + json string" to es?](https://discuss.elastic.co/t/filebeat-how-to-read-special-text-json-string-to-es/352251)

<div class="topic-metadata">

**Author:** [@uiosun](https://discuss.elastic.co/u/uiosun)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 6:21am UTC](https://discuss.elastic.co/t/filebeat-how-to-read-special-text-json-string-to-es/352251 "2024-02-01T06:21:40Z")

</div>

I have the struct in log files, like there (JSON has near 60 column......): \[2024-01-29 11:10:35\] standard.INFO: {"start\_time": "1706497834.091", "remote\_addr": "www.demo.com", "remote\_user": "a\_user"} \[2024-01-29 11:10…

---

## [Filebeat connecting to a ES cluster that is removed from config file](https://discuss.elastic.co/t/filebeat-connecting-to-a-es-cluster-that-is-removed-from-config-file/352238)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 1:46am UTC](https://discuss.elastic.co/t/filebeat-connecting-to-a-es-cluster-that-is-removed-from-config-file/352238 "2024-02-01T01:46:27Z")

</div>

Hi, I had previously configured filebeat to connect to 2 ES hosts in filebeat.yml. I have modified the config file to output.elasticsearch.hosts: \["es02.net:443"\] #output.elasticsearch.hosts: \["es01.net:443", "es02.net…

---

## [Daemon startup failed with exit code](https://discuss.elastic.co/t/daemon-startup-failed-with-exit-code/352221)

<div class="topic-metadata">

**Author:** [@userR](https://discuss.elastic.co/u/userR)\
**Replies:** 2\
**Last updated:** [January 31, 2024, 11:19pm UTC](https://discuss.elastic.co/t/daemon-startup-failed-with-exit-code/352221 "2024-01-31T23:19:54Z")

</div>

Hi everyone, I am testing out esrally and running into the following issues while running java17 and testing 8.7.0: \[user ~\]$ esrally race --distribution-version=8.7.0 --track=geonames \_\_\_\_ \_\_\_\_ / \_\_ \\\_\_…

---

## [Packetbeat mysql only works if metricbeat mysql enabled?](https://discuss.elastic.co/t/packetbeat-mysql-only-works-if-metricbeat-mysql-enabled/352113)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [January 31, 2024, 9:37pm UTC](https://discuss.elastic.co/t/packetbeat-mysql-only-works-if-metricbeat-mysql-enabled/352113 "2024-01-31T21:37:05Z")

</div>

My goal is to go to Kibana \> Dashboard \> \[Packetbeat\] MySQL performance ECS and see some visualizations of my mysql performance. I find that \[Packetbeat\] MySQL performance only shows a bunch of No results found widgets.…

---

## [Logstash 8.11 reports error 403](https://discuss.elastic.co/t/logstash-8-11-reports-error-403/352224)

<div class="topic-metadata">

**Author:** [@andrew3](https://discuss.elastic.co/u/andrew3)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 9:08pm UTC](https://discuss.elastic.co/t/logstash-8-11-reports-error-403/352224 "2024-01-31T21:08:42Z")

</div>

I am trying to connect logstash to elasticsearch. Both are on my local machine. I am using https. Logstash reports error 403. Viz: \` {:code=\>403, :url=\>"https://localhost:9200/\_bulk?filter\_path=errors,items.\*.error,i…

---

## [Logstash installation batch files v8.11.3 do not work](https://discuss.elastic.co/t/logstash-installation-batch-files-v8-11-3-do-not-work/351306)

<div class="topic-metadata">

**Author:** [@andrew3](https://discuss.elastic.co/u/andrew3)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 8:41pm UTC](https://discuss.elastic.co/t/logstash-installation-batch-files-v8-11-3-do-not-work/351306 "2024-01-31T20:41:43Z")

</div>

JRUBY\_BIN: In v8.11.3 SETUP.BAT looks for it in a directory that does not exist in the Windows distribution, causing the "first stash" in the docs. to always fail. Anyone else run across this? Details: In SETUP.BAT lin…

---

## [How to create Sub categories in Data table?](https://discuss.elastic.co/t/how-to-create-sub-categories-in-data-table/352117)

<div class="topic-metadata">

**Author:** [@Shubhankar](https://discuss.elastic.co/u/Shubhankar)\
**Replies:** 4\
**Last updated:** [January 31, 2024, 8:05pm UTC](https://discuss.elastic.co/t/how-to-create-sub-categories-in-data-table/352117 "2024-01-31T20:05:20Z")

</div>

I have generated a data table using the Kibana 8 lens visualization, but I'm uncertain about adding subcategories to it. Specifically, after including the necessary columns, I aim to further segment the data from the sec…

---

## [Unable to download Kibana Windows Winzip](https://discuss.elastic.co/t/unable-to-download-kibana-windows-winzip/351365)

<div class="topic-metadata">

**Author:** [@SPT](https://discuss.elastic.co/u/SPT)\
**Replies:** 2\
**Last updated:** [January 31, 2024, 5:29pm UTC](https://discuss.elastic.co/t/unable-to-download-kibana-windows-winzip/351365 "2024-01-31T17:29:46Z")

</div>

I tried to extract the zip file but it complains that the path is too long on some files. Any advice or an alternate option to get this? Thanks.

---

## [FSCrawler - Indexing mix of Big and small files - HTTP Entity too large error](https://discuss.elastic.co/t/fscrawler-indexing-mix-of-big-and-small-files-http-entity-too-large-error/350939)

<div class="topic-metadata">

**Author:** [@kamalsharma](https://discuss.elastic.co/u/kamalsharma)\
**Replies:** 8\
**Last updated:** [January 31, 2024, 5:12pm UTC](https://discuss.elastic.co/t/fscrawler-indexing-mix-of-big-and-small-files-http-entity-too-large-error/350939 "2024-01-31T17:12:19Z")

</div>

I have splitted a large text file into multiple files of 50 MB each. When the setting of bulk\_size is 1 in Fscrawler \_settings.json, each file is indexed into Elasticsearch without any error. If the bulk size is increase…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=316)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=318)
