# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=399

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 400

---

## [Kibana Alerts - Alert Details URL](https://discuss.elastic.co/t/kibana-alerts-alert-details-url/343398)

<div class="topic-metadata">

**Author:** [@Gelinski](https://discuss.elastic.co/u/Gelinski)\
**Replies:** 1\
**Last updated:** [October 13, 2023, 2:12pm UTC](https://discuss.elastic.co/t/kibana-alerts-alert-details-url/343398 "2023-10-13T14:12:24Z")

</div>

Hello folks, I have an alert rule configured with a ServiceNow ITOM Connector where I am setting the following content to the description field: =RULE= {{rule.name}} =REASON= {{context.reason}} =DETAILS= CRITERIA: {{…

---

## [Docker Compose ELK 8.10.2](https://discuss.elastic.co/t/docker-compose-elk-8-10-2/344770)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 8\
**Last updated:** [October 13, 2023, 2:07pm UTC](https://discuss.elastic.co/t/docker-compose-elk-8-10-2/344770 "2023-10-13T14:07:41Z")

</div>

Hi, I'm trying to create a docker-compose.yml file by following the instructions here. The only change I made to the docker-compose.yml file was to add the Logstash service. This is what I added to the docker-compose.…

---

## [AWS Lambda end of support for the Go 1.x runtime](https://discuss.elastic.co/t/aws-lambda-end-of-support-for-the-go-1-x-runtime/344983)

<div class="topic-metadata">

**Author:** [@ssdrosos](https://discuss.elastic.co/u/ssdrosos)\
**Replies:** 2\
**Last updated:** [October 13, 2023, 1:28pm UTC](https://discuss.elastic.co/t/aws-lambda-end-of-support-for-the-go-1-x-runtime/344983 "2023-10-13T13:28:53Z")

</div>

Hello, AWS has announced that they will stop the support of the Go 1.x runtime environment. From what I can see in the latest master Dockerfile, the go runtime is still v1: https://github.com/elastic/beats/blob/main/x-…

---

## [Facing Issues while Installing Elastic-Search](https://discuss.elastic.co/t/facing-issues-while-installing-elastic-search/345006)

<div class="topic-metadata">

**Author:** [@Sadhwik\_Reddy](https://discuss.elastic.co/u/Sadhwik_Reddy)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 1:07pm UTC](https://discuss.elastic.co/t/facing-issues-while-installing-elastic-search/345006 "2023-10-13T13:07:52Z")

</div>

:white\_check\_mark: Elasticsearch security features have been automatically configured! :white\_check\_mark: Authentication is enabled and cluster connections are encrypted. :x: Unable to auto-generate the password for th…

---

## [Filter data into kibana dashboard using post method](https://discuss.elastic.co/t/filter-data-into-kibana-dashboard-using-post-method/345001)

<div class="topic-metadata">

**Author:** [@Sujith\_Nair](https://discuss.elastic.co/u/Sujith_Nair)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 12:33pm UTC](https://discuss.elastic.co/t/filter-data-into-kibana-dashboard-using-post-method/345001 "2023-10-13T12:33:17Z")

</div>

Hi Team, I would like to filter out data dynamically using javascript with the help of post method. I have used the a script but getting error in the post method. Attaching the script for your reference. const kibanaDa…

---

## [Snapshot, Hot/Warm Architecture and Upgrade](https://discuss.elastic.co/t/snapshot-hot-warm-architecture-and-upgrade/344887)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 11\
**Last updated:** [October 13, 2023, 11:25am UTC](https://discuss.elastic.co/t/snapshot-hot-warm-architecture-and-upgrade/344887 "2023-10-13T11:25:36Z")

</div>

Hi there, I have a few questions here: First, if I have an index of 4.5 TB, what is the best way to back up that much data? Second, my existing cluster has 25 data nodes in total, if I want to apply hot/warm architect…

---

## [Getting doc\_count for each type under each index in a cluster](https://discuss.elastic.co/t/getting-doc-count-for-each-type-under-each-index-in-a-cluster/344987)

<div class="topic-metadata">

**Author:** [@Darshan\_J](https://discuss.elastic.co/u/Darshan_J)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 10:39am UTC](https://discuss.elastic.co/t/getting-doc-count-for-each-type-under-each-index-in-a-cluster/344987 "2023-10-13T10:39:19Z")

</div>

Im using ES 5.6. Is there a way to get doc\_count of each type in each indices in a ES cluster.

---

## [Exiting: index management requested but the Elasticsearch output is not configured/enabled](https://discuss.elastic.co/t/exiting-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/344980)

<div class="topic-metadata">

**Author:** [@pramod\_1](https://discuss.elastic.co/u/pramod_1)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 10:06am UTC](https://discuss.elastic.co/t/exiting-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/344980 "2023-10-13T10:06:49Z")

</div>

I have executed the below command filebeat setup -e got this error from the above command. {"log.level":"warn","@timestamp":"2023-10-13T15:33:15.664+0530","log.origin":{"file.name":"beater/filebeat.go","file.line":193…

---

## [“Cache Management: Insecure Policy” vulnerability detected after version upgrade](https://discuss.elastic.co/t/cache-management-insecure-policy-vulnerability-detected-after-version-upgrade/344627)

<div class="topic-metadata">

**Author:** [@Septianingrum.17](https://discuss.elastic.co/u/Septianingrum.17)\
**Replies:** 2\
**Last updated:** [October 13, 2023, 9:08am UTC](https://discuss.elastic.co/t/cache-management-insecure-policy-vulnerability-detected-after-version-upgrade/344627 "2023-10-13T09:08:16Z")

</div>

After I upgraded the elastic stack to 8.6.0 and carried out a vulnerability scan on Kibana using the microfocus tool, there were vulnerabilities as follows: I have made changes to the Kibana configuration, namely cha…

---

## [Auditbeat process memory grows every day](https://discuss.elastic.co/t/auditbeat-process-memory-grows-every-day/344061)

<div class="topic-metadata">

**Author:** [@v1k1ng0](https://discuss.elastic.co/u/v1k1ng0)\
**Replies:** 6\
**Last updated:** [October 13, 2023, 8:32am UTC](https://discuss.elastic.co/t/auditbeat-process-memory-grows-every-day/344061 "2023-10-13T08:32:53Z")

</div>

Hi, not sure if happening in all of my servers (vmware virtual servers), but I have 2 servers with antivirus installed (trend micro deep security) and auditbeat installed happening that auditbeat process memory grows 2%…

---

## [Join Id and Name](https://discuss.elastic.co/t/join-id-and-name/344898)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 2\
**Last updated:** [October 13, 2023, 8:24am UTC](https://discuss.elastic.co/t/join-id-and-name/344898 "2023-10-13T08:24:04Z")

</div>

Hi everyone, im parsing with logstash some message containing an ID refering to an user, i need to add the name of the user with the specific ID. I have all the User and ID in a CSV file. Which one is the best way to a…

---

## [Winlogbeats error when using xml\_query](https://discuss.elastic.co/t/winlogbeats-error-when-using-xml-query/344936)

<div class="topic-metadata">

**Author:** [@rojjin](https://discuss.elastic.co/u/rojjin)\
**Replies:** 6\
**Last updated:** [October 13, 2023, 7:46am UTC](https://discuss.elastic.co/t/winlogbeats-error-when-using-xml-query/344936 "2023-10-13T07:46:31Z")

</div>

Winlogbeats logs an error when trying to use an xml\_query to return custom events. I have read thru the documentation and believe the config is correct. Here is the config: output.logstash: hosts: \["server"\] path: d…

---

## [Facing issuse while running logstash of ELK version 8.10](https://discuss.elastic.co/t/facing-issuse-while-running-logstash-of-elk-version-8-10/344968)

<div class="topic-metadata">

**Author:** [@sandraimmaculate](https://discuss.elastic.co/u/sandraimmaculate)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 6:55am UTC](https://discuss.elastic.co/t/facing-issuse-while-running-logstash-of-elk-version-8-10/344968 "2023-10-13T06:55:40Z")

</div>

Hi, i have installed elk in AWS instance with AMI Ubuntu 20.04 and hardware requirement 2vpcu, 4gb ram. i have created a Logstash configuration file like and created a log file in which contain the access logs when …

---

## [Search error and escaping characters](https://discuss.elastic.co/t/search-error-and-escaping-characters/344935)

<div class="topic-metadata">

**Author:** [@Lewis030](https://discuss.elastic.co/u/Lewis030)\
**Replies:** 1\
**Last updated:** [October 13, 2023, 5:59am UTC](https://discuss.elastic.co/t/search-error-and-escaping-characters/344935 "2023-10-13T05:59:07Z")

</div>

Hello there, i'm trying to play around with a rule to search for instances of the Sticky Key being abused in Windows. The output below has been created from converting a SIGMA rule: process where (event.category : "pro…

---

## [Change the Account which is used to run the elastic stack (Windows Server)](https://discuss.elastic.co/t/change-the-account-which-is-used-to-run-the-elastic-stack-windows-server/344741)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 2\
**Last updated:** [October 13, 2023, 5:39am UTC](https://discuss.elastic.co/t/change-the-account-which-is-used-to-run-the-elastic-stack-windows-server/344741 "2023-10-13T05:39:17Z")

</div>

Hi! I´m running the Elastic Stack onPrem with the latest version 8.10.2 (Elasticsearch - Kibana - WinlogBeat + Metricbeat). The Elastic stack was installed with my normal Windows account on a Windows Server 2016. Now …

---

## [Path of query](https://discuss.elastic.co/t/path-of-query/344958)

<div class="topic-metadata">

**Author:** [@Alan\_Hsiao](https://discuss.elastic.co/u/Alan_Hsiao)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 1:40am UTC](https://discuss.elastic.co/t/path-of-query/344958 "2023-10-13T01:40:17Z")

</div>

This is one of my filter in my watcher "filter": \[ { "range": { "@timestamp": { "gte": "now-30m" } } …

---

## [Elasticsearch data directory in S3 bucket](https://discuss.elastic.co/t/elasticsearch-data-directory-in-s3-bucket/344945)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 5\
**Last updated:** [October 12, 2023, 8:04pm UTC](https://discuss.elastic.co/t/elasticsearch-data-directory-in-s3-bucket/344945 "2023-10-12T20:04:55Z")

</div>

Hi All, Is it possible to have the data directory of a newly built ES 8 cluster hosted on a S3 bucket. Idea is for the data nodes to use S3 instead of local disk or NAS. Thanks

---

## [Visualizing certain elements in an Array field](https://discuss.elastic.co/t/visualizing-certain-elements-in-an-array-field/344849)

<div class="topic-metadata">

**Author:** [@hs121](https://discuss.elastic.co/u/hs121)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 3:21pm UTC](https://discuss.elastic.co/t/visualizing-certain-elements-in-an-array-field/344849 "2023-10-12T15:21:18Z")

</div>

Hi there, This is a naive question but I have a field called "tools\_usage" that holds some Array data: e.g tools\_record = \[ "toolname:banana", "toolcategory:fruit", "success:true", \] self.es.index(index="my\_i…

---

## [Elasticsearch api returning empty response (python)](https://discuss.elastic.co/t/elasticsearch-api-returning-empty-response-python/344238)

<div class="topic-metadata">

**Author:** [@Aidan\_Campbell](https://discuss.elastic.co/u/Aidan_Campbell)\
**Replies:** 3\
**Last updated:** [October 12, 2023, 3:10pm UTC](https://discuss.elastic.co/t/elasticsearch-api-returning-empty-response-python/344238 "2023-10-12T15:10:46Z")

</div>

I am trying to retrieve elasticsearch data in python using the elasticsearch rest api. When I attempt to call the search api using the requests python library, the elasticsearch python client, or directly from the comma…

---

## [Bar chart comparison of count for today and yesterday](https://discuss.elastic.co/t/bar-chart-comparison-of-count-for-today-and-yesterday/344687)

<div class="topic-metadata">

**Author:** [@Jason\_Paralta](https://discuss.elastic.co/u/Jason_Paralta)\
**Replies:** 6\
**Last updated:** [October 12, 2023, 2:25pm UTC](https://discuss.elastic.co/t/bar-chart-comparison-of-count-for-today-and-yesterday/344687 "2023-10-12T14:25:28Z")

</div>

Hello, I have 3 different regions namely US,APAC and EMEA based licennse. Now I have index with below field: us.region.license.inuse, apac.region.license.inuse and emea.region.license.inuse and now I want to make bar c…

---

## [Unable to connect one elasticsearch master pod to another pod to setup two node cluster](https://discuss.elastic.co/t/unable-to-connect-one-elasticsearch-master-pod-to-another-pod-to-setup-two-node-cluster/344915)

<div class="topic-metadata">

**Author:** [@Santhosh\_Sekar](https://discuss.elastic.co/u/Santhosh_Sekar)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 2:23pm UTC](https://discuss.elastic.co/t/unable-to-connect-one-elasticsearch-master-pod-to-another-pod-to-setup-two-node-cluster/344915 "2023-10-12T14:23:18Z")

</div>

Hello Team, I am trying to setup two node es cluster in k8s. Issue that i am facing is that es-1 could not elect that as master and could not connect to another pod es-2.yml file cluster.name: "elastic.cluster" …

---

## [Error: Forbidden curl https://artifacts.elastic.co/GPG-KEY-elasticsearch](https://discuss.elastic.co/t/error-forbidden-curl-https-artifacts-elastic-co-gpg-key-elasticsearch/344832)

<div class="topic-metadata">

**Author:** [@qwerty1q2w](https://discuss.elastic.co/u/qwerty1q2w)\
**Replies:** 3\
**Last updated:** [October 12, 2023, 2:13pm UTC](https://discuss.elastic.co/t/error-forbidden-curl-https-artifacts-elastic-co-gpg-key-elasticsearch/344832 "2023-10-12T14:13:11Z")

</div>

Hello! I can't download GPG key from hetzner server. request - curl https://artifacts.elastic.co/GPG-KEY-elasticsearch response 403 Forbidden our client does not have permission to get URL from this server.

---

## [Is reindex from remote included in Python client](https://discuss.elastic.co/t/is-reindex-from-remote-included-in-python-client/344814)

<div class="topic-metadata">

**Author:** [@Shahab\_Malekzadeh](https://discuss.elastic.co/u/Shahab_Malekzadeh)\
**Replies:** 7\
**Last updated:** [October 12, 2023, 1:46pm UTC](https://discuss.elastic.co/t/is-reindex-from-remote-included-in-python-client/344814 "2023-10-12T13:46:04Z")

</div>

The Elasticsearch documentation specify the ability to reindex from remote. Can this be done through Python client? I can't find any example. This is what I got which returns error: host = 'https://XXXXXXXXX' indexna…

---

## [Name resolution in hierarchical facets. How to do it better?](https://discuss.elastic.co/t/name-resolution-in-hierarchical-facets-how-to-do-it-better/344719)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 1:33pm UTC](https://discuss.elastic.co/t/name-resolution-in-hierarchical-facets-how-to-do-it-better/344719 "2023-10-12T13:33:52Z")

</div>

Hi, I have a question about how to model the following scenario in ES and if there is a better way for it than we already have. In our system there are documents and categories for these documents. The categories can be…

---

## [Error with Logstash on Docker](https://discuss.elastic.co/t/error-with-logstash-on-docker/344918)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 12:54pm UTC](https://discuss.elastic.co/t/error-with-logstash-on-docker/344918 "2023-10-12T12:54:17Z")

</div>

Hi everyone, im trying to use logstash with docker but the pipeline doesn't work. I'm using the same configuration that in logstash without docker work fine. I really need help because im stuck. I posted the log and th…

---

## [Logstash Service Restart continuously](https://discuss.elastic.co/t/logstash-service-restart-continuously/344736)

<div class="topic-metadata">

**Author:** [@Kamesh\_Pratapa](https://discuss.elastic.co/u/Kamesh_Pratapa)\
**Replies:** 9\
**Last updated:** [October 12, 2023, 12:45pm UTC](https://discuss.elastic.co/t/logstash-service-restart-continuously/344736 "2023-10-12T12:45:58Z")

</div>

Hi, All of a sudden my logstash service is restarting every 3 minutes and getting the below error \[FATAL\]\[org.logstash.Logstash \] Logstash stopped processing because of an error: (LoadError) Could not load FFI Prov…

---

## [I receive this error when trying to send index to elastic output](https://discuss.elastic.co/t/i-receive-this-error-when-trying-to-send-index-to-elastic-output/344491)

<div class="topic-metadata">

**Author:** [@alex\_base](https://discuss.elastic.co/u/alex_base)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 12:43pm UTC](https://discuss.elastic.co/t/i-receive-this-error-when-trying-to-send-index-to-elastic-output/344491 "2023-10-12T12:43:20Z")

</div>

\[INFO \]\[logstash.agent \] Pipelines running {:count=\>1, :running\_pipelines=\>\[:exec\_result\], :non\_running\_pipelines=\>\[\]} \[2023-10-05T13:36:37,359\]\[ERROR\]\[logstash.javapipeline \]\[exec\_result\] Pipeline worker er…

---

## [Fleet - how does the "Oauth2 Endpoint Params" field work in integration configuration](https://discuss.elastic.co/t/fleet-how-does-the-oauth2-endpoint-params-field-work-in-integration-configuration/344833)

<div class="topic-metadata">

**Author:** [@mik0w](https://discuss.elastic.co/u/mik0w)\
**Replies:** 3\
**Last updated:** [October 12, 2023, 12:04pm UTC](https://discuss.elastic.co/t/fleet-how-does-the-oauth2-endpoint-params-field-work-in-integration-configuration/344833 "2023-10-12T12:04:00Z")

</div>

Hello, I am trying to integrate Elastic with Zoom API. Even though there's a Zoom Webhook integration plugin available in Elastic, I want to query Zoom's REST API. Zoom's API requires user to authenticate using OAuth a…

---

## [Is elasticsearch impacted by libwebp vulnerabilities](https://discuss.elastic.co/t/is-elasticsearch-impacted-by-libwebp-vulnerabilities/344910)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 12:03pm UTC](https://discuss.elastic.co/t/is-elasticsearch-impacted-by-libwebp-vulnerabilities/344910 "2023-10-12T12:03:38Z")

</div>

We have received information on vulnerabilities(CVE-2023-4863 / CVE-2023-5129) impacting libwebp packages as can be read below. Is elasticsearch or anything from the stack somehow impacted / depending on libwebp?

---

## [Elastic Search Next js 13 integration](https://discuss.elastic.co/t/elastic-search-next-js-13-integration/344905)

<div class="topic-metadata">

**Author:** [@Alex770](https://discuss.elastic.co/u/Alex770)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 11:14am UTC](https://discuss.elastic.co/t/elastic-search-next-js-13-integration/344905 "2023-10-12T11:14:19Z")

</div>

Need help to connect to my cluster using search-ui-elasticsearch-connector with my Next jx 13 app. The tls secure connection was established with elastic client. But I am unable to connect with search-ui library.

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=398)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=400)
