# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=363

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 364

---

## [ELK Compatibility with Red Hat Java 8](https://discuss.elastic.co/t/elk-compatibility-with-red-hat-java-8/348198)

<div class="topic-metadata">

**Author:** [@swarali\_vartak](https://discuss.elastic.co/u/swarali_vartak)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 8:22am UTC](https://discuss.elastic.co/t/elk-compatibility-with-red-hat-java-8/348198 "2023-11-29T08:22:50Z")

</div>

Hi, Current version of ELK Setup is 7.11.x Migrating OS from Oracle Java to Red Hat Java 8. Is elasticsearch 7.11 compatible with Red Hat java 8 ? Awaiting response. Thank you.

---

## [Frequent "No snapshot information" on default client- Azure repository](https://discuss.elastic.co/t/frequent-no-snapshot-information-on-default-client-azure-repository/348195)

<div class="topic-metadata">

**Author:** [@Anushree](https://discuss.elastic.co/u/Anushree)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 6:48am UTC](https://discuss.elastic.co/t/frequent-no-snapshot-information-on-default-client-azure-repository/348195 "2023-11-29T06:48:31Z")

</div>

We are consistently encountering the "No snapshot information" message on the 'default' client for the 'Azure' repository type, even though snapshots exist in Azure containers. Despite the repository connection verificat…

---

## [Rollover Indexes Using ILM](https://discuss.elastic.co/t/rollover-indexes-using-ilm/348190)

<div class="topic-metadata">

**Author:** [@krish1](https://discuss.elastic.co/u/krish1)\
**Replies:** 1\
**Last updated:** [November 29, 2023, 5:51am UTC](https://discuss.elastic.co/t/rollover-indexes-using-ilm/348190 "2023-11-29T05:51:05Z")

</div>

I am currently using ES version 7.17.0 and trying out rollover indexes using the ILM. I have read through the documentation and my use case is to rollover my ES index every Monday midnight once a week i.e, rollover by ag…

---

## [Multiple Anonymous Access in Kibana](https://discuss.elastic.co/t/multiple-anonymous-access-in-kibana/348111)

<div class="topic-metadata">

**Author:** [@Saksham\_Kawatra](https://discuss.elastic.co/u/Saksham_Kawatra)\
**Replies:** 2\
**Last updated:** [November 29, 2023, 4:41am UTC](https://discuss.elastic.co/t/multiple-anonymous-access-in-kibana/348111 "2023-11-29T04:41:07Z")

</div>

Suppose i have got 5 customers for whom i have to make dashboards via Kibana. I make the dashboards for each respective user. Now i want such that each user is able to access their respective dashboard anonymously. I was…

---

## [Restoring a single index for a datastream cheatsheet](https://discuss.elastic.co/t/restoring-a-single-index-for-a-datastream-cheatsheet/348180)

<div class="topic-metadata">

**Author:** [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 9:52pm UTC](https://discuss.elastic.co/t/restoring-a-single-index-for-a-datastream-cheatsheet/348180 "2023-11-28T21:52:22Z")

</div>

I feel like it took me a long time to figure this out and it may be helpful for others. These are the sets of commands that I send when I need to get back an index that already got deleted by ILM but I want to see the da…

---

## [How can I change the timezone on Kibana?](https://discuss.elastic.co/t/how-can-i-change-the-timezone-on-kibana/348172)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 2\
**Last updated:** [November 28, 2023, 7:08pm UTC](https://discuss.elastic.co/t/how-can-i-change-the-timezone-on-kibana/348172 "2023-11-28T19:08:18Z")

</div>

I've noticed that my Kibana has a 3hours difference with my actual time. I've been looking into similar cases but so far changing the timezone in the Advanced Settings hasn't worked yet. What other ways could I try to ac…

---

## [Increase the lens max results](https://discuss.elastic.co/t/increase-the-lens-max-results/345601)

<div class="topic-metadata">

**Author:** [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Replies:** 6\
**Last updated:** [November 28, 2023, 8:21pm UTC](https://discuss.elastic.co/t/increase-the-lens-max-results/345601 "2023-11-28T20:21:15Z")

</div>

I'd like to increase the number of results on kibana lens data table viz but can't find out how. I regularly export unique ids I have to csv using lens in order to run some custom analysis, etc. I'd like to increase thi…

---

## [Not able to Add Node to Existing Cluster](https://discuss.elastic.co/t/not-able-to-add-node-to-existing-cluster/348068)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 7\
**Last updated:** [November 28, 2023, 4:35pm UTC](https://discuss.elastic.co/t/not-able-to-add-node-to-existing-cluster/348068 "2023-11-28T16:35:44Z")

</div>

Hi Team, I had requirement to create two node cluster of 8.9.2 version. we did Elasticsearch installation on both nodes through RPM based. I had generated enrollment token (elasticsearch-create-enrollment-token -s node …

---

## [Stuck at setting up ELK for monitoring](https://discuss.elastic.co/t/stuck-at-setting-up-elk-for-monitoring/347999)

<div class="topic-metadata">

**Author:** [@Aamira](https://discuss.elastic.co/u/Aamira)\
**Replies:** 5\
**Last updated:** [November 28, 2023, 4:13pm UTC](https://discuss.elastic.co/t/stuck-at-setting-up-elk-for-monitoring/347999 "2023-11-28T16:13:51Z")

</div>

I'm new to ELK stack and trying to set it up to monitor my servers and services, but when i installed everything and installed metricbeat when i go to kibana to see the data that sent by metricbeat i overwhelmed by huge …

---

## [JDBC streaming array as parameter](https://discuss.elastic.co/t/jdbc-streaming-array-as-parameter/348159)

<div class="topic-metadata">

**Author:** [@Rodrigo\_Martins](https://discuss.elastic.co/u/Rodrigo_Martins)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 3:19pm UTC](https://discuss.elastic.co/t/jdbc-streaming-array-as-parameter/348159 "2023-11-28T15:19:33Z")

</div>

Hello everyone, We are trying to execute a jdbc\_streaming query that takes as parameter a array of values. Our statement looks like this: statement =\> "SELECT \`table\_name\`,\`column\_name\`,\`classification\` FROM \`tableEx\`…

---

## [\[ECK\] 404 error for elastic agent running on ec2 host](https://discuss.elastic.co/t/eck-404-error-for-elastic-agent-running-on-ec2-host/348152)

<div class="topic-metadata">

**Author:** [@nitesh.singh](https://discuss.elastic.co/u/nitesh.singh)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 2:23pm UTC](https://discuss.elastic.co/t/eck-404-error-for-elastic-agent-running-on-ec2-host/348152 "2023-11-28T14:23:07Z")

</div>

We are using ECK method of installation which is hosted on EKS in AWS account, where Fleet is also installed. We want to monitor ec2 instances and collect logs using an elastic agent which is managed by Fleet, hosted in…

---

## [Enrich IPs with geoip FileBeat and Elasticsearch](https://discuss.elastic.co/t/enrich-ips-with-geoip-filebeat-and-elasticsearch/348154)

<div class="topic-metadata">

**Author:** [@Wad1636](https://discuss.elastic.co/u/Wad1636)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 2:27pm UTC](https://discuss.elastic.co/t/enrich-ips-with-geoip-filebeat-and-elasticsearch/348154 "2023-11-28T14:27:27Z")

</div>

Hello, I would like to obtain the geolocation of IP addresses using Filebeat and Elasticsearch. To sort the IP addresses, I am using a "dissect" schema as follows: - dissect: tokenizer: '%{+MMM d HH:mm:ss} %{nextcl…

---

## [Kibana login tracking](https://discuss.elastic.co/t/kibana-login-tracking/346684)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 3\
**Last updated:** [November 28, 2023, 2:14pm UTC](https://discuss.elastic.co/t/kibana-login-tracking/346684 "2023-11-28T14:14:15Z")

</div>

Hi team, Is there a way to know who logged in kibana using specific username? If so, is IP information included? Kibana version used is 7.9.2

---

## [CCS requires wildcard after index name to search or always returns 404](https://discuss.elastic.co/t/ccs-requires-wildcard-after-index-name-to-search-or-always-returns-404/348091)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 2:12pm UTC](https://discuss.elastic.co/t/ccs-requires-wildcard-after-index-name-to-search-or-always-returns-404/348091 "2023-11-28T14:12:31Z")

</div>

Quick bit about the setup: Dedicated CCS cluster (no local indices, except for monitoring) v7.17.10 Two clusters clusterA and clusterB are connected as remote clusters v7.4.1 All of these searches are performed on the…

---

## [Auditbeat 8.10.2 caused several physical servers to crash](https://discuss.elastic.co/t/auditbeat-8-10-2-caused-several-physical-servers-to-crash/346386)

<div class="topic-metadata">

**Author:** [@kpeterson-pmts](https://discuss.elastic.co/u/kpeterson-pmts)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 2:03pm UTC](https://discuss.elastic.co/t/auditbeat-8-10-2-caused-several-physical-servers-to-crash/346386 "2023-11-28T14:03:56Z")

</div>

We upgraded auditbeats from version 8.6.2 to version 8.10.2 using automation tooling. The upgrade was first tested on some of our EC2 instances, and had no issues. When we applied the upgrade to a subset of physical host…

---

## [Create a new index with the query's result](https://discuss.elastic.co/t/create-a-new-index-with-the-querys-result/347353)

<div class="topic-metadata">

**Author:** [@Mathieu64](https://discuss.elastic.co/u/Mathieu64)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 2:00pm UTC](https://discuss.elastic.co/t/create-a-new-index-with-the-querys-result/347353 "2023-11-28T14:00:26Z")

</div>

Hi, I want to send the query's result in a new index : GET myindex/\_search { "size" : 0, "\_source" : false, "aggregations" : { "groupby" : { "composite" : { "size" : 1000, "sources" : \[ …

---

## [Elasticsearch NEST client GetSnapshotRequest method is not returning index\_details](https://discuss.elastic.co/t/elasticsearch-nest-client-getsnapshotrequest-method-is-not-returning-index-details/348015)

<div class="topic-metadata">

**Author:** [@EVINDX](https://discuss.elastic.co/u/EVINDX)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 1:49pm UTC](https://discuss.elastic.co/t/elasticsearch-nest-client-getsnapshotrequest-method-is-not-returning-index-details/348015 "2023-11-28T13:49:00Z")

</div>

I'm using NEST version 7.17 to communicate with Elasticsearch 7.17 I have a snapshot created without any issues. I'm able to restore the snapshot as well. I can get the Elasticsearch index details in the snapshot via t…

---

## [Logstash freezes during initialization](https://discuss.elastic.co/t/logstash-freezes-during-initialization/348145)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 1:26pm UTC](https://discuss.elastic.co/t/logstash-freezes-during-initialization/348145 "2023-11-28T13:26:16Z")

</div>

Hi, I got a Logstash who work well on local docker. When i use docker on Azure, Logstash freezes during initialization. I just got these logs : Using bundled JDK: /usr/share/logstash/jdk OpenJDK 64-Bit Server VM war…

---

## [No alive nodes. All the 5 nodes seem to be down](https://discuss.elastic.co/t/no-alive-nodes-all-the-5-nodes-seem-to-be-down/348138)

<div class="topic-metadata">

**Author:** [@Test\_Owner](https://discuss.elastic.co/u/Test_Owner)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 1:15pm UTC](https://discuss.elastic.co/t/no-alive-nodes-all-the-5-nodes-seem-to-be-down/348138 "2023-11-28T13:15:56Z")

</div>

"No alive nodes. All the 5 nodes seem to be down". I get such a problem when executing a request. Previously, the request was executed correctly, but with the increase in records, I have such a problem. What can you adv…

---

## [Drastic reduction in query performance when using replicas](https://discuss.elastic.co/t/drastic-reduction-in-query-performance-when-using-replicas/348090)

<div class="topic-metadata">

**Author:** [@diegomansua](https://discuss.elastic.co/u/diegomansua)\
**Replies:** 6\
**Last updated:** [November 28, 2023, 1:03pm UTC](https://discuss.elastic.co/t/drastic-reduction-in-query-performance-when-using-replicas/348090 "2023-11-28T13:03:15Z")

</div>

Hi everyone. We're facing an issue whereby having replicas drastically decreases query performance. Our set up consists of 3 nodes running ES 7.16 with 4GB heap each. We have around 1.6 million documents that contain a…

---

## [Anomaly Jobs - General Strategies to reduce false positives](https://discuss.elastic.co/t/anomaly-jobs-general-strategies-to-reduce-false-positives/348094)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 2\
**Last updated:** [November 28, 2023, 12:58pm UTC](https://discuss.elastic.co/t/anomaly-jobs-general-strategies-to-reduce-false-positives/348094 "2023-11-28T12:58:30Z")

</div>

Hello everybody, i'am struggling to baseline an anomaly detection job (filters are not really helping so far). What are the general strategies or factors which drive the model to become, simply put, more "insensitive" …

---

## [Elastic-agent entry /proc/net/udp not found](https://discuss.elastic.co/t/elastic-agent-entry-proc-net-udp-not-found/348140)

<div class="topic-metadata">

**Author:** [@atbc](https://discuss.elastic.co/u/atbc)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 12:40pm UTC](https://discuss.elastic.co/t/elastic-agent-entry-proc-net-udp-not-found/348140 "2023-11-28T12:40:33Z")

</div>

Hello, I set up a Fleet server and on this same policy I added a Juniper integration, I see that it listens on the specified ports with the command "sudo ss -tulpn" and I can see the logs arriving with a TCPDUMP. But I …

---

## [Logstash elasticsearch input plugin](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin/347207)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 3\
**Last updated:** [November 28, 2023, 12:39pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin/347207 "2023-11-28T12:39:22Z")

</div>

Hello dears, i am trying to create logstash job that have input from elasticsearch index pattern and to take a specific logs then to save them in a historical index so the configuration as below, input{ elasticsearch …

---

## [Monitoring: Error getting cgroup stats - io.pressure not found](https://discuss.elastic.co/t/monitoring-error-getting-cgroup-stats-io-pressure-not-found/348137)

<div class="topic-metadata">

**Author:** [@adsr](https://discuss.elastic.co/u/adsr)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 12:23pm UTC](https://discuss.elastic.co/t/monitoring-error-getting-cgroup-stats-io-pressure-not-found/348137 "2023-11-28T12:23:58Z")

</div>

After upgrading from kernel 5.14.0-284.11.1.el9\_2.x86\_64 to 5.14.0-362.8.1.el9\_3.x86\_64 I get the following error every ~1minute: error getting cgroup stats: error fetching stats for controller io: error fetching IO sta…

---

## [Problem in send log consistently with filebeat](https://discuss.elastic.co/t/problem-in-send-log-consistently-with-filebeat/348121)

<div class="topic-metadata">

**Author:** [@behzad\_alipoor](https://discuss.elastic.co/u/behzad_alipoor)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 10:07am UTC](https://discuss.elastic.co/t/problem-in-send-log-consistently-with-filebeat/348121 "2023-11-28T10:07:30Z")

</div>

i have problem in sending logs with filebeat to elasticsearch . it sends data and pauses and after miliseconds it sends again data . i set this config : scan\_frequency: 10s close\_inactive: 20s ignore\_older: 30s …

---

## [OpenAI connect with elastic search datasource](https://discuss.elastic.co/t/openai-connect-with-elastic-search-datasource/347901)

<div class="topic-metadata">

**Author:** [@Saurabh\_Agrawal2](https://discuss.elastic.co/u/Saurabh_Agrawal2)\
**Replies:** 5\
**Last updated:** [November 28, 2023, 9:59am UTC](https://discuss.elastic.co/t/openai-connect-with-elastic-search-datasource/347901 "2023-11-28T09:59:18Z")

</div>

I am trying call openAI with my custom index created on Elastic search but when I try to run it I am getting following error: openai.BadRequestError: Error code: 400 - {'error': {'requestid': 'aaa-bbb-404d-8a12-3da23608…

---

## [Eck on kubeadm](https://discuss.elastic.co/t/eck-on-kubeadm/348104)

<div class="topic-metadata">

**Author:** [@Swapnil2](https://discuss.elastic.co/u/Swapnil2)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 4:41am UTC](https://discuss.elastic.co/t/eck-on-kubeadm/348104 "2023-11-28T04:41:06Z")

</div>

I created 3 node kubeadm cluster. I starting setup elasticsearch using eck.when I changed count 1from 3 then other pod in pending status...plz give

---

## [Disable geoip processor via filebeat ingest pipeline](https://discuss.elastic.co/t/disable-geoip-processor-via-filebeat-ingest-pipeline/348019)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 2:57am UTC](https://discuss.elastic.co/t/disable-geoip-processor-via-filebeat-ingest-pipeline/348019 "2023-11-28T02:57:00Z")

</div>

Hi, I'm running ES and filebeat v8.8.0. I'm trying to disable the geoip processing only for netflow data written to the index test. I have netflow data written to other indices by other filebeat instances that have geoi…

---

## [\[OPNsense\] (pfsense integration) not logging unbound DNS](https://discuss.elastic.co/t/opnsense-pfsense-integration-not-logging-unbound-dns/348095)

<div class="topic-metadata">

**Author:** [@straw\_hardhat](https://discuss.elastic.co/u/straw_hardhat)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 11:01pm UTC](https://discuss.elastic.co/t/opnsense-pfsense-integration-not-logging-unbound-dns/348095 "2023-11-27T23:01:06Z")

</div>

I've set up a OPNsense which is successfully communicating with ELK (running in docker, GitHub - peasead/elastic-container: Stand up a simple Elastic container with Kibana, Fleet, and the Detection Engine) as both filter…

---

## [Elasticsearch TSDS and geo\_point as dimension](https://discuss.elastic.co/t/elasticsearch-tsds-and-geo-point-as-dimension/347674)

<div class="topic-metadata">

**Author:** [@berg](https://discuss.elastic.co/u/berg)\
**Replies:** 2\
**Last updated:** [November 27, 2023, 10:54pm UTC](https://discuss.elastic.co/t/elasticsearch-tsds-and-geo-point-as-dimension/347674 "2023-11-27T22:54:33Z")

</div>

We are migrating some data sources across to a new cluster, and we have some wireless metrics that count the number of connected devices on each floor of each building. This seemed like an effective use case for TSDS, a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=362)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=364)
