# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=420

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 421

---

## [Unable to filter older indices](https://discuss.elastic.co/t/unable-to-filter-older-indices/343359)

<div class="topic-metadata">

**Author:** [@pbmamatha](https://discuss.elastic.co/u/pbmamatha)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 12:16pm UTC](https://discuss.elastic.co/t/unable-to-filter-older-indices/343359 "2023-09-19T12:16:04Z")

</div>

Hello, I am tasked to create an alert for indices older than 3 days, however, the filter query is not working. Could you please help me identify the issue. Have tried the below queries: 1. GET /\_search { "query":…

---

## [Send emails with PDF Dashboard](https://discuss.elastic.co/t/send-emails-with-pdf-dashboard/341105)

<div class="topic-metadata">

**Author:** [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Replies:** 2\
**Last updated:** [September 19, 2023, 12:01pm UTC](https://discuss.elastic.co/t/send-emails-with-pdf-dashboard/341105 "2023-09-19T12:01:36Z")

</div>

Hello, I read the documentation about sending email with PDF dashboard in the attachment \>\>\> Automatically generate reports | Kibana Guide \[8.9\] | Elastic I wanted to create my own watcher. My Kibana version is 7.17.8 …

---

## [Log threshold alerting rule to check the presence of logs on specific hosts](https://discuss.elastic.co/t/log-threshold-alerting-rule-to-check-the-presence-of-logs-on-specific-hosts/342799)

<div class="topic-metadata">

**Author:** [@melkamar](https://discuss.elastic.co/u/melkamar)\
**Replies:** 6\
**Last updated:** [September 19, 2023, 9:40am UTC](https://discuss.elastic.co/t/log-threshold-alerting-rule-to-check-the-presence-of-logs-on-specific-hosts/342799 "2023-09-19T09:40:28Z")

</div>

Hi, I am trying to set up an alert rule that will alert me when a job that I expect to run at particular servers stops writing into the syslog. The idea is that I want to receive alerts when: Any host with a field ser…

---

## [Which Node.js client should I use for Elastic search?](https://discuss.elastic.co/t/which-node-js-client-should-i-use-for-elastic-search/343115)

<div class="topic-metadata">

**Author:** [@cosieLq](https://discuss.elastic.co/u/cosieLq)\
**Replies:** 8\
**Last updated:** [September 19, 2023, 9:40am UTC](https://discuss.elastic.co/t/which-node-js-client-should-i-use-for-elastic-search/343115 "2023-09-19T09:40:20Z")

</div>

Which package should I use as a Node.js client to connect to Elastic search? I've found this one: elasticsearch-js (GitHub - elastic/elasticsearch-js: Official Elasticsearch client library for Node.js) It seems to be r…

---

## [Installation Freeze (adding index template)](https://discuss.elastic.co/t/installation-freeze-adding-index-template/343324)

<div class="topic-metadata">

**Author:** [@fizzyBubblech](https://discuss.elastic.co/u/fizzyBubblech)\
**Replies:** 3\
**Last updated:** [September 19, 2023, 8:56am UTC](https://discuss.elastic.co/t/installation-freeze-adding-index-template/343324 "2023-09-19T08:56:06Z")

</div>

Hello My Goal: Install Kibana and Elasticsearch on my Windows 11 VM. Our Infrastructure We run our VMs on ESXi and managed them in vCenter. I have Admin rights but just for my VM. Install processes 1.) Downloaded …

---

## [Calculating the difference between datetime cells for an average](https://discuss.elastic.co/t/calculating-the-difference-between-datetime-cells-for-an-average/343225)

<div class="topic-metadata">

**Author:** [@SpicyS](https://discuss.elastic.co/u/SpicyS)\
**Replies:** 8\
**Last updated:** [September 19, 2023, 8:46am UTC](https://discuss.elastic.co/t/calculating-the-difference-between-datetime-cells-for-an-average/343225 "2023-09-19T08:46:54Z")

</div>

Hello, I'm new to kibana and I would like to know if it is possible to calculate the difference between 2 datetime fields named: "start\_date" and "end\_date", the reason for this is the fact I want to show the average du…

---

## [Error when converting Eland Dataframe to Pandas Dataframe using Eland on Jupyter](https://discuss.elastic.co/t/error-when-converting-eland-dataframe-to-pandas-dataframe-using-eland-on-jupyter/343331)

<div class="topic-metadata">

**Author:** [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 8:46am UTC](https://discuss.elastic.co/t/error-when-converting-eland-dataframe-to-pandas-dataframe-using-eland-on-jupyter/343331 "2023-09-19T08:46:50Z")

</div>

I currently have setup Eland to pull data from Elasticsearch and I am trying to rename some of the columns. However, I realised that to use the .rename() function, I would have to convert the data to Pandas Dataframe as …

---

## [Is it possible to generate or export a csv from Kibana dev tool](https://discuss.elastic.co/t/is-it-possible-to-generate-or-export-a-csv-from-kibana-dev-tool/343027)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 2\
**Last updated:** [September 19, 2023, 8:38am UTC](https://discuss.elastic.co/t/is-it-possible-to-generate-or-export-a-csv-from-kibana-dev-tool/343027 "2023-09-19T08:38:11Z")

</div>

Hi, I wonder if it is possible to generate a CSV report from dev tool ? The following is my query run on Kibana dev tool, it composed of query and aggregation. I want to generate the query response to a csv. if it is …

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/343270)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 4\
**Last updated:** [September 19, 2023, 6:38am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/343270 "2023-09-19T06:38:25Z")

</div>

I got one host with elasticsearch and kibana, i don't want to use any ssl/tls. That's an error i got in logs now. How can i fix kibana ? It's web page shows me "Kibana server is not ready yet" journalctl -efu kibana.se…

---

## [Elastic-agent and Veeam man plugin](https://discuss.elastic.co/t/elastic-agent-and-veeam-man-plugin/343316)

<div class="topic-metadata">

**Author:** [@thiesens](https://discuss.elastic.co/u/thiesens)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 6:16am UTC](https://discuss.elastic.co/t/elastic-agent-and-veeam-man-plugin/343316 "2023-09-19T06:16:36Z")

</div>

Hi all.. I have a few Oracle servers, where I want to install elastic-agent. The problem for me is that I have Veeam RMAN plugin installed, and it seems that both are using port 6791. Is it possible to change the elas…

---

## [Query\_string does not perform consistently in versions 6 and 7](https://discuss.elastic.co/t/query-string-does-not-perform-consistently-in-versions-6-and-7/343228)

<div class="topic-metadata">

**Author:** [@casterQ](https://discuss.elastic.co/u/casterQ)\
**Replies:** 2\
**Last updated:** [September 19, 2023, 6:04am UTC](https://discuss.elastic.co/t/query-string-does-not-perform-consistently-in-versions-6-and-7/343228 "2023-09-19T06:04:55Z")

</div>

version: 6.7.0 and 7.17.6 mapping: { "t1": { "type": "text", "analyzer": "ik\_max\_word" }, "t2": { "type": "text", "analyzer": "ik\_max\_word" } } DSL: POST test1/\_search { "query": { "boo…

---

## [Logstash - How to Dynamic Parse Log's value](https://discuss.elastic.co/t/logstash-how-to-dynamic-parse-logs-value/343125)

<div class="topic-metadata">

**Author:** [@Huy\_Hoang\_Le](https://discuss.elastic.co/u/Huy_Hoang_Le)\
**Replies:** 8\
**Last updated:** [September 19, 2023, 3:36am UTC](https://discuss.elastic.co/t/logstash-how-to-dynamic-parse-logs-value/343125 "2023-09-19T03:36:25Z")

</div>

Hi I have this sample Document \[Thread-13\]\[2023-09-15 09:32:35\]\[INFO\]:{'\[Sub\]0-BaseTransformer\]': '0.0004', '\[Sub\]1-NGINX Feature Extractor Service\]': '0.0135', '\[Dataloader\]\[#0.-PutToQueue\]': '0.0005', '\[Sub\]\[#1.EMA\_FP…

---

## [Install Elasticsearch with Docker](https://discuss.elastic.co/t/install-elasticsearch-with-docker/342271)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 26\
**Last updated:** [September 19, 2023, 2:35am UTC](https://discuss.elastic.co/t/install-elasticsearch-with-docker/342271 "2023-09-19T02:35:52Z")

</div>

Hello World! I'm trying to follow https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html#docker-compose-file, I copy .env file, change password, then copy and paste docker-compose.yml and then the …

---

## [Filestream take\_over mode seems to be ignored](https://discuss.elastic.co/t/filestream-take-over-mode-seems-to-be-ignored/343220)

<div class="topic-metadata">

**Author:** [@gparks](https://discuss.elastic.co/u/gparks)\
**Replies:** 1\
**Last updated:** [September 19, 2023, 1:09am UTC](https://discuss.elastic.co/t/filestream-take-over-mode-seems-to-be-ignored/343220 "2023-09-19T01:09:06Z")

</div>

I'm running filebeat 8.8.2 on centos 7 I'm in the process of switching from log inputs to filestream inputs on pre-existing servers so I was trying to use the take\_over mode in order to not re-process the logs. I'm not…

---

## [Combine Elasticsearch/Enterprise Search Ingest Pipeline and Logstash Pipelines](https://discuss.elastic.co/t/combine-elasticsearch-enterprise-search-ingest-pipeline-and-logstash-pipelines/343280)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 10:22pm UTC](https://discuss.elastic.co/t/combine-elasticsearch-enterprise-search-ingest-pipeline-and-logstash-pipelines/343280 "2023-09-18T22:22:50Z")

</div>

Hi, does anybody know whether it is possible to call a Logstash pipeline from an Elasticsearch/Enterprise Search Ingest Pipeline ? Best regards Sebastian

---

## [Elastic Search on Rocky LInux 9](https://discuss.elastic.co/t/elastic-search-on-rocky-linux-9/343293)

<div class="topic-metadata">

**Author:** [@mcarifio](https://discuss.elastic.co/u/mcarifio)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 8:27pm UTC](https://discuss.elastic.co/t/elastic-search-on-rocky-linux-9/343293 "2023-09-18T20:27:06Z")

</div>

Does anyone have experience running Elastic Search on Rocky Linux 9? The Elastic Search support matrix indicates that RHEL 9 is a supported platform. What's the best way to add a Rocky Linux 9 column? Thanks.

---

## [Can create enrollment-token but no verification code verification code not found](https://discuss.elastic.co/t/can-create-enrollment-token-but-no-verification-code-verification-code-not-found/342952)

<div class="topic-metadata">

**Author:** [@uli67](https://discuss.elastic.co/u/uli67)\
**Replies:** 4\
**Last updated:** [September 18, 2023, 4:23pm UTC](https://discuss.elastic.co/t/can-create-enrollment-token-but-no-verification-code-verification-code-not-found/342952 "2023-09-18T16:23:25Z")

</div>

Hi guys, I am running easticsearch 8.9 as docker container and installed Kibana via dnf package manager. I am able to generate the enrollment code but not the verification code. verification code not found. my elasti…

---

## [Logstash vulnerabilities around ruby-maven-libs](https://discuss.elastic.co/t/logstash-vulnerabilities-around-ruby-maven-libs/343278)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 4:23pm UTC](https://discuss.elastic.co/t/logstash-vulnerabilities-around-ruby-maven-libs/343278 "2023-09-18T16:23:12Z")

</div>

my company is pushing me for fixing vulnerablities in logstash, at this point i am in learning mode. when i looking at the below vulnerablity, does this need ruby-maven-libs upgrade or just guava upgrade Required\_Versi…

---

## [Error installing gems (\> invalid source release: 11)](https://discuss.elastic.co/t/error-installing-gems-invalid-source-release-11/343201)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 3:31pm UTC](https://discuss.elastic.co/t/error-installing-gems-invalid-source-release-11/343201 "2023-09-18T15:31:23Z")

</div>

Task :downloadPreviousJRuby UP-TO-DATE Task :downloadJRuby UP-TO-DATE Download jruby-dist-9.3.10.0-bin.tar.gz Task :benchmark-cli:compileJava FAILED FAILURE: Build failed with an exception. What went wrong: …

---

## [Kibana Space unable to access Observability functions](https://discuss.elastic.co/t/kibana-space-unable-to-access-observability-functions/343275)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 3:06pm UTC](https://discuss.elastic.co/t/kibana-space-unable-to-access-observability-functions/343275 "2023-09-18T15:06:13Z")

</div>

Elasticsearch and Kibana 7.17 Support Team, I'm looking to provide access to some of our users via a Space we'll call "autos". All I need this space to do is provide access to two different indices, logs--auto- and lo…

---

## [How to create a custom availability dashboard](https://discuss.elastic.co/t/how-to-create-a-custom-availability-dashboard/342956)

<div class="topic-metadata">

**Author:** [@BenKenobi](https://discuss.elastic.co/u/BenKenobi)\
**Replies:** 7\
**Last updated:** [September 18, 2023, 2:58pm UTC](https://discuss.elastic.co/t/how-to-create-a-custom-availability-dashboard/342956 "2023-09-18T14:58:08Z")

</div>

Hi, how can I create a dashboard containing a similar visualization as in the screenshot below? I was asked to build a dashboard monitoring a service on Windows Server by showing the availability in percentage as seen i…

---

## [Ironbank Elastic Agent 8.9.0 Issues - tinit, group writeable components](https://discuss.elastic.co/t/ironbank-elastic-agent-8-9-0-issues-tinit-group-writeable-components/343274)

<div class="topic-metadata">

**Author:** [@Eric-Domeier](https://discuss.elastic.co/u/Eric-Domeier)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 2:28pm UTC](https://discuss.elastic.co/t/ironbank-elastic-agent-8-9-0-issues-tinit-group-writeable-components/343274 "2023-09-18T14:28:02Z")

</div>

Hello, Environment information Kubernetes RKE2 Cluster v1.27.3 (DISA STIG Hardened) Ironbank ECK-operator image 2.9.0 I managed to get the agents running and report a "Healthy" status however wanted to post here to m…

---

## [Ingest Github Audit logs with Logstash](https://discuss.elastic.co/t/ingest-github-audit-logs-with-logstash/343266)

<div class="topic-metadata">

**Author:** [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 1:57pm UTC](https://discuss.elastic.co/t/ingest-github-audit-logs-with-logstash/343266 "2023-09-18T13:57:45Z")

</div>

Has anyone created a successful grok pattern to ingest Github audit logs into ELK? Or does the Github plugin support formatting those logs into ELK?

---

## [Script processor not adding a new field using ingest pipeline](https://discuss.elastic.co/t/script-processor-not-adding-a-new-field-using-ingest-pipeline/343165)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 1:49pm UTC](https://discuss.elastic.co/t/script-processor-not-adding-a-new-field-using-ingest-pipeline/343165 "2023-09-18T13:49:17Z")

</div>

I am trying to compare values with already data already indexed with some user input values through script processor, script is running successfully but its not creating a new field which actually stores the result. …

---

## [Failed to retrieve shard stats from node \[cRf-MJ\_dTDGEeR-NRfKvAg\]](https://discuss.elastic.co/t/failed-to-retrieve-shard-stats-from-node-crf-mj-dtdgeer-nrfkvag/343269)

<div class="topic-metadata">

**Author:** [@Jobin\_James](https://discuss.elastic.co/u/Jobin_James)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 1:47pm UTC](https://discuss.elastic.co/t/failed-to-retrieve-shard-stats-from-node-crf-mj-dtdgeer-nrfkvag/343269 "2023-09-18T13:47:53Z")

</div>

Can someone help me with this? I have no idea how to fix this. ECK version 2.9 Elasicsearch version 8.9 { "@timestamp":"2023-09-18T13:43:13.838Z", "log.level":"WARN", "message":"failed to retrieve shard stats…

---

## [Elasticsearch alias issue with filtering](https://discuss.elastic.co/t/elasticsearch-alias-issue-with-filtering/343268)

<div class="topic-metadata">

**Author:** [@ricadao](https://discuss.elastic.co/u/ricadao)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 1:44pm UTC](https://discuss.elastic.co/t/elasticsearch-alias-issue-with-filtering/343268 "2023-09-18T13:44:47Z")

</div>

Hi. I have on Index fullData where I store documents from various sources, having one field as docSource. After that, created an alias over this fullData to have a view over source='phone' with the following code: POST …

---

## [Send logs Citrix to logstash/elasticsearch](https://discuss.elastic.co/t/send-logs-citrix-to-logstash-elasticsearch/343263)

<div class="topic-metadata">

**Author:** [@mulbzh](https://discuss.elastic.co/u/mulbzh)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 1:01pm UTC](https://discuss.elastic.co/t/send-logs-citrix-to-logstash-elasticsearch/343263 "2023-09-18T13:01:52Z")

</div>

Hello and sorry for my bad english :slight\_smile: , I am new in logstash/elasticsearch. I have a server installed by older technician. So, i understand globally how it works but i have one trouble. I send logs from my…

---

## [Delete Older csv reports from Kibana](https://discuss.elastic.co/t/delete-older-csv-reports-from-kibana/343219)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 12:53pm UTC](https://discuss.elastic.co/t/delete-older-csv-reports-from-kibana/343219 "2023-09-18T12:53:17Z")

</div>

I want to delete older csv files automatically from reporting section from Kibana. Kibana - 7.17.3 Attached screenshot. The problem is now we have so many older reports if i run any automated script or any query wi…

---

## [Query not working as expected](https://discuss.elastic.co/t/query-not-working-as-expected/343186)

<div class="topic-metadata">

**Author:** [@DWAIPAYAN\_SOM](https://discuss.elastic.co/u/DWAIPAYAN_SOM)\
**Replies:** 4\
**Last updated:** [September 18, 2023, 12:07pm UTC](https://discuss.elastic.co/t/query-not-working-as-expected/343186 "2023-09-18T12:07:48Z")

</div>

The below are my query for selection and rejection. Selection : { "nested": { "path": "somethingnew", "query": { "bool": { "must": \[ { …

---

## [Anomaly detection Population Job](https://discuss.elastic.co/t/anomaly-detection-population-job/342451)

<div class="topic-metadata">

**Author:** [@NamithaJ97](https://discuss.elastic.co/u/NamithaJ97)\
**Replies:** 6\
**Last updated:** [September 18, 2023, 12:07pm UTC](https://discuss.elastic.co/t/anomaly-detection-population-job/342451 "2023-09-18T12:07:39Z")

</div>

country state child\_count a a\_s1 302 a a\_s2 310 a a\_s3 308 a a\_s4 21 b b\_s1 14 b b\_s2 16 b b\_s3 17 b b\_s4 218 I have a population anomaly detecti…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=419)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=421)
