# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=364

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 365

---

## [Alerting on compared aggregations](https://discuss.elastic.co/t/alerting-on-compared-aggregations/348075)

<div class="topic-metadata">

**Author:** [@GD\_DV](https://discuss.elastic.co/u/GD_DV)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 8:51pm UTC](https://discuss.elastic.co/t/alerting-on-compared-aggregations/348075 "2023-11-27T20:51:06Z")

</div>

Hello folks, I'm hoping to get a little insight from experienced folks as to how to approach my problem. I have a bunch of devices creating documents in my index. Each document is identified as belonging to a particular…

---

## [Add multiple index per kubernetes metadata for filebeat](https://discuss.elastic.co/t/add-multiple-index-per-kubernetes-metadata-for-filebeat/348082)

<div class="topic-metadata">

**Author:** [@farhad\_kh](https://discuss.elastic.co/u/farhad_kh)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 8:15pm UTC](https://discuss.elastic.co/t/add-multiple-index-per-kubernetes-metadata-for-filebeat/348082 "2023-11-27T20:15:00Z")

</div>

I have a limited number of index names that I can use for each namespace How can I do this using Kubernetes metadata? I configured filebeat as below, but red elastic index is not created apiVersion: v1 kind: ConfigMap…

---

## [Unable to search phrase anywhere in the text](https://discuss.elastic.co/t/unable-to-search-phrase-anywhere-in-the-text/348081)

<div class="topic-metadata">

**Author:** [@Mistgun\_Scripts](https://discuss.elastic.co/u/Mistgun_Scripts)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 8:10pm UTC](https://discuss.elastic.co/t/unable-to-search-phrase-anywhere-in-the-text/348081 "2023-11-27T20:10:12Z")

</div>

So I'm trying to search for a given phrase in text, already tried different methods e.g match\_phrase/query\_string but I still get invalid results. Let's say we have such documents with titles: "This is a phrase" "Anot…

---

## [How to install elastic agent on remote machine out of docker container using fleet](https://discuss.elastic.co/t/how-to-install-elastic-agent-on-remote-machine-out-of-docker-container-using-fleet/348079)

<div class="topic-metadata">

**Author:** [@datalaf](https://discuss.elastic.co/u/datalaf)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 8:01pm UTC](https://discuss.elastic.co/t/how-to-install-elastic-agent-on-remote-machine-out-of-docker-container-using-fleet/348079 "2023-11-27T20:01:58Z")

</div>

Hi, i am currently running elasticsearch with kibana on a cloud server in a docker container and i want to use the fleetserver to enroll a elastic agent on a remote linux machine. But when i am trying to setup a fleet s…

---

## [Unable to connect to Elasticsearch. Error: index\_not\_found\_exception index\_not\_found\_exception: no such index \[.kibana\]](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-error-index-not-found-exception-index-not-found-exception-no-such-index-kibana/348026)

<div class="topic-metadata">

**Author:** [@abkrim](https://discuss.elastic.co/u/abkrim)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 6:31pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-error-index-not-found-exception-index-not-found-exception-no-such-index-kibana/348026 "2023-11-27T18:31:54Z")

</div>

I'm trying to install and configure a simple node on my local machine using Docker, following the documentation. However, when I try to execute the first step of the Kibana configuration and paste the enrollment token, …

---

## [Failed migration of system indices (.triggered\_watches) with Upgrade Assistant using v7.17.14](https://discuss.elastic.co/t/failed-migration-of-system-indices-triggered-watches-with-upgrade-assistant-using-v7-17-14/346966)

<div class="topic-metadata">

**Author:** [@AEA27](https://discuss.elastic.co/u/AEA27)\
**Replies:** 3\
**Last updated:** [November 27, 2023, 4:37pm UTC](https://discuss.elastic.co/t/failed-migration-of-system-indices-triggered-watches-with-upgrade-assistant-using-v7-17-14/346966 "2023-11-27T16:37:55Z")

</div>

Using the upgrade assistant the migration of system indices fails for watcher which we're using. We're using elastic cloud and trying to migrate to Elasticsearch 8. Another fun fact is that the index that is failing to …

---

## [How to view file content](https://discuss.elastic.co/t/how-to-view-file-content/348036)

<div class="topic-metadata">

**Author:** [@min\_liu](https://discuss.elastic.co/u/min_liu)\
**Replies:** 4\
**Last updated:** [November 27, 2023, 3:45pm UTC](https://discuss.elastic.co/t/how-to-view-file-content/348036 "2023-11-27T15:45:03Z")

</div>

I would like to know what is written inside the Elasticsearch data directory file. Is there a tool available to view the file content? thanks

---

## [Elastic Forwarder for Cloudwatch](https://discuss.elastic.co/t/elastic-forwarder-for-cloudwatch/348056)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 1:49pm UTC](https://discuss.elastic.co/t/elastic-forwarder-for-cloudwatch/348056 "2023-11-27T13:49:39Z")

</div>

Hi, We're using the Elastic Serverless forwarder with Cloudwatch and I was wondering if anyone can clarify these questions? What are the parameters around the subscription filter, is it every time a new log hits Cloud…

---

## [Limit Metricbeat Memory Usage](https://discuss.elastic.co/t/limit-metricbeat-memory-usage/348062)

<div class="topic-metadata">

**Author:** [@nvanalphen](https://discuss.elastic.co/u/nvanalphen)\
**Replies:** 2\
**Last updated:** [November 27, 2023, 3:41pm UTC](https://discuss.elastic.co/t/limit-metricbeat-memory-usage/348062 "2023-11-27T15:41:29Z")

</div>

Is it possible to limit the memory that Metricbeat may use? I am seeing huge memory loads on my Windows Servers (2016, 2019 and 2022), between 2 and 3 Gb on VMs and a staggering 24Gb on a HyperV host Stopping and sta…

---

## [Metricbeat, filebeat](https://discuss.elastic.co/t/metricbeat-filebeat/348049)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 2:42pm UTC](https://discuss.elastic.co/t/metricbeat-filebeat/348049 "2023-11-27T14:42:28Z")

</div>

I am trying to find Metricbeat and filebeat versions for AIX systems, with no luck is elastic support AIX servers with filebeat and metricbeat?

---

## [Windows service monitoring options](https://discuss.elastic.co/t/windows-service-monitoring-options/348060)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 2:23pm UTC](https://discuss.elastic.co/t/windows-service-monitoring-options/348060 "2023-11-27T14:23:59Z")

</div>

I'm currently working on monitoring Windows Services and the best way to do this seems to be within Stack Management. I would have thought this would be done in the Observability area but when I looked through the avail…

---

## [Custom date\_format for parse\_origination\_date](https://discuss.elastic.co/t/custom-date-format-for-parse-origination-date/348042)

<div class="topic-metadata">

**Author:** [@tbabic](https://discuss.elastic.co/u/tbabic)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 12:50pm UTC](https://discuss.elastic.co/t/custom-date-format-for-parse-origination-date/348042 "2023-11-27T12:50:05Z")

</div>

Currently date\_format is yyyy.MM.dd in index.lifecycle.parse\_origination\_date which is great if you have logs in format like logs-2016.10.31-000002, but since index name is custom and can be like eg logs-2016-10-31-00 th…

---

## [Metricbeat's docker.diskio.read/write.rate is always zero when using cgroups v2](https://discuss.elastic.co/t/metricbeats-docker-diskio-read-write-rate-is-always-zero-when-using-cgroups-v2/348048)

<div class="topic-metadata">

**Author:** [@christian.k](https://discuss.elastic.co/u/christian.k)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 12:46pm UTC](https://discuss.elastic.co/t/metricbeats-docker-diskio-read-write-rate-is-always-zero-when-using-cgroups-v2/348048 "2023-11-27T12:46:19Z")

</div>

We want to use the docker.diskio.read/write.rate metric to monitor our systems. However, Metricbeat's Docker module reports all docker.diskio metrics (except the docker.diskio.read/write.bytes metric) as zero when using …

---

## ["Input not supported" with File Integrity Monitoring on Elastic Agent](https://discuss.elastic.co/t/input-not-supported-with-file-integrity-monitoring-on-elastic-agent/346671)

<div class="topic-metadata">

**Author:** [@ivanchak](https://discuss.elastic.co/u/ivanchak)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 12:35pm UTC](https://discuss.elastic.co/t/input-not-supported-with-file-integrity-monitoring-on-elastic-agent/346671 "2023-11-27T12:35:11Z")

</div>

As stated in the title, once adding the FIM integration to my Ubuntu 22.04 server. The fleet agent turned "Unhealthy", and shows "input not supported". Once I remove the FIM integration, then everything works just fine a…

---

## [Update an event fields based on another event](https://discuss.elastic.co/t/update-an-event-fields-based-on-another-event/347975)

<div class="topic-metadata">

**Author:** [@marcowiskhy](https://discuss.elastic.co/u/marcowiskhy)\
**Replies:** 5\
**Last updated:** [November 27, 2023, 12:25pm UTC](https://discuss.elastic.co/t/update-an-event-fields-based-on-another-event/347975 "2023-11-27T12:25:34Z")

</div>

Hi, i have some logs indexed in elasticsearch by logstash that provides two types of events: { "@timestamp": "Nov 23, 2023 @ 15:24:33.064", "Detection ID": "ldt:87654321", "logSource": "CS De…

---

## [Trouble connecting logstash to a secure elastic search cluster](https://discuss.elastic.co/t/trouble-connecting-logstash-to-a-secure-elastic-search-cluster/348045)

<div class="topic-metadata">

**Author:** [@debo9912](https://discuss.elastic.co/u/debo9912)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 12:22pm UTC](https://discuss.elastic.co/t/trouble-connecting-logstash-to-a-secure-elastic-search-cluster/348045 "2023-11-27T12:22:17Z")

</div>

Hi, I'm facing issues connecting logstash to elasticsearch cluster over https. I'm using the official elastic helm charts to setup my cluster. I'm pretty new to setting up such clusters so might be missing out something. …

---

## [How to change logo and header](https://discuss.elastic.co/t/how-to-change-logo-and-header/348034)

<div class="topic-metadata">

**Author:** [@Rutuja\_More](https://discuss.elastic.co/u/Rutuja_More)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 12:19pm UTC](https://discuss.elastic.co/t/how-to-change-logo-and-header/348034 "2023-11-27T12:19:07Z")

</div>

How can i change the logo of login page and Welcome to elastic, is it free or paid , if paid then what is the process and which paid Elastic Stack subscriptions is there ?

---

## [Error: fail to enroll: fail to execute request to fleet-server: x509: cannot validate certificate for X.X.X.X because it doesn't contain any IP SANs](https://discuss.elastic.co/t/error-fail-to-enroll-fail-to-execute-request-to-fleet-server-x509-cannot-validate-certificate-for-x-x-x-x-because-it-doesnt-contain-any-ip-sans/347124)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 5\
**Last updated:** [November 27, 2023, 12:03pm UTC](https://discuss.elastic.co/t/error-fail-to-enroll-fail-to-execute-request-to-fleet-server-x509-cannot-validate-certificate-for-x-x-x-x-because-it-doesnt-contain-any-ip-sans/347124 "2023-11-27T12:03:15Z")

</div>

Hi, i was using elastic 8.8.0 and all my agents were online green. Updating the stack went smooth but when came to upgrade the elastic agents from fleet to 8.9.1 i can see that the agents are offline but still getting d…

---

## [Elastic serverless forwarder json formatting](https://discuss.elastic.co/t/elastic-serverless-forwarder-json-formatting/347959)

<div class="topic-metadata">

**Author:** [@vsv0001](https://discuss.elastic.co/u/vsv0001)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 11:45am UTC](https://discuss.elastic.co/t/elastic-serverless-forwarder-json-formatting/347959 "2023-11-27T11:45:01Z")

</div>

we write our logs in json format to cloudwatch. does elastic serverless forwarder have any way (Deploy Elastic Serverless Forwarder | Elastic Serverless Forwarder Guide | Elastic) to send the logs in a json structure to…

---

## [Spatial Join results](https://discuss.elastic.co/t/spatial-join-results/347980)

<div class="topic-metadata">

**Author:** [@Cory34](https://discuss.elastic.co/u/Cory34)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 10:34am UTC](https://discuss.elastic.co/t/spatial-join-results/347980 "2023-11-27T10:34:54Z")

</div>

Can the results of a spatial join (8.11) be displayed in any other way besides as a map layer? Lens? Alerts? Thanks.

---

## [Keyword typed field partially matching user query](https://discuss.elastic.co/t/keyword-typed-field-partially-matching-user-query/348033)

<div class="topic-metadata">

**Author:** [@spino17](https://discuss.elastic.co/u/spino17)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 10:03am UTC](https://discuss.elastic.co/t/keyword-typed-field-partially-matching-user-query/348033 "2023-11-27T10:03:25Z")

</div>

I am using ES 7.9 version. I have a category index with document like doc\_1 = { "value": "laptops" } doc-2 = { "value": "air cooler" } with following schema: { "mappings": { "properties": { "v…

---

## [Elasticsearch configure 2 network host](https://discuss.elastic.co/t/elasticsearch-configure-2-network-host/348024)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [November 27, 2023, 9:31am UTC](https://discuss.elastic.co/t/elasticsearch-configure-2-network-host/348024 "2023-11-27T09:31:09Z")

</div>

Hi, Is it possible to configure elasticsearch to be accessible for both localhost and and ip address?

---

## [Run Rally races against an ES cluster built on OpenShift](https://discuss.elastic.co/t/run-rally-races-against-an-es-cluster-built-on-openshift/348028)

<div class="topic-metadata">

**Author:** [@benelastic](https://discuss.elastic.co/u/benelastic)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 9:18am UTC](https://discuss.elastic.co/t/run-rally-races-against-an-es-cluster-built-on-openshift/348028 "2023-11-27T09:18:37Z")

</div>

Here is how I do benchmarking with my existing ES cluster: I have an existing ES cluster built on OpenShift environment The cluster has 5 nodes and each is having exactly same resources The ES cluster is being exposed …

---

## [Does Filebeat support cgroupV2](https://discuss.elastic.co/t/does-filebeat-support-cgroupv2/348017)

<div class="topic-metadata">

**Author:** [@Thiruvikraman](https://discuss.elastic.co/u/Thiruvikraman)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 7:54am UTC](https://discuss.elastic.co/t/does-filebeat-support-cgroupv2/348017 "2023-11-27T07:54:10Z")

</div>

There are no indication in filebeat document that cgroupV2 is supported by beats or not, Is there any page or pointers to look for that details

---

## [Custom index not getting created in Kibana](https://discuss.elastic.co/t/custom-index-not-getting-created-in-kibana/347970)

<div class="topic-metadata">

**Author:** [@sunil\_s](https://discuss.elastic.co/u/sunil_s)\
**Replies:** 5\
**Last updated:** [November 27, 2023, 5:21am UTC](https://discuss.elastic.co/t/custom-index-not-getting-created-in-kibana/347970 "2023-11-27T05:21:12Z")

</div>

Unable to create new index in ES. Please find below Filebeat configuration filebeat.inputs: - type: log enabled: true paths: - xxx.log processors: - add\_cloud\_metadata: ~ - add\_docker\_metadata: ~ - add\_k…

---

## [Logstash filter to create a subfield based on specific text in a log message](https://discuss.elastic.co/t/logstash-filter-to-create-a-subfield-based-on-specific-text-in-a-log-message/347978)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 7:39pm UTC](https://discuss.elastic.co/t/logstash-filter-to-create-a-subfield-based-on-specific-text-in-a-log-message/347978 "2023-11-26T19:39:20Z")

</div>

I've been working on a Logstash configuration where I'm trying to create a subfield within the 'message1' field based on a specific text pattern ('Started'). Here's a snippet of my current Logstash filter: filter { gr…

---

## [NVMe storage with bitnami helm chart](https://discuss.elastic.co/t/nvme-storage-with-bitnami-helm-chart/347952)

<div class="topic-metadata">

**Author:** [@O\_K](https://discuss.elastic.co/u/O_K)\
**Replies:** 2\
**Last updated:** [November 26, 2023, 6:01pm UTC](https://discuss.elastic.co/t/nvme-storage-with-bitnami-helm-chart/347952 "2023-11-26T18:01:14Z")

</div>

Does bitnami helm chart support NVMe storage?

---

## [Slow elasticsearch search performance](https://discuss.elastic.co/t/slow-elasticsearch-search-performance/347902)

<div class="topic-metadata">

**Author:** [@habibkka1234](https://discuss.elastic.co/u/habibkka1234)\
**Replies:** 4\
**Last updated:** [November 26, 2023, 4:37pm UTC](https://discuss.elastic.co/t/slow-elasticsearch-search-performance/347902 "2023-11-26T16:37:02Z")

</div>

i have a eck operator based Elasticsearch cluster with 4 nodes - each with 6 cpu cores and 16 gb ram configured on eck operator. Note: Configured ILM with alias, and have 3 index already created when max size is great…

---

## [Filebeat 7.10.2: connection reset by peer Error flooding in filebeat log](https://discuss.elastic.co/t/filebeat-7-10-2-connection-reset-by-peer-error-flooding-in-filebeat-log/347826)

<div class="topic-metadata">

**Author:** [@epadmav](https://discuss.elastic.co/u/epadmav)\
**Replies:** 2\
**Last updated:** [November 26, 2023, 4:31pm UTC](https://discuss.elastic.co/t/filebeat-7-10-2-connection-reset-by-peer-error-flooding-in-filebeat-log/347826 "2023-11-26T16:31:18Z")

</div>

Hi, We have a cluster in which we're inconsistently observing the below errors filbeat.log within time periods of 5mins/10mins/15mins so on, when using filebeat to send logs to logstash. 2023-11-23T04:40:07.524+0100 …

---

## [Kibana SSO authentication configuration requirement](https://discuss.elastic.co/t/kibana-sso-authentication-configuration-requirement/347988)

<div class="topic-metadata">

**Author:** [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 2:03pm UTC](https://discuss.elastic.co/t/kibana-sso-authentication-configuration-requirement/347988 "2023-11-26T14:03:59Z")

</div>

Hello All, Thanks, in advance. We have an AWS hosted Elasticsearch and Kibana (8.10 version). Logstash is configured on AWS RHEL7 server. For Kibana I need to enable the AD based SSO authentication. Could anyone pleas…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=363)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=365)
