# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=379

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 380

---

## [Restarting kibana](https://discuss.elastic.co/t/restarting-kibana/346705)

<div class="topic-metadata">

**Author:** [@mzm1370](https://discuss.elastic.co/u/mzm1370)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 12:32pm UTC](https://discuss.elastic.co/t/restarting-kibana/346705 "2023-11-08T12:32:54Z")

</div>

Hello, Kibana 8.10.4 does not restart in the server part of the plugin after changing the code and saving it can you help me?

---

## [{\\"error\\":{\\"root\_cause\\":\[{\\"type\\":\\"x\_content\_parse\_exception\\",\\"reason\\":\\"\[1:2\] Unexpected character ('\<' (code 60)):](https://discuss.elastic.co/t/error-root-cause-type-x-content-parse-exception-reason-1-2-unexpected-character-code-60/346704)

<div class="topic-metadata">

**Author:** [@sichuanmcl](https://discuss.elastic.co/u/sichuanmcl)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 12:21pm UTC](https://discuss.elastic.co/t/error-root-cause-type-x-content-parse-exception-reason-1-2-unexpected-character-code-60/346704 "2023-11-08T12:21:41Z")

</div>

Hi, I'm trying to send json string data using bulk update but the json string contain html component Is that possible? Because sometimes it's just okay, and sometimes it's error parsing. This is one of the body that …

---

## [Hybrid search by using knn and query in java client](https://discuss.elastic.co/t/hybrid-search-by-using-knn-and-query-in-java-client/346594)

<div class="topic-metadata">

**Author:** [@wshan13](https://discuss.elastic.co/u/wshan13)\
**Replies:** 1\
**Last updated:** [November 8, 2023, 12:18pm UTC](https://discuss.elastic.co/t/hybrid-search-by-using-knn-and-query-in-java-client/346594 "2023-11-08T12:18:50Z")

</div>

Hello. I want the hybrid search by using both the knn option and a query on the page below with java client. With spring-boot 3.1.5 and elasticsarch-java 8.7.1 environment, I made some codes as below, but seems like…

---

## [Elasticsearch Unable to access 'path.repo' shared folder](https://discuss.elastic.co/t/elasticsearch-unable-to-access-path-repo-shared-folder/346377)

<div class="topic-metadata">

**Author:** [@Aasif\_Ansari](https://discuss.elastic.co/u/Aasif_Ansari)\
**Replies:** 2\
**Last updated:** [November 8, 2023, 10:23am UTC](https://discuss.elastic.co/t/elasticsearch-unable-to-access-path-repo-shared-folder/346377 "2023-11-08T10:23:36Z")

</div>

Hi Team, I have Elasticsearch installed to my windows server. And I have another windows server with file system shared with the first one. I have map network drive to "I" letter and path "I:\\Elasticsearch-Snapshot-v2" …

---

## [Indices got deleted anonymously](https://discuss.elastic.co/t/indices-got-deleted-anonymously/346641)

<div class="topic-metadata">

**Author:** [@aneesh](https://discuss.elastic.co/u/aneesh)\
**Replies:** 3\
**Last updated:** [November 8, 2023, 10:15am UTC](https://discuss.elastic.co/t/indices-got-deleted-anonymously/346641 "2023-11-08T10:15:22Z")

</div>

Hi, some of the indices are deleted. Following is the log we have. Can you please let us know for the possibilities for same. \[2023-11-07T00:52:00,000\]\[INFO \]\[o.e.x.m.MlDailyMaintenanceService\] \[ServerName1\] triggerin…

---

## [Elasticsearch installation issues](https://discuss.elastic.co/t/elasticsearch-installation-issues/346584)

<div class="topic-metadata">

**Author:** [@bosimaosh](https://discuss.elastic.co/u/bosimaosh)\
**Replies:** 2\
**Last updated:** [November 8, 2023, 10:10am UTC](https://discuss.elastic.co/t/elasticsearch-installation-issues/346584 "2023-11-08T10:10:57Z")

</div>

After installing Elasticsearch, when I try to start the elasticsearch.service service, it fails to start and I receive the following error. system is Ubuntu 20.04. Elasticsearch version is 7.17.14 sudo systemctl stat…

---

## [O365 no failed loggins shown](https://discuss.elastic.co/t/o365-no-failed-loggins-shown/346034)

<div class="topic-metadata">

**Author:** [@helldunkel](https://discuss.elastic.co/u/helldunkel)\
**Replies:** 5\
**Last updated:** [November 8, 2023, 10:08am UTC](https://discuss.elastic.co/t/o365-no-failed-loggins-shown/346034 "2023-11-08T10:08:00Z")

</div>

Hi, we test the o365 integration in elastic. Most works correct, but we don´t see the failed loggins. We only see the success state. In O365 it shows alle failed loggins, but no logs in elastic. ELK Stack: 8.8.2 Int…

---

## [Understanding query difference](https://discuss.elastic.co/t/understanding-query-difference/346690)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 9:44am UTC](https://discuss.elastic.co/t/understanding-query-difference/346690 "2023-11-08T09:44:42Z")

</div>

Below are two queries with their respective responses. I would like to understand the difference between the below queries from the point of aggregation. In Request 1 I filter docs based on "unique\_name" and then group t…

---

## [Filebeat don't send files without errors in log](https://discuss.elastic.co/t/filebeat-dont-send-files-without-errors-in-log/346396)

<div class="topic-metadata">

**Author:** [@enp2s6](https://discuss.elastic.co/u/enp2s6)\
**Replies:** 16\
**Last updated:** [November 8, 2023, 7:49am UTC](https://discuss.elastic.co/t/filebeat-dont-send-files-without-errors-in-log/346396 "2023-11-08T07:49:58Z")

</div>

Hi forum, I apologize for having to spam again. However, I just can't find the solution. I have a newly installed elasticsearch + kibana + filebeat. Installed the latest 8.x packages from the Debian repositories. I …

---

## [How can I filter certain information from the logs?](https://discuss.elastic.co/t/how-can-i-filter-certain-information-from-the-logs/344293)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 7\
**Last updated:** [November 8, 2023, 7:41am UTC](https://discuss.elastic.co/t/how-can-i-filter-certain-information-from-the-logs/344293 "2023-11-08T07:41:48Z")

</div>

We work with ELK Stack and I have the task of creating meaningful visualizations from the log entries. I have logs in the following format: { "@timestamp": \[ "2023-08-08T00:00:11.2123" \], "xxxxx": \[ "yyyyy…

---

## [ElasticSearch cluster backup](https://discuss.elastic.co/t/elasticsearch-cluster-backup/346680)

<div class="topic-metadata">

**Author:** [@laurentiusoica](https://discuss.elastic.co/u/laurentiusoica)\
**Replies:** 3\
**Last updated:** [November 8, 2023, 7:34am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-backup/346680 "2023-11-08T07:34:24Z")

</div>

Hi, For an Elasticsearch cluster, is it a supported way to backup the cluster by completely shutting it down and take data volumes snapshots?

---

## [Error "String length exceeds the maximum length (5000000)" when transferring a large document to the attachment pipeline](https://discuss.elastic.co/t/error-string-length-exceeds-the-maximum-length-5000000-when-transferring-a-large-document-to-the-attachment-pipeline/345687)

<div class="topic-metadata">

**Author:** [@Vlad\_I](https://discuss.elastic.co/u/Vlad_I)\
**Replies:** 5\
**Last updated:** [November 8, 2023, 3:25am UTC](https://discuss.elastic.co/t/error-string-length-exceeds-the-maximum-length-5000000-when-transferring-a-large-document-to-the-attachment-pipeline/345687 "2023-11-08T03:25:44Z")

</div>

I'm using Elasticsearch 8.9.1 Using python, I send an 8MB xlsx document to the Elasticsearch index via attachment pipeline. But the error "String length (5046272) exceeds the maximum length (5000000)" appears. For exam…

---

## [I have a question, can I take the ldap attribute to create a role map? and the following is the ldap configuration in elasticsearch.yml](https://discuss.elastic.co/t/i-have-a-question-can-i-take-the-ldap-attribute-to-create-a-role-map-and-the-following-is-the-ldap-configuration-in-elasticsearch-yml/346676)

<div class="topic-metadata">

**Author:** [@Tsabitul\_azmi1](https://discuss.elastic.co/u/Tsabitul_azmi1)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 3:04am UTC](https://discuss.elastic.co/t/i-have-a-question-can-i-take-the-ldap-attribute-to-create-a-role-map-and-the-following-is-the-ldap-configuration-in-elasticsearch-yml/346676 "2023-11-08T03:04:30Z")

</div>

xpack: security: authc: realms: ldap: ldap1: order: 0 url: "ldap://xxx.xxx.xxx.xxx:389" bind\_dn: "uid=xxxxx,ou=accounts,o=xxx,dc=xx,dc=xx" #user\_search.attribute: "branchalias" #user\_group\_attribute: "branchali…

---

## [Elastic agent(synthetics) error connecting to fleet](https://discuss.elastic.co/t/elastic-agent-synthetics-error-connecting-to-fleet/346669)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 11:47pm UTC](https://discuss.elastic.co/t/elastic-agent-synthetics-error-connecting-to-fleet/346669 "2023-11-07T23:47:03Z")

</div>

Deployed elastic stack using ECK operator Trying to deploy elastic agent as deployment to run synthetics. Deployed fleet server as its required for synthetics elastic agent Followed the config from below https://raw.g…

---

## [Logstash export not working correctly, only a part of data exported](https://discuss.elastic.co/t/logstash-export-not-working-correctly-only-a-part-of-data-exported/346657)

<div class="topic-metadata">

**Author:** [@andre22](https://discuss.elastic.co/u/andre22)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 10:27pm UTC](https://discuss.elastic.co/t/logstash-export-not-working-correctly-only-a-part-of-data-exported/346657 "2023-11-07T22:27:33Z")

</div>

Hi, i want to export some data from old indexes and write them into a text file. When I restart logstash, it exports some data (a part of one day, the index has a complete month) and goes back to do nothing. I am using …

---

## [Logstash s3 output plugin and linux fs inode](https://discuss.elastic.co/t/logstash-s3-output-plugin-and-linux-fs-inode/346437)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 9:25pm UTC](https://discuss.elastic.co/t/logstash-s3-output-plugin-and-linux-fs-inode/346437 "2023-11-07T21:25:57Z")

</div>

Hello World! I'm using Logstash 7.17 and experiencing an issue with Logstash and S3 output plugin: $ logstash --version Using bundled JDK: /usr/share/logstash/jdk logstash 7.17.13 $ ./bin/logstash-plugin list logstash-…

---

## [VegaLite Code Error: Cannot convert undefined or null to object](https://discuss.elastic.co/t/vegalite-code-error-cannot-convert-undefined-or-null-to-object/346656)

<div class="topic-metadata">

**Author:** [@rahuja23](https://discuss.elastic.co/u/rahuja23)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 9:02pm UTC](https://discuss.elastic.co/t/vegalite-code-error-cannot-convert-undefined-or-null-to-object/346656 "2023-11-07T21:02:35Z")

</div>

System Specifications: Kibana Version: 8.8.2 Elastic Search Version: 8.8.2 Environment: local (Mac OS arm64) I am new to vega. I am trying to create a Gantt chart visualisation using vega code but for some reason the…

---

## [How to solve \_geoip\_expired\_database](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 6\
**Last updated:** [November 7, 2023, 5:53pm UTC](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583 "2023-11-07T17:53:15Z")

</div>

Hi, I've been experiencing an issue with the GeoIP filter here. So, at the beginning of my logstash deployment, the GeoIP filter was working well but recently I saw a tag on all my documents that said \_geoip\_expired\_dat…

---

## [Failure to install package \[checkpoint\]](https://discuss.elastic.co/t/failure-to-install-package-checkpoint/346646)

<div class="topic-metadata">

**Author:** [@shaam1](https://discuss.elastic.co/u/shaam1)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 5:44pm UTC](https://discuss.elastic.co/t/failure-to-install-package-checkpoint/346646 "2023-11-07T17:44:03Z")

</div>

Hi, I am not new to ELK, but I have an issue which I hope to solve with your help. I installed the Checkpoint integration using the button, but I get the error below: I am not able to \[WARN \]\[plugins.fleet\] Failure to…

---

## [How to add multiline on custom logs](https://discuss.elastic.co/t/how-to-add-multiline-on-custom-logs/346637)

<div class="topic-metadata">

**Author:** [@MirkoSpezie](https://discuss.elastic.co/u/MirkoSpezie)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 3:39pm UTC](https://discuss.elastic.co/t/how-to-add-multiline-on-custom-logs/346637 "2023-11-07T15:39:36Z")

</div>

I'm trying to figure out on how to configure the custom logs integration to manage multiline logs (log4j)

---

## [ILM for new indices created via Logstash](https://discuss.elastic.co/t/ilm-for-new-indices-created-via-logstash/346621)

<div class="topic-metadata">

**Author:** [@tecbox41](https://discuss.elastic.co/u/tecbox41)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 1:40pm UTC](https://discuss.elastic.co/t/ilm-for-new-indices-created-via-logstash/346621 "2023-11-07T13:40:33Z")

</div>

I am trying to apply ILM to new indices created via Logstash, but it doesn't seem to show the new indices being managed by ILM. I am using the default index template and do not have streams configured for these indices. …

---

## [Logstash log containing huge nested JSON-objects](https://discuss.elastic.co/t/logstash-log-containing-huge-nested-json-objects/346623)

<div class="topic-metadata">

**Author:** [@apt-get\_install\_skil](https://discuss.elastic.co/u/apt-get_install_skil)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 2:08pm UTC](https://discuss.elastic.co/t/logstash-log-containing-huge-nested-json-objects/346623 "2023-11-07T14:08:46Z")

</div>

Hey guys, since we upgraded our stack components to version 8.10.2, Logstash's internal logging behaviour has changed. For example, after all pipelines were startet, Logstash logs the following message: { "level": "…

---

## [How I can obtain an average from a normalization formula](https://discuss.elastic.co/t/how-i-can-obtain-an-average-from-a-normalization-formula/345644)

<div class="topic-metadata">

**Author:** [@Silvy20](https://discuss.elastic.co/u/Silvy20)\
**Replies:** 3\
**Last updated:** [November 7, 2023, 2:15pm UTC](https://discuss.elastic.co/t/how-i-can-obtain-an-average-from-a-normalization-formula/345644 "2023-11-07T14:15:04Z")

</div>

Hello, I've created a data histogram chart based in a formula where I'm expecting to analyze the amount of requests per device. However. I'd like to plot in the same chart a static line with the average around that day. …

---

## [Aggregation of aggregation](https://discuss.elastic.co/t/aggregation-of-aggregation/346472)

<div class="topic-metadata">

**Author:** [@Hakan\_Kucuk](https://discuss.elastic.co/u/Hakan_Kucuk)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 1:37pm UTC](https://discuss.elastic.co/t/aggregation-of-aggregation/346472 "2023-11-07T13:37:39Z")

</div>

Hello, I’m struggling to create a query and dashboard for my specific scenario. I have a dataset of orders with the following structure: order\_id order\_status timestamp 1 started 01.01.2023 1 in\_progress 02.0…

---

## [Kibana custom labels missing from CSV export](https://discuss.elastic.co/t/kibana-custom-labels-missing-from-csv-export/346616)

<div class="topic-metadata">

**Author:** [@jonnyo](https://discuss.elastic.co/u/jonnyo)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 12:00pm UTC](https://discuss.elastic.co/t/kibana-custom-labels-missing-from-csv-export/346616 "2023-11-07T12:00:52Z")

</div>

Hi. I have a Kibana report that utilises Custom Labels, but these labels do not get exported when using the Share option to CSV. Is it possible to export my report to CSV and retain the custom labels that I have set? Th…

---

## [Creating JSON structure for sensor.community API](https://discuss.elastic.co/t/creating-json-structure-for-sensor-community-api/346470)

<div class="topic-metadata">

**Author:** [@CargoBikoMeter](https://discuss.elastic.co/u/CargoBikoMeter)\
**Replies:** 8\
**Last updated:** [November 7, 2023, 11:47am UTC](https://discuss.elastic.co/t/creating-json-structure-for-sensor-community-api/346470 "2023-11-07T11:47:54Z")

</div>

I will send data from my logstash pipeline to the sensor.community API. The API requires the following structure which works with my curl command: curl --location --request POST 'https://api.sensor.community/v1/push-sen…

---

## [Getting 401 first time and able to login in same session in second attempt](https://discuss.elastic.co/t/getting-401-first-time-and-able-to-login-in-same-session-in-second-attempt/346524)

<div class="topic-metadata">

**Author:** [@amitkumar.gupta](https://discuss.elastic.co/u/amitkumar.gupta)\
**Replies:** 3\
**Last updated:** [November 7, 2023, 11:42am UTC](https://discuss.elastic.co/t/getting-401-first-time-and-able-to-login-in-same-session-in-second-attempt/346524 "2023-11-07T11:42:53Z")

</div>

I am implementing SSO with elastic/Kibana. and using Wso2 credential to login. When i login first time, i see 401, below is the curl i can copy from browser. curl 'http://server1.local:5601/api/security/oidc/callback?c…

---

## [Filebeat 7.10.2 : logging Configurations logging.files.rotateeverybytes not working](https://discuss.elastic.co/t/filebeat-7-10-2-logging-configurations-logging-files-rotateeverybytes-not-working/346611)

<div class="topic-metadata">

**Author:** [@epadmav](https://discuss.elastic.co/u/epadmav)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 9:45am UTC](https://discuss.elastic.co/t/filebeat-7-10-2-logging-configurations-logging-files-rotateeverybytes-not-working/346611 "2023-11-07T09:45:15Z")

</div>

Hello All, I am trying to rotate the logs generated by filebeat process by setting maximum file size of 1MB by configuring logging.files.rotateeverybytes: 1048576 but logs files are getting generated more than 10 MB and…

---

## [Supporting Exact Search while obeying punctuations using ES](https://discuss.elastic.co/t/supporting-exact-search-while-obeying-punctuations-using-es/346604)

<div class="topic-metadata">

**Author:** [@prakharchaube](https://discuss.elastic.co/u/prakharchaube)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 9:22am UTC](https://discuss.elastic.co/t/supporting-exact-search-while-obeying-punctuations-using-es/346604 "2023-11-07T09:22:36Z")

</div>

Hi folks, I am new to ES and was stuck at something so seeking help! I have a search requirement where I need to get results for "Exact Matches". Consider it similar to Google's double quote search but only on content…

---

## [In kibana under oberservabilty /uptime/monitor uptime setting need to configure with installation](https://discuss.elastic.co/t/in-kibana-under-oberservabilty-uptime-monitor-uptime-setting-need-to-configure-with-installation/344698)

<div class="topic-metadata">

**Author:** [@Monika1](https://discuss.elastic.co/u/Monika1)\
**Replies:** 2\
**Last updated:** [November 7, 2023, 8:54am UTC](https://discuss.elastic.co/t/in-kibana-under-oberservabilty-uptime-monitor-uptime-setting-need-to-configure-with-installation/344698 "2023-11-07T08:54:06Z")

</div>

Hi, In Kibana uptime setting need to add new indices in uptime indices and need to set alert connector as well not from UI Thanks

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=378)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=380)
