# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=388

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 389

---

## [Can't access Kibana in Docker of Window Server 2022](https://discuss.elastic.co/t/cant-access-kibana-in-docker-of-window-server-2022/345910)

<div class="topic-metadata">

**Author:** [@TienNguyen994](https://discuss.elastic.co/u/TienNguyen994)\
**Replies:** 0\
**Last updated:** [October 27, 2023, 11:00am UTC](https://discuss.elastic.co/t/cant-access-kibana-in-docker-of-window-server-2022/345910 "2023-10-27T11:00:32Z")

</div>

Could you please tell me: I have a Windows server 2022, I have docker installed on it, run 2 elasticsearch (port 9200), kibana (5601), opened Inbound for the firewall, we access the server via VPN, IP server is 192.168.1…

---

## [Manage Kibana artefacts with Ansible](https://discuss.elastic.co/t/manage-kibana-artefacts-with-ansible/345099)

<div class="topic-metadata">

**Author:** [@litsegaard](https://discuss.elastic.co/u/litsegaard)\
**Replies:** 2\
**Last updated:** [October 27, 2023, 10:23am UTC](https://discuss.elastic.co/t/manage-kibana-artefacts-with-ansible/345099 "2023-10-27T10:23:07Z")

</div>

We want to be able to automate Elastic/Kibana provisioning as much as possible which includes Kibana roles and spaces. We use Ansible for provisioning and provisioning Elasticsearch is straightforward, however, we're str…

---

## [Multiple Metric in canvas](https://discuss.elastic.co/t/multiple-metric-in-canvas/345256)

<div class="topic-metadata">

**Author:** [@fay](https://discuss.elastic.co/u/fay)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 10:15am UTC](https://discuss.elastic.co/t/multiple-metric-in-canvas/345256 "2023-10-27T10:15:45Z")

</div>

Hi everyone , I am using Canvas and I want to represent top 5 of field and break it down with another field I can simply do that in Visualization by Metric type and select Maximum of Field1 and break it down with top 5…

---

## [Springboot integration Elasticsearch @Filed fails](https://discuss.elastic.co/t/springboot-integration-elasticsearch-filed-fails/345891)

<div class="topic-metadata">

**Author:** [@wu\_wei](https://discuss.elastic.co/u/wu_wei)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 9:48am UTC](https://discuss.elastic.co/t/springboot-integration-elasticsearch-filed-fails/345891 "2023-10-27T09:48:07Z")

</div>

The springboot version is 2.3.12.RELEASE, the Elasticsearch client uses 7.6.2, and the corresponding spring data Elasticsearch is 4.0.9 Now when using the officially provided ElasticsearchRepository interface to save…

---

## [Kibana is not starting 8.10.2](https://discuss.elastic.co/t/kibana-is-not-starting-8-10-2/345860)

<div class="topic-metadata">

**Author:** [@layalhasan](https://discuss.elastic.co/u/layalhasan)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 9:36am UTC](https://discuss.elastic.co/t/kibana-is-not-starting-8-10-2/345860 "2023-10-27T09:36:19Z")

</div>

I am having this error while kibana pod is starting ValidationError: \[config validation of \[elastic\]\]: could not parse object value from json input at ObjectType.validate (/usr/share/kibana/node\_modules/@kbn/config-…

---

## [Failed Node Join in Elasticsearch Cluster "jaeger-es" due to Cluster UUID Mismatch](https://discuss.elastic.co/t/failed-node-join-in-elasticsearch-cluster-jaeger-es-due-to-cluster-uuid-mismatch/345888)

<div class="topic-metadata">

**Author:** [@Srinivas\_Rayudu](https://discuss.elastic.co/u/Srinivas_Rayudu)\
**Replies:** 12\
**Last updated:** [October 27, 2023, 9:36am UTC](https://discuss.elastic.co/t/failed-node-join-in-elasticsearch-cluster-jaeger-es-due-to-cluster-uuid-mismatch/345888 "2023-10-27T09:36:16Z")

</div>

Hello, I am encountering an issue where one of the data nodes in my Elasticsearch cluster is unable to join the cluster. The cluster name is "jaeger-es" and the problematic node is "jaeger-es-data-0". I found an error i…

---

## [Can Kibana group events around a common id and perform statistics on the group, then plot it?](https://discuss.elastic.co/t/can-kibana-group-events-around-a-common-id-and-perform-statistics-on-the-group-then-plot-it/345613)

<div class="topic-metadata">

**Author:** [@Wpq](https://discuss.elastic.co/u/Wpq)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 9:23am UTC](https://discuss.elastic.co/t/can-kibana-group-events-around-a-common-id-and-perform-statistics-on-the-group-then-plot-it/345613 "2023-10-27T09:23:43Z")

</div>

I usually use Kibana (as a basic user) with a flow of independent timed events. I then make some graphs on the evolution or statistics of a population in a specific timeframe. I now face a problem I do not know how to a…

---

## [Fielddata is disabled on various fields - new install of winlogbeats](https://discuss.elastic.co/t/fielddata-is-disabled-on-various-fields-new-install-of-winlogbeats/345604)

<div class="topic-metadata">

**Author:** [@cstewa20](https://discuss.elastic.co/u/cstewa20)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 11:48pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-various-fields-new-install-of-winlogbeats/345604 "2023-10-23T23:48:08Z")

</div>

I have a the following setup: 3 - EL Cluster Servers v8.5 1 - Logstash Server v 8.5 1 - Kibana Server v8.5 2 - Windows 2019 Domain Controllers with winbeats installed connecting to the logstash server. When I try an…

---

## [Alerting in zabbix based on elasticsearch data](https://discuss.elastic.co/t/alerting-in-zabbix-based-on-elasticsearch-data/345636)

<div class="topic-metadata">

**Author:** [@Lakshay](https://discuss.elastic.co/u/Lakshay)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 9:00am UTC](https://discuss.elastic.co/t/alerting-in-zabbix-based-on-elasticsearch-data/345636 "2023-10-27T09:00:27Z")

</div>

Hello everyone, I have some data in elasticsearch cluster which I am visualizing using kibana. The data is actually some figures (integers). Now, I need to have an alerting in Zabbix in case those figures(which are in…

---

## [Display Overall Max and Average of Sum in TSVB in Metric and Markdown Visualizations (v8.6.1)](https://discuss.elastic.co/t/display-overall-max-and-average-of-sum-in-tsvb-in-metric-and-markdown-visualizations-v8-6-1/345411)

<div class="topic-metadata">

**Author:** [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Replies:** 3\
**Last updated:** [October 27, 2023, 8:57am UTC](https://discuss.elastic.co/t/display-overall-max-and-average-of-sum-in-tsvb-in-metric-and-markdown-visualizations-v8-6-1/345411 "2023-10-27T08:57:05Z")

</div>

Hi all, I'm using Elastic version 8.6.1. In Kibana's TSVB, I've set up a Time Series visualization where I've first aggregated using the Sum of a specific field. I then applied a secondary pipeline aggregation to comput…

---

## [Elasticsearch-net no JsonNetSerializer nuget package](https://discuss.elastic.co/t/elasticsearch-net-no-jsonnetserializer-nuget-package/345681)

<div class="topic-metadata">

**Author:** [@Maxim\_Stepanov](https://discuss.elastic.co/u/Maxim_Stepanov)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 8:52am UTC](https://discuss.elastic.co/t/elasticsearch-net-no-jsonnetserializer-nuget-package/345681 "2023-10-27T08:52:46Z")

</div>

Hi, I need to use newtonsoft serializer, and I see the Elastic.Clients.Elasticsearch.JsonNetSerializer project in github, but I can't find corresponding Nuget package.

---

## [Collect log of docker containerized Apache Httpd using Filebeat](https://discuss.elastic.co/t/collect-log-of-docker-containerized-apache-httpd-using-filebeat/345889)

<div class="topic-metadata">

**Author:** [@yohanwongso](https://discuss.elastic.co/u/yohanwongso)\
**Replies:** 0\
**Last updated:** [October 27, 2023, 8:13am UTC](https://discuss.elastic.co/t/collect-log-of-docker-containerized-apache-httpd-using-filebeat/345889 "2023-10-27T08:13:07Z")

</div>

How to deploy a filebeat for collecting log of Apache Httpd which is running on Docker?

---

## [Missing objects after update](https://discuss.elastic.co/t/missing-objects-after-update/345733)

<div class="topic-metadata">

**Author:** [@Ljapunov](https://discuss.elastic.co/u/Ljapunov)\
**Replies:** 1\
**Last updated:** [October 27, 2023, 7:19am UTC](https://discuss.elastic.co/t/missing-objects-after-update/345733 "2023-10-27T07:19:23Z")

</div>

Hey there, after updating kibana I am missing a few (that is not all, but some) of the dashboards and index-patters that have been there prior to the update. Some more background: We have a multinode elasticsearch-clus…

---

## [Load Balancer for Elastic Cloud](https://discuss.elastic.co/t/load-balancer-for-elastic-cloud/344839)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 3\
**Last updated:** [October 27, 2023, 7:05am UTC](https://discuss.elastic.co/t/load-balancer-for-elastic-cloud/344839 "2023-10-27T07:05:27Z")

</div>

Would like to know whether Load Balancer can be used for Elastic Cloud in Azure. Any reference architecture diagram will help.

---

## [Logstash JMX plugin offline installation - why the creator dont create a zip with all dependency for install offline?](https://discuss.elastic.co/t/logstash-jmx-plugin-offline-installation-why-the-creator-dont-create-a-zip-with-all-dependency-for-install-offline/345884)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 0\
**Last updated:** [October 27, 2023, 6:58am UTC](https://discuss.elastic.co/t/logstash-jmx-plugin-offline-installation-why-the-creator-dont-create-a-zip-with-all-dependency-for-install-offline/345884 "2023-10-27T06:58:36Z")

</div>

Hey, Im very bored, I read the post about installing a plugin in offline mode, but why not force the creators to make a zip with everything needed to do it offline?? seriously.. only have one gem file and this one must…

---

## [Ordering Gauge Visualisation](https://discuss.elastic.co/t/ordering-gauge-visualisation/345690)

<div class="topic-metadata">

**Author:** [@Ric\_UTS](https://discuss.elastic.co/u/Ric_UTS)\
**Replies:** 2\
**Last updated:** [October 27, 2023, 1:30am UTC](https://discuss.elastic.co/t/ordering-gauge-visualisation/345690 "2023-10-27T01:30:15Z")

</div>

Hello. I have been trying to create a gauge-based dashboard visualisation but it appears that I am unable to oder it, either by count or by the metric keyword. Please see attached image. I would have preferred it to b…

---

## [JSON timestamp coming as text](https://discuss.elastic.co/t/json-timestamp-coming-as-text/345633)

<div class="topic-metadata">

**Author:** [@ataylor](https://discuss.elastic.co/u/ataylor)\
**Replies:** 6\
**Last updated:** [October 27, 2023, 12:45am UTC](https://discuss.elastic.co/t/json-timestamp-coming-as-text/345633 "2023-10-27T00:45:25Z")

</div>

Basically I am not getting a @timestamp field that is a date - its coming through as text. #this is my .conf file (with some stuff excluded for security) input{ beats{ port =\> 5048 } } filter { json { …

---

## [Updating cluster's node certificate failed to register](https://discuss.elastic.co/t/updating-clusters-node-certificate-failed-to-register/345762)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 10:07pm UTC](https://discuss.elastic.co/t/updating-clusters-node-certificate-failed-to-register/345762 "2023-10-26T22:07:59Z")

</div>

Dear all, Today I'm once again dealing with :face\_with\_symbols\_over\_mouth: certificates! Each time I'm touching those, there always an issue! I started by replacing one certificate on an ingest node (ingest-prod01.dom…

---

## [Extract hostname from log file name](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 9\
**Last updated:** [October 26, 2023, 8:44pm UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761 "2023-10-26T20:44:26Z")

</div>

Hi on logstash need to use file as input, output as http. now question is how can i extract hostname from log filename, here is file name: /tmp/log.hostname1.20230720 /tmp/log.hostname2.20230720 Any idea Thanks

---

## [Cisco Logs Module - No logs received](https://discuss.elastic.co/t/cisco-logs-module-no-logs-received/345865)

<div class="topic-metadata">

**Author:** [@phant0m\_phr3ak](https://discuss.elastic.co/u/phant0m_phr3ak)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 7:43pm UTC](https://discuss.elastic.co/t/cisco-logs-module-no-logs-received/345865 "2023-10-26T19:43:46Z")

</div>

I am very new to this. Sorry in advance as this will probably be a trivial fix but I have not been able to figure it out. I am trying to send logs from Cisco Switch via udp 9002 to Filebeat with the Cisco Logs Integratio…

---

## [How to move indexes withing one node between mount points](https://discuss.elastic.co/t/how-to-move-indexes-withing-one-node-between-mount-points/345707)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 7:26pm UTC](https://discuss.elastic.co/t/how-to-move-indexes-withing-one-node-between-mount-points/345707 "2023-10-26T19:26:50Z")

</div>

Hello, im running one Elastic node 8.10.4. Im using logstash to create one index per linux machines per day as can be seen below: But because of huge amount of data. I would like move indexes 30days and older from c…

---

## [Stop shard balancing](https://discuss.elastic.co/t/stop-shard-balancing/345678)

<div class="topic-metadata">

**Author:** [@SleekPainter01](https://discuss.elastic.co/u/SleekPainter01)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 7:21pm UTC](https://discuss.elastic.co/t/stop-shard-balancing/345678 "2023-10-26T19:21:13Z")

</div>

Good morning everything is fine? I have 3 clients receiving logs via filebeat. And I have 1 Elasticsearch node for each client. However, load balancing of fragments between nodes is taking place. How could this balan…

---

## [One of the primary shard of the index is corrupt](https://discuss.elastic.co/t/one-of-the-primary-shard-of-the-index-is-corrupt/345838)

<div class="topic-metadata">

**Author:** [@Aayush\_Kumar1](https://discuss.elastic.co/u/Aayush_Kumar1)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 7:04pm UTC](https://discuss.elastic.co/t/one-of-the-primary-shard-of-the-index-is-corrupt/345838 "2023-10-26T19:04:52Z")

</div>

Hi, I am getting this error. Is there any way to restore this shard? /\_cluster/allocation/explain?pretty { "index" : "es-document-000004", "shard" : 2, "primary" : true, "current\_state" : "unassigned", "unass…

---

## [ElasticsearchClient v.8 QueryContainer alternative](https://discuss.elastic.co/t/elasticsearchclient-v-8-querycontainer-alternative/345861)

<div class="topic-metadata">

**Author:** [@Carlos\_Barros](https://discuss.elastic.co/u/Carlos_Barros)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 6:32pm UTC](https://discuss.elastic.co/t/elasticsearchclient-v-8-querycontainer-alternative/345861 "2023-10-26T18:32:16Z")

</div>

Hi, I'm migrating .net 7 Nest client to the newer v8 .net client. I have the following code and would like to question if there is an alternative to QueryContainer usage as you see next. QueryContainer filt…

---

## [Filebeat can't connect to elastic - Cert unknown authority](https://discuss.elastic.co/t/filebeat-cant-connect-to-elastic-cert-unknown-authority/345848)

<div class="topic-metadata">

**Author:** [@phant0m\_phr3ak](https://discuss.elastic.co/u/phant0m_phr3ak)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 5:24pm UTC](https://discuss.elastic.co/t/filebeat-cant-connect-to-elastic-cert-unknown-authority/345848 "2023-10-26T17:24:21Z")

</div>

When trying to run "sudo filebeat setup -e" I get the below error about cert signed by unknown authority. I have not been able to figure this out. Any ideas what I am missing here? Errors: \[error connecting to Elasticse…

---

## [Clean index when change IAM phase](https://discuss.elastic.co/t/clean-index-when-change-iam-phase/345831)

<div class="topic-metadata">

**Author:** [@Hugo\_Perez\_Fernandez](https://discuss.elastic.co/u/Hugo_Perez_Fernandez)\
**Replies:** 3\
**Last updated:** [October 26, 2023, 4:52pm UTC](https://discuss.elastic.co/t/clean-index-when-change-iam-phase/345831 "2023-10-26T16:52:09Z")

</div>

Hello, I am doing some tests with the lifecycle policies on an index and I would like to know if it is possible that at the moment in which it passes from the WARM stage to the COLD stage, those documents that have a pr…

---

## [CustomLogs integration turns unhealthy with simple wildcard change](https://discuss.elastic.co/t/customlogs-integration-turns-unhealthy-with-simple-wildcard-change/345423)

<div class="topic-metadata">

**Author:** [@CiscoMT](https://discuss.elastic.co/u/CiscoMT)\
**Replies:** 7\
**Last updated:** [October 26, 2023, 4:34pm UTC](https://discuss.elastic.co/t/customlogs-integration-turns-unhealthy-with-simple-wildcard-change/345423 "2023-10-26T16:34:53Z")

</div>

Hello y'all, I am trying to break down the different paths I have for app logs in my server into different customLogs integrations. Originally I was using a single integration of the CustomLog type with path : C:\\ine…

---

## [Kibana 8.6 TVSB Gauge chart does not show large numbers](https://discuss.elastic.co/t/kibana-8-6-tvsb-gauge-chart-does-not-show-large-numbers/345738)

<div class="topic-metadata">

**Author:** [@RobertC1](https://discuss.elastic.co/u/RobertC1)\
**Replies:** 5\
**Last updated:** [October 26, 2023, 3:52pm UTC](https://discuss.elastic.co/t/kibana-8-6-tvsb-gauge-chart-does-not-show-large-numbers/345738 "2023-10-26T15:52:19Z")

</div>

FInd out the nunber of a SUM in a lens visualization. But when I try to do the same visualization in TVSB gauge option, and this is the value that shows: Are there parameters to adjust? Thanks in advance

---

## [Script field](https://discuss.elastic.co/t/script-field/345827)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 1:42pm UTC](https://discuss.elastic.co/t/script-field/345827 "2023-10-26T13:42:49Z")

</div>

Good morning, I'm beginning to work with scripting fields and I have doubts and problems. I have created this index: POST /sergi-script/\_doc/1 { "access": "2023-10-26T00:00:00" } POST /sergi-script/\_doc/2 { "acce…

---

## [Unable to Pull GHAS integration into Elastic](https://discuss.elastic.co/t/unable-to-pull-ghas-integration-into-elastic/345822)

<div class="topic-metadata">

**Author:** [@handuo](https://discuss.elastic.co/u/handuo)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 1:25pm UTC](https://discuss.elastic.co/t/unable-to-pull-ghas-integration-into-elastic/345822 "2023-10-26T13:25:10Z")

</div>

I'm trying to integrate GHAS into Elastic. Created the API in GitHub with all read-only permissions, and setup per instruction the GitHub in Elastic. When going to Discover and doing a query, for the dataset, nothing s…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=387)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=389)
