# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=371

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 372

---

## [Not able to parse completely with grok](https://discuss.elastic.co/t/not-able-to-parse-completely-with-grok/346870)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 2\
**Last updated:** [November 18, 2023, 10:56pm UTC](https://discuss.elastic.co/t/not-able-to-parse-completely-with-grok/346870 "2023-11-18T22:56:46Z")

</div>

"10/Nov/2023:12:59:05 +0530" 192.54.23.32 GET "GET /healthcheck HTTP/1.1" 178 200 453 2 "nginx/1.23.4 (health check server\_192.87.23.870\_Pool-1\_http\_ok)" 127.0.0.1:3000 200 0.001 0.002 0.000 0.002 apimumbcms.hydtimes…

---

## [How to hide FilterFor/FilterOut option in kibana visualization](https://discuss.elastic.co/t/how-to-hide-filterfor-filterout-option-in-kibana-visualization/347188)

<div class="topic-metadata">

**Author:** [@Saniya1](https://discuss.elastic.co/u/Saniya1)\
**Replies:** 1\
**Last updated:** [November 18, 2023, 10:28pm UTC](https://discuss.elastic.co/t/how-to-hide-filterfor-filterout-option-in-kibana-visualization/347188 "2023-11-18T22:28:58Z")

</div>

Hi, I'm using kibana lens bar charts and embedding them in my project using iFrame URL. I am facing issues with the FilterOut and FilterIn options in the legend of the chart. Is it possible to hide them? I saw that disa…

---

## [How to create a script statically in Logstash 7.17](https://discuss.elastic.co/t/how-to-create-a-script-statically-in-logstash-7-17/347446)

<div class="topic-metadata">

**Author:** [@getsolaris](https://discuss.elastic.co/u/getsolaris)\
**Replies:** 18\
**Last updated:** [November 18, 2023, 5:42pm UTC](https://discuss.elastic.co/t/how-to-create-a-script-statically-in-logstash-7-17/347446 "2023-11-18T17:42:50Z")

</div>

How to statically generate a script in Logstash 7.17 Hi, I would like to add elements to nested in elasticsearch via script via Logstash. Currently, compilations, cache\_evisions are increasing. I also increased max\_co…

---

## [Different values in new runs of logstash with Aggregate filter](https://discuss.elastic.co/t/different-values-in-new-runs-of-logstash-with-aggregate-filter/347451)

<div class="topic-metadata">

**Author:** [@Ilia](https://discuss.elastic.co/u/Ilia)\
**Replies:** 1\
**Last updated:** [November 18, 2023, 5:40pm UTC](https://discuss.elastic.co/t/different-values-in-new-runs-of-logstash-with-aggregate-filter/347451 "2023-11-18T17:40:10Z")

</div>

I've used jdbc input plugin to extract financial transactions from database. But each logical transaction is composed from multiple transactions so I used aggregate filter to merge them in one event. Here is the code of …

---

## [Elasticsearch to DB](https://discuss.elastic.co/t/elasticsearch-to-db/347381)

<div class="topic-metadata">

**Author:** [@dms6978](https://discuss.elastic.co/u/dms6978)\
**Replies:** 4\
**Last updated:** [November 18, 2023, 12:52pm UTC](https://discuss.elastic.co/t/elasticsearch-to-db/347381 "2023-11-18T12:52:03Z")

</div>

Is there a way to move Elasticsearch data into RDBMS?

---

## [Is there a way to throttle or stagger ILM?](https://discuss.elastic.co/t/is-there-a-way-to-throttle-or-stagger-ilm/346324)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 8\
**Last updated:** [November 18, 2023, 7:13am UTC](https://discuss.elastic.co/t/is-there-a-way-to-throttle-or-stagger-ilm/346324 "2023-11-18T07:13:26Z")

</div>

So, a system I'm building that uses ES heavily has been periodically not getting the data that it should out of ES. After digging in a bit, I finally noticed that there was a pattern. The elastic agent queue depth ke…

---

## [Unable to retrieve version information from Elasticsearch nodes. security\_exception](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-security-exception/347442)

<div class="topic-metadata">

**Author:** [@sp0ydiYO](https://discuss.elastic.co/u/sp0ydiYO)\
**Replies:** 4\
**Last updated:** [November 18, 2023, 6:00am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-security-exception/347442 "2023-11-18T06:00:11Z")

</div>

I've read other related questions and I confirmed this is a new question I have started the elasticsearch service, but because other clients will report certificate errors, I turned off ssl in config/elasticsearch.yml #…

---

## [Can I deploy .elser\_model\_2\_linux-x86\_64 model on elasticsearch 8.6.2?](https://discuss.elastic.co/t/can-i-deploy-elser-model-2-linux-x86-64-model-on-elasticsearch-8-6-2/347419)

<div class="topic-metadata">

**Author:** [@Rakesh\_Nayak](https://discuss.elastic.co/u/Rakesh_Nayak)\
**Replies:** 2\
**Last updated:** [November 18, 2023, 2:40am UTC](https://discuss.elastic.co/t/can-i-deploy-elser-model-2-linux-x86-64-model-on-elasticsearch-8-6-2/347419 "2023-11-18T02:40:36Z")

</div>

We have an enterprise license and are keen to explore the .elser\_model\_2\_linux-x86\_64 model for our use case. Currently, we use easticsearch 8.6.2 version. How can we deploy the elser models for this?

---

## [Kibana plug-in as a option on space selection menu](https://discuss.elastic.co/t/kibana-plug-in-as-a-option-on-space-selection-menu/347440)

<div class="topic-metadata">

**Author:** [@Chicken\_Bake](https://discuss.elastic.co/u/Chicken_Bake)\
**Replies:** 0\
**Last updated:** [November 18, 2023, 2:06am UTC](https://discuss.elastic.co/t/kibana-plug-in-as-a-option-on-space-selection-menu/347440 "2023-11-18T02:06:23Z")

</div>

I am creating a custom plug-in at this time with the kibana plug-in generator. Is there a way to set the plug-in as an option on the space selection menu rather than on a spaces navigation slide out?

---

## [Can I Ingest Excel (.xlsx) Files Of Multiple Sheets Into Elasticsearch?](https://discuss.elastic.co/t/can-i-ingest-excel-xlsx-files-of-multiple-sheets-into-elasticsearch/347427)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 1\
**Last updated:** [November 17, 2023, 11:37pm UTC](https://discuss.elastic.co/t/can-i-ingest-excel-xlsx-files-of-multiple-sheets-into-elasticsearch/347427 "2023-11-17T23:37:39Z")

</div>

I have a year's worth of Excel .xlsx files that are basically tabular reports manually updated by people. 1 file = 1 day worth of Occurrence Reports. The data in here is not in typical csv format. But its manually pop…

---

## [How to store sparse index in Elasticsearch](https://discuss.elastic.co/t/how-to-store-sparse-index-in-elasticsearch/347434)

<div class="topic-metadata">

**Author:** [@DavidAdamczyk](https://discuss.elastic.co/u/DavidAdamczyk)\
**Replies:** 0\
**Last updated:** [November 17, 2023, 9:13pm UTC](https://discuss.elastic.co/t/how-to-store-sparse-index-in-elasticsearch/347434 "2023-11-17T21:13:49Z")

</div>

I would like to store sparse vectors from my models, but I don't want to use ELSER because I need control over the entire process. How can I store sparse vectors, and how can I execute queries without relying on ELSER?

---

## [Guidelines with elastic/kibana update](https://discuss.elastic.co/t/guidelines-with-elastic-kibana-update/347131)

<div class="topic-metadata">

**Author:** [@bobmatheus](https://discuss.elastic.co/u/bobmatheus)\
**Replies:** 2\
**Last updated:** [November 17, 2023, 8:07pm UTC](https://discuss.elastic.co/t/guidelines-with-elastic-kibana-update/347131 "2023-11-17T20:07:57Z")

</div>

Hi All! I will need to update my elastic/kibana. I'm on version 6.8.11 and will need to migrate to version 7.17.4 due to a java update/security (from 8.201 to 11.0.12, log4j). Do you have any guidance or good practices…

---

## [Discover vertical grid lines gone - new "feature"?](https://discuss.elastic.co/t/discover-vertical-grid-lines-gone-new-feature/347378)

<div class="topic-metadata">

**Author:** [@qd-danh](https://discuss.elastic.co/u/qd-danh)\
**Replies:** 2\
**Last updated:** [November 17, 2023, 8:00pm UTC](https://discuss.elastic.co/t/discover-vertical-grid-lines-gone-new-feature/347378 "2023-11-17T20:00:00Z")

</div>

We just upgraded our cluster to 8.11.1 (previously 8.10.3). I'm seeing that the vertical grid lines in the discover results grid are gone. Is that a new "feature"? Changeable somewhere? I've looked through release not…

---

## [Logstash instance shows as Standalone in Kibana Stack Monitoring](https://discuss.elastic.co/t/logstash-instance-shows-as-standalone-in-kibana-stack-monitoring/347429)

<div class="topic-metadata">

**Author:** [@james\_fourth](https://discuss.elastic.co/u/james_fourth)\
**Replies:** 0\
**Last updated:** [November 17, 2023, 7:33pm UTC](https://discuss.elastic.co/t/logstash-instance-shows-as-standalone-in-kibana-stack-monitoring/347429 "2023-11-17T19:33:26Z")

</div>

Hello, this very likely could be incorrectly categorized, but because it involves monitoring of Logstash, visibility in Kibana, and metric collection using Metricbeat, I've placed it here. I've configured an ELK stack m…

---

## [HIPPA and PHI compliance](https://discuss.elastic.co/t/hippa-and-phi-compliance/347248)

<div class="topic-metadata">

**Author:** [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Replies:** 1\
**Last updated:** [November 17, 2023, 7:22pm UTC](https://discuss.elastic.co/t/hippa-and-phi-compliance/347248 "2023-11-17T19:22:09Z")

</div>

Hi, we are a health care company thinking about using Elastic cloud solutions, mainly storing our logs on Elasticsearch. Our main concern is whether Elastic cloud is HIPPA and PHI compliant?

---

## [Cannot Use Keyword Multifield that is Child of Text Field in Script](https://discuss.elastic.co/t/cannot-use-keyword-multifield-that-is-child-of-text-field-in-script/347416)

<div class="topic-metadata">

**Author:** [@Ian\_Simpson](https://discuss.elastic.co/u/Ian_Simpson)\
**Replies:** 1\
**Last updated:** [November 17, 2023, 6:52pm UTC](https://discuss.elastic.co/t/cannot-use-keyword-multifield-that-is-child-of-text-field-in-script/347416 "2023-11-17T18:52:13Z")

</div>

I am trying to accomplish case-insensitive aggregation filters on fields with multiple values as via scripting as shown here: Support case\_insensitive for 'Include' of Terms Aggregation · Issue #68819 · elastic/elasticse…

---

## [Not able to find logstash plain log in the var/log/logstash directory](https://discuss.elastic.co/t/not-able-to-find-logstash-plain-log-in-the-var-log-logstash-directory/347296)

<div class="topic-metadata">

**Author:** [@Domnic\_Raj\_D](https://discuss.elastic.co/u/Domnic_Raj_D)\
**Replies:** 5\
**Last updated:** [November 17, 2023, 6:44pm UTC](https://discuss.elastic.co/t/not-able-to-find-logstash-plain-log-in-the-var-log-logstash-directory/347296 "2023-11-17T18:44:50Z")

</div>

I am not able to find logstash-plain.log in the var/log/logstash directory. Configurations are set to write logs in /var/log/logstash directory. please advise.

---

## [Minimal security but CORS handling](https://discuss.elastic.co/t/minimal-security-but-cors-handling/347426)

<div class="topic-metadata">

**Author:** [@javerleo](https://discuss.elastic.co/u/javerleo)\
**Replies:** 0\
**Last updated:** [November 17, 2023, 6:27pm UTC](https://discuss.elastic.co/t/minimal-security-but-cors-handling/347426 "2023-11-17T18:27:11Z")

</div>

Hello. I'm trying to set up a local Elasticsearch instance for development purposes. So I started with a basic docker-compose.yml file: services: elasticsearch: image: elasticsearch:8.7.1 ports: - 9200…

---

## [How a user can favorite a item in a search ( many to many ) - product - user](https://discuss.elastic.co/t/how-a-user-can-favorite-a-item-in-a-search-many-to-many-product-user/347424)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 0\
**Last updated:** [November 17, 2023, 4:33pm UTC](https://discuss.elastic.co/t/how-a-user-can-favorite-a-item-in-a-search-many-to-many-product-user/347424 "2023-11-17T16:33:15Z")

</div>

hello , I wonder to know how a user could to save favorites , like this image . if I use a relational database , I could make a many to many relational . but with Elasticsearch . how could I do it ? I know that I c…

---

## [Filebeat-OSS 7.16.2 compatibility with Logstash-OSS (Opensearch)](https://discuss.elastic.co/t/filebeat-oss-7-16-2-compatibility-with-logstash-oss-opensearch/347414)

<div class="topic-metadata">

**Author:** [@saqib\_tune](https://discuss.elastic.co/u/saqib_tune)\
**Replies:** 3\
**Last updated:** [November 17, 2023, 3:37pm UTC](https://discuss.elastic.co/t/filebeat-oss-7-16-2-compatibility-with-logstash-oss-opensearch/347414 "2023-11-17T15:37:51Z")

</div>

I am implementing Opensearch, Logstash and filebeat stack on Kubernetes with the following versions, Filebeat: Filebeat 7.16.2 | Elastic Logstash: docker pull opensearchproject/logstash-oss-with-opensearch-output-plugi…

---

## [Production deployment with dedicated masters](https://discuss.elastic.co/t/production-deployment-with-dedicated-masters/346965)

<div class="topic-metadata">

**Author:** [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Replies:** 9\
**Last updated:** [November 17, 2023, 3:20pm UTC](https://discuss.elastic.co/t/production-deployment-with-dedicated-masters/346965 "2023-11-17T15:20:00Z")

</div>

Hi, I plan to deploy Elasticsearch for a production environment following this architecture : 3 x dedicated Master node (node.roles: \[ master \]) 1 x Hot Data node (node.roles: \[ data\_hot \]) 1 x Warm Data node (node.ro…

---

## [Cannot generate report in kibana](https://discuss.elastic.co/t/cannot-generate-report-in-kibana/347091)

<div class="topic-metadata">

**Author:** [@hasan.idriss](https://discuss.elastic.co/u/hasan.idriss)\
**Replies:** 6\
**Last updated:** [November 17, 2023, 3:08pm UTC](https://discuss.elastic.co/t/cannot-generate-report-in-kibana/347091 "2023-11-17T15:08:11Z")

</div>

I am using Elasticsearch 8.7.1 my cluster consists of 2 nodes and the Kibana version is 8.7.1, I am facing a problem with generating CSV it was working normally, but two weeks from now it stopped with the error "reportin…

---

## [Elasticsearch not working post migration of OS](https://discuss.elastic.co/t/elasticsearch-not-working-post-migration-of-os/347375)

<div class="topic-metadata">

**Author:** [@Techiebee](https://discuss.elastic.co/u/Techiebee)\
**Replies:** 1\
**Last updated:** [November 17, 2023, 2:33pm UTC](https://discuss.elastic.co/t/elasticsearch-not-working-post-migration-of-os/347375 "2023-11-17T14:33:05Z")

</div>

I have migrated my Elasticsearch cluster servers from centos7 to RHEL8 , post migration my cluster isn’t picking the hostname, for every server re-build I have to manually edit the hostname and restart the Elasticsearch …

---

## [403 auth error when using the filebeat input azure-blob-storage (error: Request date header too old)](https://discuss.elastic.co/t/403-auth-error-when-using-the-filebeat-input-azure-blob-storage-error-request-date-header-too-old/343089)

<div class="topic-metadata">

**Author:** [@djesus](https://discuss.elastic.co/u/djesus)\
**Replies:** 8\
**Last updated:** [November 17, 2023, 2:27pm UTC](https://discuss.elastic.co/t/403-auth-error-when-using-the-filebeat-input-azure-blob-storage-error-request-date-header-too-old/343089 "2023-11-17T14:27:12Z")

</div>

Hi , while using the azure-blob-storage input for filebeat im constantly getting this error. { "@timestamp": "2023-09-14T21:03:15.549Z", "account\_name": "xxxx", "container\_name": "xxxxx", "ecs.version": "1.6.0", "…

---

## [Partition HNSW graph per user, elastic KNN](https://discuss.elastic.co/t/partition-hnsw-graph-per-user-elastic-knn/346394)

<div class="topic-metadata">

**Author:** [@s.ankursonawane](https://discuss.elastic.co/u/s.ankursonawane)\
**Replies:** 4\
**Last updated:** [November 17, 2023, 2:21pm UTC](https://discuss.elastic.co/t/partition-hnsw-graph-per-user-elastic-knn/346394 "2023-11-17T14:21:53Z")

</div>

Hi, I was exploring the performance of Elastic KNN search scaling. I would like to section off my hnsw graph per user as my searches will always be filtered by the user. The only way I can think to do this in ES seems to…

---

## [Custom Elasticsearch queries without using script](https://discuss.elastic.co/t/custom-elasticsearch-queries-without-using-script/347404)

<div class="topic-metadata">

**Author:** [@vickram](https://discuss.elastic.co/u/vickram)\
**Replies:** 0\
**Last updated:** [November 17, 2023, 12:39pm UTC](https://discuss.elastic.co/t/custom-elasticsearch-queries-without-using-script/347404 "2023-11-17T12:39:40Z")

</div>

{"publishDate":"2023-08-06T10:34:00Z","data":{"evalFrequency":"3"}} Above is the sample data that I have in Elasticsearch, where I am struggling to find the right query to get results on the basis of the below condition…

---

## [Beat setup dashboards don't work in different spaces](https://discuss.elastic.co/t/beat-setup-dashboards-dont-work-in-different-spaces/346925)

<div class="topic-metadata">

**Author:** [@litsegaard](https://discuss.elastic.co/u/litsegaard)\
**Replies:** 19\
**Last updated:** [November 17, 2023, 12:58pm UTC](https://discuss.elastic.co/t/beat-setup-dashboards-dont-work-in-different-spaces/346925 "2023-11-17T12:58:02Z")

</div>

I'm running the 8.10.4 stack and having trouble settings up the dashboards for various beats. I run a simple setup command using Docker and all the dashboards for a given beat are imported. However, when clicking a link …

---

## [Ssl between nodes](https://discuss.elastic.co/t/ssl-between-nodes/346742)

<div class="topic-metadata">

**Author:** [@My\_Self](https://discuss.elastic.co/u/My_Self)\
**Replies:** 3\
**Last updated:** [November 17, 2023, 11:09am UTC](https://discuss.elastic.co/t/ssl-between-nodes/346742 "2023-11-17T11:09:37Z")

</div>

hi I'm upgrading to 8.5.1 in a kubernetes solution with helm installation And had an issue with ssl between nodes Found The truststore does not contain any trusted certificate entries after upgrade to 8.0 and used so…

---

## [Filebeat elastic slow logs not showing](https://discuss.elastic.co/t/filebeat-elastic-slow-logs-not-showing/347385)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 1\
**Last updated:** [November 17, 2023, 10:16am UTC](https://discuss.elastic.co/t/filebeat-elastic-slow-logs-not-showing/347385 "2023-11-17T10:16:01Z")

</div>

Hi Team, I have 2 node Elasticsearch cluster on docker. I was enabled slow logs and logs file storing at /var/log/elasticsearh/\<cluster\_name\_\_index\_indexing\_slowlog.log\> so that i configured filebeat as filebeat.confi…

---

## [Filebeat elasticsearh](https://discuss.elastic.co/t/filebeat-elasticsearh/347077)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 13\
**Last updated:** [November 17, 2023, 10:14am UTC](https://discuss.elastic.co/t/filebeat-elasticsearh/347077 "2023-11-17T10:14:04Z")

</div>

Hi Team, I have Elasticsearch database cluster with two nodes in docker. and Kibana configured. while adding filebeat getting an error. filebeat error log pasted here. {"@timestamp":"2023-11-14T04:19:07.634Z", "log.lev…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=370)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=372)
