# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=395

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 396

---

## [Copy dashboards from one kibana space to another space](https://discuss.elastic.co/t/copy-dashboards-from-one-kibana-space-to-another-space/345311)

<div class="topic-metadata">

**Author:** [@israel\_teran](https://discuss.elastic.co/u/israel_teran)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 8:10pm UTC](https://discuss.elastic.co/t/copy-dashboards-from-one-kibana-space-to-another-space/345311 "2023-10-18T20:10:35Z")

</div>

I´m on Elastic Stack v8.6.2, I want to know if there is a procedure to copy a complete dashboard from my default space to a new kibana space.

---

## [Need Assistance with Displaying Current Rate Metric in Kibana](https://discuss.elastic.co/t/need-assistance-with-displaying-current-rate-metric-in-kibana/345190)

<div class="topic-metadata">

**Author:** [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Replies:** 7\
**Last updated:** [October 18, 2023, 7:35pm UTC](https://discuss.elastic.co/t/need-assistance-with-displaying-current-rate-metric-in-kibana/345190 "2023-10-18T19:35:07Z")

</div>

I'm using Elasticsearch 8.6 and I've set up a line chart showing the sum of picked items (sum(quantity)) in a project. I've adjusted the chart to display hourly rates, even though Kibana dynamically changes the interval …

---

## [How to create data view of metricbeat stack monitoring index in discover(xpack settings used)](https://discuss.elastic.co/t/how-to-create-data-view-of-metricbeat-stack-monitoring-index-in-discover-xpack-settings-used/345234)

<div class="topic-metadata">

**Author:** [@Jason\_Paralta](https://discuss.elastic.co/u/Jason_Paralta)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 6:41pm UTC](https://discuss.elastic.co/t/how-to-create-data-view-of-metricbeat-stack-monitoring-index-in-discover-xpack-settings-used/345234 "2023-10-18T18:41:14Z")

</div>

Hello All, I am trying to monitor my Elastic stack consisting of metricbeat,filebeat,heartbeat and logstash stats to be monitored in discover. Somehow I implemented metricbeat monitoring reading docs using modules.d fol…

---

## [Metricbeat are not collecting all Logstash data](https://discuss.elastic.co/t/metricbeat-are-not-collecting-all-logstash-data/342889)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 5\
**Last updated:** [October 18, 2023, 6:35pm UTC](https://discuss.elastic.co/t/metricbeat-are-not-collecting-all-logstash-data/342889 "2023-10-18T18:35:36Z")

</div>

Hi Community, I have a ELK Stack 8.2. I am trying to configure my Metricbeat to monitoring logstash node to monitore it but, for any reason, Kibana does not show all information of Logstash (like Events Emiited Rate, E…

---

## [Ingest Pipelines in Logstash](https://discuss.elastic.co/t/ingest-pipelines-in-logstash/345316)

<div class="topic-metadata">

**Author:** [@lucasyuki](https://discuss.elastic.co/u/lucasyuki)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 6:28pm UTC](https://discuss.elastic.co/t/ingest-pipelines-in-logstash/345316 "2023-10-18T18:28:32Z")

</div>

Hi, In the ingestion pipelines tab that I created and tested the dissect , how can I index it since it changes daily, in the index file I can see that the pipeline is as default, how can I change this default to the pip…

---

## [IIS integration dashboards missing](https://discuss.elastic.co/t/iis-integration-dashboards-missing/345305)

<div class="topic-metadata">

**Author:** [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 5:31pm UTC](https://discuss.elastic.co/t/iis-integration-dashboards-missing/345305 "2023-10-18T17:31:46Z")

</div>

Hi all, After a successful deploiement of Fleet-Server and Elastic-Agent on a IIS server, sadly I couldn't find the associated dashboards that should come with the IIS integration. Is it a limitation of a basic subscri…

---

## [Are ingest pipelines created by agent expected to be different from the same type of pipeline created by beats?](https://discuss.elastic.co/t/are-ingest-pipelines-created-by-agent-expected-to-be-different-from-the-same-type-of-pipeline-created-by-beats/345313)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 4:43pm UTC](https://discuss.elastic.co/t/are-ingest-pipelines-created-by-agent-expected-to-be-different-from-the-same-type-of-pipeline-created-by-beats/345313 "2023-10-18T16:43:49Z")

</div>

So, I've been assuming that the ingest pipelines created by Elastic Agent and those created by Filebeat, would be pretty much identical. I expected some differences, but nothing that would make them output different fiel…

---

## [Can number of shards per node be the bottleneck in a cluster?](https://discuss.elastic.co/t/can-number-of-shards-per-node-be-the-bottleneck-in-a-cluster/344970)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 15\
**Last updated:** [October 18, 2023, 4:23pm UTC](https://discuss.elastic.co/t/can-number-of-shards-per-node-be-the-bottleneck-in-a-cluster/344970 "2023-10-18T16:23:20Z")

</div>

Hi Folks, I have the following cluster. Nodes: 6 (48vCPUs and 384GB memory) Shards: 158 EBS volume: 24TB GP3 type (Provisioned IOPS: 50,000 and 1781 Mb/sec throughput per node) 0 replica. ~11B documents for ~10KB e…

---

## [How do I detect that a previous processor has succeeded in an ingest pipeline?](https://discuss.elastic.co/t/how-do-i-detect-that-a-previous-processor-has-succeeded-in-an-ingest-pipeline/345240)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 4:20pm UTC](https://discuss.elastic.co/t/how-do-i-detect-that-a-previous-processor-has-succeeded-in-an-ingest-pipeline/345240 "2023-10-18T16:20:47Z")

</div>

I'm using Filebeat, plus hints based auto discovery, to get my Docker Swarmt container Apache logs passed through the built in Apache logs ingest pipelines. The thing is, that several of my apache containers are also ou…

---

## [Multi-get vs Terms query performance](https://discuss.elastic.co/t/multi-get-vs-terms-query-performance/345241)

<div class="topic-metadata">

**Author:** [@CletusTSJY](https://discuss.elastic.co/u/CletusTSJY)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 3:55pm UTC](https://discuss.elastic.co/t/multi-get-vs-terms-query-performance/345241 "2023-10-18T15:55:45Z")

</div>

I'm using Elasticsearch 7.16.2 and for one of my use-cases I need to fetch documents out of my Elasticsearch index in batches of 200 to 400 at a time. Each document is around 40k on disk but I only fetch certain fields, …

---

## [Elastic agent not running](https://discuss.elastic.co/t/elastic-agent-not-running/345153)

<div class="topic-metadata">

**Author:** [@Akshay\_Ranka](https://discuss.elastic.co/u/Akshay_Ranka)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 3:49pm UTC](https://discuss.elastic.co/t/elastic-agent-not-running/345153 "2023-10-18T15:49:11Z")

</div>

Hi, I am facing the error Error: failed to communicate with Elastic Agent daemon: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing: dial unix /run/elastic-agent.sock: connec…

---

## [ILM and alias error](https://discuss.elastic.co/t/ilm-and-alias-error/345230)

<div class="topic-metadata">

**Author:** [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 2:37pm UTC](https://discuss.elastic.co/t/ilm-and-alias-error/345230 "2023-10-18T14:37:19Z")

</div>

Hi, i've followed the ILM setup guide and came accross this error "illegal\_argument\_exception: index.lifecycle.rollover\_alias \[test-alias\] does not point to index x" Now i understand that you should create the index …

---

## [I can't find kibana when I open tpot](https://discuss.elastic.co/t/i-cant-find-kibana-when-i-open-tpot/345299)

<div class="topic-metadata">

**Author:** [@Chacko\_Devasia](https://discuss.elastic.co/u/Chacko_Devasia)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 2:29pm UTC](https://discuss.elastic.co/t/i-cant-find-kibana-when-i-open-tpot/345299 "2023-10-18T14:29:09Z")

</div>

I have installed tpot in my vms on cloud. However after a few days of deployment I cant see kibana, the page opens up as follows. The option just disappears. This has been happening multiple times. can someone suggest a …

---

## [Plug in's into Kibana](https://discuss.elastic.co/t/plug-ins-into-kibana/345188)

<div class="topic-metadata">

**Author:** [@Manasa\_BR](https://discuss.elastic.co/u/Manasa_BR)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 2:22pm UTC](https://discuss.elastic.co/t/plug-ins-into-kibana/345188 "2023-10-18T14:22:35Z")

</div>

Is it possible plugin charts into existing Kibana Dashboard? If possible do let me know how to do it , what's the procedure?

---

## [LogStash not processing log as specified in pipeline.conf](https://discuss.elastic.co/t/logstash-not-processing-log-as-specified-in-pipeline-conf/345266)

<div class="topic-metadata">

**Author:** [@AmnonH](https://discuss.elastic.co/u/AmnonH)\
**Replies:** 3\
**Last updated:** [October 18, 2023, 2:22pm UTC](https://discuss.elastic.co/t/logstash-not-processing-log-as-specified-in-pipeline-conf/345266 "2023-10-18T14:22:27Z")

</div>

I am using a pipeline.conf file to start LS It looks like this: input { file { path ==\> "C:/Elastic-stack/logstash/event-data/apache\_access.log" } } output { stdout { codec ==\> rubydebug } } However, …

---

## [Setting up Kibana development environement](https://discuss.elastic.co/t/setting-up-kibana-development-environement/344901)

<div class="topic-metadata">

**Author:** [@iamsan](https://discuss.elastic.co/u/iamsan)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 2:13pm UTC](https://discuss.elastic.co/t/setting-up-kibana-development-environement/344901 "2023-10-18T14:13:18Z")

</div>

Hi All, I am facing an issue setting up a Kibana development environment to customize the kibana-enhanced-table plugin. I am running Kibana in a Docker container on my local machine and have followed the following steps…

---

## [Scripted URL field of optional field](https://discuss.elastic.co/t/scripted-url-field-of-optional-field/345245)

<div class="topic-metadata">

**Author:** [@Bohdan\_Dubyk](https://discuss.elastic.co/u/Bohdan_Dubyk)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 2:06pm UTC](https://discuss.elastic.co/t/scripted-url-field-of-optional-field/345245 "2023-10-18T14:06:13Z")

</div>

Some of my logs/documents contain request information, and one of the fields is message.request\_id, so that field does not exist on every document. What I want to achieve is to add a Scripted Field of URL type, that'll …

---

## [Elastic Stack with security enabled automatically not working for multiple node](https://discuss.elastic.co/t/elastic-stack-with-security-enabled-automatically-not-working-for-multiple-node/345296)

<div class="topic-metadata">

**Author:** [@Ramakrishna\_M](https://discuss.elastic.co/u/Ramakrishna_M)\
**Replies:** 0\
**Last updated:** [October 18, 2023, 2:04pm UTC](https://discuss.elastic.co/t/elastic-stack-with-security-enabled-automatically-not-working-for-multiple-node/345296 "2023-10-18T14:04:05Z")

</div>

Error:- \[2023-10-18T19:09:36,604\]\[WARN \]\[o.e.x.c.s.t.n.SecurityNetty4Transport\] \[node-1\] client did not trust this server's certificate, closing connection Netty4TcpChannel{localAddress=/0.0.0.29:9300, remoteAddress=/0.…

---

## [Logstash - using jdbc input plugin as input. And pipiline delay as 30 seconds and batch size as 1000. Still input plugin reads all data from database doesnt get impacted by pipeline configuration of size and delay](https://discuss.elastic.co/t/logstash-using-jdbc-input-plugin-as-input-and-pipiline-delay-as-30-seconds-and-batch-size-as-1000-still-input-plugin-reads-all-data-from-database-doesnt-get-impacted-by-pipeline-configuration-of-size-and-delay/344480)

<div class="topic-metadata">

**Author:** [@Lovin\_Saini](https://discuss.elastic.co/u/Lovin_Saini)\
**Replies:** 4\
**Last updated:** [October 18, 2023, 1:56pm UTC](https://discuss.elastic.co/t/logstash-using-jdbc-input-plugin-as-input-and-pipiline-delay-as-30-seconds-and-batch-size-as-1000-still-input-plugin-reads-all-data-from-database-doesnt-get-impacted-by-pipeline-configuration-of-size-and-delay/344480 "2023-10-18T13:56:51Z")

</div>

JDBC input plugin input { jdbc { jdbc\_driver\_library =\> "/usr/share/logstash/driver/mysql-connector-java-8.0.32.jar" jdbc\_driver\_class =\> "com.mysql.cj.jdbc.Driver" jdbc\_connection\_stri…

---

## [How to implement max\_analyzed\_offset limit in Kibana \> Discovery for extra long fields](https://discuss.elastic.co/t/how-to-implement-max-analyzed-offset-limit-in-kibana-discovery-for-extra-long-fields/344892)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 1:55pm UTC](https://discuss.elastic.co/t/how-to-implement-max-analyzed-offset-limit-in-kibana-discovery-for-extra-long-fields/344892 "2023-10-18T13:55:02Z")

</div>

Hello. I have problems with logs that having field message even 10 millions characters long. I will be removed from logs in future. But for now I'm getting shard fail error. The solution is setting max\_analyzed\_offset l…

---

## [Is point in time ID considered sensitive information?](https://discuss.elastic.co/t/is-point-in-time-id-considered-sensitive-information/345292)

<div class="topic-metadata">

**Author:** [@matheisco](https://discuss.elastic.co/u/matheisco)\
**Replies:** 0\
**Last updated:** [October 18, 2023, 1:47pm UTC](https://discuss.elastic.co/t/is-point-in-time-id-considered-sensitive-information/345292 "2023-10-18T13:47:31Z")

</div>

Hi! I'm implementing pagination using search\_after and the PIT API and am wondering if it's safe to propagate the PIT ID to an end user device. Am I exposing internal information to end users this way? Thank you!

---

## [Temperature in Celsius shown in negative](https://discuss.elastic.co/t/temperature-in-celsius-shown-in-negative/344726)

<div class="topic-metadata">

**Author:** [@fay](https://discuss.elastic.co/u/fay)\
**Replies:** 5\
**Last updated:** [October 18, 2023, 1:42pm UTC](https://discuss.elastic.co/t/temperature-in-celsius-shown-in-negative/344726 "2023-10-18T13:42:55Z")

</div>

I want to show a temperature of each device , I used metrics and the number shown but in negative !

---

## [In my Elastic Watcher , Unable to get system.cpu.user.norm.pct value in percentage](https://discuss.elastic.co/t/in-my-elastic-watcher-unable-to-get-system-cpu-user-norm-pct-value-in-percentage/345109)

<div class="topic-metadata">

**Author:** [@sonirajil](https://discuss.elastic.co/u/sonirajil)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 1:16pm UTC](https://discuss.elastic.co/t/in-my-elastic-watcher-unable-to-get-system-cpu-user-norm-pct-value-in-percentage/345109 "2023-10-18T13:16:50Z")

</div>

I am newbie to Painless , In my watch , I want to get system.cpu.user.norm.pct value in percentage not actual value (i.e. currently I am getting 0.90 for 90%) for which I need to multiply by 100 which I am unable to do s…

---

## [Is it possible to remove unenrolled Agents from Fleet?](https://discuss.elastic.co/t/is-it-possible-to-remove-unenrolled-agents-from-fleet/345286)

<div class="topic-metadata">

**Author:** [@miela](https://discuss.elastic.co/u/miela)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 1:07pm UTC](https://discuss.elastic.co/t/is-it-possible-to-remove-unenrolled-agents-from-fleet/345286 "2023-10-18T13:07:49Z")

</div>

Hi, I did see the following question: Is it possible to remove Inactive Agents from Fleet? And actually there is an undocumented (and potentially dangerous) way to remove unenrolled agents. Because I couldn't add my an…

---

## [Logstash not ready, when output goes down and then comes up during certificate renewal](https://discuss.elastic.co/t/logstash-not-ready-when-output-goes-down-and-then-comes-up-during-certificate-renewal/345269)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 12:14pm UTC](https://discuss.elastic.co/t/logstash-not-ready-when-output-goes-down-and-then-comes-up-during-certificate-renewal/345269 "2023-10-18T12:14:55Z")

</div>

I was running a test scenario where I was using TTL period 15 mins. After first 15 mins, certificate got renewed, then I scaled down elasticsearch to zero and waited for another 15 mins, it showed that elasticsearch Host…

---

## [Plugin syslog output](https://discuss.elastic.co/t/plugin-syslog-output/345282)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 12:11pm UTC](https://discuss.elastic.co/t/plugin-syslog-output/345282 "2023-10-18T12:11:26Z")

</div>

I successfully installed the syslog output plugin on my Red Hat virtual machine. However, when I attempt to start Logstash and use the syslog output in my Logstash configuration file, I encounter the following error mess…

---

## [Showing visualizaiton in custom plugin kibana v.8.8.0](https://discuss.elastic.co/t/showing-visualizaiton-in-custom-plugin-kibana-v-8-8-0/345178)

<div class="topic-metadata">

**Author:** [@Amit\_Dhiman](https://discuss.elastic.co/u/Amit_Dhiman)\
**Replies:** 8\
**Last updated:** [October 18, 2023, 12:10pm UTC](https://discuss.elastic.co/t/showing-visualizaiton-in-custom-plugin-kibana-v-8-8-0/345178 "2023-10-18T12:10:10Z")

</div>

I want to render visualizations in my plugin using embeddables. Here is my code, I am stuck in the errors and unable to solve this. : Uncaught TypeError: Cannot read properties of undefined (reading 'create') Uncaught…

---

## [TTL Value for Documents Under the Indices](https://discuss.elastic.co/t/ttl-value-for-documents-under-the-indices/345194)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 8\
**Last updated:** [October 18, 2023, 11:54am UTC](https://discuss.elastic.co/t/ttl-value-for-documents-under-the-indices/345194 "2023-10-18T11:54:09Z")

</div>

Hi Team, We had one requirement to set the TTL value for the documents present in a index. Could you please help me how to achieve the same. Thanks, Debasis

---

## [Elastic Translog corrupted error (Unassigned shards)](https://discuss.elastic.co/t/elastic-translog-corrupted-error-unassigned-shards/345255)

<div class="topic-metadata">

**Author:** [@Rajesh123](https://discuss.elastic.co/u/Rajesh123)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 11:39am UTC](https://discuss.elastic.co/t/elastic-translog-corrupted-error-unassigned-shards/345255 "2023-10-18T11:39:18Z")

</div>

Hello Friends, Can you suggest below error related translog corrupted .100+ shards are red (unassigned state) due disk failure and most of the shards recover but few shards not getting recovery. tried below option to r…

---

## [Creating a "join" mapping between two indexes using lookup](https://discuss.elastic.co/t/creating-a-join-mapping-between-two-indexes-using-lookup/345204)

<div class="topic-metadata">

**Author:** [@ugurcandede](https://discuss.elastic.co/u/ugurcandede)\
**Replies:** 4\
**Last updated:** [October 18, 2023, 11:22am UTC](https://discuss.elastic.co/t/creating-a-join-mapping-between-two-indexes-using-lookup/345204 "2023-10-18T11:22:48Z")

</div>

when I make following request. I got the following error. PUT /develop\_tickets\_dev/\_mapping { "properties": { "fieldMap": { "type": "nested", "properties": { "ts.requester": { "type":…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=394)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=396)
