# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=370

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 371

---

## [Docker Hard Disk Image File Being Too Large](https://discuss.elastic.co/t/docker-hard-disk-image-file-being-too-large/347443)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 2\
**Last updated:** [November 20, 2023, 6:19pm UTC](https://discuss.elastic.co/t/docker-hard-disk-image-file-being-too-large/347443 "2023-11-20T18:19:30Z")

</div>

Its now killing my computer space. I'm in the midst of ingesting 537 csv files (total 10.7GB) into elasticsearch. C:\\Users\\ethan\\AppData\\Local\\Docker\\wsl\\data I'm not sure why it became so big.

---

## [CSV Export Permission Issue for Kibana Users (Non-Superuser) in Elasticsearch 8.6.1](https://discuss.elastic.co/t/csv-export-permission-issue-for-kibana-users-non-superuser-in-elasticsearch-8-6-1/346627)

<div class="topic-metadata">

**Author:** [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Replies:** 3\
**Last updated:** [November 20, 2023, 5:46pm UTC](https://discuss.elastic.co/t/csv-export-permission-issue-for-kibana-users-non-superuser-in-elasticsearch-8-6-1/346627 "2023-11-20T17:46:21Z")

</div>

I have installed Elasticsearch with an active license, but I am encountering an issue when trying to export data to CSV while logged in as either the kibana-viewer or kibana-full user. Notably, exporting works fine when …

---

## [RequestAbortedError on bulk indexing happens randomly](https://discuss.elastic.co/t/requestabortederror-on-bulk-indexing-happens-randomly/347518)

<div class="topic-metadata">

**Author:** [@Ashan-FCC](https://discuss.elastic.co/u/Ashan-FCC)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 5:23pm UTC](https://discuss.elastic.co/t/requestabortederror-on-bulk-indexing-happens-randomly/347518 "2023-11-20T17:23:25Z")

</div>

I use the bulk api to index fairly large objects. My indexing cronjob runs every 30 seconds which will index any objects updated in the last 30 seconds. I have another cronjob that runs at midnight which updates alot of …

---

## [Winlogbeat Powershell Module](https://discuss.elastic.co/t/winlogbeat-powershell-module/347019)

<div class="topic-metadata">

**Author:** [@fsch](https://discuss.elastic.co/u/fsch)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 5:07pm UTC](https://discuss.elastic.co/t/winlogbeat-powershell-module/347019 "2023-11-20T17:07:37Z")

</div>

Hi everyone we try to ship Powershell logs (Event ID: 4103 / Provider: Microsoft-Windows-PowerShell) to elastic. Using the field "powershell.command.name" in our .yml file ( PowerShell module fields | Winlogbeat Refere…

---

## [Metricbeat 8.11.0 - system module using excessive amount of memory](https://discuss.elastic.co/t/metricbeat-8-11-0-system-module-using-excessive-amount-of-memory/347236)

<div class="topic-metadata">

**Author:** [@twilson](https://discuss.elastic.co/u/twilson)\
**Replies:** 4\
**Last updated:** [November 20, 2023, 4:51pm UTC](https://discuss.elastic.co/t/metricbeat-8-11-0-system-module-using-excessive-amount-of-memory/347236 "2023-11-20T16:51:43Z")

</div>

I'm using the system integration with the Elastic agent and have the ' Collect metrics from System instances' option enabled, with all the default datasets within that selected. With the 8.11.0 version of this integrati…

---

## [Configure auditbeats to work with auditd](https://discuss.elastic.co/t/configure-auditbeats-to-work-with-auditd/347544)

<div class="topic-metadata">

**Author:** [@cdy5159](https://discuss.elastic.co/u/cdy5159)\
**Replies:** 3\
**Last updated:** [November 20, 2023, 3:36pm UTC](https://discuss.elastic.co/t/configure-auditbeats-to-work-with-auditd/347544 "2023-11-20T15:36:48Z")

</div>

My systems are required to have auditd operating and immutable. Can auditbeat be configured to work with immutable auditd? If so, how?

---

## [Hide table column if used as filter](https://discuss.elastic.co/t/hide-table-column-if-used-as-filter/347391)

<div class="topic-metadata">

**Author:** [@gconradi](https://discuss.elastic.co/u/gconradi)\
**Replies:** 5\
**Last updated:** [November 20, 2023, 3:05pm UTC](https://discuss.elastic.co/t/hide-table-column-if-used-as-filter/347391 "2023-11-20T15:05:47Z")

</div>

Hi community, I'm using Kibana 8.10 (Cloud) for log analysis, with quite some columns shown in a lens table. When I filter for a specific column value, the value is shown in the filter bar and the column value is highli…

---

## [Is there any way to avoid using dfs\_query\_then\_fetch ?](https://discuss.elastic.co/t/is-there-any-way-to-avoid-using-dfs-query-then-fetch/347540)

<div class="topic-metadata">

**Author:** [@Arnaud\_Schneider](https://discuss.elastic.co/u/Arnaud_Schneider)\
**Replies:** 0\
**Last updated:** [November 20, 2023, 2:42pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-avoid-using-dfs-query-then-fetch/347540 "2023-11-20T14:42:33Z")

</div>

Hello, i have an Elastic query using score to sort results by relevancy. Me, and others devs, have observed that, on one particular request, the order of the results is inconsistent, because the differents documents ar…

---

## [SSL error in docker container](https://discuss.elastic.co/t/ssl-error-in-docker-container/347542)

<div class="topic-metadata">

**Author:** [@Manoj\_Chander](https://discuss.elastic.co/u/Manoj_Chander)\
**Replies:** 0\
**Last updated:** [November 20, 2023, 2:43pm UTC](https://discuss.elastic.co/t/ssl-error-in-docker-container/347542 "2023-11-20T14:43:50Z")

</div>

I am setting up docker container for elasticsearch and kibana : (customised from docker compose) im doing setup container steps manually image used : docker.elastic.co/elasticsearch/elasticsearch:8.11.1 ==============…

---

## [Elastic Agents don't see upgrade available in Kibana](https://discuss.elastic.co/t/elastic-agents-dont-see-upgrade-available-in-kibana/347271)

<div class="topic-metadata">

**Author:** [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Replies:** 6\
**Last updated:** [November 20, 2023, 2:28pm UTC](https://discuss.elastic.co/t/elastic-agents-dont-see-upgrade-available-in-kibana/347271 "2023-11-20T14:28:55Z")

</div>

Hi, My Elastic Agents are currently at 8.11.0 but they don't seem to see that there is 8.11.1 so I am unable to upgrade them using Kibana. It was the same way when they were still at version 8.10.x and version 8.11.0 wa…

---

## [SSL\_ERROR\_SYSCALL error connecting to Elasticsearch using SSL CA Certificate](https://discuss.elastic.co/t/ssl-error-syscall-error-connecting-to-elasticsearch-using-ssl-ca-certificate/347536)

<div class="topic-metadata">

**Author:** [@Giovanni\_Martarello](https://discuss.elastic.co/u/Giovanni_Martarello)\
**Replies:** 0\
**Last updated:** [November 20, 2023, 2:11pm UTC](https://discuss.elastic.co/t/ssl-error-syscall-error-connecting-to-elasticsearch-using-ssl-ca-certificate/347536 "2023-11-20T14:11:38Z")

</div>

Hello I have an Elasticsearch server that uses ssl certificates issued by a certification unit. This is my configuration: #----------------------- BEGIN SECURITY AUTO CONFIGURATION ---------------------- - # # The fol…

---

## [How can create datastream automatically](https://discuss.elastic.co/t/how-can-create-datastream-automatically/347531)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 2:04pm UTC](https://discuss.elastic.co/t/how-can-create-datastream-automatically/347531 "2023-11-20T14:04:53Z")

</div>

This is my logstash output part : after run , It will create index with the name of "TXT" but I want to create automatically datastream with all index templates and .. . Is that possible? output{ stdout{} elast…

---

## [ML : detects unusually low number of users](https://discuss.elastic.co/t/ml-detects-unusually-low-number-of-users/346057)

<div class="topic-metadata">

**Author:** [@AmS](https://discuss.elastic.co/u/AmS)\
**Replies:** 7\
**Last updated:** [November 20, 2023, 1:55pm UTC](https://discuss.elastic.co/t/ml-detects-unusually-low-number-of-users/346057 "2023-11-20T13:55:02Z")

</div>

Hello , I'm using machine learning detector on version 7.17. I would like to detect unusually low number of users. I m using for that low\_distinct\_count as function. It works fine when at least there is at least one …

---

## [Vault database plugin](https://discuss.elastic.co/t/vault-database-plugin/346756)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 1:37pm UTC](https://discuss.elastic.co/t/vault-database-plugin/346756 "2023-11-20T13:37:58Z")

</div>

Hi Team, I was deployed Elasticsearch 8.8.1 on docker and while installing the vault Elasticsearch database plugin getting an error as

---

## [Why my query does not work correctly after create new filed in logstash](https://discuss.elastic.co/t/why-my-query-does-not-work-correctly-after-create-new-filed-in-logstash/347504)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 5\
**Last updated:** [November 20, 2023, 12:16pm UTC](https://discuss.elastic.co/t/why-my-query-does-not-work-correctly-after-create-new-filed-in-logstash/347504 "2023-11-20T12:16:23Z")

</div>

This is my sample data: 134.255.248.30 - - \[20/Nov/2023:09:04:57 +0330\] "GET /serve/finnotech/validateDest?key=3f94393b5eaab29a167e5edc8a99860cba121550053bd113d291d71f146a7fa0&parameters=%7B%22dest%22:%22IR5201900000002…

---

## [Kibana couldn't connect to remote elastic-search cluster](https://discuss.elastic.co/t/kibana-couldnt-connect-to-remote-elastic-search-cluster/347508)

<div class="topic-metadata">

**Author:** [@nazmus\_sakib\_1987](https://discuss.elastic.co/u/nazmus_sakib_1987)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 12:11pm UTC](https://discuss.elastic.co/t/kibana-couldnt-connect-to-remote-elastic-search-cluster/347508 "2023-11-20T12:11:04Z")

</div>

I'm configuring kibana:6.8.23 for remote elasticsearch host . I used docker compose file to install it. I use the env ELASTICSEARCH\_HOSTS: '\["my elasticsearch host"\]' . But find that /usr/share/kibana/config/kibana.yamlf…

---

## [Track changes in Logstash](https://discuss.elastic.co/t/track-changes-in-logstash/347452)

<div class="topic-metadata">

**Author:** [@Felicien\_Ihirwe](https://discuss.elastic.co/u/Felicien_Ihirwe)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 12:05pm UTC](https://discuss.elastic.co/t/track-changes-in-logstash/347452 "2023-11-20T12:05:14Z")

</div>

How to come from data in 1 to data in 2? Note that the col1 is continuous. col1 2.3 2.3 2.3 5.7 5.7 6.1 6.1 .... .. . I want to achieve this: col1 | col2 2.3 | 1 2.3 |1 2.3 |1 5.7 |2 5.7 |2 6.1 |3 6.1…

---

## [UnavailableShardsException: at least one primary shard for the index \[.security-7\] is unavailable](https://discuss.elastic.co/t/unavailableshardsexception-at-least-one-primary-shard-for-the-index-security-7-is-unavailable/347393)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 5\
**Last updated:** [November 20, 2023, 11:03am UTC](https://discuss.elastic.co/t/unavailableshardsexception-at-least-one-primary-shard-for-the-index-security-7-is-unavailable/347393 "2023-11-20T11:03:48Z")

</div>

Hi, I have deleted all files manually from /var/lib/elasticsearch/nodes/0/indices/. Now when i restart Elasticsearch server. \[2023-11-17T09:20:22,899\]\[INFO \]\[o.e.x.s.a.RealmsAuthenticator\] \[ip\] Authentication of \[elast…

---

## [Logstash pipeline does not work](https://discuss.elastic.co/t/logstash-pipeline-does-not-work/347487)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 2\
**Last updated:** [November 20, 2023, 10:56am UTC](https://discuss.elastic.co/t/logstash-pipeline-does-not-work/347487 "2023-11-20T10:56:27Z")

</div>

This is my pattern log : 80.253.157.26 - - \[19/Nov/2023:15:17:50 +0330\] "POST /followup/danesh/5b81bc62-d82d-4f98-aacd-eab80474faca HTTP/1.1" 200 852 This is apache log . As I know if I want to use this log in logstash…

---

## [Logstash The order of synchronized data fields is inconsistent with the source end](https://discuss.elastic.co/t/logstash-the-order-of-synchronized-data-fields-is-inconsistent-with-the-source-end/347509)

<div class="topic-metadata">

**Author:** [@haimaren](https://discuss.elastic.co/u/haimaren)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 10:29am UTC](https://discuss.elastic.co/t/logstash-the-order-of-synchronized-data-fields-is-inconsistent-with-the-source-end/347509 "2023-11-20T10:29:58Z")

</div>

My Logstash Configuration input { elasticsearch { hosts =\> "http://172.19.23.12:9200" index =\> "\*" size =\> 1000 scroll =\> "5m" docinfo =\> true } } filter { mutate { …

---

## [Slow Wildcard searches are prioritized in Bool queries](https://discuss.elastic.co/t/slow-wildcard-searches-are-prioritized-in-bool-queries/347521)

<div class="topic-metadata">

**Author:** [@ratinhoo](https://discuss.elastic.co/u/ratinhoo)\
**Replies:** 0\
**Last updated:** [November 20, 2023, 10:07am UTC](https://discuss.elastic.co/t/slow-wildcard-searches-are-prioritized-in-bool-queries/347521 "2023-11-20T10:07:10Z")

</div>

Hi, we are dynamically generating bool queries that sometimes include wildcard searches. I understood that the execution order of bool queries is depending on term frequencies, document frequencies and other metrics. Pr…

---

## [How design tracks based on our reality usage?](https://discuss.elastic.co/t/how-design-tracks-based-on-our-reality-usage/347265)

<div class="topic-metadata">

**Author:** [@benelastic](https://discuss.elastic.co/u/benelastic)\
**Replies:** 2\
**Last updated:** [November 20, 2023, 8:56am UTC](https://discuss.elastic.co/t/how-design-tracks-based-on-our-reality-usage/347265 "2023-11-20T08:56:14Z")

</div>

Rally has provided a bunch of out-of-box default tracks. But we may not use those tracks to benchmark our ES deployment, right? What are the best practices to benchmark ES based on our actual scenarios? Is it necessary t…

---

## [Failed to retrieve password hash for reserved user \[elastic\] org.elasticsearch.action.UnavailableShardsException: at least one primary shard for the index \[.security-7\] is unavailable](https://discuss.elastic.co/t/failed-to-retrieve-password-hash-for-reserved-user-elastic-org-elasticsearch-action-unavailableshardsexception-at-least-one-primary-shard-for-the-index-security-7-is-unavailable/347499)

<div class="topic-metadata">

**Author:** [@NIK2501nc](https://discuss.elastic.co/u/NIK2501nc)\
**Replies:** 0\
**Last updated:** [November 20, 2023, 6:42am UTC](https://discuss.elastic.co/t/failed-to-retrieve-password-hash-for-reserved-user-elastic-org-elasticsearch-action-unavailableshardsexception-at-least-one-primary-shard-for-the-index-security-7-is-unavailable/347499 "2023-11-20T06:42:11Z")

</div>

failed to retrieve password hash for reserved user \[elastic\] org.elasticsearch.action.UnavailableShardsException: at least one primary shard for the index \[.security-7\] is unavailable You'll get this issue when in your …

---

## [How to define workload basing on my usage on ElasticSearch?](https://discuss.elastic.co/t/how-to-define-workload-basing-on-my-usage-on-elasticsearch/347386)

<div class="topic-metadata">

**Author:** [@benelastic](https://discuss.elastic.co/u/benelastic)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 4:24am UTC](https://discuss.elastic.co/t/how-to-define-workload-basing-on-my-usage-on-elasticsearch/347386 "2023-11-20T04:24:04Z")

</div>

How to define workload basing on my usage on Elasticsearch?

---

## [Security\_exception: unable to authenticate user \[kibana\_system\] for REST request \[/\_nodes?filter\_path=nodes.\*.version%2Cnodes.\*.http.publish\_address%2Cnodes.\*.ip\]](https://discuss.elastic.co/t/security-exception-unable-to-authenticate-user-kibana-system-for-rest-request-nodes-filter-path-nodes-version-2cnodes-http-publish-address-2cnodes-ip/347456)

<div class="topic-metadata">

**Author:** [@nikhil\_vippala](https://discuss.elastic.co/u/nikhil_vippala)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 12:11am UTC](https://discuss.elastic.co/t/security-exception-unable-to-authenticate-user-kibana-system-for-rest-request-nodes-filter-path-nodes-version-2cnodes-http-publish-address-2cnodes-ip/347456 "2023-11-20T00:11:15Z")

</div>

I am using the below docker-compose file for spinning up the elasticsearch 8.11v version: "2.2" services: setup: image: docker.elastic.co/elasticsearch/elasticsearch:${STACK\_VERSION} volumes: - certs:/u…

---

## [Why logstash cannot start after define new pipeline](https://discuss.elastic.co/t/why-logstash-cannot-start-after-define-new-pipeline/347483)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 3\
**Last updated:** [November 19, 2023, 8:39pm UTC](https://discuss.elastic.co/t/why-logstash-cannot-start-after-define-new-pipeline/347483 "2023-11-19T20:39:20Z")

</div>

I was created pipeline1 in logstash and it was working excellent but I added a new pipeline now when I want to start logstash it shows follow error and cannot start icsearch is unreachable or down?) {:message=\>"No Avail…

---

## [Why does translate not work for me?](https://discuss.elastic.co/t/why-does-translate-not-work-for-me/347478)

<div class="topic-metadata">

**Author:** [@andre22](https://discuss.elastic.co/u/andre22)\
**Replies:** 2\
**Last updated:** [November 19, 2023, 5:45pm UTC](https://discuss.elastic.co/t/why-does-translate-not-work-for-me/347478 "2023-11-19T17:45:08Z")

</div>

Hi, I can't wrap my head around why I don't get this translate filter to work. I have a bunch of IoT logfiles (csv) that I want to import. One of the fields (KO-ID) does contain an internal ID of the old log engine, …

---

## [How to build dsl query in spring-data-elasticsearch 5 (ElasticsearchOperations , CriteriaQuery)](https://discuss.elastic.co/t/how-to-build-dsl-query-in-spring-data-elasticsearch-5-elasticsearchoperations-criteriaquery/347475)

<div class="topic-metadata">

**Author:** [@dan\_kim](https://discuss.elastic.co/u/dan_kim)\
**Replies:** 0\
**Last updated:** [November 19, 2023, 1:56pm UTC](https://discuss.elastic.co/t/how-to-build-dsl-query-in-spring-data-elasticsearch-5-elasticsearchoperations-criteriaquery/347475 "2023-11-19T13:56:31Z")

</div>

Im trying to write some query using spring data elasticsearch 5 and this is my environment elasticsearch 8 spring boot 3 spring-data-elasticsearch 5 and i can not make query like this so PLEASE help me with building …

---

## [Logstash is shutting down after connecting to Elastic Search due to One or more required cgroup files or directories not found](https://discuss.elastic.co/t/logstash-is-shutting-down-after-connecting-to-elastic-search-due-to-one-or-more-required-cgroup-files-or-directories-not-found/347448)

<div class="topic-metadata">

**Author:** [@sathishkumarD](https://discuss.elastic.co/u/sathishkumarD)\
**Replies:** 6\
**Last updated:** [November 19, 2023, 1:56pm UTC](https://discuss.elastic.co/t/logstash-is-shutting-down-after-connecting-to-elastic-search-due-to-one-or-more-required-cgroup-files-or-directories-not-found/347448 "2023-11-19T13:56:15Z")

</div>

\[2023-11-18T14:35:04,262\]\[DEBUG\]\[org.logstash.execution.PeriodicFlush\]\[main\] Pushing flush onto pipeline. \[2023-11-18T14:35:04,906\]\[DEBUG\]\[logstash.instrument.periodicpoller.cgroup\] One or more required cgroup files or …

---

## [Filebeat not indexing files immediately, have to make changes to files for it to get sent](https://discuss.elastic.co/t/filebeat-not-indexing-files-immediately-have-to-make-changes-to-files-for-it-to-get-sent/347468)

<div class="topic-metadata">

**Author:** [@Ahmed\_Faisal](https://discuss.elastic.co/u/Ahmed_Faisal)\
**Replies:** 0\
**Last updated:** [November 19, 2023, 8:07am UTC](https://discuss.elastic.co/t/filebeat-not-indexing-files-immediately-have-to-make-changes-to-files-for-it-to-get-sent/347468 "2023-11-19T08:07:39Z")

</div>

I am an ELK newbie. I have created some text files using a python script and saved them in a folder. I have configured Filebeat to send to Logstash and Logstash to Elasticsearch. I have set the path as - /home/vboxuser/…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=369)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=371)
