# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=390

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 391

---

## [Remove HTTP encondings](https://discuss.elastic.co/t/remove-http-encondings/345720)

<div class="topic-metadata">

**Author:** [@lemospt](https://discuss.elastic.co/u/lemospt)\
**Replies:** 3\
**Last updated:** [October 25, 2023, 5:03pm UTC](https://discuss.elastic.co/t/remove-http-encondings/345720 "2023-10-25T17:03:12Z")

</div>

Hi guys, i'm integrating log from proxy squid, there is a field called 'Original Received Request Header' that has data like below, User-Agent:%20git/2.30.2%0D%0AProxy-Connection:%20Keep-Alive%0D%0AHost:%20github.priva…

---

## [Certificate configuration for an Elastic 8.10.3 cluster](https://discuss.elastic.co/t/certificate-configuration-for-an-elastic-8-10-3-cluster/345745)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 2\
**Last updated:** [October 25, 2023, 4:40pm UTC](https://discuss.elastic.co/t/certificate-configuration-for-an-elastic-8-10-3-cluster/345745 "2023-10-25T16:40:23Z")

</div>

I have a question, how can I configure the certificates for an elastic cluster in version 8.10.3, it will contain master roles, coordinators, data and machine learning. Is it intended to have several roles on the nodes,…

---

## [Logstash fails with "FFI not available" message when starting logstash on Centos 7.9](https://discuss.elastic.co/t/logstash-fails-with-ffi-not-available-message-when-starting-logstash-on-centos-7-9/345387)

<div class="topic-metadata">

**Author:** [@shaigbdb](https://discuss.elastic.co/u/shaigbdb)\
**Replies:** 2\
**Last updated:** [October 25, 2023, 3:37pm UTC](https://discuss.elastic.co/t/logstash-fails-with-ffi-not-available-message-when-starting-logstash-on-centos-7-9/345387 "2023-10-25T15:37:59Z")

</div>

1. Logstash version (e.g. bin/logstash --version) - 8.10.2 \*\*2. Logstash installation source \*\* - RPM \*\*3. How is Logstash being run \*\* - systemd JVM - tried both the bundled JVM (openjdk version "17.0.8" 2023-07-18) …

---

## [Wtacher or Ingest pipeline avoiding duplicates](https://discuss.elastic.co/t/wtacher-or-ingest-pipeline-avoiding-duplicates/345747)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 3:36pm UTC](https://discuss.elastic.co/t/wtacher-or-ingest-pipeline-avoiding-duplicates/345747 "2023-10-25T15:36:35Z")

</div>

Hello colleagues! I have a question. Is there a way to put in watcher or ingest pipelines an update based on a document\_id ( field, fields, fingerprint... ) to avoid duplicates as in the logstash output ? I have a wat…

---

## [Unassigned shards](https://discuss.elastic.co/t/unassigned-shards/344125)

<div class="topic-metadata">

**Author:** [@abisinio](https://discuss.elastic.co/u/abisinio)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 10:21am UTC](https://discuss.elastic.co/t/unassigned-shards/344125 "2023-09-29T10:21:41Z")

</div>

Hi mates, I've made a mistake in my ELK deployment. I was trying to install a new elastic agent and I put the wrong token and used the one used to configure a new server. Now I've got a lot of unassigned shards and I d…

---

## [Can we remove the date column from our reports?](https://discuss.elastic.co/t/can-we-remove-the-date-column-from-our-reports/344072)

<div class="topic-metadata">

**Author:** [@mpjjonker](https://discuss.elastic.co/u/mpjjonker)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 3:03pm UTC](https://discuss.elastic.co/t/can-we-remove-the-date-column-from-our-reports/344072 "2023-10-25T15:03:23Z")

</div>

I have seen topics about removing the date (time) column from the discover tableview and I understand it is not that easy. But maybe there is an easy way to prevent this column from being included in the CSV reports ?

---

## [Query retrieving documents when only one of two conditions are found under same aggregation](https://discuss.elastic.co/t/query-retrieving-documents-when-only-one-of-two-conditions-are-found-under-same-aggregation/345746)

<div class="topic-metadata">

**Author:** [@roblopes](https://discuss.elastic.co/u/roblopes)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 2:52pm UTC](https://discuss.elastic.co/t/query-retrieving-documents-when-only-one-of-two-conditions-are-found-under-same-aggregation/345746 "2023-10-25T14:52:50Z")

</div>

There is a process that logs every step of the way. I am looking for processes that have the log informing the process start but don't have the end process log. Log example: { "app": "myapp", "content": "End Pro…

---

## [Logstash 8.6 low performance](https://discuss.elastic.co/t/logstash-8-6-low-performance/344661)

<div class="topic-metadata">

**Author:** [@RobertC1](https://discuss.elastic.co/u/RobertC1)\
**Replies:** 8\
**Last updated:** [October 25, 2023, 2:24pm UTC](https://discuss.elastic.co/t/logstash-8-6-low-performance/344661 "2023-10-25T14:24:09Z")

</div>

Hi there I ha a server with Linux Ubuntu 20.04 and ELK 8.6 I noticed that the ingestion proccess became slow and I have not change any parameters. This is the conf file for theindex. input { file { …

---

## [Invalid major version 2.5.0](https://discuss.elastic.co/t/invalid-major-version-2-5-0/345684)

<div class="topic-metadata">

**Author:** [@spearsear](https://discuss.elastic.co/u/spearsear)\
**Replies:** 4\
**Last updated:** [October 25, 2023, 2:25pm UTC](https://discuss.elastic.co/t/invalid-major-version-2-5-0/345684 "2023-10-25T14:25:10Z")

</div>

I have two OpenSearch 2.5 clusters running in 2 AWS accounts (environments), dev and stg. I use elasticsearch-spark-30\_2.12-7.15.2.jar to write data to an index in OpenSearch. dev works fine, but stg throws error below…

---

## [Dependant nodes in dockerized Elasticsearch 3-node cluster](https://discuss.elastic.co/t/dependant-nodes-in-dockerized-elasticsearch-3-node-cluster/345713)

<div class="topic-metadata">

**Author:** [@thibaut\_a](https://discuss.elastic.co/u/thibaut_a)\
**Replies:** 2\
**Last updated:** [October 25, 2023, 2:15pm UTC](https://discuss.elastic.co/t/dependant-nodes-in-dockerized-elasticsearch-3-node-cluster/345713 "2023-10-25T14:15:31Z")

</div>

Hi, I try to install an Elasticsearch (v8.10.2) cluster (with one Kibana and one Logstash container) on Docker for a production environment. My 3 nodes are running correctly on the same server (it will be different in pr…

---

## [Approximate KNN search with filtering vs. exact search after the filtering](https://discuss.elastic.co/t/approximate-knn-search-with-filtering-vs-exact-search-after-the-filtering/345736)

<div class="topic-metadata">

**Author:** [@AlwaysLearning](https://discuss.elastic.co/u/AlwaysLearning)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 1:51pm UTC](https://discuss.elastic.co/t/approximate-knn-search-with-filtering-vs-exact-search-after-the-filtering/345736 "2023-10-25T13:51:55Z")

</div>

Suppose I want to use KNN search to search for best matching documents (represented by their high-dimensional vector embeddings) belonging to a particular user. As explained here, the approximate search (i.e. using HNSW…

---

## [Add alert exclusion for "grandfather" process](https://discuss.elastic.co/t/add-alert-exclusion-for-grandfather-process/344835)

<div class="topic-metadata">

**Author:** [@stenbot1](https://discuss.elastic.co/u/stenbot1)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 1:44pm UTC](https://discuss.elastic.co/t/add-alert-exclusion-for-grandfather-process/344835 "2023-10-25T13:44:53Z")

</div>

We have an agent on our Linux servers that will spawn a shell and then that shell will spawn a process that creates an alert. This agent is trusted software on the host, and I have added it to the whitelist. The problem …

---

## [ANN Search is super slow](https://discuss.elastic.co/t/ann-search-is-super-slow/344863)

<div class="topic-metadata">

**Author:** [@spliter2157](https://discuss.elastic.co/u/spliter2157)\
**Replies:** 14\
**Last updated:** [October 25, 2023, 1:38pm UTC](https://discuss.elastic.co/t/ann-search-is-super-slow/344863 "2023-10-25T13:38:02Z")

</div>

Hello There, Hello, I have a question regarding Elasticsearch vector search. Our vector index has 768 dimensions, and it contains 25,000,000 documents split into two indices. Here are the results from /\_cat/indices: he…

---

## [Adding support for multi-language partial matching querying](https://discuss.elastic.co/t/adding-support-for-multi-language-partial-matching-querying/344828)

<div class="topic-metadata">

**Author:** [@Shachar0n](https://discuss.elastic.co/u/Shachar0n)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 1:21pm UTC](https://discuss.elastic.co/t/adding-support-for-multi-language-partial-matching-querying/344828 "2023-10-25T13:21:36Z")

</div>

Hi all, I'm trying to add support for partial-matching search on certain fields that may contain text in multiple languages. Specifically I currently lack support for Japanese, but IIUC - same applies for Cyrillic and C…

---

## [Unable to restore snapshot on elasticsearch 8.x](https://discuss.elastic.co/t/unable-to-restore-snapshot-on-elasticsearch-8-x/345731)

<div class="topic-metadata">

**Author:** [@Kiran\_K](https://discuss.elastic.co/u/Kiran_K)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 12:58pm UTC](https://discuss.elastic.co/t/unable-to-restore-snapshot-on-elasticsearch-8-x/345731 "2023-10-25T12:58:53Z")

</div>

We have copy the snapshot backup over the restoration path but we unable to restore snapshot backup. As per attached snapshot please guide.

---

## [Start of Kibana fails](https://discuss.elastic.co/t/start-of-kibana-fails/345627)

<div class="topic-metadata">

**Author:** [@JohannesKjellberg](https://discuss.elastic.co/u/JohannesKjellberg)\
**Replies:** 4\
**Last updated:** [October 25, 2023, 12:55pm UTC](https://discuss.elastic.co/t/start-of-kibana-fails/345627 "2023-10-25T12:55:22Z")

</div>

Hello! I have installed Kibana 8.8.1 on Windows Server 2012 from the downloaded .zip file. I want to access Kibana via a reverse-proxy site in IIS. Therefore, I have created a scheduled task that runs kibana.bat. That t…

---

## [System Logs visiualizations is not showing in kibana dashboards](https://discuss.elastic.co/t/system-logs-visiualizations-is-not-showing-in-kibana-dashboards/345728)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 12:53pm UTC](https://discuss.elastic.co/t/system-logs-visiualizations-is-not-showing-in-kibana-dashboards/345728 "2023-10-25T12:53:14Z")

</div>

I have installed filebeat 8.10.2 and follow the doc to install, i have enabled nginx Apache and system modules. The nginx and apache data is showing in kibana discovery tab and also showing visualizations of these module…

---

## [Logstash refusing connection error](https://discuss.elastic.co/t/logstash-refusing-connection-error/345708)

<div class="topic-metadata">

**Author:** [@vaishalik03](https://discuss.elastic.co/u/vaishalik03)\
**Replies:** 2\
**Last updated:** [October 25, 2023, 12:43pm UTC](https://discuss.elastic.co/t/logstash-refusing-connection-error/345708 "2023-10-25T12:43:08Z")

</div>

Hi All, I'm trying to connect to Kibana after running the logstash but could see that the connection is getting refused after running the file. Following are the responses on batch. Could you please let me know when a…

---

## [Not able to send logs to elastic search via Nlog.config](https://discuss.elastic.co/t/not-able-to-send-logs-to-elastic-search-via-nlog-config/345702)

<div class="topic-metadata">

**Author:** [@prakshi91](https://discuss.elastic.co/u/prakshi91)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 12:11pm UTC](https://discuss.elastic.co/t/not-able-to-send-logs-to-elastic-search-via-nlog-config/345702 "2023-10-25T12:11:24Z")

</div>

Hi Everyone, Our aim is to send logs to Elasticsearch and we have made changes to the NLog.config file as per the documentation - Home · markmcdowell/NLog.Targets.ElasticSearch Wiki · GitHub NLog File However, we a…

---

## [Can't show distinct value in canvas](https://discuss.elastic.co/t/cant-show-distinct-value-in-canvas/345552)

<div class="topic-metadata">

**Author:** [@fay](https://discuss.elastic.co/u/fay)\
**Replies:** 3\
**Last updated:** [October 25, 2023, 11:42am UTC](https://discuss.elastic.co/t/cant-show-distinct-value-in-canvas/345552 "2023-10-25T11:42:26Z")

</div>

Hi, I want to write a sql query to show distinct value in Markdown I got the value as a table but its duplicate so I want to show the distinct value only! I try to write SELECT DISTINCT "Field\_name" from "index\_name"…

---

## [Install logstash-integration-jdbc" exit code: 137 - Dockerfile](https://discuss.elastic.co/t/install-logstash-integration-jdbc-exit-code-137-dockerfile/345719)

<div class="topic-metadata">

**Author:** [@Animesh\_Pathak](https://discuss.elastic.co/u/Animesh_Pathak)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 10:45am UTC](https://discuss.elastic.co/t/install-logstash-integration-jdbc-exit-code-137-dockerfile/345719 "2023-10-25T10:45:21Z")

</div>

This is my dockerfile, i have my docker-compose.yml file where i'm building this file using docker-compose up --build. But each time it fails showing exit code 137 Dockerfile FROM docker.elastic.co/logstash/logstash:8.1…

---

## [Logs are not visible in Kibana via Elastic-Agent](https://discuss.elastic.co/t/logs-are-not-visible-in-kibana-via-elastic-agent/345432)

<div class="topic-metadata">

**Author:** [@swapnil.pimpalkar](https://discuss.elastic.co/u/swapnil.pimpalkar)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 10:36am UTC](https://discuss.elastic.co/t/logs-are-not-visible-in-kibana-via-elastic-agent/345432 "2023-10-25T10:36:41Z")

</div>

I have install elastic-agent on my one of the host and enabled the sophos module on TCP. I have receiving logs on elastic i have this with the help of tcpdump but not able to see in discovery and dashboard. Can someone …

---

## [Logstash does not support to read logs from multiple Docker containers](https://discuss.elastic.co/t/logstash-does-not-support-to-read-logs-from-multiple-docker-containers/345542)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 2\
**Last updated:** [October 25, 2023, 10:13am UTC](https://discuss.elastic.co/t/logstash-does-not-support-to-read-logs-from-multiple-docker-containers/345542 "2023-10-25T10:13:46Z")

</div>

I have multiple docker containers in host. For example :- tomcat process docker container, elasticsearch process docker container, postgresql process docker container. And Logstash are running in seperate docker cont…

---

## [Kibana Dashboards constantly showing 408 errors](https://discuss.elastic.co/t/kibana-dashboards-constantly-showing-408-errors/345645)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 9:48am UTC](https://discuss.elastic.co/t/kibana-dashboards-constantly-showing-408-errors/345645 "2023-10-25T09:48:59Z")

</div>

Hello, We have a couple of dashboards with multiple visualizations, some of them have a automatic refresh of 5 or 10 minutes and we are stating to get the following error: \[layeredXyVis\] \> \[esaggs\] \> Check your networ…

---

## [Issue while upgrade kibana 7.16.2 to 7.17.0](https://discuss.elastic.co/t/issue-while-upgrade-kibana-7-16-2-to-7-17-0/345715)

<div class="topic-metadata">

**Author:** [@Dheerendra\_Singh\_Na1](https://discuss.elastic.co/u/Dheerendra_Singh_Na1)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 9:45am UTC](https://discuss.elastic.co/t/issue-while-upgrade-kibana-7-16-2-to-7-17-0/345715 "2023-10-25T09:45:52Z")

</div>

Getting error " \[info\]\[savedobjects-service\] \[.kibana\] WAIT\_FOR\_YELLOW\_SOURCE -\> WAIT\_FOR\_YELLOW\_SOURCE. took: 124084ms. " while upgrade kibana from 7.16.2 to 7.17.0

---

## [IIS Integration Log Missing Fields](https://discuss.elastic.co/t/iis-integration-log-missing-fields/345704)

<div class="topic-metadata">

**Author:** [@ivanchak](https://discuss.elastic.co/u/ivanchak)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 8:31am UTC](https://discuss.elastic.co/t/iis-integration-log-missing-fields/345704 "2023-10-25T08:31:22Z")

</div>

Having IIS integration v1.12.2 with default settings setup. All metric dashboard work just fine. Checked receiving both access and error logs from IIS server as well. However, fields like http.response.status\_code and et…

---

## [Fleet server status offline](https://discuss.elastic.co/t/fleet-server-status-offline/345444)

<div class="topic-metadata">

**Author:** [@candyli](https://discuss.elastic.co/u/candyli)\
**Replies:** 5\
**Last updated:** [October 25, 2023, 7:58am UTC](https://discuss.elastic.co/t/fleet-server-status-offline/345444 "2023-10-25T07:58:29Z")

</div>

I install fleet server on my centos7 Successfully. But status always display offline. I also check integration status: commandline status shows as follow: ''' \[root@fleet02 elastic-agent-8.10.4-linux-x86\_64\]# cd …

---

## [Canvas average values getting error](https://discuss.elastic.co/t/canvas-average-values-getting-error/344660)

<div class="topic-metadata">

**Author:** [@fay](https://discuss.elastic.co/u/fay)\
**Replies:** 2\
**Last updated:** [October 25, 2023, 7:20am UTC](https://discuss.elastic.co/t/canvas-average-values-getting-error/344660 "2023-10-25T07:20:59Z")

</div>

Hi , I'm using canvas and I have a field sensordata.value.numeric which is a field with many numbers I want to take the average in this field and show it as a % in Gauge visualization but I got an error while doing that …

---

## [Add a new Elasticsearch to TLS/SSL cluster](https://discuss.elastic.co/t/add-a-new-elasticsearch-to-tls-ssl-cluster/345500)

<div class="topic-metadata">

**Author:** [@Farid\_Niasti](https://discuss.elastic.co/u/Farid_Niasti)\
**Replies:** 3\
**Last updated:** [October 25, 2023, 5:56am UTC](https://discuss.elastic.co/t/add-a-new-elasticsearch-to-tls-ssl-cluster/345500 "2023-10-25T05:56:41Z")

</div>

Hi I have a cluster with 2 nodes of Elasticsearch. TLS/SSL is enables according to the bellow blog: Everything is OK and monitor-node-01 with IP 192.168.11.142 and monitor-node-02 with IP 192.168.11.143 works correct…

---

## [Is possible to create multiple Stored Scripts in 1 single operation using the API?](https://discuss.elastic.co/t/is-possible-to-create-multiple-stored-scripts-in-1-single-operation-using-the-api/345680)

<div class="topic-metadata">

**Author:** [@iTiago](https://discuss.elastic.co/u/iTiago)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 5:31am UTC](https://discuss.elastic.co/t/is-possible-to-create-multiple-stored-scripts-in-1-single-operation-using-the-api/345680 "2023-10-25T05:31:16Z")

</div>

I have more than 2.5K lines in StoredScripts in my old Cloud 5.6 cluster. I want to transfer them to my new Cloud 8.10.4 Cluster. For this, is there a way to automate the creation of these a little using the API? I crea…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=389)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=391)
