# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=324

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 325

---

## [Elasticsearch Cluster health is RED](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-red/351622)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 8:02am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-red/351622 "2024-01-24T08:02:17Z")

</div>

Hi Team, We had Elasticsearch with two node and due to some infra issues the server went down . Once it become online , I started the service and it was successful. But while checking the log showing below error. Could…

---

## [SSL Cert in MySQL Connector](https://discuss.elastic.co/t/ssl-cert-in-mysql-connector/351687)

<div class="topic-metadata">

**Author:** [@DEXUAN\_ZHU](https://discuss.elastic.co/u/DEXUAN_ZHU)\
**Replies:** 0\
**Last updated:** [January 24, 2024, 7:38am UTC](https://discuss.elastic.co/t/ssl-cert-in-mysql-connector/351687 "2024-01-24T07:38:21Z")

</div>

Hi, I just wanna confirm the source of this SSL cert in MySQL. Is it elasticsearch cluster SSL or MySQL server SSL? Thanks I tried both, but got some connection issue.

---

## [Normalize data on time interval](https://discuss.elastic.co/t/normalize-data-on-time-interval/351556)

<div class="topic-metadata">

**Author:** [@venturieffect](https://discuss.elastic.co/u/venturieffect)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 7:34am UTC](https://discuss.elastic.co/t/normalize-data-on-time-interval/351556 "2024-01-24T07:34:26Z")

</div>

Hello Everyone, This might seem stupid but it's an issue I can't find a definitive answer and I'm not really sure how to search for it, so I might ask here: I'm trying to visualize server requests rate over time by sen…

---

## [Seeking Guidance on Implementing Retry Mechanism and Handling Delayed PubSub Messages in Bulk Document Operations](https://discuss.elastic.co/t/seeking-guidance-on-implementing-retry-mechanism-and-handling-delayed-pubsub-messages-in-bulk-document-operations/351627)

<div class="topic-metadata">

**Author:** [@Ivelin\_Yanev](https://discuss.elastic.co/u/Ivelin_Yanev)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 7:27am UTC](https://discuss.elastic.co/t/seeking-guidance-on-implementing-retry-mechanism-and-handling-delayed-pubsub-messages-in-bulk-document-operations/351627 "2024-01-24T07:27:04Z")

</div>

Dear all, I hope this message finds you well. I am currently immersed in the implementation of bulk operations for handling documents. The process involves receiving PubSub messages and dynamically generating correspon…

---

## [Logstash cannot upload to https Elasticsearch](https://discuss.elastic.co/t/logstash-cannot-upload-to-https-elasticsearch/351601)

<div class="topic-metadata">

**Author:** [@cisupport-zkb](https://discuss.elastic.co/u/cisupport-zkb)\
**Replies:** 13\
**Last updated:** [January 24, 2024, 7:13am UTC](https://discuss.elastic.co/t/logstash-cannot-upload-to-https-elasticsearch/351601 "2024-01-24T07:13:11Z")

</div>

Hi everyone, I'm having troubles on uploading data from a csv file to https Elasticsearch, using Logstash. This is the logstash.conf configured: input { file { path =\> "${pwd}/some-metrics.csv" fil…

---

## [Error while running pyspark connecting to elastic search](https://discuss.elastic.co/t/error-while-running-pyspark-connecting-to-elastic-search/351195)

<div class="topic-metadata">

**Author:** [@kashi\_mn](https://discuss.elastic.co/u/kashi_mn)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 5:03am UTC](https://discuss.elastic.co/t/error-while-running-pyspark-connecting-to-elastic-search/351195 "2024-01-24T05:03:36Z")

</div>

I am new to Pyspark and currently running pyspark and trying to connect to elasticsearch running on localhost. Below are the details : Elastic Details : localhost Port : 9200 No https. Code : from pyspark.sql impor…

---

## [API for Managing Synthetic monitoring](https://discuss.elastic.co/t/api-for-managing-synthetic-monitoring/350819)

<div class="topic-metadata">

**Author:** [@Raj\_Jikadra](https://discuss.elastic.co/u/Raj_Jikadra)\
**Replies:** 6\
**Last updated:** [January 24, 2024, 2:58am UTC](https://discuss.elastic.co/t/api-for-managing-synthetic-monitoring/350819 "2024-01-24T02:58:10Z")

</div>

To manage Monitors created via Synthetic monitoring, we can use @elastic/synthetics package, as per the code of @elastic/synthetics , it internally uses API to communicate with Kibana regarding monitor changes. I want t…

---

## [How to retrieve data from a data stream using Elasticsearch API keys](https://discuss.elastic.co/t/how-to-retrieve-data-from-a-data-stream-using-elasticsearch-api-keys/351343)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 12:41am UTC](https://discuss.elastic.co/t/how-to-retrieve-data-from-a-data-stream-using-elasticsearch-api-keys/351343 "2024-01-24T00:41:54Z")

</div>

Hello from Japan I have a question for you respected engineers. I would like to know about Elasticsearch API keys. I am using Winlogbeat (Ver8.11.1) to send Windows log information to Elasticsearch (Ver8.11.1). I wou…

---

## [Monitoring specific processes via Elastic Agent?](https://discuss.elastic.co/t/monitoring-specific-processes-via-elastic-agent/350037)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 3\
**Last updated:** [January 23, 2024, 11:31pm UTC](https://discuss.elastic.co/t/monitoring-specific-processes-via-elastic-agent/350037 "2024-01-23T23:31:21Z")

</div>

Does anyone have a good method for monitoring that specific processes are running, even if said processes are not in the top N cpu/ram usage group? The System integration lets you monitor the Top N processes. You can li…

---

## [Align date histogram to 6:00 instead of 0:00](https://discuss.elastic.co/t/align-date-histogram-to-6-00-instead-of-0-00/351436)

<div class="topic-metadata">

**Author:** [@allatrue](https://discuss.elastic.co/u/allatrue)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 9:48pm UTC](https://discuss.elastic.co/t/align-date-histogram-to-6-00-instead-of-0-00/351436 "2024-01-23T21:48:23Z")

</div>

Hello all! I'm trying to create a bar chart in Lens. It should aggregate some metrics using 8h buckets and use starting point at 6:00/14:00/22:00. I configured date histogram for horizontal axis, set minimum interval to…

---

## [Use variable to define index pattern in Vega query](https://discuss.elastic.co/t/use-variable-to-define-index-pattern-in-vega-query/351633)

<div class="topic-metadata">

**Author:** [@Ryan\_Clark](https://discuss.elastic.co/u/Ryan_Clark)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 9:36pm UTC](https://discuss.elastic.co/t/use-variable-to-define-index-pattern-in-vega-query/351633 "2024-01-23T21:36:12Z")

</div>

Hi, I have multiple queries and plan to have many more in this vega visualization. Right now, I define the index/index pattern in each query. Is there a way to make the index/index pattern a variable and then use the va…

---

## [Elastic Search causing major page memory errors on Azure Kubernetes (AKS)](https://discuss.elastic.co/t/elastic-search-causing-major-page-memory-errors-on-azure-kubernetes-aks/351670)

<div class="topic-metadata">

**Author:** [@DavidDean](https://discuss.elastic.co/u/DavidDean)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 9:35pm UTC](https://discuss.elastic.co/t/elastic-search-causing-major-page-memory-errors-on-azure-kubernetes-aks/351670 "2024-01-23T21:35:18Z")

</div>

ES version: 7.17.5.1 Hosting: Azure Kubernetes (AKS) Kubernetes: 1.24.9 Virtual machine: D8ads v5 (8 vCPUs, 32 GB RAM) Virtual machine OS: Ubuntu 18.04.6 LTS Prometheus is reporting very high rates of major memory p…

---

## [FULL SCREEN mode](https://discuss.elastic.co/t/full-screen-mode/351435)

<div class="topic-metadata">

**Author:** [@Charan\_Kumar\_reddy](https://discuss.elastic.co/u/Charan_Kumar_reddy)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 9:15pm UTC](https://discuss.elastic.co/t/full-screen-mode/351435 "2024-01-23T21:15:19Z")

</div>

Hi, Is there a way to set "Full screen" mode as default for a dashboard? The goal is that every time we call the dashboard, it will open in full screen mode, without having to click on the button. Thanks

---

## [Cant create a data view on fresh kibana deployment on k8s](https://discuss.elastic.co/t/cant-create-a-data-view-on-fresh-kibana-deployment-on-k8s/351663)

<div class="topic-metadata">

**Author:** [@kAs1m](https://discuss.elastic.co/u/kAs1m)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 8:30pm UTC](https://discuss.elastic.co/t/cant-create-a-data-view-on-fresh-kibana-deployment-on-k8s/351663 "2024-01-23T20:30:52Z")

</div>

I've deployed elasticsearch:8.5.1, fluent-bit:2.2.1 and kibana:8.5.1 via helm charts on my kubernetes cluster. When I login in kibana web interface and go to Analytics - Discover, this is the page I'm ending with: i.po…

---

## [Error reading empty line from CSV file with CSV codec](https://discuss.elastic.co/t/error-reading-empty-line-from-csv-file-with-csv-codec/351635)

<div class="topic-metadata">

**Author:** [@tsegars](https://discuss.elastic.co/u/tsegars)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 7:59pm UTC](https://discuss.elastic.co/t/error-reading-empty-line-from-csv-file-with-csv-codec/351635 "2024-01-23T19:59:08Z")

</div>

My input CSV files will have empty lines interspersed in them. The CSV codec decoder generates the following error when encountering an empty line: \[ERROR\]\[filewatch.tailmode.handlers.grow\]\[main\]\[62dd5eb2b6763ff5522ed54…

---

## [Failed parsing date from field Oracle alert log](https://discuss.elastic.co/t/failed-parsing-date-from-field-oracle-alert-log/351590)

<div class="topic-metadata">

**Author:** [@Prabhu\_Athithan](https://discuss.elastic.co/u/Prabhu_Athithan)\
**Replies:** 19\
**Last updated:** [January 23, 2024, 7:00pm UTC](https://discuss.elastic.co/t/failed-parsing-date-from-field-oracle-alert-log/351590 "2024-01-23T19:00:26Z")

</div>

Failed parsing date from field {:field=\>"timestamp", :value=\>"%{year} %{month} %{monthday} %{time}", :exception=\>"Invalid format: "%{year} %{month} %{monthday} %{t..."", :config\_parsers=\>"yyyy MMM dd HH:mm:ss", :config\_l…

---

## [Help in capturing E2E timestamp from raw logs](https://discuss.elastic.co/t/help-in-capturing-e2e-timestamp-from-raw-logs/351335)

<div class="topic-metadata">

**Author:** [@Anurag101](https://discuss.elastic.co/u/Anurag101)\
**Replies:** 5\
**Last updated:** [January 23, 2024, 5:41pm UTC](https://discuss.elastic.co/t/help-in-capturing-e2e-timestamp-from-raw-logs/351335 "2024-01-23T17:41:55Z")

</div>

Hi All, I am new to ELK and am trying to achieve a real time monitoring framework which captures E2E timestamp of an ansync logback application. The ask is to capture the timestamp corresponding to a unique ID in the l…

---

## [Elastic Cluster Balancing](https://discuss.elastic.co/t/elastic-cluster-balancing/351456)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 3\
**Last updated:** [January 23, 2024, 5:18pm UTC](https://discuss.elastic.co/t/elastic-cluster-balancing/351456 "2024-01-23T17:18:02Z")

</div>

ELK stack 8.11, How do i get my cluster to balance by available disk space, 1 node keeps hitting the watermark while the other 3 nodes have 2TB available Here are the Cluster settings { "persistent": { "cluster"…

---

## [No data in suricata dashboard](https://discuss.elastic.co/t/no-data-in-suricata-dashboard/351373)

<div class="topic-metadata">

**Author:** [@e-ferrari](https://discuss.elastic.co/u/e-ferrari)\
**Replies:** 6\
**Last updated:** [January 23, 2024, 4:56pm UTC](https://discuss.elastic.co/t/no-data-in-suricata-dashboard/351373 "2024-01-23T16:56:11Z")

</div>

Hi, i'm pretty new to ELK and struggling a lot. I try to read my suricata log with filebeat and visualize it with kibana. But the dashboard is empty: 0 events and "No results found". Suricata is running and constant…

---

## [Parse/process json array with filebeat](https://discuss.elastic.co/t/parse-process-json-array-with-filebeat/351455)

<div class="topic-metadata">

**Author:** [@andrejcoliveira](https://discuss.elastic.co/u/andrejcoliveira)\
**Replies:** 10\
**Last updated:** [January 23, 2024, 4:48pm UTC](https://discuss.elastic.co/t/parse-process-json-array-with-filebeat/351455 "2024-01-23T16:48:44Z")

</div>

Hi everyone, at my company we're trying to load our Cucumber logs to Elastic. Currently i want to check if it is possible to do it just using filebeat. The main problem to execute this task is that our logs are single li…

---

## [Failed to perform any bulk index operations: Post "http://my\_elastic\_ip/\_bulk": EOF](https://discuss.elastic.co/t/failed-to-perform-any-bulk-index-operations-post-http-my-elastic-ip-bulk-eof/351582)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 4:16pm UTC](https://discuss.elastic.co/t/failed-to-perform-any-bulk-index-operations-post-http-my-elastic-ip-bulk-eof/351582 "2024-01-23T16:16:06Z")

</div>

Hi, Im getting this errors in filebeat Jan 22 18:56:38 proxy-120 filebeat\[15099\]: 2024-01-22T18:56:38.420-0300 ERROR \[elasticsearch\] elasticsearch/client.go:226 failed to perform any bulk ind…

---

## [\`null\` is returned for sort instead of field value](https://discuss.elastic.co/t/null-is-returned-for-sort-instead-of-field-value/351642)

<div class="topic-metadata">

**Author:** [@sashatrn](https://discuss.elastic.co/u/sashatrn)\
**Replies:** 0\
**Last updated:** [January 23, 2024, 3:33pm UTC](https://discuss.elastic.co/t/null-is-returned-for-sort-instead-of-field-value/351642 "2024-01-23T15:33:19Z")

</div>

We have a strange behavior with sorting. The value returned for sorting is null. We decided to add a sub-field lowercase for all fields to support case-insensitive sorting. We did the following: Added custom lowercase…

---

## [Forcing a Logstash pipeline to restart](https://discuss.elastic.co/t/forcing-a-logstash-pipeline-to-restart/351639)

<div class="topic-metadata">

**Author:** [@intrepid1](https://discuss.elastic.co/u/intrepid1)\
**Replies:** 0\
**Last updated:** [January 23, 2024, 3:11pm UTC](https://discuss.elastic.co/t/forcing-a-logstash-pipeline-to-restart/351639 "2024-01-23T15:11:10Z")

</div>

Hi there, I have a pipeline that extracts documents from Elasticsearch and sends them to S3. I want to do some reconciliation on the process to prove that the number of documents extracted from Elasticsearch and the num…

---

## [Speeding up deep pagination for large ids query](https://discuss.elastic.co/t/speeding-up-deep-pagination-for-large-ids-query/351636)

<div class="topic-metadata">

**Author:** [@dsc](https://discuss.elastic.co/u/dsc)\
**Replies:** 0\
**Last updated:** [January 23, 2024, 2:45pm UTC](https://discuss.elastic.co/t/speeding-up-deep-pagination-for-large-ids-query/351636 "2024-01-23T14:45:08Z")

</div>

I've got an Elasticsearch index with ~100M documents, and typically need to search within a subset of them using an IDs query combined with other search terms/filters. These subsets of IDs are dynamic and come from an e…

---

## [Updating dateparts of timestamp using query update and/or reindex/pipeline](https://discuss.elastic.co/t/updating-dateparts-of-timestamp-using-query-update-and-or-reindex-pipeline/351618)

<div class="topic-metadata">

**Author:** [@petlit2049](https://discuss.elastic.co/u/petlit2049)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 2:41pm UTC](https://discuss.elastic.co/t/updating-dateparts-of-timestamp-using-query-update-and-or-reindex-pipeline/351618 "2024-01-23T14:41:08Z")

</div>

I have log-data from various sources that have been pre-indexed into "master indices". I'd like to re-use that data by copying/re-indexing it into new indices but with parts of the timestamp updated - year, month, day to…

---

## [Create independent indices](https://discuss.elastic.co/t/create-independent-indices/351603)

<div class="topic-metadata">

**Author:** [@marotaal](https://discuss.elastic.co/u/marotaal)\
**Replies:** 3\
**Last updated:** [January 23, 2024, 2:00pm UTC](https://discuss.elastic.co/t/create-independent-indices/351603 "2024-01-23T14:00:40Z")

</div>

Hello, I am setting up a lab for log collection (Apache, Sophos, ...) I want to create different indices for each device (Apache, Sophos, Windows, Linux, ...) Is it possible to create independent indices? How can thi…

---

## [Setting parameters from \[Canvas\] into \[Reporting\]](https://discuss.elastic.co/t/setting-parameters-from-canvas-into-reporting/351630)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 0\
**Last updated:** [January 23, 2024, 1:30pm UTC](https://discuss.elastic.co/t/setting-parameters-from-canvas-into-reporting/351630 "2024-01-23T13:30:32Z")

</div>

I would like to have a button in the canvas that could trigger a reporting job of all the data in the index within the selected range in the timefilter. Where could I start to achieve such thing? I've been looking into …

---

## [Size parameter ignored in nested knn search](https://discuss.elastic.co/t/size-parameter-ignored-in-nested-knn-search/350285)

<div class="topic-metadata">

**Author:** [@Jasper\_Simon](https://discuss.elastic.co/u/Jasper_Simon)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 12:34pm UTC](https://discuss.elastic.co/t/size-parameter-ignored-in-nested-knn-search/350285 "2024-01-23T12:34:34Z")

</div>

I noticed the quote below in the documentation, about the limitation to retrieve only the best match vector regardless of the "size" parameter in the inner\_hits section of the search request. inner\_hits for kNN will on…

---

## [Data nodes not ingesting new documents for over 10 min](https://discuss.elastic.co/t/data-nodes-not-ingesting-new-documents-for-over-10-min/351462)

<div class="topic-metadata">

**Author:** [@luana](https://discuss.elastic.co/u/luana)\
**Replies:** 4\
**Last updated:** [January 23, 2024, 12:10pm UTC](https://discuss.elastic.co/t/data-nodes-not-ingesting-new-documents-for-over-10-min/351462 "2024-01-23T12:10:00Z")

</div>

Hi, I've got about 10 data nodes (this value fluctuates throughout the day) that are triggering my "no new documents" alert, that'll trigger if a node doesn't ingest documents for over 10 minutes. When checking the logs…

---

## [I am trying to Use Webhook connector from ELK- Need Help](https://discuss.elastic.co/t/i-am-trying-to-use-webhook-connector-from-elk-need-help/350901)

<div class="topic-metadata">

**Author:** [@MOHAMMED\_ASIF\_Z](https://discuss.elastic.co/u/MOHAMMED_ASIF_Z)\
**Replies:** 6\
**Last updated:** [January 23, 2024, 11:45am UTC](https://discuss.elastic.co/t/i-am-trying-to-use-webhook-connector-from-elk-need-help/350901 "2024-01-23T11:45:14Z")

</div>

I am capturing IBM Tivoli Schedular logs using Elastic stach - so my idea is to retrigger a failed job based on the reasoning, so using query on the specify field i could get only the failure , but i want to try reach ou…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=323)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=325)
