# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=415

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 416

---

## [Update ILM and link to an existing index](https://discuss.elastic.co/t/update-ilm-and-link-to-an-existing-index/343762)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 1:03pm UTC](https://discuss.elastic.co/t/update-ilm-and-link-to-an-existing-index/343762 "2023-09-25T13:03:21Z")

</div>

Hello, I have to update an ILM and update link to an existing index but i have a doubt on my API call Is that good one? curl -u elastic:xxxx -k -X PUT "https://elasticsearch-1:9200/index-raw-syslog/settings?pretty" -H…

---

## [Fine grained access control to reports](https://discuss.elastic.co/t/fine-grained-access-control-to-reports/343743)

<div class="topic-metadata">

**Author:** [@mpjjonker](https://discuss.elastic.co/u/mpjjonker)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 12:40pm UTC](https://discuss.elastic.co/t/fine-grained-access-control-to-reports/343743 "2023-09-25T12:40:22Z")

</div>

Hi there, In Kibana there is the page where the reports appear. I have been looking for documentation around the access control to these reports. this is the page I am referring to: app/management/insightsAndAlerting…

---

## [Calculate the number of ERUs (Elasticsearch Resource Units) with an enterprise license](https://discuss.elastic.co/t/calculate-the-number-of-erus-elasticsearch-resource-units-with-an-enterprise-license/343754)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 12:32pm UTC](https://discuss.elastic.co/t/calculate-the-number-of-erus-elasticsearch-resource-units-with-an-enterprise-license/343754 "2023-09-25T12:32:33Z")

</div>

How do you calculate the number of ERUs (Elasticsearch Resource Units) with an enterprise license for master and data nodes in Elasticsearch ,please ?

---

## [Fleet server cannot connect to Elasticsearch when it's behind nginx reverse proxy](https://discuss.elastic.co/t/fleet-server-cannot-connect-to-elasticsearch-when-its-behind-nginx-reverse-proxy/343751)

<div class="topic-metadata">

**Author:** [@totobarbar](https://discuss.elastic.co/u/totobarbar)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 12:21pm UTC](https://discuss.elastic.co/t/fleet-server-cannot-connect-to-elasticsearch-when-its-behind-nginx-reverse-proxy/343751 "2023-09-25T12:21:55Z")

</div>

Hello everyone, I want to use Elastic Stack behind nginx reverse proxies. So Kibana and Elasticsearch have a reverse proxy and they work very well together. But Fleet Server can't connect to Elasticsearch through its …

---

## [Add link to a dashboard in the email alert of Kibana Watcher](https://discuss.elastic.co/t/add-link-to-a-dashboard-in-the-email-alert-of-kibana-watcher/343565)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 3\
**Last updated:** [September 25, 2023, 12:12pm UTC](https://discuss.elastic.co/t/add-link-to-a-dashboard-in-the-email-alert-of-kibana-watcher/343565 "2023-09-25T12:12:45Z")

</div>

I have a watcher that send email every time a condition is met. I wonder if it is possible - and if so, then how - to add to the body text a link to a Kibana dashboard? When the recipients get that email they would the…

---

## [Configuring SSL and X-Pack Security for ElasticSearch and Kibana using Bitnami Helm Chart with Ingress](https://discuss.elastic.co/t/configuring-ssl-and-x-pack-security-for-elasticsearch-and-kibana-using-bitnami-helm-chart-with-ingress/342521)

<div class="topic-metadata">

**Author:** [@Naasir\_Mohamed](https://discuss.elastic.co/u/Naasir_Mohamed)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 12:11pm UTC](https://discuss.elastic.co/t/configuring-ssl-and-x-pack-security-for-elasticsearch-and-kibana-using-bitnami-helm-chart-with-ingress/342521 "2023-09-25T12:11:40Z")

</div>

Hello Elastic community, I'm currently working on deploying Elasticsearch (ES) and Kibana using the Bitnami Helm chart, and I've successfully enabled the cluster with Ingress. Now, I'm looking to enhance the security of…

---

## [Not able to see watchers UI in kibana 8.7.1 version](https://discuss.elastic.co/t/not-able-to-see-watchers-ui-in-kibana-8-7-1-version/343593)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 4\
**Last updated:** [September 25, 2023, 12:02pm UTC](https://discuss.elastic.co/t/not-able-to-see-watchers-ui-in-kibana-8-7-1-version/343593 "2023-09-25T12:02:56Z")

</div>

Hi, We have updated the kibana from version 7.10.2 to 8.7.1. We are not able to see watcher UI tab. With the dev tools command we are able to see the watchers. Is there any way to get watchers UI? Could someone please…

---

## [Default space](https://discuss.elastic.co/t/default-space/343747)

<div class="topic-metadata">

**Author:** [@ponpon](https://discuss.elastic.co/u/ponpon)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 11:05am UTC](https://discuss.elastic.co/t/default-space/343747 "2023-09-25T11:05:48Z")

</div>

Hi, my default space is unaccessible. when I am presented with the " Select your space" page and I choose Default, I am redirected to one of the other spaces. I have restarted Kibana and I have checked that .kabana is w…

---

## ["logs threshold rule" missing "comparator": "MATCHES"](https://discuss.elastic.co/t/logs-threshold-rule-missing-comparator-matches/343734)

<div class="topic-metadata">

**Author:** [@BRINDAH\_B](https://discuss.elastic.co/u/BRINDAH_B)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 9:46am UTC](https://discuss.elastic.co/t/logs-threshold-rule-missing-comparator-matches/343734 "2023-09-25T09:46:03Z")

</div>

I want to create a "logs threshold rule" with "comparator": "MATCHES" or "MATCHES PHRASE". I want to be able to use the "message" field in my log-threshold rule, which is of type "text". Is this possible? Right now im …

---

## [UNASSIGNED NODE\_LEFT](https://discuss.elastic.co/t/unassigned-node-left/343737)

<div class="topic-metadata">

**Author:** [@PugachevLB](https://discuss.elastic.co/u/PugachevLB)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 9:51am UTC](https://discuss.elastic.co/t/unassigned-node-left/343737 "2023-09-25T09:51:30Z")

</div>

We have a cluster of 30 nodes (3 phys servers 64 cpu + 512 mem with 10 ES instances on each (1 master + 9 data)). Sometimes after uploading a new index (~700 Gb 24 shards \* 2 rep factor) we have some instances crushed (…

---

## [Filebeat-7.17.12-system-syslog-pi peline\] does not exist](https://discuss.elastic.co/t/filebeat-7-17-12-system-syslog-pi-peline-does-not-exist/343735)

<div class="topic-metadata">

**Author:** [@YassBout](https://discuss.elastic.co/u/YassBout)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 9:46am UTC](https://discuss.elastic.co/t/filebeat-7-17-12-system-syslog-pi-peline-does-not-exist/343735 "2023-09-25T09:46:18Z")

</div>

Hello, I've installed the ELK stack on a VPS to monitor remote logs from multiple companies. However, when I install and start all the services, I encounter this error: 2023-08-27T09:17:59.426Z#011INFO#011\[publisher\]#0…

---

## [Kibana Dashboard - Display difference between two counts](https://discuss.elastic.co/t/kibana-dashboard-display-difference-between-two-counts/343687)

<div class="topic-metadata">

**Author:** [@seb.sch](https://discuss.elastic.co/u/seb.sch)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 8:56am UTC](https://discuss.elastic.co/t/kibana-dashboard-display-difference-between-two-counts/343687 "2023-09-25T08:56:29Z")

</div>

Hi there, I've been searching on anything new to this issue for the whole weekend now, but I've found only posts which are 3+ years old. If I needed to do implement my requirement manually, I'd do the following: GET m…

---

## [Implement word cloud in Kibana](https://discuss.elastic.co/t/implement-word-cloud-in-kibana/307480)

<div class="topic-metadata">

**Author:** [@Abhishek\_Shinde](https://discuss.elastic.co/u/Abhishek_Shinde)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 8:41am UTC](https://discuss.elastic.co/t/implement-word-cloud-in-kibana/307480 "2023-09-25T08:41:28Z")

</div>

I wanted to implement Word Cloud visualization using Kibana in my application. The example is attached. I'm looking for reference material on the Elastic site on how to get this done. It would be good if someone can shar…

---

## [Error "illegal base64 data at input byte 56" when enroll elastic-agent](https://discuss.elastic.co/t/error-illegal-base64-data-at-input-byte-56-when-enroll-elastic-agent/343553)

<div class="topic-metadata">

**Author:** [@neva-ops](https://discuss.elastic.co/u/neva-ops)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 8:12am UTC](https://discuss.elastic.co/t/error-illegal-base64-data-at-input-byte-56-when-enroll-elastic-agent/343553 "2023-09-25T08:12:45Z")

</div>

Can't enroll elastic-agent in Fleet. When I run elastic-agent with docker compose then I get this errors: {"log.level":"info","@timestamp":"2023-09-21T14:02:42.544Z","message":"HTTP request error","component":{"binary…

---

## [Fleet Server Agent Not able to 'identify' kibana secret in ECK](https://discuss.elastic.co/t/fleet-server-agent-not-able-to-identify-kibana-secret-in-eck/343105)

<div class="topic-metadata">

**Author:** [@VVK](https://discuss.elastic.co/u/VVK)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 8:00am UTC](https://discuss.elastic.co/t/fleet-server-agent-not-able-to-identify-kibana-secret-in-eck/343105 "2023-09-25T08:00:03Z")

</div>

Environment: We are managing our own k8s enviornment and have our kibana/Elasticsearch w/o any problems. Filebeat and Metricbeat are working fine. No issues. Observability & Elastic APM is working as per expectation. …

---

## [Creating Multi-Fields using Kibana UI](https://discuss.elastic.co/t/creating-multi-fields-using-kibana-ui/343707)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 6:24am UTC](https://discuss.elastic.co/t/creating-multi-fields-using-kibana-ui/343707 "2023-09-25T06:24:51Z")

</div>

Hello All, Apologies in advance if this is the wrong sub-forum to ask the question. I am new to the forum and ELK in general. I am looking to create multi-field mapping for a legacy index template using the Kibana crea…

---

## [How to fetch nested json data in separate fields](https://discuss.elastic.co/t/how-to-fetch-nested-json-data-in-separate-fields/343701)

<div class="topic-metadata">

**Author:** [@bharti](https://discuss.elastic.co/u/bharti)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 5:23am UTC](https://discuss.elastic.co/t/how-to-fetch-nested-json-data-in-separate-fields/343701 "2023-09-25T05:23:02Z")

</div>

Hello I need a little help. I want to fetch some nested json data into separate fields input { beats { port =\> 5044 } } filter { if "/var/log/ABC.log" in \[log\]\[file\]\[path\] { grok { match =\> …

---

## [Elasticsearch Node went down abruptly and lost data](https://discuss.elastic.co/t/elasticsearch-node-went-down-abruptly-and-lost-data/343566)

<div class="topic-metadata">

**Author:** [@nsoni](https://discuss.elastic.co/u/nsoni)\
**Replies:** 4\
**Last updated:** [September 25, 2023, 5:16am UTC](https://discuss.elastic.co/t/elasticsearch-node-went-down-abruptly-and-lost-data/343566 "2023-09-25T05:16:23Z")

</div>

I am running Elasticsearch cluster version 7.10.0 It's running for a year now, never faced any issues. Our setup comprises 1 primary and 1 replica in a different availability zone. Distribution is through the rack\_id a…

---

## [Elastic Agent, aws-s3-default-aws-s3-vpcflow keeps failing](https://discuss.elastic.co/t/elastic-agent-aws-s3-default-aws-s3-vpcflow-keeps-failing/343697)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 4:51am UTC](https://discuss.elastic.co/t/elastic-agent-aws-s3-default-aws-s3-vpcflow-keeps-failing/343697 "2023-09-25T04:51:41Z")

</div>

I have an AWS environment which ships VPC logs to a S3 bucket. I am using the AWS VPC Log Processing integration within Elastic Agent to process these logs and to monitor for new logs. It connects to the bucket success…

---

## [Regarding the usage of nested fields](https://discuss.elastic.co/t/regarding-the-usage-of-nested-fields/343655)

<div class="topic-metadata">

**Author:** [@yeikel](https://discuss.elastic.co/u/yeikel)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 4:22am UTC](https://discuss.elastic.co/t/regarding-the-usage-of-nested-fields/343655 "2023-09-25T04:22:45Z")

</div>

Hi all, I need to ingest a large volume of records from one data source to another and one topic that I am currently debating is regarding the usage of Nested Field with Arrays or using Multi match and search across mu…

---

## [Api to get saved objects info like Dashboard for kibana 8.9.0?](https://discuss.elastic.co/t/api-to-get-saved-objects-info-like-dashboard-for-kibana-8-9-0/341855)

<div class="topic-metadata">

**Author:** [@Daemon1](https://discuss.elastic.co/u/Daemon1)\
**Replies:** 7\
**Last updated:** [September 24, 2023, 11:48pm UTC](https://discuss.elastic.co/t/api-to-get-saved-objects-info-like-dashboard-for-kibana-8-9-0/341855 "2023-09-24T23:48:24Z")

</div>

GET \<kibana host\>:\<port\>/api/saved\_objects/\<type\>/\<id\> The above API is deprecated for version 8.9.0 GET \<kibana host\>:\<port\>/api/data\_views This API only returns the info about data\_views not dashboard. What is the …

---

## [Kibana Table (dashboard) - compute percentage when all row are filters](https://discuss.elastic.co/t/kibana-table-dashboard-compute-percentage-when-all-row-are-filters/343647)

<div class="topic-metadata">

**Author:** [@ctinp](https://discuss.elastic.co/u/ctinp)\
**Replies:** 2\
**Last updated:** [September 23, 2023, 10:49pm UTC](https://discuss.elastic.co/t/kibana-table-dashboard-compute-percentage-when-all-row-are-filters/343647 "2023-09-23T22:49:14Z")

</div>

One of the fields in my logs contains a list of vulnerabilities separated by comma (e.g. attacks=XSS,SQLI,LOG4J. In Kibana, I have created a table visualisation where each row is a filter for one of the signals (e.g. at…

---

## [Kibana Visualisations](https://discuss.elastic.co/t/kibana-visualisations/342622)

<div class="topic-metadata">

**Author:** [@DivyaDileep](https://discuss.elastic.co/u/DivyaDileep)\
**Replies:** 1\
**Last updated:** [September 23, 2023, 10:46pm UTC](https://discuss.elastic.co/t/kibana-visualisations/342622 "2023-09-23T22:46:13Z")

</div>

If I want to create a dashboad for "instance\_name & diskIndex in message to be matched, then the diskPath & diskPercent fields displayed so it shows what the partition is called & how full it is in a percentage." diskPer…

---

## [Do collapse keys benefit from document routing?](https://discuss.elastic.co/t/do-collapse-keys-benefit-from-document-routing/343677)

<div class="topic-metadata">

**Author:** [@davidgAID](https://discuss.elastic.co/u/davidgAID)\
**Replies:** 0\
**Last updated:** [September 23, 2023, 7:02pm UTC](https://discuss.elastic.co/t/do-collapse-keys-benefit-from-document-routing/343677 "2023-09-23T19:02:29Z")

</div>

I have an index with denormalized data that is almost exclusively used with collapse queries. If I configure index routing to use the collapse key, which would keep denormalized sibling documents on the same shard, would…

---

## [I have elk, logstash, kibana and filebeat version 7.10.1 and want upgarde to latest](https://discuss.elastic.co/t/i-have-elk-logstash-kibana-and-filebeat-version-7-10-1-and-want-upgarde-to-latest/343662)

<div class="topic-metadata">

**Author:** [@Mostafa\_Faridi](https://discuss.elastic.co/u/Mostafa_Faridi)\
**Replies:** 5\
**Last updated:** [September 23, 2023, 5:33pm UTC](https://discuss.elastic.co/t/i-have-elk-logstash-kibana-and-filebeat-version-7-10-1-and-want-upgarde-to-latest/343662 "2023-09-23T17:33:18Z")

</div>

I have install ELK stack with RPM on my Oracle Linux and its work and I have six Oracle Linux and install elasticserch and kibana and logstash on one server and install filebeat on other servers. I want right now upgrad…

---

## [Logstash cannot connect to my postgresql database, they are both running in docker containers on the same compose network](https://discuss.elastic.co/t/logstash-cannot-connect-to-my-postgresql-database-they-are-both-running-in-docker-containers-on-the-same-compose-network/343668)

<div class="topic-metadata">

**Author:** [@descholar-ceo](https://discuss.elastic.co/u/descholar-ceo)\
**Replies:** 0\
**Last updated:** [September 23, 2023, 9:33am UTC](https://discuss.elastic.co/t/logstash-cannot-connect-to-my-postgresql-database-they-are-both-running-in-docker-containers-on-the-same-compose-network/343668 "2023-09-23T09:33:39Z")

</div>

I am looking for a help, I am struggling with connecting Logstash to my postgres db, they are both running on the same docker compose network and the connection string I passed works from my application which is running …

---

## [Elasticsearch ILM Policies](https://discuss.elastic.co/t/elasticsearch-ilm-policies/343671)

<div class="topic-metadata">

**Author:** [@gsekar](https://discuss.elastic.co/u/gsekar)\
**Replies:** 0\
**Last updated:** [September 23, 2023, 10:30am UTC](https://discuss.elastic.co/t/elasticsearch-ilm-policies/343671 "2023-09-23T10:30:52Z")

</div>

Hi All Currently we are sending logs to elasticsearch and it's configured in such a way that daily datastreams are created. For Eg: logs-app1-2023-09-23, logs-app1-2023-09-24 etc. Goal is to keep logs for 3 days. We hav…

---

## [DEMORA EN CARGAR INTERFAZ GRAFICA WAZUH](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343653)

<div class="topic-metadata">

**Author:** [@stefanny\_chavez\_anto](https://discuss.elastic.co/u/stefanny_chavez_anto)\
**Replies:** 1\
**Last updated:** [September 23, 2023, 2:04am UTC](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343653 "2023-09-23T02:04:04Z")

</div>

Tengo un problema al visualizar la interfaz grafica de Wazuh, he procedido a reinicar el servidor ubuntu y al momento de encender todos los servicios (filebeat, elasticsearch, kibana y wazuh-manager) están activos, pero …

---

## [Alter Index so every user can see it](https://discuss.elastic.co/t/alter-index-so-every-user-can-see-it/343537)

<div class="topic-metadata">

**Author:** [@yogobah921](https://discuss.elastic.co/u/yogobah921)\
**Replies:** 1\
**Last updated:** [September 23, 2023, 12:11am UTC](https://discuss.elastic.co/t/alter-index-so-every-user-can-see-it/343537 "2023-09-23T00:11:33Z")

</div>

I have multiple accounts with different roles and now I created a new index. Now the roles can't access the new index because it is not listed in their indices configuration. how can I alter the index so every user can…

---

## [DEMORA EN CARGAR INTERFAZ GRAFICA WAZUH](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343654)

<div class="topic-metadata">

**Author:** [@stefanny\_chavez\_anto](https://discuss.elastic.co/u/stefanny_chavez_anto)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 8:24pm UTC](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343654 "2023-09-22T20:24:41Z")

</div>

Tengo un problema al visualizar la interfaz grafica de Wazuh, he procedido a reinicar el servidor ubuntu y al momento de encender todos los servicios (filebeat, elasticsearch, kibana y wazuh-manager) están activos, pero …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=414)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=416)
