# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=372

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 373

---

## [Auto reload autodiscover](https://discuss.elastic.co/t/auto-reload-autodiscover/347395)

<div class="topic-metadata">

**Author:** [@Casper\_Thrane](https://discuss.elastic.co/u/Casper_Thrane)\
**Replies:** 0\
**Last updated:** [November 17, 2023, 10:03am UTC](https://discuss.elastic.co/t/auto-reload-autodiscover/347395 "2023-11-17T10:03:35Z")

</div>

Hi Is possible to auto reload the configuration, for autodiscover? Br Casper

---

## [Action variables for a Logs threshold rule](https://discuss.elastic.co/t/action-variables-for-a-logs-threshold-rule/347394)

<div class="topic-metadata">

**Author:** [@Arty](https://discuss.elastic.co/u/Arty)\
**Replies:** 0\
**Last updated:** [November 17, 2023, 9:53am UTC](https://discuss.elastic.co/t/action-variables-for-a-logs-threshold-rule/347394 "2023-11-17T09:53:57Z")

</div>

Hi everyone, I have set up a log threshold rule to retrieve incoming suricata alerts data and send them to another tool using a webhook action. I tried accessing available variables using mustache such as {{#context.al…

---

## [Index Management](https://discuss.elastic.co/t/index-management/347321)

<div class="topic-metadata">

**Author:** [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Replies:** 4\
**Last updated:** [November 17, 2023, 6:25am UTC](https://discuss.elastic.co/t/index-management/347321 "2023-11-17T06:25:51Z")

</div>

Hi, I am currently running out of storage on my Wazuh Server Hosted server. And from the search I found "/var/lib/wazuh-indexes/\* " is consuming a lot of disk space. First Question, Will it be okay if I delete all the p…

---

## [Migrating Elastic Cluster to another cluster](https://discuss.elastic.co/t/migrating-elastic-cluster-to-another-cluster/347221)

<div class="topic-metadata">

**Author:** [@Putri\_Arsyi](https://discuss.elastic.co/u/Putri_Arsyi)\
**Replies:** 2\
**Last updated:** [November 17, 2023, 2:04am UTC](https://discuss.elastic.co/t/migrating-elastic-cluster-to-another-cluster/347221 "2023-11-17T02:04:34Z")

</div>

Hi, I would like to upgrade elastic to latest version. I'm going to create new cluster with latest version then migrate the data from existing cluster (version 8.6) to new cluster. I'm going to migrate the data also th…

---

## [Filebeat7.12 Does it support writing to multiple kafka clusters](https://discuss.elastic.co/t/filebeat7-12-does-it-support-writing-to-multiple-kafka-clusters/347376)

<div class="topic-metadata">

**Author:** [@13068098071](https://discuss.elastic.co/u/13068098071)\
**Replies:** 0\
**Last updated:** [November 17, 2023, 1:45am UTC](https://discuss.elastic.co/t/filebeat7-12-does-it-support-writing-to-multiple-kafka-clusters/347376 "2023-11-17T01:45:48Z")

</div>

I currently have multiple collection paths and want to write them to different Kafka clusters. For example: /home/work/service1 write kafka cluster1 /home/work/service2;/home/work/service3//home/work/service4 write…

---

## [Where is the bottleneck of KNN retrieval speed? How to analyze?](https://discuss.elastic.co/t/where-is-the-bottleneck-of-knn-retrieval-speed-how-to-analyze/347269)

<div class="topic-metadata">

**Author:** [@Lack](https://discuss.elastic.co/u/Lack)\
**Replies:** 2\
**Last updated:** [November 16, 2023, 11:44pm UTC](https://discuss.elastic.co/t/where-is-the-bottleneck-of-knn-retrieval-speed-how-to-analyze/347269 "2023-11-16T23:44:41Z")

</div>

I have three data nodes, configured as 16 core 64g, with an index of about 19million documents, including 768 dimensional vector fields. The number of fragments is 24, the number of copies is 1, and the total size includ…

---

## [Why plugin needed instead of SDK](https://discuss.elastic.co/t/why-plugin-needed-instead-of-sdk/347370)

<div class="topic-metadata">

**Author:** [@Prabhu\_shanmughapriy](https://discuss.elastic.co/u/Prabhu_shanmughapriy)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 9:28pm UTC](https://discuss.elastic.co/t/why-plugin-needed-instead-of-sdk/347370 "2023-11-16T21:28:15Z")

</div>

Hi, I would like to understand why should we write an Elasticsearch plugin vs Elasticsearch SDK.. This for fuzzy search for indices. Is there any performance reasons with plugins?

---

## [Verify filebeat is reading logs from a docker container](https://discuss.elastic.co/t/verify-filebeat-is-reading-logs-from-a-docker-container/347365)

<div class="topic-metadata">

**Author:** [@Jim\_Maroulis](https://discuss.elastic.co/u/Jim_Maroulis)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 8:24pm UTC](https://discuss.elastic.co/t/verify-filebeat-is-reading-logs-from-a-docker-container/347365 "2023-11-16T20:24:08Z")

</div>

I am attempting to setup reading logs from a docker container running a web server to filebeat to logstash and I cannot seem to get it right. My question is how do I verify if filebeat is even getting anything from the …

---

## [Parsing multiline java execption](https://discuss.elastic.co/t/parsing-multiline-java-execption/347262)

<div class="topic-metadata">

**Author:** [@apsh](https://discuss.elastic.co/u/apsh)\
**Replies:** 3\
**Last updated:** [November 16, 2023, 7:20pm UTC](https://discuss.elastic.co/t/parsing-multiline-java-execption/347262 "2023-11-16T19:20:29Z")

</div>

Hello, I am trying to add multiline to handle javaexception in our logs but still having issue : This is my pattern : paths: - /var/log/tomcat10/\* multiline.type: pattern multiline.pattern: '^\\d{2}-\\w{3}-\\d{4…

---

## [404 When Using Copy Saved Objects to Space API](https://discuss.elastic.co/t/404-when-using-copy-saved-objects-to-space-api/344942)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 2\
**Last updated:** [November 16, 2023, 7:15pm UTC](https://discuss.elastic.co/t/404-when-using-copy-saved-objects-to-space-api/344942 "2023-11-16T19:15:27Z")

</div>

Hello, Elastic! I'm currently trying to use the Copy Saved Objects api (copying an Uptime status Rule from our 'sandbox' space to our 'default' space) and am having issues with 404s. The object exists in the Sandbox sp…

---

## [How to change index pattern used by visualization/widget in kibana dashboard in kibana 7.17.9?](https://discuss.elastic.co/t/how-to-change-index-pattern-used-by-visualization-widget-in-kibana-dashboard-in-kibana-7-17-9/347080)

<div class="topic-metadata">

**Author:** [@Daemon1](https://discuss.elastic.co/u/Daemon1)\
**Replies:** 2\
**Last updated:** [November 16, 2023, 7:09pm UTC](https://discuss.elastic.co/t/how-to-change-index-pattern-used-by-visualization-widget-in-kibana-dashboard-in-kibana-7-17-9/347080 "2023-11-16T19:09:31Z")

</div>

Steps: click on All type\>\>\>Aggregation based\>\>\>data table\>\> select index pattern(index-pattern1) from the list(index-pattern1, index-pattern2, index-pattern3) save the widget. Now I want to change the index-pattern1 u…

---

## [Logstash re-ingests files](https://discuss.elastic.co/t/logstash-re-ingests-files/347358)

<div class="topic-metadata">

**Author:** [@hjsroldan](https://discuss.elastic.co/u/hjsroldan)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 6:21pm UTC](https://discuss.elastic.co/t/logstash-re-ingests-files/347358 "2023-11-16T18:21:11Z")

</div>

Hi, I have a Logstash to Elasticsearch project where logstash collects all the logs from the server and pushes it to elasticsearch. However, seems like the Logstash ingests my logs multiple times. Ingested logs from yes…

---

## [Docker-compose.yml Fleet server failing to start](https://discuss.elastic.co/t/docker-compose-yml-fleet-server-failing-to-start/347356)

<div class="topic-metadata">

**Author:** [@ster1ingArch3r](https://discuss.elastic.co/u/ster1ingArch3r)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 5:20pm UTC](https://discuss.elastic.co/t/docker-compose-yml-fleet-server-failing-to-start/347356 "2023-11-16T17:20:21Z")

</div>

Good Day all, I am working on setting up docker-compose for the elastic stack and I cannot seem to get the fleet-server component to work properly. The dcumentation seems a bit lack luster in this regard. Below is my d…

---

## [How Kibana's parameters env work in docker?](https://discuss.elastic.co/t/how-kibanas-parameters-env-work-in-docker/347354)

<div class="topic-metadata">

**Author:** [@a-fly-fly-bird](https://discuss.elastic.co/u/a-fly-fly-bird)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 4:56pm UTC](https://discuss.elastic.co/t/how-kibanas-parameters-env-work-in-docker/347354 "2023-11-16T16:56:40Z")

</div>

I am reading the docker file of Kibana. Here is the link: Kibana official docker file. I noticed that the config can come into force by just set the environments. I've seen the annotation of its theory. But I do not kno…

---

## [Problem with filebeat](https://discuss.elastic.co/t/problem-with-filebeat/346913)

<div class="topic-metadata">

**Author:** [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Replies:** 20\
**Last updated:** [November 16, 2023, 2:34pm UTC](https://discuss.elastic.co/t/problem-with-filebeat/346913 "2023-11-16T14:34:38Z")

</div>

Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: \[error connecting to Elasticsearch at http://localhost:9200: Get "http://localhost:9200": EOF\]

---

## [Changing from Elasticsearch 7.10.2 OSS to Basic version](https://discuss.elastic.co/t/changing-from-elasticsearch-7-10-2-oss-to-basic-version/347347)

<div class="topic-metadata">

**Author:** [@Talha1](https://discuss.elastic.co/u/Talha1)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 3:35pm UTC](https://discuss.elastic.co/t/changing-from-elasticsearch-7-10-2-oss-to-basic-version/347347 "2023-11-16T15:35:23Z")

</div>

Hi, I'm currently using Elasticsearch version 7.10. OSS version but when trying to implement security ran into challenges which turns out is because I am not on the basic version of Elasticsearch. Is there a way I can ch…

---

## [Adding incremental column based on values of another column](https://discuss.elastic.co/t/adding-incremental-column-based-on-values-of-another-column/346443)

<div class="topic-metadata">

**Author:** [@Felicien\_Ihirwe](https://discuss.elastic.co/u/Felicien_Ihirwe)\
**Replies:** 2\
**Last updated:** [November 16, 2023, 3:13pm UTC](https://discuss.elastic.co/t/adding-incremental-column-based-on-values-of-another-column/346443 "2023-11-16T15:13:58Z")

</div>

I want to create a logstash filter to come from table 1 to table 2: col1 in in out in out .. . I want to add a new column that will contain incremental values and the data will look like col1 | col 2 in | …

---

## [Why Filebeat cannot start and work correctly on windows](https://discuss.elastic.co/t/why-filebeat-cannot-start-and-work-correctly-on-windows/346926)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 22\
**Last updated:** [November 16, 2023, 2:37pm UTC](https://discuss.elastic.co/t/why-filebeat-cannot-start-and-work-correctly-on-windows/346926 "2023-11-16T14:37:58Z")

</div>

I want to install filebeat on my windows server . My filebeat version is : 8.10.4 This is my filebeat config : output.elasticsearch: # Array of hosts to connect to. hosts: \["https://10.20.11.29:9200"\] protocol: …

---

## [Tracking from GeoLocation using Kibana Maps](https://discuss.elastic.co/t/tracking-from-geolocation-using-kibana-maps/347337)

<div class="topic-metadata">

**Author:** [@Leonadius](https://discuss.elastic.co/u/Leonadius)\
**Replies:** 1\
**Last updated:** [November 16, 2023, 2:27pm UTC](https://discuss.elastic.co/t/tracking-from-geolocation-using-kibana-maps/347337 "2023-11-16T14:27:17Z")

</div>

Dear Elastic Team, I want to ask about kibana maps. I have a usecase where i need to track a vehicles based on its location (using coordinates) and visualize it on Kibana Maps. Is there a feature that i can use to draw …

---

## [Elasticsearch V8.10.4 died with a "noClassDefFoundError"](https://discuss.elastic.co/t/elasticsearch-v8-10-4-died-with-a-noclassdeffounderror/345555)

<div class="topic-metadata">

**Author:** [@Franco901](https://discuss.elastic.co/u/Franco901)\
**Replies:** 6\
**Last updated:** [November 16, 2023, 2:15pm UTC](https://discuss.elastic.co/t/elasticsearch-v8-10-4-died-with-a-noclassdeffounderror/345555 "2023-11-16T14:15:10Z")

</div>

Hey folks, I just setup a new ES node with V8.10.4 for indexing our nextcloud documents. After about 3 millions of index docs created, the Nextcloud indexer sends a (encrypted) PDF which lets ES die poorly. :cold\_face: …

---

## [Unable to create Elasticsearch Cluster](https://discuss.elastic.co/t/unable-to-create-elasticsearch-cluster/347336)

<div class="topic-metadata">

**Author:** [@Esakki](https://discuss.elastic.co/u/Esakki)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 1:52pm UTC](https://discuss.elastic.co/t/unable-to-create-elasticsearch-cluster/347336 "2023-11-16T13:52:19Z")

</div>

@Sunile\_Manjee , Hi there, due to some issue I deleted elasticsearch, kibana and APM deployment completely from my on-prem K8s cluster, now when try to create it's not creating any pods, I waited for 2 hours nothing is…

---

## [Question regarding the parameter max\_term\_freq in term suggester](https://discuss.elastic.co/t/question-regarding-the-parameter-max-term-freq-in-term-suggester/347334)

<div class="topic-metadata">

**Author:** [@qwertzu](https://discuss.elastic.co/u/qwertzu)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 1:04pm UTC](https://discuss.elastic.co/t/question-regarding-the-parameter-max-term-freq-in-term-suggester/347334 "2023-11-16T13:04:49Z")

</div>

Howdy, I am new to the ES community so feel free to criticize my rookie mistakes. Currently I am playing around the term suggester and stumbled across the following behavior that seems counter intuitive: Here is the co…

---

## [Logstash pod is not coming up once the pipeline status is running](https://discuss.elastic.co/t/logstash-pod-is-not-coming-up-once-the-pipeline-status-is-running/347333)

<div class="topic-metadata">

**Author:** [@sathishkumarD](https://discuss.elastic.co/u/sathishkumarD)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 1:04pm UTC](https://discuss.elastic.co/t/logstash-pod-is-not-coming-up-once-the-pipeline-status-is-running/347333 "2023-11-16T13:04:14Z")

</div>

Logstash is deployed in a kubernetes cluster and Elastic Search is deployed in another cluster. For transferring the log files from logstash to Elasticsearch using outputs in the logstash.conf file. // output { // …

---

## [Elastic search authentication issue with helm](https://discuss.elastic.co/t/elastic-search-authentication-issue-with-helm/347331)

<div class="topic-metadata">

**Author:** [@Mithun\_Walawalkar](https://discuss.elastic.co/u/Mithun_Walawalkar)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 12:54pm UTC](https://discuss.elastic.co/t/elastic-search-authentication-issue-with-helm/347331 "2023-11-16T12:54:06Z")

</div>

Hi, I am using Helm to install Elastic. I am able to successfully install it but when I try to log into Elastic with a predefined username and password it returns 401. It is very strange that it fails even if I use the …

---

## [Cannot determine timezone from nil logstash](https://discuss.elastic.co/t/cannot-determine-timezone-from-nil-logstash/347217)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 9\
**Last updated:** [November 16, 2023, 12:27pm UTC](https://discuss.elastic.co/t/cannot-determine-timezone-from-nil-logstash/347217 "2023-11-16T12:27:06Z")

</div>

I'm getting an error while running logstash " (ArgumentError) Cannot determine timezone from nil\\n(secs:1700041898.446,utc~:"2023-11-15 09:51:38.4460000991821289",ltz~:nil)" I have tried solutions from other threads (a…

---

## [Corrupt index removal](https://discuss.elastic.co/t/corrupt-index-removal/347316)

<div class="topic-metadata">

**Author:** [@Jack123](https://discuss.elastic.co/u/Jack123)\
**Replies:** 1\
**Last updated:** [November 16, 2023, 10:16am UTC](https://discuss.elastic.co/t/corrupt-index-removal/347316 "2023-11-16T10:16:03Z")

</div>

Hello I've a small index that contains only a time stamp on a three node ES deployment. However its stuck initializing and there are no allocated secondary's. As the data in this index is unimportant I planed to just …

---

## [Connection reset between LogStash and ES](https://discuss.elastic.co/t/connection-reset-between-logstash-and-es/347315)

<div class="topic-metadata">

**Author:** [@Giuliano\_Dessimone](https://discuss.elastic.co/u/Giuliano_Dessimone)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 10:06am UTC](https://discuss.elastic.co/t/connection-reset-between-logstash-and-es/347315 "2023-11-16T10:06:50Z")

</div>

Hello, has anyone ever had random "connection reset" errors between logstash and elastic using http\_poller? In a reliable and well-tested solution that implements ingestion to an ES cluster via http\_poller, we continuous…

---

## [Backup & restore dashboard and workspace](https://discuss.elastic.co/t/backup-restore-dashboard-and-workspace/347097)

<div class="topic-metadata">

**Author:** [@StefanC](https://discuss.elastic.co/u/StefanC)\
**Replies:** 3\
**Last updated:** [November 16, 2023, 10:05am UTC](https://discuss.elastic.co/t/backup-restore-dashboard-and-workspace/347097 "2023-11-16T10:05:51Z")

</div>

What is the prefered way to backup a workspace and dashboard in order to edit them on another installation and copy them back to production machine. Uptill now we're confronted with id problems and license that gets lo…

---

## [Kibana alerts - Observability](https://discuss.elastic.co/t/kibana-alerts-observability/347307)

<div class="topic-metadata">

**Author:** [@AlekseyD](https://discuss.elastic.co/u/AlekseyD)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 9:52am UTC](https://discuss.elastic.co/t/kibana-alerts-observability/347307 "2023-11-16T09:52:46Z")

</div>

Hello! Env: ECK 2.9.0 Kibana, Elasticsearch, APM-server: 8.10.2 APM agetnt Java: 1.43.0 Kibana Alerts setting Using Server log connector type Message template: Rule.name: {{rule.name}} Service name: {{context.…

---

## [HeartBeat monitor does not display in Kibana](https://discuss.elastic.co/t/heartbeat-monitor-does-not-display-in-kibana/346262)

<div class="topic-metadata">

**Author:** [@AlekseyD](https://discuss.elastic.co/u/AlekseyD)\
**Replies:** 5\
**Last updated:** [November 16, 2023, 9:41am UTC](https://discuss.elastic.co/t/heartbeat-monitor-does-not-display-in-kibana/346262 "2023-11-16T09:41:40Z")

</div>

Kibana: 8.10.2 Heartbeat: 8.10.2 Elasticsearch: 8.10.2 ECK: 2.9 K8s: 1.24.3 Hi! I have a problem with display Heartbeat monitor in Kibana! Heartbeat config: apiVersion: beat.k8s.elastic.co/v1beta1 kind: Beat metad…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=371)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=373)
