# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=418

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 419

---

## [Top N User Control - In the Kibana Dashboard](https://discuss.elastic.co/t/top-n-user-control-in-the-kibana-dashboard/343488)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 9:21pm UTC](https://discuss.elastic.co/t/top-n-user-control-in-the-kibana-dashboard/343488 "2023-09-20T21:21:23Z")

</div>

I am grouping the visuals in my dashboard with Top 10 or 20 + others + missing. I want to give this control to users to filter the data to see themselves in how many counts they want to see that data. How should I do i…

---

## [Can't get Filebeat to ship Nginx Ingress Controller logs using ECK](https://discuss.elastic.co/t/cant-get-filebeat-to-ship-nginx-ingress-controller-logs-using-eck/343472)

<div class="topic-metadata">

**Author:** [@krische](https://discuss.elastic.co/u/krische)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 7:54pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-ship-nginx-ingress-controller-logs-using-eck/343472 "2023-09-20T19:54:06Z")

</div>

I have ECK setup and running on my kubernetes cluster. I followed the Configuration Examples to setup filebeat ship all container logs to Elasticsearch. That is working fine. However, now I am trying to parse the logs o…

---

## [Any Updates on Controlling Access to Jobs In Kibana ML?](https://discuss.elastic.co/t/any-updates-on-controlling-access-to-jobs-in-kibana-ml/343299)

<div class="topic-metadata">

**Author:** [@johnlbellamy](https://discuss.elastic.co/u/johnlbellamy)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 7:40pm UTC](https://discuss.elastic.co/t/any-updates-on-controlling-access-to-jobs-in-kibana-ml/343299 "2023-09-20T19:40:05Z")

</div>

Hello, I have seen posts about controlling access to ML jobs. How can we stop all users from seeing other user's jobs? Any movement on this in 8.9? Have tried using the custom index name and etc. to no avail. Thank Yo…

---

## [REST api: delete dashboard](https://discuss.elastic.co/t/rest-api-delete-dashboard/343471)

<div class="topic-metadata">

**Author:** [@emmanuel\_t](https://discuss.elastic.co/u/emmanuel_t)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 7:24pm UTC](https://discuss.elastic.co/t/rest-api-delete-dashboard/343471 "2023-09-20T19:24:16Z")

</div>

I see that the saved objects API is deprecated, and that's a real bummer, the API was extremely useful for us. For most of our use cases we can probably get by using the import/export API as a worse (from our point of vi…

---

## [Integration Dashboard Links](https://discuss.elastic.co/t/integration-dashboard-links/342842)

<div class="topic-metadata">

**Author:** [@cappy](https://discuss.elastic.co/u/cappy)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 6:08pm UTC](https://discuss.elastic.co/t/integration-dashboard-links/342842 "2023-09-20T18:08:08Z")

</div>

I am using version 8.8.2. No matter if I set server.basePath or server.publicBaseUrl, the links inside of the dashboards for the integrations still reference a static path like $host/app/dashboards/blah, even if I remov…

---

## [How can I remove the duplicate in the logs and prevent to create new docs](https://discuss.elastic.co/t/how-can-i-remove-the-duplicate-in-the-logs-and-prevent-to-create-new-docs/343417)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 7\
**Last updated:** [September 20, 2023, 5:34pm UTC](https://discuss.elastic.co/t/how-can-i-remove-the-duplicate-in-the-logs-and-prevent-to-create-new-docs/343417 "2023-09-20T17:34:44Z")

</div>

Hello everyone! I have this logs { "\_index": ".ds-my-neoada-stream-2023.09.14-000005", "\_id": "T8v5sIoB0eBbzdbCLRnW", "\_version": 1, "\_score": 0, "\_source": { "from\_plant": "N/A", "tick\_current": "IT-…

---

## [Invalid cron expression for schedule field of elasticsearch input plugin](https://discuss.elastic.co/t/invalid-cron-expression-for-schedule-field-of-elasticsearch-input-plugin/343478)

<div class="topic-metadata">

**Author:** [@mikec1](https://discuss.elastic.co/u/mikec1)\
**Replies:** 5\
**Last updated:** [September 20, 2023, 5:08pm UTC](https://discuss.elastic.co/t/invalid-cron-expression-for-schedule-field-of-elasticsearch-input-plugin/343478 "2023-09-20T17:08:07Z")

</div>

I have a pipeline whereby the input section looks like this: input { elasticsearch { hosts =\> \["elasticsearch.my.host.here:port"\] index =\> 'my\_index\_name\_pattern' query =\> '{ "query": { "mat…

---

## [AWS logging integration error](https://discuss.elastic.co/t/aws-logging-integration-error/343469)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 4:27pm UTC](https://discuss.elastic.co/t/aws-logging-integration-error/343469 "2023-09-20T16:27:30Z")

</div>

Hi, I want to integrate the AWS logs into my Kibana Observability log stream. Here is the access policy of SQS queue: { "Version": "2012-10-17", "Id": "arn:aws:sqs:us-east-1:334811116626:ingest-ec2-logs-sqs/SQSDef…

---

## [Restore request has no response and doesnt execute](https://discuss.elastic.co/t/restore-request-has-no-response-and-doesnt-execute/343476)

<div class="topic-metadata">

**Author:** [@Chris\_Brown](https://discuss.elastic.co/u/Chris_Brown)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 4:09pm UTC](https://discuss.elastic.co/t/restore-request-has-no-response-and-doesnt-execute/343476 "2023-09-20T16:09:44Z")

</div>

Hello. I've successfully created a snapshot in s3 and it appears to be fine when calling \_snapshot/name/\_all. When trying to restore it with a POST to \_snapshot/name/snapshot/\_restore the request hangs indefinitely, nev…

---

## [Multi-level nested query structure — bug or feature](https://discuss.elastic.co/t/multi-level-nested-query-structure-bug-or-feature/343475)

<div class="topic-metadata">

**Author:** [@jonnyeom](https://discuss.elastic.co/u/jonnyeom)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 3:42pm UTC](https://discuss.elastic.co/t/multi-level-nested-query-structure-bug-or-feature/343475 "2023-09-20T15:42:00Z")

</div>

Hello, Im working with multi-level nested query filters. Documentation in Nested query | Elasticsearch Guide \[8.10\] | Elastic shows an example where each level is nested as part of the search query. i.e. Query Example…

---

## [CA Certificate for Elasticsearch and Kibana in K8s](https://discuss.elastic.co/t/ca-certificate-for-elasticsearch-and-kibana-in-k8s/342733)

<div class="topic-metadata">

**Author:** [@Esakki](https://discuss.elastic.co/u/Esakki)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 2:21pm UTC](https://discuss.elastic.co/t/ca-certificate-for-elasticsearch-and-kibana-in-k8s/342733 "2023-09-20T14:21:26Z")

</div>

Hi All, Can someone share the steps how to configure certificate for Elasticsearch and Kiabana which is deployed on-prem K8s cluster. Thanks in advance. Kind Regards, Esakki

---

## [Documentation on the relationship between output fields and input plugins/processors](https://discuss.elastic.co/t/documentation-on-the-relationship-between-output-fields-and-input-plugins-processors/343467)

<div class="topic-metadata">

**Author:** [@frans-wtax](https://discuss.elastic.co/u/frans-wtax)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 1:53pm UTC](https://discuss.elastic.co/t/documentation-on-the-relationship-between-output-fields-and-input-plugins-processors/343467 "2023-09-20T13:53:16Z")

</div>

Various pages on the Filebeat documentation describe inputs: Configure inputs | Filebeat Reference \[8.10\] | Elastic . Similarly, processors are documented: Filter and enhance data with processors | Filebeat Reference \[8.…

---

## [Issue on db query](https://discuss.elastic.co/t/issue-on-db-query/343369)

<div class="topic-metadata">

**Author:** [@girolamo](https://discuss.elastic.co/u/girolamo)\
**Replies:** 5\
**Last updated:** [September 20, 2023, 1:49pm UTC](https://discuss.elastic.co/t/issue-on-db-query/343369 "2023-09-20T13:49:57Z")

</div>

Hello there, I'm having issues making a query on a Elasticsearch db. Indeed, if I make this request: POST my-index/\_search I get almost all documents in the index. In this way: { "took" : 15, "timed\_out" : fals…

---

## [Use variable with logstash](https://discuss.elastic.co/t/use-variable-with-logstash/343462)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 1:48pm UTC](https://discuss.elastic.co/t/use-variable-with-logstash/343462 "2023-09-20T13:48:41Z")

</div>

Hello I have a long list like this if \[monitoring\_data\_name\] == "componentFault" { pipeline { send\_to =\> "componentFault" } } else if \[monitoring\_data\_name\] == "localAccountPasswordModification" { pipeline { send\_t…

---

## [What's the equivalent of NEST's QueryBase.IsVerbatim property in Elastic.Clients.Elasticsearch (8.x)](https://discuss.elastic.co/t/whats-the-equivalent-of-nests-querybase-isverbatim-property-in-elastic-clients-elasticsearch-8-x/343455)

<div class="topic-metadata">

**Author:** [@yansklyarenko](https://discuss.elastic.co/u/yansklyarenko)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 1:26pm UTC](https://discuss.elastic.co/t/whats-the-equivalent-of-nests-querybase-isverbatim-property-in-elastic-clients-elasticsearch-8-x/343455 "2023-09-20T13:26:08Z")

</div>

NEST (7.x) client has QueryBase class, which in its turn has IsVerbatim boolean property. Hence, all derived query classes inherit it. However, query classes in Elastic.Clients.Elasticsearch (8.x) client don't inherit/de…

---

## [How do I count and visualize only latest doc based on certain field?](https://discuss.elastic.co/t/how-do-i-count-and-visualize-only-latest-doc-based-on-certain-field/343457)

<div class="topic-metadata">

**Author:** [@Doron\_Abramovich](https://discuss.elastic.co/u/Doron_Abramovich)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 12:54pm UTC](https://discuss.elastic.co/t/how-do-i-count-and-visualize-only-latest-doc-based-on-certain-field/343457 "2023-09-20T12:54:47Z")

</div>

Hi everyone :slight\_smile: First post here after working for over year with elastic. I have an index with docs representing items moving from station to station, each doc represents a station. For example - an item mo…

---

## [Logstash json input file only required fields to output](https://discuss.elastic.co/t/logstash-json-input-file-only-required-fields-to-output/342400)

<div class="topic-metadata">

**Author:** [@Narayan\_Rao](https://discuss.elastic.co/u/Narayan_Rao)\
**Replies:** 11\
**Last updated:** [September 20, 2023, 12:53pm UTC](https://discuss.elastic.co/t/logstash-json-input-file-only-required-fields-to-output/342400 "2023-09-20T12:53:37Z")

</div>

I'm new in ELK & I have logs in JSON format. Below is the json sample log file. I want only item level array, others fields not required. Sample logs { "source": "mdm/pim", "topic": "pim-record-globalfields", "subj…

---

## [Custom CSS conditional formatting TSVB](https://discuss.elastic.co/t/custom-css-conditional-formatting-tsvb/343460)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 12:53pm UTC](https://discuss.elastic.co/t/custom-css-conditional-formatting-tsvb/343460 "2023-09-20T12:53:27Z")

</div>

Hi Team, i am working on TSVB visualization and using filter ratio. it gives me metric as below now here i have a markdown as APP1 and i have value coming as {{ a.a.last.formatted }}. Based upon this value of {{ a.a.…

---

## [Failed to load SSL configuration \[xpack.security.transport.ssl\] - the truststore \[/usr/share/elasticsearch/ssl/qa.pfx\] does not contain any trusted certificate entries](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-the-truststore-usr-share-elasticsearch-ssl-qa-pfx-does-not-contain-any-trusted-certificate-entries/343138)

<div class="topic-metadata">

**Author:** [@Anushree](https://discuss.elastic.co/u/Anushree)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 12:10pm UTC](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-the-truststore-usr-share-elasticsearch-ssl-qa-pfx-does-not-contain-any-trusted-certificate-entries/343138 "2023-09-20T12:10:08Z")

</div>

Hello, I encountered an SSL certificate trust issue when attempting to upgrade a single-node Elasticsearch instance from version 7.17 to 8.0, same certificate was working on 7.17. I am using a valid certificate chain pr…

---

## [Validation error on Kibana8 upgrade from Kibana7.17](https://discuss.elastic.co/t/validation-error-on-kibana8-upgrade-from-kibana7-17/343449)

<div class="topic-metadata">

**Author:** [@Vikrant\_Dewangan](https://discuss.elastic.co/u/Vikrant_Dewangan)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 11:15am UTC](https://discuss.elastic.co/t/validation-error-on-kibana8-upgrade-from-kibana7-17/343449 "2023-09-20T11:15:07Z")

</div>

Hi, I am upgrading installing kibana8 from kibana7.17, and receiving the following error. Are there any leads for the validation type error? Configuring logger failed: ValidationError: \[config validation of \[logging\].a…

---

## [Logstash JDBC plugin](https://discuss.elastic.co/t/logstash-jdbc-plugin/343456)

<div class="topic-metadata">

**Author:** [@Akulainelastic](https://discuss.elastic.co/u/Akulainelastic)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 12:04pm UTC](https://discuss.elastic.co/t/logstash-jdbc-plugin/343456 "2023-09-20T12:04:15Z")

</div>

Hello All , so I have a requirement where I need to use JDBC plugin to fetch the database data and reflect it in kibana , although I have successfully ingested data and pipelined it in logstash , the pipelines are runnin…

---

## [jakarta.json.stream.JsonParsingException when deserializing data retrieved from Elasticsearch](https://discuss.elastic.co/t/jakarta-json-stream-jsonparsingexception-when-deserializing-data-retrieved-from-elasticsearch/343367)

<div class="topic-metadata">

**Author:** [@Georgi\_Nikolov](https://discuss.elastic.co/u/Georgi_Nikolov)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 11:44am UTC](https://discuss.elastic.co/t/jakarta-json-stream-jsonparsingexception-when-deserializing-data-retrieved-from-elasticsearch/343367 "2023-09-20T11:44:41Z")

</div>

for some time now I have been trying to incorporate the Elastic Java 8.10 client into my code, I have a big ELK stack with a lot of data. I am trying to fetch continuously data from it, but I am encountering some inconsi…

---

## [Time-based rule exclusions](https://discuss.elastic.co/t/time-based-rule-exclusions/343451)

<div class="topic-metadata">

**Author:** [@austinvdm](https://discuss.elastic.co/u/austinvdm)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 11:42am UTC](https://discuss.elastic.co/t/time-based-rule-exclusions/343451 "2023-09-20T11:42:44Z")

</div>

Hello, I am curious if there is a way to implement "time-based exclusions" for security rules? For example, we are trying to excluded specific endpoints from a rule on Saturday and Sundays when we run OS updates but stil…

---

## [Error while starting elasticsearch v8.9.1](https://discuss.elastic.co/t/error-while-starting-elasticsearch-v8-9-1/343335)

<div class="topic-metadata">

**Author:** [@sanyam](https://discuss.elastic.co/u/sanyam)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 10:32am UTC](https://discuss.elastic.co/t/error-while-starting-elasticsearch-v8-9-1/343335 "2023-09-20T10:32:21Z")

</div>

Whenever I start up ES by running ES .bat file on Windows, I receive this error: \[ERROR\]\[o.e.b.Elasticsearch \] \[node-1\] fatal exception while booting Elasticsearchorg.elasticsearch.ElasticsearchSecurityException: i…

---

## [Kiaban generated url for index pattern](https://discuss.elastic.co/t/kiaban-generated-url-for-index-pattern/343438)

<div class="topic-metadata">

**Author:** [@O\_K](https://discuss.elastic.co/u/O_K)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 9:50am UTC](https://discuss.elastic.co/t/kiaban-generated-url-for-index-pattern/343438 "2023-09-20T09:50:13Z")

</div>

I'm writing some app which will be generating kibana URLs with particular logs. The problem I faced that I can discover indexes in kibana UI using data view or get data view id from kibana API /api/data\_views and then ma…

---

## [Metricbeat 7.13 not working](https://discuss.elastic.co/t/metricbeat-7-13-not-working/343439)

<div class="topic-metadata">

**Author:** [@Spottie](https://discuss.elastic.co/u/Spottie)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 9:56am UTC](https://discuss.elastic.co/t/metricbeat-7-13-not-working/343439 "2023-09-20T09:56:10Z")

</div>

I have a docker setup with multiple containers running and then setup a filebeat that logs into my elasticsearch. Now I wanted to setup a metricbeat as described here: Set up and run Metricbeat | Metricbeat Reference \[7…

---

## [Daily index size with rollover](https://discuss.elastic.co/t/daily-index-size-with-rollover/343402)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 9:55am UTC](https://discuss.elastic.co/t/daily-index-size-with-rollover/343402 "2023-09-20T09:55:21Z")

</div>

Hi Can You help me to find a solution how to make a chart with daily index size.Such index are rollover a few times per day. Thx for hint

---

## [Reference line with the median of max values](https://discuss.elastic.co/t/reference-line-with-the-median-of-max-values/343433)

<div class="topic-metadata">

**Author:** [@SpicyS](https://discuss.elastic.co/u/SpicyS)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 9:29am UTC](https://discuss.elastic.co/t/reference-line-with-the-median-of-max-values/343433 "2023-09-20T09:29:09Z")

</div>

Hello, In kibana lens I would like to know if it is possible to create a reference line layer that show me de median of the max values over time. This way i can compare the current average with the median of max value t…

---

## ["Failed to decode response" error from Java Client 8.8.0](https://discuss.elastic.co/t/failed-to-decode-response-error-from-java-client-8-8-0/343309)

<div class="topic-metadata">

**Author:** [@Roman\_Kagan](https://discuss.elastic.co/u/Roman_Kagan)\
**Replies:** 10\
**Last updated:** [September 20, 2023, 9:12am UTC](https://discuss.elastic.co/t/failed-to-decode-response-error-from-java-client-8-8-0/343309 "2023-09-20T09:12:14Z")

</div>

Hello: I am trying to use Elastic Java Client 8.8.0 (also known low-level rest client) and getting the error: status: 200, \[es/search\] Failed to decode response I used the same library to create a new index and insert …

---

## [Document to setup on-prem single node ECK on Kubernetes with elastic agent](https://discuss.elastic.co/t/document-to-setup-on-prem-single-node-eck-on-kubernetes-with-elastic-agent/343428)

<div class="topic-metadata">

**Author:** [@sankumar](https://discuss.elastic.co/u/sankumar)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 8:19am UTC](https://discuss.elastic.co/t/document-to-setup-on-prem-single-node-eck-on-kubernetes-with-elastic-agent/343428 "2023-09-20T08:19:00Z")

</div>

Want to setup single node ECK on Kubernetes with elastic agent. So looking for the document to setup.

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=417)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=419)
