# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=377

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 378

---

## [Kibana 8.5.3, Aggregation Based Visualization Error](https://discuss.elastic.co/t/kibana-8-5-3-aggregation-based-visualization-error/346868)

<div class="topic-metadata">

**Author:** [@Kavikrishnan\_P](https://discuss.elastic.co/u/Kavikrishnan_P)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 11:57am UTC](https://discuss.elastic.co/t/kibana-8-5-3-aggregation-based-visualization-error/346868 "2023-11-10T11:57:55Z")

</div>

In kibana 8.5.3 version, using Aggregation based Visualization, I created 3 'split slices' sub-buckets and in 1st level, one filter type sub aggregation and in 2nd level, two filter type sub aggregation and in 3rd lev…

---

## [Watcher - find difference between 2 buckets keys](https://discuss.elastic.co/t/watcher-find-difference-between-2-buckets-keys/346863)

<div class="topic-metadata">

**Author:** [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 11:05am UTC](https://discuss.elastic.co/t/watcher-find-difference-between-2-buckets-keys/346863 "2023-11-10T11:05:49Z")

</div>

Hello, I would like to ask for help. I would like to have a watcher that would find the difference between 2 buckets keys. The goal is to find out if there is a difference in the values of the HOST field now and some t…

---

## [I can't install plugins elasticsearch in docker](https://discuss.elastic.co/t/i-cant-install-plugins-elasticsearch-in-docker/346723)

<div class="topic-metadata">

**Author:** [@arro](https://discuss.elastic.co/u/arro)\
**Replies:** 1\
**Last updated:** [November 10, 2023, 10:43am UTC](https://discuss.elastic.co/t/i-cant-install-plugins-elasticsearch-in-docker/346723 "2023-11-10T10:43:53Z")

</div>

I'm trying to install a plugin for elasticsearch in a docker container. I run the command: docker exec a15de2d3dc21 bin/elasticsearch-plugin install analysis-phonetic and get an error: -\> Installing analysis-phonetic …

---

## [Extend the expiry of the certificates](https://discuss.elastic.co/t/extend-the-expiry-of-the-certificates/346548)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 5\
**Last updated:** [November 10, 2023, 10:37am UTC](https://discuss.elastic.co/t/extend-the-expiry-of-the-certificates/346548 "2023-11-10T10:37:45Z")

</div>

Hi, we have enabled security for Elasticsearch. We extended the expiry of certificates. But still instance certificate does not get changed and retains the default expiry of 3 years Is there a way to make it work

---

## [ Logstash stopped processing because of an error: (SystemExit) exit Logstash stopped processing because of an error: (SystemExit) exit](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit-logstash-stopped-processing-because-of-an-error-systemexit-exit/346805)

<div class="topic-metadata">

**Author:** [@17\_Chinmay\_Shelke](https://discuss.elastic.co/u/17_Chinmay_Shelke)\
**Replies:** 3\
**Last updated:** [November 10, 2023, 10:34am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit-logstash-stopped-processing-because-of-an-error-systemexit-exit/346805 "2023-11-10T10:34:33Z")

</div>

Successfully started Logstash API endpoint {:port=\>9600, :ssl\_enabled=\>false} \[2023-11-09T11:25:11,753\]\[INFO \]\[logstash.runner \] Logstash shut down. \[2023-11-09T11:25:11,758\]\[FATAL\]\[org.logstash.Logstash \] …

---

## [Xiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to https://kibana.demo.net:5601/api/status fails: fail to execute the HTTP GET request: Get "https://kibana.demo.net:5601/api/status": x509: certificate signed by unkn](https://discuss.elastic.co/t/xiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-https-kibana-demo-net-5601-api-status-fails-fail-to-execute-the-http-get-request-get-https-kibana-demo-net-5601-api-status-x509-certificate-signed-by-unkn/346717)

<div class="topic-metadata">

**Author:** [@whanklee](https://discuss.elastic.co/u/whanklee)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 9:22am UTC](https://discuss.elastic.co/t/xiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-https-kibana-demo-net-5601-api-status-fails-fail-to-execute-the-http-get-request-get-https-kibana-demo-net-5601-api-status-x509-certificate-signed-by-unkn/346717 "2023-11-10T09:22:05Z")

</div>

Hi there, I run the following command and always get error message. sudo filebeat setup -E output.logstash.enabled=false -E output.elasticsearch.hosts=\['https://elastic.demo.net:9200'\] -E setup.kibana.host=https://kiba…

---

## [Understanding why only one agent policy can be assigned to an agent](https://discuss.elastic.co/t/understanding-why-only-one-agent-policy-can-be-assigned-to-an-agent/346828)

<div class="topic-metadata">

**Author:** [@HHobeck](https://discuss.elastic.co/u/HHobeck)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 8:23am UTC](https://discuss.elastic.co/t/understanding-why-only-one-agent-policy-can-be-assigned-to-an-agent/346828 "2023-11-10T08:23:59Z")

</div>

Dear community. I'm in the situation to setup an elastic agent to retrieve logs with custom integration from a directory e.g. d:\\Logs\\MyApp\_Staging\\\*.log on machine A and on machine B. So I have created an agent policy…

---

## [Winlogbeat only sends logs when I restart the service](https://discuss.elastic.co/t/winlogbeat-only-sends-logs-when-i-restart-the-service/346610)

<div class="topic-metadata">

**Author:** [@Jann](https://discuss.elastic.co/u/Jann)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 7:50am UTC](https://discuss.elastic.co/t/winlogbeat-only-sends-logs-when-i-restart-the-service/346610 "2023-11-10T07:50:58Z")

</div>

Hello, At the moment I try to send only critical, warning en errors to my Kibana dashboard. It does work, but only when I restart Winlogbeat. It must sent the logs 24/7. Any help?

---

## [Can I change http client used for @elastic/elasticsearch in node js?](https://discuss.elastic.co/t/can-i-change-http-client-used-for-elastic-elasticsearch-in-node-js/346843)

<div class="topic-metadata">

**Author:** [@ghanshyam1](https://discuss.elastic.co/u/ghanshyam1)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 7:39am UTC](https://discuss.elastic.co/t/can-i-change-http-client-used-for-elastic-elasticsearch-in-node-js/346843 "2023-11-10T07:39:42Z")

</div>

I want to use axios as http client underneath @elastic/elasticsearch.... I am trying using following code, const { Client } = require('@elastic/elasticsearch'); const axios = require('axios'); // Create a custom trans…

---

## [How can I fix a query dsl so that ALL documents are boosted in the function\_score?](https://discuss.elastic.co/t/how-can-i-fix-a-query-dsl-so-that-all-documents-are-boosted-in-the-function-score/346839)

<div class="topic-metadata">

**Author:** [@Kirill\_Cyber](https://discuss.elastic.co/u/Kirill_Cyber)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 7:05am UTC](https://discuss.elastic.co/t/how-can-i-fix-a-query-dsl-so-that-all-documents-are-boosted-in-the-function-score/346839 "2023-11-10T07:05:45Z")

</div>

I have dsl query with structure { "query": { "function\_score": { "query": { "bool": { "must": { "multi\_match": { …

---

## [Want to create new index daily with date associated with index name](https://discuss.elastic.co/t/want-to-create-new-index-daily-with-date-associated-with-index-name/346197)

<div class="topic-metadata">

**Author:** [@Swapnadeep\_Mondal](https://discuss.elastic.co/u/Swapnadeep_Mondal)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 6:57am UTC](https://discuss.elastic.co/t/want-to-create-new-index-daily-with-date-associated-with-index-name/346197 "2023-11-10T06:57:22Z")

</div>

Hello Team, I've recently learned about date math and I'm interested in creating an ILM (Index Lifecycle Management) policy to generate a new index every day, with the index name associated with the date. For example, I…

---

## [Ingest kafka syslog to elasticsearch or kibana](https://discuss.elastic.co/t/ingest-kafka-syslog-to-elasticsearch-or-kibana/346834)

<div class="topic-metadata">

**Author:** [@manasi](https://discuss.elastic.co/u/manasi)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 6:08am UTC](https://discuss.elastic.co/t/ingest-kafka-syslog-to-elasticsearch-or-kibana/346834 "2023-11-10T06:08:37Z")

</div>

Hi all, How to ingest kafka syslog to elasticsearch or kibana? I'm using elasticsearch and Kibana of 8.10.4 version. I want to visualize kafka syslogs on kibana dashboards. But I don't know how to push or integrate the…

---

## [Kibana Plugin error : "Elastic did not load properly. Check the server output for more information."](https://discuss.elastic.co/t/kibana-plugin-error-elastic-did-not-load-properly-check-the-server-output-for-more-information/346412)

<div class="topic-metadata">

**Author:** [@Srini-99](https://discuss.elastic.co/u/Srini-99)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 3:53am UTC](https://discuss.elastic.co/t/kibana-plugin-error-elastic-did-not-load-properly-check-the-server-output-for-more-information/346412 "2023-11-10T03:53:15Z")

</div>

Hi ! ES Version - 8.10.2 Kibana version - 8.10.2 So i have written a plugin to add to kibana. and i did this in kibana 8.10.2 dev only. it works perfectly in my wsl (my dev env). when i use "yarn build" and use it, …

---

## [Set "index.mapping.dimension\_fields.limit" does not work](https://discuss.elastic.co/t/set-index-mapping-dimension-fields-limit-does-not-work/346330)

<div class="topic-metadata">

**Author:** [@VietDuc](https://discuss.elastic.co/u/VietDuc)\
**Replies:** 1\
**Last updated:** [November 10, 2023, 3:39am UTC](https://discuss.elastic.co/t/set-index-mapping-dimension-fields-limit-does-not-work/346330 "2023-11-10T03:39:59Z")

</div>

Hi everyone, We would like to extend the number of dimension\_fields of our TSDS by POST \_index\_template/ds-micrometer-metrics-prod { "index\_patterns": \[ "micrometer" \], "data\_stream": {}, "template": { …

---

## [Unable to get Metricbeat to communicate with Elasticsearch](https://discuss.elastic.co/t/unable-to-get-metricbeat-to-communicate-with-elasticsearch/346747)

<div class="topic-metadata">

**Author:** [@james\_fourth](https://discuss.elastic.co/u/james_fourth)\
**Replies:** 17\
**Last updated:** [November 10, 2023, 1:47am UTC](https://discuss.elastic.co/t/unable-to-get-metricbeat-to-communicate-with-elasticsearch/346747 "2023-11-10T01:47:01Z")

</div>

I'm working on upgrading the Elastic stack to the current version for my company. So, I'm testing the deployment of Elasticsearch, Kibana, Logstash, and Metricbeat. Each component is in a separate docker container but al…

---

## [Kibana bouncing degraded - available](https://discuss.elastic.co/t/kibana-bouncing-degraded-available/346685)

<div class="topic-metadata">

**Author:** [@wrsnrno](https://discuss.elastic.co/u/wrsnrno)\
**Replies:** 4\
**Last updated:** [November 10, 2023, 1:06am UTC](https://discuss.elastic.co/t/kibana-bouncing-degraded-available/346685 "2023-11-10T01:06:28Z")

</div>

Would appreciate some points in the right direction here. I have a new stack up and running but Kibana is bouncing availalbe - degraded, frequently but not at regular intervals. The environment is new, (so am I to Elas…

---

## [Sorting results not working properly](https://discuss.elastic.co/t/sorting-results-not-working-properly/346816)

<div class="topic-metadata">

**Author:** [@Mubolio](https://discuss.elastic.co/u/Mubolio)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 11:27pm UTC](https://discuss.elastic.co/t/sorting-results-not-working-properly/346816 "2023-11-09T23:27:38Z")

</div>

Hello, I have a datastream that is updated often, I want to get unique results for the field @timestamp, I use this query: GET datastream\_name/\_search { "sort" : \[ { "@timestamp" : { "order":"desc…

---

## [You are not authorized to access Monitoring. To use Monitoring, you need the privileges granted by both the \`kibana\_admin\` and \`monitoring\_user \` roles](https://discuss.elastic.co/t/you-are-not-authorized-to-access-monitoring-to-use-monitoring-you-need-the-privileges-granted-by-both-the-kibana-admin-and-monitoring-user-roles/346448)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 8:43pm UTC](https://discuss.elastic.co/t/you-are-not-authorized-to-access-monitoring-to-use-monitoring-you-need-the-privileges-granted-by-both-the-kibana-admin-and-monitoring-user-roles/346448 "2023-11-09T20:43:19Z")

</div>

Hello World! I'm trying out eck'quickstart: and even though I'm logging in as elastic user, which is superadmin, I get the following message when I try to access Kibana'Monitoring app: Access Denied You are not aut…

---

## [Prune filter does not work with whitelist but it does with blacklist](https://discuss.elastic.co/t/prune-filter-does-not-work-with-whitelist-but-it-does-with-blacklist/346549)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 8:11pm UTC](https://discuss.elastic.co/t/prune-filter-does-not-work-with-whitelist-but-it-does-with-blacklist/346549 "2023-11-09T20:11:15Z")

</div>

Hello colleagues! I am trying to use the prune filter with first level fields ( I know the problem with nested fields ) but I can't get it to work. I have a json of 900 fields and I am interested in keeping only a few,…

---

## [Using Key-value(KV) with multiple Value splits](https://discuss.elastic.co/t/using-key-value-kv-with-multiple-value-splits/346527)

<div class="topic-metadata">

**Author:** [@robnew](https://discuss.elastic.co/u/robnew)\
**Replies:** 6\
**Last updated:** [November 9, 2023, 7:53pm UTC](https://discuss.elastic.co/t/using-key-value-kv-with-multiple-value-splits/346527 "2023-11-09T19:53:20Z")

</div>

I have a wineventlog-application log which has (ie) 'EventCode=33210 EventRecordID=12345' then changes to session\_id:69,server\_principal\_id:226,etc etc so from = to : with , instead of spaces. Is there a way I can use th…

---

## [Mapping Geospatial Time Events](https://discuss.elastic.co/t/mapping-geospatial-time-events/345958)

<div class="topic-metadata">

**Author:** [@Cal](https://discuss.elastic.co/u/Cal)\
**Replies:** 5\
**Last updated:** [November 9, 2023, 6:20pm UTC](https://discuss.elastic.co/t/mapping-geospatial-time-events/345958 "2023-11-09T18:20:25Z")

</div>

I have an index wherein one of the pieces of data is the date a last even occurred as well as location. Using geospatial I want to map the events occurring based on the dates assigned to each document. I want to use th…

---

## [Search for any error exceptions or any specific string in a log file which is pushed from client machine using filebeat agent to Elastic stack server](https://discuss.elastic.co/t/search-for-any-error-exceptions-or-any-specific-string-in-a-log-file-which-is-pushed-from-client-machine-using-filebeat-agent-to-elastic-stack-server/346534)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 7\
**Last updated:** [November 9, 2023, 6:09pm UTC](https://discuss.elastic.co/t/search-for-any-error-exceptions-or-any-specific-string-in-a-log-file-which-is-pushed-from-client-machine-using-filebeat-agent-to-elastic-stack-server/346534 "2023-11-09T18:09:12Z")

</div>

Hi, I have this log file /opt/apigee/var/log/edge-message-processor/messagelogging/apigee-dac-training/test/sf-response-parameters/6/log-api/elk.log which is seen in the kibana dashboard. I am searching for a specific s…

---

## [Create Rules in kibana-\> unknown field \[aggs\]](https://discuss.elastic.co/t/create-rules-in-kibana-unknown-field-aggs/346522)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 5:53pm UTC](https://discuss.elastic.co/t/create-rules-in-kibana-unknown-field-aggs/346522 "2023-11-09T17:53:10Z")

</div>

Hi I need to create some rules in kibana over aggregation function but I don't understand what's wrong I got "Error testing query: EsError: \[1:118\] unknown field \[aggs\]" { "query":{ "aggs": { "last\_values"…

---

## [Fingerprint for json does not get resolved](https://discuss.elastic.co/t/fingerprint-for-json-does-not-get-resolved/346772)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 9\
**Last updated:** [November 9, 2023, 5:12pm UTC](https://discuss.elastic.co/t/fingerprint-for-json-does-not-get-resolved/346772 "2023-11-09T17:12:08Z")

</div>

fingerprint for json is not working input { file { path =\> "/shared/logs/logi2/stats.\*" start\_position =\> "beginning" sincedb\_path =\> "/shared/logs/.sincedb" type =\> "logi2-stats" …

---

## [Showing query parameters in DSL query results](https://discuss.elastic.co/t/showing-query-parameters-in-dsl-query-results/345758)

<div class="topic-metadata">

**Author:** [@bgyomorei\_c](https://discuss.elastic.co/u/bgyomorei_c)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 5:00pm UTC](https://discuss.elastic.co/t/showing-query-parameters-in-dsl-query-results/345758 "2023-11-09T17:00:10Z")

</div>

Let's take the DSL query example below. I'd like to see the value of fixed\_interval in date\_histogram in the generated response. Is it possible to tell in the DSL query to display this or any parameter value in the resul…

---

## [Understanding search-as-you-type Fields](https://discuss.elastic.co/t/understanding-search-as-you-type-fields/346661)

<div class="topic-metadata">

**Author:** [@safakkbilici](https://discuss.elastic.co/u/safakkbilici)\
**Replies:** 2\
**Last updated:** [November 9, 2023, 4:36pm UTC](https://discuss.elastic.co/t/understanding-search-as-you-type-fields/346661 "2023-11-09T16:36:43Z")

</div>

Hello community, I am using ES on my local machine with version of 8.10.4 I was experimenting with search-as-you-type lately and I am confused by ".\_2gram" and ".\_3gram" fields. I created a basic index as PUT autosugg…

---

## [Containerized Metricbeat/Filebeat to monitor E,K,EntSearch](https://discuss.elastic.co/t/containerized-metricbeat-filebeat-to-monitor-e-k-entsearch/346707)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 4:30pm UTC](https://discuss.elastic.co/t/containerized-metricbeat-filebeat-to-monitor-e-k-entsearch/346707 "2023-11-09T16:30:33Z")

</div>

Hello, I am working on getting metricbeat (and eventually filebeat ) to report on Elasticsearch, Kibana and Enterprise Search via Docker. I'm using RHEL as the single-node host and as such it is using Podman as the Doc…

---

## [Same shards on different physicals servers](https://discuss.elastic.co/t/same-shards-on-different-physicals-servers/346768)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 7\
**Last updated:** [November 9, 2023, 4:01pm UTC](https://discuss.elastic.co/t/same-shards-on-different-physicals-servers/346768 "2023-11-09T16:01:04Z")

</div>

Hi I have deployed EFK stack on Kubernetes cluster, I have 3 nodes that have both roles data and master, the 3 Elasticsearch nodes are on 3 different Kubernetes nodes, but the Kubernetes nodes are on 2 different physical…

---

## [How to know wich grok is failing?](https://discuss.elastic.co/t/how-to-know-wich-grok-is-failing/346535)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [November 9, 2023, 3:46pm UTC](https://discuss.elastic.co/t/how-to-know-wich-grok-is-failing/346535 "2023-11-09T15:46:11Z")

</div>

Hi, Im reviewing the pipeline of an ex colleague, and there is almos 30 grok filters, wich will be the best way to identify wich grok is failing? Im using stdout in the output. Thanks!

---

## [Showcasing Date as yesterday, this week, this month in Kibana Dashboard control options](https://discuss.elastic.co/t/showcasing-date-as-yesterday-this-week-this-month-in-kibana-dashboard-control-options/345435)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 2\
**Last updated:** [November 9, 2023, 3:39pm UTC](https://discuss.elastic.co/t/showcasing-date-as-yesterday-this-week-this-month-in-kibana-dashboard-control-options/345435 "2023-11-09T15:39:56Z")

</div>

Hi Team, i have a date field which showcases date only as per below snap. this date is basically being extracted from one of the available field invoice\_date. Now my requirement is that suppose today is 20 Oct and i…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=376)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=378)
