# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=338

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 339

---

## [Configure LDAP Authentication](https://discuss.elastic.co/t/configure-ldap-authentication/350460)

<div class="topic-metadata">

**Author:** [@kadmin](https://discuss.elastic.co/u/kadmin)\
**Replies:** 3\
**Last updated:** [January 5, 2024, 3:34pm UTC](https://discuss.elastic.co/t/configure-ldap-authentication/350460 "2024-01-05T15:34:53Z")

</div>

Hello I want to configure LDAP authentication for my elastic cluster. On a test cluster I can check the configs before going to production. For this I use docker with this git repo. elasticsearch.yml cluster.name: do…

---

## [How to delete huge number of documents from Index? What can be better option?](https://discuss.elastic.co/t/how-to-delete-huge-number-of-documents-from-index-what-can-be-better-option/350469)

<div class="topic-metadata">

**Author:** [@msabnis79](https://discuss.elastic.co/u/msabnis79)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 2:31pm UTC](https://discuss.elastic.co/t/how-to-delete-huge-number-of-documents-from-index-what-can-be-better-option/350469 "2024-01-05T14:31:48Z")

</div>

For example, we are having 2 billion documents in an index in ES and want to delete 1 billion documents based on some data from Oracle database? So i have to copy data from Oracle 1 billion records and based on Primary …

---

## [Kibana Discover browser title (looks) not set 1st time](https://discuss.elastic.co/t/kibana-discover-browser-title-looks-not-set-1st-time/350458)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 1:48pm UTC](https://discuss.elastic.co/t/kibana-discover-browser-title-looks-not-set-1st-time/350458 "2024-01-05T13:48:53Z")

</div>

Hello, I noticed Kibana puts name of Discover search in browser title. This is very useful feature, but I see it is "unreliable". When I save search for first time, it sets title to "Discover: Errors". When I load sa…

---

## [Sharding and index settings](https://discuss.elastic.co/t/sharding-and-index-settings/350457)

<div class="topic-metadata">

**Author:** [@Mertozturkk](https://discuss.elastic.co/u/Mertozturkk)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 12:31pm UTC](https://discuss.elastic.co/t/sharding-and-index-settings/350457 "2024-01-05T12:31:39Z")

</div>

The 3 Node Elasticsearch we have set up currently has a 6TB index set into 16 P and 1 R shards and is slow to respond to queries. If we want to create an index from scratch that will reach a similar volume in the new ver…

---

## [Csp error for custom kibana login page](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701)

<div class="topic-metadata">

**Author:** [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Replies:** 9\
**Last updated:** [January 5, 2024, 11:42am UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701 "2024-01-05T11:42:28Z")

</div>

heeyy i am using a custom plugin for my kibana that changes the login page to give a custom look but i am getting an errror relating to csp

---

## [Visualize customerId mapped to customer name in e.g. Kibana table](https://discuss.elastic.co/t/visualize-customerid-mapped-to-customer-name-in-e-g-kibana-table/350390)

<div class="topic-metadata">

**Author:** [@rickardo](https://discuss.elastic.co/u/rickardo)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 9:43am UTC](https://discuss.elastic.co/t/visualize-customerid-mapped-to-customer-name-in-e-g-kibana-table/350390 "2024-01-05T09:43:30Z")

</div>

We have reports entries like below and Visualize statistics from "reports" in a Kibana table. But to show customerId=1 makes no sense so want to show them by their name that are defined in another Index in this case. L…

---

## [LDAP Configuration - ELK 8.8.1](https://discuss.elastic.co/t/ldap-configuration-elk-8-8-1/350444)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 9:42am UTC](https://discuss.elastic.co/t/ldap-configuration-elk-8-8-1/350444 "2024-01-05T09:42:50Z")

</div>

I'm currently configuring the LDAP on my coordinator & Kibana nodes (8.8.1) Here are the steps I've taken: Tested the connection with the LDAP server on my coordinator, and it's successful. Configured my elasticsearc…

---

## [Logstash tcp input plugin connection reset error](https://discuss.elastic.co/t/logstash-tcp-input-plugin-connection-reset-error/350441)

<div class="topic-metadata">

**Author:** [@fmelk65](https://discuss.elastic.co/u/fmelk65)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 9:10am UTC](https://discuss.elastic.co/t/logstash-tcp-input-plugin-connection-reset-error/350441 "2024-01-05T09:10:16Z")

</div>

Hello, I have 25 Kubernetes clusters forward their logs to logstash VM (k8s fluentd ---\> logstash). I'm getting a lot of connection reset errors. It's been discussed here before, can @true64gurus specifically help? \[…

---

## [How to set volume map for logstash.conf file in docker compose file](https://discuss.elastic.co/t/how-to-set-volume-map-for-logstash-conf-file-in-docker-compose-file/350422)

<div class="topic-metadata">

**Author:** [@Sunny84](https://discuss.elastic.co/u/Sunny84)\
**Replies:** 1\
**Last updated:** [January 5, 2024, 8:46am UTC](https://discuss.elastic.co/t/how-to-set-volume-map-for-logstash-conf-file-in-docker-compose-file/350422 "2024-01-05T08:46:06Z")

</div>

Hello, I am trying to setup a docker compose file for setting up ELK stack to be able to use logging on local machine. Below is the error shown in the terminal window, my stack is windows 11 home, Docker Engine v24.0.7,…

---

## [What is the meaning of brackets in an index name?](https://discuss.elastic.co/t/what-is-the-meaning-of-brackets-in-an-index-name/350376)

<div class="topic-metadata">

**Author:** [@mbby](https://discuss.elastic.co/u/mbby)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 7:24am UTC](https://discuss.elastic.co/t/what-is-the-meaning-of-brackets-in-an-index-name/350376 "2024-01-05T07:24:22Z")

</div>

We are using heartbeat and I saw a data view like this: (synthetics-data-view),heartbeat-8,heartbeat-7\*,synthetics-\* Why is synthetics-data-view written in brackets?

---

## [Watermark sonarqube](https://discuss.elastic.co/t/watermark-sonarqube/350406)

<div class="topic-metadata">

**Author:** [@walterh91](https://discuss.elastic.co/u/walterh91)\
**Replies:** 3\
**Last updated:** [January 5, 2024, 7:17am UTC](https://discuss.elastic.co/t/watermark-sonarqube/350406 "2024-01-05T07:17:18Z")

</div>

Hello how are you? Currently, I am using two versions of SonarQube: Development environment: Community Edition Version 9.1 (build 47736) Production environment: Developer Edition Version 9.9.1 (build 69595) In both c…

---

## [Error-Failed version compatibility check with elasticsearch: tls: failed to verify certificate: x509: certificate signed by unknown authority](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711)

<div class="topic-metadata">

**Author:** [@Austin1](https://discuss.elastic.co/u/Austin1)\
**Replies:** 6\
**Last updated:** [January 5, 2024, 5:26am UTC](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711 "2024-01-05T05:26:41Z")

</div>

Hi all , Please help me with setting up elastic agent container! I got below error when I used podman run command followed: Error-Failed version compatibility check with elasticsearch: tls: failed to verify certificat…

---

## [Error Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate](https://discuss.elastic.co/t/error-unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/350389)

<div class="topic-metadata">

**Author:** [@kray](https://discuss.elastic.co/u/kray)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 4:32am UTC](https://discuss.elastic.co/t/error-unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/350389 "2024-01-05T04:32:47Z")

</div>

please help, when I open the wazuh web the following error and I checked the kibana log, there is the following error {"type":"log","@timestamp":"2024-01-04T20:11:27+07:00","tags":\["error","elasticsearch-service"\],"p…

---

## [Parse Kibana Query to sql object](https://discuss.elastic.co/t/parse-kibana-query-to-sql-object/350335)

<div class="topic-metadata">

**Author:** [@Ofir\_Safin](https://discuss.elastic.co/u/Ofir_Safin)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 10:35pm UTC](https://discuss.elastic.co/t/parse-kibana-query-to-sql-object/350335 "2024-01-04T22:35:27Z")

</div>

Hi everyone, I'm trying to monitor logs from Elasticsearch in python My problem is that each log has a different structure. For example: "error" and applicationName :"test" "query" will be like this: { "bool": { …

---

## [Changing the log-in text](https://discuss.elastic.co/t/changing-the-log-in-text/350363)

<div class="topic-metadata">

**Author:** [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 6:27pm UTC](https://discuss.elastic.co/t/changing-the-log-in-text/350363 "2024-01-04T18:27:49Z")

</div>

Hey there, I am trying to change the login text to "Welcome to Elastic." I tried changing the source code in the \\kibana-7.17.0-windowsx86\_64\\xpack\\plugins\\security\\target\\public\\security.chunk.5.js file, but it won't wo…

---

## [Backup/Restore Indexes](https://discuss.elastic.co/t/backup-restore-indexes/350411)

<div class="topic-metadata">

**Author:** [@marcowiskhy](https://discuss.elastic.co/u/marcowiskhy)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 8:31pm UTC](https://discuss.elastic.co/t/backup-restore-indexes/350411 "2024-01-04T20:31:25Z")

</div>

Hey guys, I have an Elasticsearch node in production and am experiencing issues regarding disk storage. At the moment I cannot increase computational resources or add other nodes because I depend on collaboration with a…

---

## [What should be specified in the filebeats config to connect to Elastic search cloud?](https://discuss.elastic.co/t/what-should-be-specified-in-the-filebeats-config-to-connect-to-elastic-search-cloud/350401)

<div class="topic-metadata">

**Author:** [@jcc2186](https://discuss.elastic.co/u/jcc2186)\
**Replies:** 4\
**Last updated:** [January 4, 2024, 7:52pm UTC](https://discuss.elastic.co/t/what-should-be-specified-in-the-filebeats-config-to-connect-to-elastic-search-cloud/350401 "2024-01-04T19:52:40Z")

</div>

I am trying to setup filebeats to connect to elasticsearch cloud to send my custom application .json log file. What configuration setting do I need to add to the filebeat.yml config to send logs to the correct elasticse…

---

## [Can't log in other than from the local host](https://discuss.elastic.co/t/cant-log-in-other-than-from-the-local-host/349883)

<div class="topic-metadata">

**Author:** [@rcfa](https://discuss.elastic.co/u/rcfa)\
**Replies:** 3\
**Last updated:** [January 4, 2024, 7:51pm UTC](https://discuss.elastic.co/t/cant-log-in-other-than-from-the-local-host/349883 "2024-01-04T19:51:08Z")

</div>

I'm a newby, so excuse if I ask a dummy question, but I got to start somewhere, and being able to log in is, well, prerequisite... So on my server, let's call it 10.0.0.1 I have installed the Elasticsearch and kibana pa…

---

## [savedVisualization / embeddable in canvas broken after upgrading to version 8.9.2 due to saved Objects Id](https://discuss.elastic.co/t/savedvisualization-embeddable-in-canvas-broken-after-upgrading-to-version-8-9-2-due-to-saved-objects-id/349652)

<div class="topic-metadata">

**Author:** [@preetish\_P](https://discuss.elastic.co/u/preetish_P)\
**Replies:** 4\
**Last updated:** [January 4, 2024, 6:32pm UTC](https://discuss.elastic.co/t/savedvisualization-embeddable-in-canvas-broken-after-upgrading-to-version-8-9-2-due-to-saved-objects-id/349652 "2024-01-04T18:32:53Z")

</div>

Hi folks, We are looking to upgrade elk stack from 7.17.2 to 8.9.2. One of the first observations we made in Canvas is that savedVisualization is broken. We have Canvas dashboards having upto 9 kibana visualisation impo…

---

## [Is it possible to run beats agent as a container](https://discuss.elastic.co/t/is-it-possible-to-run-beats-agent-as-a-container/350393)

<div class="topic-metadata">

**Author:** [@ACodingfreak](https://discuss.elastic.co/u/ACodingfreak)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 4:05pm UTC](https://discuss.elastic.co/t/is-it-possible-to-run-beats-agent-as-a-container/350393 "2024-01-04T16:05:20Z")

</div>

Hi All, I am quite new to Elastic and have a very basic doubt. I understand that beats is used as an agent running on edge node shipping the data to Elasticsearch. It is installed as an RPM or DEB package but can it be…

---

## [\[Elasticsearch user settings and extensions\] Increase http.max\_initial\_line\_length](https://discuss.elastic.co/t/elasticsearch-user-settings-and-extensions-increase-http-max-initial-line-length/350387)

<div class="topic-metadata">

**Author:** [@Xavier\_Huberdeau](https://discuss.elastic.co/u/Xavier_Huberdeau)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 4:53pm UTC](https://discuss.elastic.co/t/elasticsearch-user-settings-and-extensions-increase-http-max-initial-line-length/350387 "2024-01-04T16:53:46Z")

</div>

Hello, I'm trying to change the elasticsearch settings yml configuration from elastic.co When I put http.max\_initial\_line\_length: 32kb, it says: Your changes cannot be applied Elasticsearch - 'http.max\_initial\_li…

---

## [Kindly suggest hardware sizing](https://discuss.elastic.co/t/kindly-suggest-hardware-sizing/350348)

<div class="topic-metadata">

**Author:** [@sakda.pk](https://discuss.elastic.co/u/sakda.pk)\
**Replies:** 0\
**Last updated:** [January 4, 2024, 4:12am UTC](https://discuss.elastic.co/t/kindly-suggest-hardware-sizing/350348 "2024-01-04T04:12:28Z")

</div>

I have size of data is 850 GB per day and must keep data in 91 days. Total size about 77 TB. pleased help to suggest. - quantity node - quantity shade of index per day Additional Question - how maximum space of n…

---

## [How to modify total memory of existing nodes?](https://discuss.elastic.co/t/how-to-modify-total-memory-of-existing-nodes/349958)

<div class="topic-metadata">

**Author:** [@SanthoshKMurugadass](https://discuss.elastic.co/u/SanthoshKMurugadass)\
**Replies:** 8\
**Last updated:** [January 4, 2024, 3:51pm UTC](https://discuss.elastic.co/t/how-to-modify-total-memory-of-existing-nodes/349958 "2024-01-04T15:51:32Z")

</div>

Hi, I am new to elasticresearch. I have set up 3 node cluster following docker setup procedure explained as per section: Section Start a multi-node cluster with Docker Compose in below help link Here is my cluster nod…

---

## [How to integrate Ironscales to Elastic Cloud?](https://discuss.elastic.co/t/how-to-integrate-ironscales-to-elastic-cloud/350161)

<div class="topic-metadata">

**Author:** [@Anilkumar](https://discuss.elastic.co/u/Anilkumar)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 3:01pm UTC](https://discuss.elastic.co/t/how-to-integrate-ironscales-to-elastic-cloud/350161 "2024-01-04T15:01:31Z")

</div>

Hi All, I am looking to integrate Ironscales audit logs into Elastic cloud& can't find the Integration for it. How to ingest this logs, can anyone help?

---

## [Using location data to show a route taken](https://discuss.elastic.co/t/using-location-data-to-show-a-route-taken/350263)

<div class="topic-metadata">

**Author:** [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Replies:** 2\
**Last updated:** [January 4, 2024, 1:38pm UTC](https://discuss.elastic.co/t/using-location-data-to-show-a-route-taken/350263 "2024-01-04T13:38:40Z")

</div>

Hi I have time based data for the location of an item, that I'd like to visualise as a sort of "route map", i.e. a sequnece of lines joining the various location points as traversed in time series order. Maybe I'm miss…

---

## [Kibana: Cold indices not showing when using filter in index management](https://discuss.elastic.co/t/kibana-cold-indices-not-showing-when-using-filter-in-index-management/350200)

<div class="topic-metadata">

**Author:** [@basiltitus](https://discuss.elastic.co/u/basiltitus)\
**Replies:** 8\
**Last updated:** [January 4, 2024, 12:40pm UTC](https://discuss.elastic.co/t/kibana-cold-indices-not-showing-when-using-filter-in-index-management/350200 "2024-01-04T12:40:47Z")

</div>

I have a two node cluster with a master/hot and a single data node defined in cold tier. I have created few indices for testing data tier. But when I apply "lifecycle phase" filter the indices supposed to be in cold tie…

---

## [Maximum timeout reached while retrying request. Call: Status code unknown from](https://discuss.elastic.co/t/maximum-timeout-reached-while-retrying-request-call-status-code-unknown-from/350378)

<div class="topic-metadata">

**Author:** [@ali\_haider](https://discuss.elastic.co/u/ali_haider)\
**Replies:** 0\
**Last updated:** [January 4, 2024, 12:14pm UTC](https://discuss.elastic.co/t/maximum-timeout-reached-while-retrying-request-call-status-code-unknown-from/350378 "2024-01-04T12:14:31Z")

</div>

Hi, I have installed Elasticsearch 7.17.7 version on Windows Server 2022 I am facing the following error and exception Index goes to red zone after this exception. In Elasticsearch logs it's says that that indices fi…

---

## [Geo.location as object and not as geo\_point](https://discuss.elastic.co/t/geo-location-as-object-and-not-as-geo-point/349230)

<div class="topic-metadata">

**Author:** [@helldunkel](https://discuss.elastic.co/u/helldunkel)\
**Replies:** 3\
**Last updated:** [January 4, 2024, 11:48am UTC](https://discuss.elastic.co/t/geo-location-as-object-and-not-as-geo-point/349230 "2024-01-04T11:48:44Z")

</div>

Hi, I created a component template for a custon sensor. everything works, has the right datatypes. Only destination.geo.location is set to object and not to geo\_point: "destination": { "type": "object", …

---

## [Multiple Kibanas on 1 cluster](https://discuss.elastic.co/t/multiple-kibanas-on-1-cluster/350372)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 10:32am UTC](https://discuss.elastic.co/t/multiple-kibanas-on-1-cluster/350372 "2024-01-04T10:32:47Z")

</div>

Hi, Is it possible\\alowed to run multiple Kibana instances connected to same cluster? Will it create internal index (.monitoring, etc) per instance? Thanks...

---

## [I facing error while setup elasticsearch cluster in docker using 2 host server those servers from azure ERROR i am getting like this Peer{transportAddress=10.33.8.79:9300, discoveryNode=null, peersRequestInFlight=false} connection failed org.elasticsearc](https://discuss.elastic.co/t/i-facing-error-while-setup-elasticsearch-cluster-in-docker-using-2-host-server-those-servers-from-azure-error-i-am-getting-like-this-peer-transportaddress-10-33-8-79-9300-discoverynode-null-peersrequestinflight-false-connection-failed-org-elasticsearc/350369)

<div class="topic-metadata">

**Author:** [@Pasupuleti\_siva](https://discuss.elastic.co/u/Pasupuleti_siva)\
**Replies:** 4\
**Last updated:** [January 4, 2024, 10:08am UTC](https://discuss.elastic.co/t/i-facing-error-while-setup-elasticsearch-cluster-in-docker-using-2-host-server-those-servers-from-azure-error-i-am-getting-like-this-peer-transportaddress-10-33-8-79-9300-discoverynode-null-peersrequestinflight-false-connection-failed-org-elasticsearc/350369 "2024-01-04T10:08:37Z")

</div>

ERROR: \[2024-01-04T09:04:24,575\]\[DEBUG\]\[o.e.d.PeerFinder \] \[odfe-node2\] Peer{transportAddress=10.33.8.79:9300, discoveryNode=null, peersRequestInFlight=false} connection failed org.elasticsearch.transport.Connect…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=337)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=339)
