# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=327

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 328

---

## [ElasticSearch Index Mapping for Dynamic](https://discuss.elastic.co/t/elasticsearch-index-mapping-for-dynamic/351325)

<div class="topic-metadata">

**Author:** [@Burak\_Karatay](https://discuss.elastic.co/u/Burak_Karatay)\
**Replies:** 1\
**Last updated:** [January 21, 2024, 7:55pm UTC](https://discuss.elastic.co/t/elasticsearch-index-mapping-for-dynamic/351325 "2024-01-21T19:55:54Z")

</div>

I have Nodejs Application and I want to send request and response to elastic, I have an issue with mapping, so basically my code looks like this: static sendLogToElastic = (req, res, next) =\> { const self = this; …

---

## [How to send multiline json file and send it to elasticsearch](https://discuss.elastic.co/t/how-to-send-multiline-json-file-and-send-it-to-elasticsearch/351500)

<div class="topic-metadata">

**Author:** [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Replies:** 1\
**Last updated:** [January 21, 2024, 5:45pm UTC](https://discuss.elastic.co/t/how-to-send-multiline-json-file-and-send-it-to-elasticsearch/351500 "2024-01-21T17:45:09Z")

</div>

I have a json log files which is in multi line json format and i need to send it to elasticsearch as it is. how can i do it?

---

## [Can't Install Winlogbeat](https://discuss.elastic.co/t/cant-install-winlogbeat/351492)

<div class="topic-metadata">

**Author:** [@aguskhohar](https://discuss.elastic.co/u/aguskhohar)\
**Replies:** 2\
**Last updated:** [January 21, 2024, 3:41pm UTC](https://discuss.elastic.co/t/cant-install-winlogbeat/351492 "2024-01-21T15:41:27Z")

</div>

I just installed winlogbeat, execute this on ps : .\\winlogbeat.exe setup --dashboards , and then get message this. fail to get the Kibana version: fail to parse kibana version (): passed version is not semver: Could yo…

---

## [A new contributor for elastic search](https://discuss.elastic.co/t/a-new-contributor-for-elastic-search/351480)

<div class="topic-metadata">

**Author:** [@hasanjaddouh](https://discuss.elastic.co/u/hasanjaddouh)\
**Replies:** 1\
**Last updated:** [January 21, 2024, 3:34pm UTC](https://discuss.elastic.co/t/a-new-contributor-for-elastic-search/351480 "2024-01-21T15:34:34Z")

</div>

Hello, My name is Hasan Jaddouh and I've been a software engineer at Noon for the past three years. Noon is very popular e-commerce company operating in the UAE. As part of my role, I handle the search engine responsibl…

---

## [Users in Kibana and Elasticsearch](https://discuss.elastic.co/t/users-in-kibana-and-elasticsearch/351496)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 3\
**Last updated:** [January 21, 2024, 3:05pm UTC](https://discuss.elastic.co/t/users-in-kibana-and-elasticsearch/351496 "2024-01-21T15:05:37Z")

</div>

Hello, Very basic question, but the documentation is not that clear I think. I am looking how elastic and kibana communicate user info. When creating a user in kibana is this user automaticaly available in elastic or …

---

## [How to Implement ILM on a Fixed Index?](https://discuss.elastic.co/t/how-to-implement-ilm-on-a-fixed-index/351493)

<div class="topic-metadata">

**Author:** [@vnajUWni](https://discuss.elastic.co/u/vnajUWni)\
**Replies:** 2\
**Last updated:** [January 21, 2024, 12:12pm UTC](https://discuss.elastic.co/t/how-to-implement-ilm-on-a-fixed-index/351493 "2024-01-21T12:12:07Z")

</div>

I am currently using the elasticsearch-logger plugin from APISIX (GitHub - apache/apisix: The Cloud-Native API Gateway) to write logs to Elasticsearch. However, this plugin does not support creating new index by date and…

---

## [\[Transforms\] How to add an aggregation field?](https://discuss.elastic.co/t/transforms-how-to-add-an-aggregation-field/350657)

<div class="topic-metadata">

**Author:** [@lizozom](https://discuss.elastic.co/u/lizozom)\
**Replies:** 3\
**Last updated:** [January 21, 2024, 11:34am UTC](https://discuss.elastic.co/t/transforms-how-to-add-an-aggregation-field/350657 "2024-01-21T11:34:40Z")

</div>

I'm using Transforms to pivot my log data for analytics. I want to add another aggregation to the transform (obviously only for future runs). I don't see this option in the UI neither in the API. Is it possible to add …

---

## [The parent/child of the join type sort by child field](https://discuss.elastic.co/t/the-parent-child-of-the-join-type-sort-by-child-field/351489)

<div class="topic-metadata">

**Author:** [@ChiMu\_Yuan](https://discuss.elastic.co/u/ChiMu_Yuan)\
**Replies:** 0\
**Last updated:** [January 21, 2024, 3:52am UTC](https://discuss.elastic.co/t/the-parent-child-of-the-join-type-sort-by-child-field/351489 "2024-01-21T03:52:55Z")

</div>

Hello everyone I'm not good at English.Please bear with some of my language errors. I have an index based on the parent-child structure using the join type. User can view the page based on the parent mode or the child…

---

## [Does not exist target folder in the external plugin in Kibana 8.10.4](https://discuss.elastic.co/t/does-not-exist-target-folder-in-the-external-plugin-in-kibana-8-10-4/350652)

<div class="topic-metadata">

**Author:** [@mzm1370](https://discuss.elastic.co/u/mzm1370)\
**Replies:** 2\
**Last updated:** [January 20, 2024, 8:14am UTC](https://discuss.elastic.co/t/does-not-exist-target-folder-in-the-external-plugin-in-kibana-8-10-4/350652 "2024-01-20T08:14:57Z")

</div>

Hi I installed the external plugin in KIbana and there is no exit target folder in the external plugin in Kibana 8.10.4 and no run Kibana 8.10.4

---

## [How to edit kibana.yml and incress kibana CSV report download size?](https://discuss.elastic.co/t/how-to-edit-kibana-yml-and-incress-kibana-csv-report-download-size/351059)

<div class="topic-metadata">

**Author:** [@MD\_Rezaul\_Karim](https://discuss.elastic.co/u/MD_Rezaul_Karim)\
**Replies:** 3\
**Last updated:** [January 19, 2024, 11:40pm UTC](https://discuss.elastic.co/t/how-to-edit-kibana-yml-and-incress-kibana-csv-report-download-size/351059 "2024-01-19T23:40:02Z")

</div>

How to edit kibana.yml and incress kibana CSV report download size?

---

## [Can\`t build and install kibana external plugins](https://discuss.elastic.co/t/can-t-build-and-install-kibana-external-plugins/351007)

<div class="topic-metadata">

**Author:** [@laripour](https://discuss.elastic.co/u/laripour)\
**Replies:** 2\
**Last updated:** [January 19, 2024, 11:25pm UTC](https://discuss.elastic.co/t/can-t-build-and-install-kibana-external-plugins/351007 "2024-01-19T23:25:01Z")

</div>

hi everyone. i have problem on Kibana 8.10.4 when i execute kibana plugin build command, target directory is not created in given .zip, and also .zip file can not be installed on production mode. thanks.

---

## [Visualization lens chart filter by max and min timestamp](https://discuss.elastic.co/t/visualization-lens-chart-filter-by-max-and-min-timestamp/350922)

<div class="topic-metadata">

**Author:** [@Liam619](https://discuss.elastic.co/u/Liam619)\
**Replies:** 1\
**Last updated:** [January 19, 2024, 11:13pm UTC](https://discuss.elastic.co/t/visualization-lens-chart-filter-by-max-and-min-timestamp/350922 "2024-01-19T23:13:38Z")

</div>

Hi everyone, I'm trying to figure out how to filter timestamp by getting the max and min of 2 date. I have tried to use "aggs" but I get error instead. I have a sql query condition that I need to turn into kibana chart…

---

## [View only Dashboard on ELK 8.6.2!](https://discuss.elastic.co/t/view-only-dashboard-on-elk-8-6-2/350816)

<div class="topic-metadata">

**Author:** [@Kvoyce2023](https://discuss.elastic.co/u/Kvoyce2023)\
**Replies:** 4\
**Last updated:** [January 19, 2024, 11:08pm UTC](https://discuss.elastic.co/t/view-only-dashboard-on-elk-8-6-2/350816 "2024-01-19T23:08:52Z")

</div>

Hi all, So I got a working cross cluster Kibana dashboard which we have built as superuser. Now we have a request to share this dashboard as view only mode with another department. For the above request , I created a …

---

## [Dashboards using \_cat APIs](https://discuss.elastic.co/t/dashboards-using-cat-apis/350888)

<div class="topic-metadata">

**Author:** [@jcruz](https://discuss.elastic.co/u/jcruz)\
**Replies:** 1\
**Last updated:** [January 19, 2024, 11:04pm UTC](https://discuss.elastic.co/t/dashboards-using-cat-apis/350888 "2024-01-19T23:04:32Z")

</div>

Hello guys, I would like to create some visualizations using the \_cat/indices API, so I can monitoring and understand the index usage during time. Is there any way to get the \_cat API output into some lens panels to c…

---

## [Kibana markdown - clickable location for an image linked to URL - take 2](https://discuss.elastic.co/t/kibana-markdown-clickable-location-for-an-image-linked-to-url-take-2/350753)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 1\
**Last updated:** [January 19, 2024, 10:47pm UTC](https://discuss.elastic.co/t/kibana-markdown-clickable-location-for-an-image-linked-to-url-take-2/350753 "2024-01-19T22:47:43Z")

</div>

Hello, Background: I had this issue where the clickable image area was only the bottom portion of the image. A fix (\[Dashboard\] Add styling to allow clickable TSVB markdown images by Heenawter · Pull Request #147802 ·…

---

## [\[ERROR\]\[plugins.fleet\] Failed to fetch latest version of cloud\_defend from registry:](https://discuss.elastic.co/t/error-plugins-fleet-failed-to-fetch-latest-version-of-cloud-defend-from-registry/350742)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 1\
**Last updated:** [January 19, 2024, 10:45pm UTC](https://discuss.elastic.co/t/error-plugins-fleet-failed-to-fetch-latest-version-of-cloud-defend-from-registry/350742 "2024-01-19T22:45:16Z")

</div>

Hi I am upgrading kibana from 7.17.13 to 8.11.3. Kibana working fine but I got a error logs in my syslog like below OS: ububtu 22.04 Jan 10 16:37:20 TEST02 kibana\[1285\]: \[2024-01-10T16:37:20.641+05:30\]\[ERROR\]\[plugins.…

---

## [Kibana - elasticsearch connexion](https://discuss.elastic.co/t/kibana-elasticsearch-connexion/350698)

<div class="topic-metadata">

**Author:** [@boubou](https://discuss.elastic.co/u/boubou)\
**Replies:** 1\
**Last updated:** [January 19, 2024, 10:36pm UTC](https://discuss.elastic.co/t/kibana-elasticsearch-connexion/350698 "2024-01-19T22:36:25Z")

</div>

Hello everyone, I just installed Kibana and Elasticsearch on my server. I downloaded versions 8.2.0 in tar.gz on Linux. To set up these two software, I modified two documents: elasticsearch.yml kibana.yml Here is th…

---

## [Elastic runtimes fields](https://discuss.elastic.co/t/elastic-runtimes-fields/350677)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 3\
**Last updated:** [January 19, 2024, 9:53pm UTC](https://discuss.elastic.co/t/elastic-runtimes-fields/350677 "2024-01-19T21:53:50Z")

</div>

Hi, I try to make a dashboard with term agg (with three different values). But one of the values is too big, so it does not show it. This is the field value So I guess thats why it does not appears on my visuali…

---

## [Index got locked](https://discuss.elastic.co/t/index-got-locked/351464)

<div class="topic-metadata">

**Author:** [@Keith\_Lin](https://discuss.elastic.co/u/Keith_Lin)\
**Replies:** 1\
**Last updated:** [January 19, 2024, 9:51pm UTC](https://discuss.elastic.co/t/index-got-locked/351464 "2024-01-19T21:51:12Z")

</div>

Jan 19, 2024 @ 12:17 PM PUT /\*/\_settings { "index": { "blocks.read\_only": false, "blocks.read\_only\_allow\_delete": null, "blocks.write": true } } The run the above. The blocks.write: true block all index…

---

## [Need help building dashboard](https://discuss.elastic.co/t/need-help-building-dashboard/351467)

<div class="topic-metadata">

**Author:** [@gnatola](https://discuss.elastic.co/u/gnatola)\
**Replies:** 1\
**Last updated:** [January 19, 2024, 9:45pm UTC](https://discuss.elastic.co/t/need-help-building-dashboard/351467 "2024-01-19T21:45:18Z")

</div>

Hello, I want to build a dashboard that shows users with failed logins and the number of failed logins for the last 24 hours. I built a dashboard, but it shows all users, even those whose login did not fail. How do I lim…

---

## [Software Inventory Management](https://discuss.elastic.co/t/software-inventory-management/350585)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 1\
**Last updated:** [January 19, 2024, 9:15pm UTC](https://discuss.elastic.co/t/software-inventory-management/350585 "2024-01-19T21:15:20Z")

</div>

Hi, We currently have 5000 virtual machines under monitoring using the Elastic Stack (using elastic agent). In light of recent changes, specifically the removal of the SAM module from ServiceNow, we are interested in cr…

---

## [How to delete kibana dashboard via API in ELK 8.11.3?](https://discuss.elastic.co/t/how-to-delete-kibana-dashboard-via-api-in-elk-8-11-3/350520)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [January 19, 2024, 8:29pm UTC](https://discuss.elastic.co/t/how-to-delete-kibana-dashboard-via-api-in-elk-8-11-3/350520 "2024-01-19T20:29:55Z")

</div>

Right now I'm using ELK 8.11.3 I made a Kibana Dashboard with the id 7eb136ba-4ef4-4f99-8ec3-b58673a748ec. Then I ran this curl statement to delete the dashboard: curl -k -X DELETE -u elastic:changeme "https://kibana:…

---

## [Logstash filter if statement when detecting multiple whitespace in middle of string](https://discuss.elastic.co/t/logstash-filter-if-statement-when-detecting-multiple-whitespace-in-middle-of-string/351457)

<div class="topic-metadata">

**Author:** [@mhoward](https://discuss.elastic.co/u/mhoward)\
**Replies:** 2\
**Last updated:** [January 19, 2024, 7:45pm UTC](https://discuss.elastic.co/t/logstash-filter-if-statement-when-detecting-multiple-whitespace-in-middle-of-string/351457 "2024-01-19T19:45:10Z")

</div>

Hey all. I'm working on a Logstash pipeline that includes processing addresses. Here's what my sample data might look like: " 123 ABC Street" "456 XYZ Street (a bunch of whitespaces here) PO Box 78…

---

## [Mismatch Between Query Result and Index Immediately After Re-Indexing](https://discuss.elastic.co/t/mismatch-between-query-result-and-index-immediately-after-re-indexing/351419)

<div class="topic-metadata">

**Author:** [@safakkbilici](https://discuss.elastic.co/u/safakkbilici)\
**Replies:** 6\
**Last updated:** [January 19, 2024, 7:49pm UTC](https://discuss.elastic.co/t/mismatch-between-query-result-and-index-immediately-after-re-indexing/351419 "2024-01-19T19:49:10Z")

</div>

Hello community, I have an index and our post-indexing step, we re-index the index and after, the pipeline (written in Java) uses an aggregation query to fetch product attributes (for example categories and their counts…

---

## [My Timestamp in audit log using SYSLOG input plugin not in correct format](https://discuss.elastic.co/t/my-timestamp-in-audit-log-using-syslog-input-plugin-not-in-correct-format/351127)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 9\
**Last updated:** [January 19, 2024, 7:07pm UTC](https://discuss.elastic.co/t/my-timestamp-in-audit-log-using-syslog-input-plugin-not-in-correct-format/351127 "2024-01-19T19:07:22Z")

</div>

Configuration is below : input { syslog { port =\> 5514 type =\> "scylladb" } } filter { if \[type\] == "scylladb" { grok{ match =\> {"message" =\> "%{IP:server\_ip}:%{DATA:server\_port},\\s%{DATA:categ…

---

## [Logstash Integration Plugin configuration option field issue (Logstash Input Plugin add\_filed issue)](https://discuss.elastic.co/t/logstash-integration-plugin-configuration-option-field-issue-logstash-input-plugin-add-filed-issue/351439)

<div class="topic-metadata">

**Author:** [@siva0030](https://discuss.elastic.co/u/siva0030)\
**Replies:** 3\
**Last updated:** [January 19, 2024, 6:58pm UTC](https://discuss.elastic.co/t/logstash-integration-plugin-configuration-option-field-issue-logstash-input-plugin-add-filed-issue/351439 "2024-01-19T18:58:13Z")

</div>

Hello Team, Good noon! Recently, I've upgraded my Logstash to 8.11.3 version. Starting from Logstash 8.11 version, Logstash Integration Plugin is available. I was trying to use the Logstash input plugin to receive the …

---

## [How to write the following Elastic Search into advanced script query?](https://discuss.elastic.co/t/how-to-write-the-following-elastic-search-into-advanced-script-query/351111)

<div class="topic-metadata">

**Author:** [@ElasticDev1](https://discuss.elastic.co/u/ElasticDev1)\
**Replies:** 8\
**Last updated:** [January 19, 2024, 4:22pm UTC](https://discuss.elastic.co/t/how-to-write-the-following-elastic-search-into-advanced-script-query/351111 "2024-01-19T16:22:18Z")

</div>

{ "took": 13, "timed\_out": false, "\_shards": { "total": 5, "successful": 5, "skipped": 0, "failed": 0 }, "hits": { "total": { "value": 2, "relation": "eq" }, "max\_score":…

---

## [Sort Results by Matching Pair of GeoPoints within a single document](https://discuss.elastic.co/t/sort-results-by-matching-pair-of-geopoints-within-a-single-document/351199)

<div class="topic-metadata">

**Author:** [@ty.mivance](https://discuss.elastic.co/u/ty.mivance)\
**Replies:** 3\
**Last updated:** [January 19, 2024, 3:16pm UTC](https://discuss.elastic.co/t/sort-results-by-matching-pair-of-geopoints-within-a-single-document/351199 "2024-01-19T15:16:43Z")

</div>

Hi Everyone, We have an elastic index that contains the following field mapping: "mappings": { "properties": { "destination": { "type": "geo\_point" }, …

---

## [One node with high specs vs two nodes with medium specs. Performance expectation](https://discuss.elastic.co/t/one-node-with-high-specs-vs-two-nodes-with-medium-specs-performance-expectation/351133)

<div class="topic-metadata">

**Author:** [@Prashant\_Rana](https://discuss.elastic.co/u/Prashant_Rana)\
**Replies:** 2\
**Last updated:** [January 19, 2024, 2:22pm UTC](https://discuss.elastic.co/t/one-node-with-high-specs-vs-two-nodes-with-medium-specs-performance-expectation/351133 "2024-01-19T14:22:49Z")

</div>

I want to know, what indexing performance (logs indexed per second) I can expect with the single machine of 16 cores,16GB vs two-node setup of 8 cores and 16 GB RAM. (Two shards per index. Both nodes contain one shar…

---

## [Metrics system overview dashboard redirects to a 404 Dashboard not found page in Kibana](https://discuss.elastic.co/t/metrics-system-overview-dashboard-redirects-to-a-404-dashboard-not-found-page-in-kibana/351033)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 10\
**Last updated:** [January 19, 2024, 2:22pm UTC](https://discuss.elastic.co/t/metrics-system-overview-dashboard-redirects-to-a-404-dashboard-not-found-page-in-kibana/351033 "2024-01-19T14:22:04Z")

</div>

Hello, We are using Kibana v8.10.4 and have installed elastic agent on one linux and a windows system. I do see logs/metrics coming in and see the dashboard visualizations getting populated for the Metrics system overv…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=326)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=328)
