# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=339

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 340

---

## [Alternatives to kibana](https://discuss.elastic.co/t/alternatives-to-kibana/350360)

<div class="topic-metadata">

**Author:** [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Replies:** 2\
**Last updated:** [January 4, 2024, 9:53am UTC](https://discuss.elastic.co/t/alternatives-to-kibana/350360 "2024-01-04T09:53:18Z")

</div>

Hey i was wondering if i could connect my elasticsearch and logstash with some other vizualisation tool like powerbi or tablue for free . I tried to do so but it seems i have to buy the platinum version to download the e…

---

## [Logstash output adding ES cluster exception](https://discuss.elastic.co/t/logstash-output-adding-es-cluster-exception/350345)

<div class="topic-metadata">

**Author:** [@kinho](https://discuss.elastic.co/u/kinho)\
**Replies:** 2\
**Last updated:** [January 4, 2024, 9:30am UTC](https://discuss.elastic.co/t/logstash-output-adding-es-cluster-exception/350345 "2024-01-04T09:30:52Z")

</div>

Logstash docker I plan to use Docker Compose to deploy ELK in Docker, where ES is a cluster The version is 8.11.3 .env: ELASTIC\_PASSWORD=123456 KIBANA\_PASSWORD=123456 STACK\_VERSION=8.11.3 CLUSTER\_NAME=docker-clu…

---

## [I want to know details about how we reduced the heap usage per shard](https://discuss.elastic.co/t/i-want-to-know-details-about-how-we-reduced-the-heap-usage-per-shard/350346)

<div class="topic-metadata">

**Author:** [@emmning](https://discuss.elastic.co/u/emmning)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 9:28am UTC](https://discuss.elastic.co/t/i-want-to-know-details-about-how-we-reduced-the-heap-usage-per-shard/350346 "2024-01-04T09:28:15Z")

</div>

Through this blog I see that starting from 8.3, we have significantly reduced Usage of each shard of the heap. I would like to know more details about how we can reduce the heap usage per shard. Anyone knows a PR or blog…

---

## [Embedding kibana using iframe](https://discuss.elastic.co/t/embedding-kibana-using-iframe/350042)

<div class="topic-metadata">

**Author:** [@Atul87](https://discuss.elastic.co/u/Atul87)\
**Replies:** 3\
**Last updated:** [January 4, 2024, 8:28am UTC](https://discuss.elastic.co/t/embedding-kibana-using-iframe/350042 "2024-01-04T08:28:10Z")

</div>

Hi team, I am trying to embed kibana url using iframe, but its not working for me. I am using kibana version 7.17.13, I want to embed overall kibana, with all its functionality not just any one dashbord of it. Authenti…

---

## [Backup large indexes to other locations on a time-by-time basis and clean up the index](https://discuss.elastic.co/t/backup-large-indexes-to-other-locations-on-a-time-by-time-basis-and-clean-up-the-index/350191)

<div class="topic-metadata">

**Author:** [@sqq](https://discuss.elastic.co/u/sqq)\
**Replies:** 12\
**Last updated:** [January 4, 2024, 7:42am UTC](https://discuss.elastic.co/t/backup-large-indexes-to-other-locations-on-a-time-by-time-basis-and-clean-up-the-index/350191 "2024-01-04T07:42:25Z")

</div>

Backup large indexes to other locations on a time-by-time basis and clean up the index

---

## [Logstash metrics using modules in Metricbeat](https://discuss.elastic.co/t/logstash-metrics-using-modules-in-metricbeat/350279)

<div class="topic-metadata">

**Author:** [@maadhav](https://discuss.elastic.co/u/maadhav)\
**Replies:** 4\
**Last updated:** [January 4, 2024, 5:41am UTC](https://discuss.elastic.co/t/logstash-metrics-using-modules-in-metricbeat/350279 "2024-01-04T05:41:29Z")

</div>

Hi Team There are 2 modules in Metricbeat to collect Logstash metrics logstash logstash-xpack Which module should be used ? Regards

---

## [Is dfs\_query\_then\_fetch automatically disabled on single shard?](https://discuss.elastic.co/t/is-dfs-query-then-fetch-automatically-disabled-on-single-shard/350351)

<div class="topic-metadata">

**Author:** [@Yukha\_Dharmeswara](https://discuss.elastic.co/u/Yukha_Dharmeswara)\
**Replies:** 0\
**Last updated:** [January 4, 2024, 5:17am UTC](https://discuss.elastic.co/t/is-dfs-query-then-fetch-automatically-disabled-on-single-shard/350351 "2024-01-04T05:17:34Z")

</div>

When we specify search\_type=dfs\_query\_then\_fetch in querystring, does Elasticsearch automatically disable dfs\_query\_then\_fetch when there's only 1 shard in single node mode? Or do i have to use query\_then\_fetch to trigge…

---

## [Configure ingest pipeline to add both GeoLite2-City AND GeoLite2-ASN fields](https://discuss.elastic.co/t/configure-ingest-pipeline-to-add-both-geolite2-city-and-geolite2-asn-fields/350339)

<div class="topic-metadata">

**Author:** [@jbrowe](https://discuss.elastic.co/u/jbrowe)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 12:00am UTC](https://discuss.elastic.co/t/configure-ingest-pipeline-to-add-both-geolite2-city-and-geolite2-asn-fields/350339 "2024-01-04T00:00:58Z")

</div>

I have and event stream that contains IP addresses. I wish to add meta-data from the GeoLite2 Max Mind databases. I can successfully add the city data. I can also successfully add the ASN data. Somehow, I cannot add both…

---

## [Rollup or downsampling](https://discuss.elastic.co/t/rollup-or-downsampling/350342)

<div class="topic-metadata">

**Author:** [@EdRayQO](https://discuss.elastic.co/u/EdRayQO)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 11:17pm UTC](https://discuss.elastic.co/t/rollup-or-downsampling/350342 "2024-01-03T23:17:07Z")

</div>

I'm trying to compress log data I have in a monitoring cluster and that is configured to be erased after 7 days, and I'm not sure which path should I follow between rollup jobs and down sampling in order to compress that…

---

## [Stack Monitoring Access Denied](https://discuss.elastic.co/t/stack-monitoring-access-denied/350313)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 9:32pm UTC](https://discuss.elastic.co/t/stack-monitoring-access-denied/350313 "2024-01-03T21:32:48Z")

</div>

When I try to view Stack Monitoring, I receive an error message. I get the same message with the default elastic admin user as well as my provisioned unique admin user account I use. I only have one cluster, so I'm not…

---

## [Error log curl: (52) Empty reply from server in v8.11.3](https://discuss.elastic.co/t/error-log-curl-52-empty-reply-from-server-in-v8-11-3/350338)

<div class="topic-metadata">

**Author:** [@ACodingfreak](https://discuss.elastic.co/u/ACodingfreak)\
**Replies:** 2\
**Last updated:** [January 3, 2024, 8:18pm UTC](https://discuss.elastic.co/t/error-log-curl-52-empty-reply-from-server-in-v8-11-3/350338 "2024-01-03T20:18:34Z")

</div>

Hi All, I am new to ELK and started using the same via docker compose. I have used the standard docker-compose.yaml file which is available in below link. As shown in below logs all containers are up and running $ …

---

## [Share a dashboard in read-only mode](https://discuss.elastic.co/t/share-a-dashboard-in-read-only-mode/350326)

<div class="topic-metadata">

**Author:** [@gnatola](https://discuss.elastic.co/u/gnatola)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 7:58pm UTC](https://discuss.elastic.co/t/share-a-dashboard-in-read-only-mode/350326 "2024-01-03T19:58:40Z")

</div>

Hello, using Kibana 8.11. Created a dashboard that I would like to share in read-only mode. I would like to be the only person who can edit the dashboard. What is the best way to accomplish this? Thanks.

---

## [ES SQL custom mappings](https://discuss.elastic.co/t/es-sql-custom-mappings/349980)

<div class="topic-metadata">

**Author:** [@ES\_SQL\_HELP](https://discuss.elastic.co/u/ES_SQL_HELP)\
**Replies:** 6\
**Last updated:** [January 3, 2024, 5:08pm UTC](https://discuss.elastic.co/t/es-sql-custom-mappings/349980 "2024-01-03T17:08:54Z")

</div>

Hello, I'm wondering if it's possible to use ES SQL on custom field mappings for types e.g. long, integer, doubles.

---

## [Audit logging in Elastic Cloud](https://discuss.elastic.co/t/audit-logging-in-elastic-cloud/348688)

<div class="topic-metadata">

**Author:** [@lreger](https://discuss.elastic.co/u/lreger)\
**Replies:** 2\
**Last updated:** [January 3, 2024, 5:08pm UTC](https://discuss.elastic.co/t/audit-logging-in-elastic-cloud/348688 "2024-01-03T17:08:34Z")

</div>

I have two questions I was hoping someone could answer. Question 1: I am using an elastic cloud deployment running ES 7.17.5. I know how to enable audit logging and ship those logs to my monitoring deployment. I noticed…

---

## [How to read GZIP and encoding with UTF-8 logs from kafka topic through logstash pipeline](https://discuss.elastic.co/t/how-to-read-gzip-and-encoding-with-utf-8-logs-from-kafka-topic-through-logstash-pipeline/349775)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 5\
**Last updated:** [January 3, 2024, 4:53pm UTC](https://discuss.elastic.co/t/how-to-read-gzip-and-encoding-with-utf-8-logs-from-kafka-topic-through-logstash-pipeline/349775 "2024-01-03T16:53:39Z")

</div>

Hi All, Application team doing "GZIP and encoding with UTF-8" and sending their logs to kafka topics. Now i want to read those logs through logstash pipeline. Could you please guide me on this? Thanks

---

## [Error running Elastic Maps behind proxy](https://discuss.elastic.co/t/error-running-elastic-maps-behind-proxy/350082)

<div class="topic-metadata">

**Author:** [@m.hanna](https://discuss.elastic.co/u/m.hanna)\
**Replies:** 7\
**Last updated:** [January 3, 2024, 4:52pm UTC](https://discuss.elastic.co/t/error-running-elastic-maps-behind-proxy/350082 "2024-01-03T16:52:38Z")

</div>

I am trying to run an EMS server on a disconnected network behind an Nginx reverse-proxy in a docker swarm. I am able to start EMS up and it looks to connect to elasticsearch without the basePath setting. As soon as I a…

---

## [Inconsistencies between platforms](https://discuss.elastic.co/t/inconsistencies-between-platforms/350261)

<div class="topic-metadata">

**Author:** [@nml1988](https://discuss.elastic.co/u/nml1988)\
**Replies:** 11\
**Last updated:** [January 3, 2024, 3:35pm UTC](https://discuss.elastic.co/t/inconsistencies-between-platforms/350261 "2024-01-03T15:35:06Z")

</div>

Hello! I need help with a problem I'm having between 2 versions of ELK. These versions correspond to two different platforms that consume data from the same source. The first image corresponds to an ELK stack 7.9, where…

---

## [How to use Filters, Facets and Group By feature in .NET client?](https://discuss.elastic.co/t/how-to-use-filters-facets-and-group-by-feature-in-net-client/350322)

<div class="topic-metadata">

**Author:** [@RamuAnnamalai](https://discuss.elastic.co/u/RamuAnnamalai)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 3:21pm UTC](https://discuss.elastic.co/t/how-to-use-filters-facets-and-group-by-feature-in-net-client/350322 "2024-01-03T15:21:48Z")

</div>

I have integrated Elastic Search feature in .NET 6.0 API framework. I need to know how to use filters, facets & group by features in REST API .NET Client? Do you have any documentation for this? Thanks, Ramu

---

## [Delete by query conflict](https://discuss.elastic.co/t/delete-by-query-conflict/350320)

<div class="topic-metadata">

**Author:** [@Hariharan](https://discuss.elastic.co/u/Hariharan)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 3:06pm UTC](https://discuss.elastic.co/t/delete-by-query-conflict/350320 "2024-01-03T15:06:35Z")

</div>

Hey folks, I have a quick question on how to handle a particular scenario I'm running into. So we have a sync between a person's calendar events and Elasticsearch to index the events from Calendar and build some sort of…

---

## [Connectors Relationship with Db](https://discuss.elastic.co/t/connectors-relationship-with-db/349611)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 2:23pm UTC](https://discuss.elastic.co/t/connectors-relationship-with-db/349611 "2024-01-03T14:23:21Z")

</div>

Hello Elastic, I want to ask, I have issue where I've been configuring Connectors in Production environment which specifically Microsoft SQL connectors to pull the data into Elasticsearch Indices and it seems like it co…

---

## [ELSER2 | Spell check before creating embeddings](https://discuss.elastic.co/t/elser2-spell-check-before-creating-embeddings/350303)

<div class="topic-metadata">

**Author:** [@Rakesh\_Nayak](https://discuss.elastic.co/u/Rakesh_Nayak)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 2:07pm UTC](https://discuss.elastic.co/t/elser2-spell-check-before-creating-embeddings/350303 "2024-01-03T14:07:16Z")

</div>

Hello Team, Any suggestion of doing spell check before creating embeddings? e.g. if the query is misspelt "toiket rolls" instead of "toilet rolls" can we create the embeddings for "toilet rolls" using ELSER2 model POST…

---

## [Production configuration question](https://discuss.elastic.co/t/production-configuration-question/350302)

<div class="topic-metadata">

**Author:** [@Aleksandar\_Aleksand1](https://discuss.elastic.co/u/Aleksandar_Aleksand1)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 1:07pm UTC](https://discuss.elastic.co/t/production-configuration-question/350302 "2024-01-03T13:07:42Z")

</div>

Hi all, I am preparing the following elasticsearch cluster architecture: Total 6 Nodes: 1 Node with roles: master and remote\_cluster\_client 3 Nodes with roles: data, data\_hot, data\_content and ingest 1 Node with role…

---

## [Metricbeat fails to fetch metrics for mongoDB 6.0.4](https://discuss.elastic.co/t/metricbeat-fails-to-fetch-metrics-for-mongodb-6-0-4/349660)

<div class="topic-metadata">

**Author:** [@Usama\_Tariq](https://discuss.elastic.co/u/Usama_Tariq)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 1:03pm UTC](https://discuss.elastic.co/t/metricbeat-fails-to-fetch-metrics-for-mongodb-6-0-4/349660 "2024-01-03T13:03:42Z")

</div>

Metricbeat version: 8.3.1 MongoDB version: 6.0.4 My metricbeat config is as follows: ################### metricbeat Configuration ######################### ############################# metricbeat ###################…

---

## [Integration of elastic and logstash with other vizualization](https://discuss.elastic.co/t/integration-of-elastic-and-logstash-with-other-vizualization/350292)

<div class="topic-metadata">

**Author:** [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 12:50pm UTC](https://discuss.elastic.co/t/integration-of-elastic-and-logstash-with-other-vizualization/350292 "2024-01-03T12:50:41Z")

</div>

Hey there i am working on a project that requires me to integrate ELK stack with other vizualiation tools fo free , however i am running into the issue of downloading the ODBC driver as it is showing that i would need a …

---

## [ES curator not deleting the indices data](https://discuss.elastic.co/t/es-curator-not-deleting-the-indices-data/350241)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 2\
**Last updated:** [January 3, 2024, 12:49pm UTC](https://discuss.elastic.co/t/es-curator-not-deleting-the-indices-data/350241 "2024-01-03T12:49:26Z")

</div>

Hello, I have installed the ES-curator and below are my curator.yml and action.yml. I am seeing below errors while running the dry run and also when I tried with the cronjob entries. Because I don't see the indices dat…

---

## [Plugin installation was unsuccessful due to error Plugin kibanaPrometheusExporter \[7.17.0\] is incompatible with Kibana \[7.17.15\]](https://discuss.elastic.co/t/plugin-installation-was-unsuccessful-due-to-error-plugin-kibanaprometheusexporter-7-17-0-is-incompatible-with-kibana-7-17-15/350231)

<div class="topic-metadata">

**Author:** [@Domnic\_Raj\_D](https://discuss.elastic.co/u/Domnic_Raj_D)\
**Replies:** 6\
**Last updated:** [January 3, 2024, 12:44pm UTC](https://discuss.elastic.co/t/plugin-installation-was-unsuccessful-due-to-error-plugin-kibanaprometheusexporter-7-17-0-is-incompatible-with-kibana-7-17-15/350231 "2024-01-03T12:44:55Z")

</div>

I have upgraded Kibana to version 7.17.15 in our environment, but I cannot find the Kibana Prometheus Exporter version 7.17.15 on the GitHub page. I attempted versions 7.17.0 and the latest patch version, but encountered…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/350280)

<div class="topic-metadata">

**Author:** [@MD\_Rezaul\_Karim](https://discuss.elastic.co/u/MD_Rezaul_Karim)\
**Replies:** 10\
**Last updated:** [January 3, 2024, 11:11am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/350280 "2024-01-03T11:11:08Z")

</div>

Hi, I am getting following error. anyone pls. help me .. Jan 03 13:21:50 siem kibana\[10792\]: FATAL Error: Unable to complete saved object migrations for the \[.kibana\_task\_manager\] index. Please check the health of you…

---

## [Kibana 7.17.6 \> 8 Kibana\_system 403 unauthorized?](https://discuss.elastic.co/t/kibana-7-17-6-8-kibana-system-403-unauthorized/350288)

<div class="topic-metadata">

**Author:** [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 11:10am UTC](https://discuss.elastic.co/t/kibana-7-17-6-8-kibana-system-403-unauthorized/350288 "2024-01-03T11:10:32Z")

</div>

Hi everyone ! i've been upgrading my cluster recently everything went well until i got kibana HTTP 403 Errors with both kibana\_system and elastic users. Am i supposed to create a user with \[manage\] \[manage\_all\] perms i…

---

## [TopHits aggregation | How to get strong type from Java API?](https://discuss.elastic.co/t/tophits-aggregation-how-to-get-strong-type-from-java-api/341343)

<div class="topic-metadata">

**Author:** [@denbo](https://discuss.elastic.co/u/denbo)\
**Replies:** 2\
**Last updated:** [January 3, 2024, 10:52am UTC](https://discuss.elastic.co/t/tophits-aggregation-how-to-get-strong-type-from-java-api/341343 "2024-01-03T10:52:09Z")

</div>

I am extracting the hits from a TopHits aggregation using the Java API: Map\<String, Aggregate\> aggregations = searchResponse.aggregations(); TopHitsAggregate topHitsAggregate = searchResponse.aggregations().get("topHits…

---

## [How to read base64 encoded logs from kafka through logstash pipeline](https://discuss.elastic.co/t/how-to-read-base64-encoded-logs-from-kafka-through-logstash-pipeline/349688)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 9\
**Last updated:** [January 3, 2024, 9:28am UTC](https://discuss.elastic.co/t/how-to-read-base64-encoded-logs-from-kafka-through-logstash-pipeline/349688 "2024-01-03T09:28:30Z")

</div>

Hello all, I am working on something I have never worked on before and I really do not know where to go from here and I am hoping someone might have some direction for me to attempt trying to get this parsed to Elastics…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=338)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=340)
