# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=424

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 425

---

## [What is the best way to detect inconsistency between elasticsearch with another authorized data store](https://discuss.elastic.co/t/what-is-the-best-way-to-detect-inconsistency-between-elasticsearch-with-another-authorized-data-store/343009)

<div class="topic-metadata">

**Author:** [@zouyang](https://discuss.elastic.co/u/zouyang)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 5:11am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-detect-inconsistency-between-elasticsearch-with-another-authorized-data-store/343009 "2023-09-14T05:11:37Z")

</div>

Hi, Our system uses dynamoDB as the data store and sync the data to elasticsearch with kafka. In case there are any data loss due to the failure of any part of the system, we would have inconsistency between dynamo and…

---

## [Kibana quits 1 second after launch](https://discuss.elastic.co/t/kibana-quits-1-second-after-launch/342997)

<div class="topic-metadata">

**Author:** [@ljk602308](https://discuss.elastic.co/u/ljk602308)\
**Replies:** 1\
**Last updated:** [September 14, 2023, 3:31am UTC](https://discuss.elastic.co/t/kibana-quits-1-second-after-launch/342997 "2023-09-14T03:31:29Z")

</div>

It was running a week ago, but when I ran it this time, Kibana did not run. The issue of the console window closing as soon as you run kibana.bat still occurs even if you reinstall Kibana. I'm using Windows 10, and Ela…

---

## [Discuss configuration connectors about mail exchange](https://discuss.elastic.co/t/discuss-configuration-connectors-about-mail-exchange/343000)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 2\
**Last updated:** [September 14, 2023, 2:38am UTC](https://discuss.elastic.co/t/discuss-configuration-connectors-about-mail-exchange/343000 "2023-09-14T02:38:43Z")

</div>

Hi everyone! I getting issue when after completed configure connector mail exchange with Client ID and Tenant ID . So I have tried test send but it still shows error And this is a text configure connect mail exch…

---

## [Why is my latest rollover index collecting the data from beginning to last?](https://discuss.elastic.co/t/why-is-my-latest-rollover-index-collecting-the-data-from-beginning-to-last/342893)

<div class="topic-metadata">

**Author:** [@Geeboy](https://discuss.elastic.co/u/Geeboy)\
**Replies:** 6\
**Last updated:** [September 14, 2023, 1:12am UTC](https://discuss.elastic.co/t/why-is-my-latest-rollover-index-collecting-the-data-from-beginning-to-last/342893 "2023-09-14T01:12:22Z")

</div>

good day, I'm experiencing this scenario, the rollover index is collecting data from the beginning to the newest/last data of the logs, as I know only the newest log should be written to the latest rollover index and the…

---

## [How to resolve "Infinite extent for field" if the field is not in all ingested documents?](https://discuss.elastic.co/t/how-to-resolve-infinite-extent-for-field-if-the-field-is-not-in-all-ingested-documents/342996)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 12:15am UTC](https://discuss.elastic.co/t/how-to-resolve-infinite-extent-for-field-if-the-field-is-not-in-all-ingested-documents/342996 "2023-09-14T00:15:13Z")

</div>

I have a field named runtime, however, it does not present in all ingested document within the index pattern. Is there a way to filter out the document that does not contains the runtime field for Vega to work? { $sch…

---

## [Migration of ELK users](https://discuss.elastic.co/t/migration-of-elk-users/342647)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 3\
**Last updated:** [September 13, 2023, 8:59pm UTC](https://discuss.elastic.co/t/migration-of-elk-users/342647 "2023-09-13T20:59:59Z")

</div>

Hello, Is there a secure way to migrate kibana users from one instance to another along with their passwords? Thanks

---

## [Logstash file plugin on windows](https://discuss.elastic.co/t/logstash-file-plugin-on-windows/342852)

<div class="topic-metadata">

**Author:** [@mahmoud.shsuite](https://discuss.elastic.co/u/mahmoud.shsuite)\
**Replies:** 7\
**Last updated:** [September 13, 2023, 8:03pm UTC](https://discuss.elastic.co/t/logstash-file-plugin-on-windows/342852 "2023-09-13T20:03:41Z")

</div>

I've just installed logstach version 8.9.2 on windows and tried to do first file sample but I am greeting message=\>"Unable to configure plugins: (PluginLoadingError) Couldn't find any input plugin named 'file' I insured…

---

## [REST API Crowdstrike FDR Dashboard Error](https://discuss.elastic.co/t/rest-api-crowdstrike-fdr-dashboard-error/342966)

<div class="topic-metadata">

**Author:** [@sgrubb](https://discuss.elastic.co/u/sgrubb)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 7:57pm UTC](https://discuss.elastic.co/t/rest-api-crowdstrike-fdr-dashboard-error/342966 "2023-09-13T19:57:43Z")

</div>

Good morning, I recently integrated the Crowdstrike FDR stream into my Elastic instance. The integration includes a premade dashboard called \[Crowdstrike\] FDR Overview. When I load the dashboard up, the data is populate…

---

## [Monitor cluster with elastic agent](https://discuss.elastic.co/t/monitor-cluster-with-elastic-agent/342413)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 16\
**Last updated:** [September 13, 2023, 6:39pm UTC](https://discuss.elastic.co/t/monitor-cluster-with-elastic-agent/342413 "2023-09-13T18:39:17Z")

</div>

Hey Everyone, We're trying to move from the legacy exporters over to Elastic Agent. Our data pipeline is Elastic Agent \> Logstash \> Kafka \> Elastic. I have a couple of questions and would appreciate any and all knowledg…

---

## [Fleet Server shutdown after enroll](https://discuss.elastic.co/t/fleet-server-shutdown-after-enroll/342791)

<div class="topic-metadata">

**Author:** [@bixiyan](https://discuss.elastic.co/u/bixiyan)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 8:47am UTC](https://discuss.elastic.co/t/fleet-server-shutdown-after-enroll/342791 "2023-09-12T08:47:39Z")

</div>

Hi Team: I want to set up fleet server but failed after executed enroll command. My es version is v 7.16.3 . Let me know any more infomation you needed. Here is my fleet enroll command. elastic-agent enroll --url=htt…

---

## [Logstash crashing](https://discuss.elastic.co/t/logstash-crashing/342972)

<div class="topic-metadata">

**Author:** [@sc5283](https://discuss.elastic.co/u/sc5283)\
**Replies:** 4\
**Last updated:** [September 13, 2023, 5:49pm UTC](https://discuss.elastic.co/t/logstash-crashing/342972 "2023-09-13T17:49:37Z")

</div>

Input is from S3 layout of S3 bucket is : s3 { .... bucket =\> "bucket" prefix =\> "YYYY/MM/DD/hh/" ..... } so every hour I have to create a new conf file with the corresponding prefix…

---

## [How are you supposed to use downsampled TSDS data?](https://discuss.elastic.co/t/how-are-you-supposed-to-use-downsampled-tsds-data/342643)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 5:39pm UTC](https://discuss.elastic.co/t/how-are-you-supposed-to-use-downsampled-tsds-data/342643 "2023-09-13T17:39:43Z")

</div>

Hey all, yet another topic here related to my efforts at reducing ELK's footprint. This time I'm trying to figure out downsampling. I've successfully configured my dev environment to downsample data. I have downsample\* …

---

## [Error toasts rendering in canvas pdfs](https://discuss.elastic.co/t/error-toasts-rendering-in-canvas-pdfs/342742)

<div class="topic-metadata">

**Author:** [@Krikkits](https://discuss.elastic.co/u/Krikkits)\
**Replies:** 6\
**Last updated:** [September 13, 2023, 5:12pm UTC](https://discuss.elastic.co/t/error-toasts-rendering-in-canvas-pdfs/342742 "2023-09-13T17:12:25Z")

</div>

I saw that there was a github issue raised about it (Kibana should stop rendering security warning on PDFs on unsecured cluster · Issue #82891 · elastic/kibana · GitHub) but I was wondering if there has been a fix or wor…

---

## [Certificate signature failure](https://discuss.elastic.co/t/certificate-signature-failure/342981)

<div class="topic-metadata">

**Author:** [@solo1](https://discuss.elastic.co/u/solo1)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 5:11pm UTC](https://discuss.elastic.co/t/certificate-signature-failure/342981 "2023-09-13T17:11:10Z")

</div>

I tried to follow this (elastic security-basic-setup-https) to configure my elasticsearch and kibana. While the elasticsearch works fine and clients is able to connect successfully with username,password and ca cert(sign…

---

## [Top n over Max() aggregation with group by and then return all fields](https://discuss.elastic.co/t/top-n-over-max-aggregation-with-group-by-and-then-return-all-fields/342954)

<div class="topic-metadata">

**Author:** [@aakashagrawal](https://discuss.elastic.co/u/aakashagrawal)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 4:24pm UTC](https://discuss.elastic.co/t/top-n-over-max-aggregation-with-group-by-and-then-return-all-fields/342954 "2023-09-13T16:24:56Z")

</div>

Hi, I'm a total newbie to Elasticsearch and hence please ignore if you think my question is very basic. I've already looked at this post which solves one part of my problem: What I want is only top n (say top 2) resu…

---

## [Elastic agent indices - ILM](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243)

<div class="topic-metadata">

**Author:** [@Tyty](https://discuss.elastic.co/u/Tyty)\
**Replies:** 5\
**Last updated:** [September 13, 2023, 3:30pm UTC](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243 "2023-09-13T15:30:02Z")

</div>

Hi All, Currently using ELK stack 8.91. Fleet enable. Elasticc-agent deployed on around 100 Servers/vm. I notice that indexes will never be cleared. Seems to be a default behavior. I need to know how to setup an Inde…

---

## [A query builder java library for parsing web query into an elastic client Query object](https://discuss.elastic.co/t/a-query-builder-java-library-for-parsing-web-query-into-an-elastic-client-query-object/342958)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 3:28pm UTC](https://discuss.elastic.co/t/a-query-builder-java-library-for-parsing-web-query-into-an-elastic-client-query-object/342958 "2023-09-13T15:28:32Z")

</div>

I am building an elastic client Java application that users will enter a search query from the browser. I am looking for an open source Java library that can take the user inputs and parse them into an elasticsearch clie…

---

## [How to delete the records older than certain time using elastic java rest client](https://discuss.elastic.co/t/how-to-delete-the-records-older-than-certain-time-using-elastic-java-rest-client/342960)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 3:27pm UTC](https://discuss.elastic.co/t/how-to-delete-the-records-older-than-certain-time-using-elastic-java-rest-client/342960 "2023-09-13T15:27:18Z")

</div>

Hi, I am looking to delete all the records older than 1 month or so(in bulk). How to get this done using java restclient.

---

## [Global Filter Overrides the Hard coded Date Range](https://discuss.elastic.co/t/global-filter-overrides-the-hard-coded-date-range/342090)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 10\
**Last updated:** [September 13, 2023, 2:38pm UTC](https://discuss.elastic.co/t/global-filter-overrides-the-hard-coded-date-range/342090 "2023-09-13T14:38:08Z")

</div>

Hello everyone, I've been working on a Kibana dashboard to track item expirations over time. I created a Visualization table that displays the Date Range, Item Name, Item Location, Item Expiry Date, and Quantity. Specif…

---

## [How to aggregate conditionally logs](https://discuss.elastic.co/t/how-to-aggregate-conditionally-logs/342945)

<div class="topic-metadata">

**Author:** [@Marieta](https://discuss.elastic.co/u/Marieta)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 2:30pm UTC](https://discuss.elastic.co/t/how-to-aggregate-conditionally-logs/342945 "2023-09-13T14:30:07Z")

</div>

Hi I am trying to aggregate the following logs: 2023-09-06 07:36:22,573 | INFO | Thread-934 | Config | ENTERORDER: identifier = 'Barbie', buy = false, quantity = 290000.0, price = 96.1, account = '123', reference = '',…

---

## [Please help kibana show server not ready yet](https://discuss.elastic.co/t/please-help-kibana-show-server-not-ready-yet/342943)

<div class="topic-metadata">

**Author:** [@Mbrezzy](https://discuss.elastic.co/u/Mbrezzy)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 1:07pm UTC](https://discuss.elastic.co/t/please-help-kibana-show-server-not-ready-yet/342943 "2023-09-13T13:07:48Z")

</div>

I have active the trial version of security but when its ended i face this problem and kibana show me server is not ready yet

---

## [Want to figure that how the mapping of an index gets changed on one env](https://discuss.elastic.co/t/want-to-figure-that-how-the-mapping-of-an-index-gets-changed-on-one-env/342934)

<div class="topic-metadata">

**Author:** [@Mansi\_Ghule](https://discuss.elastic.co/u/Mansi_Ghule)\
**Replies:** 7\
**Last updated:** [September 13, 2023, 12:53pm UTC](https://discuss.elastic.co/t/want-to-figure-that-how-the-mapping-of-an-index-gets-changed-on-one-env/342934 "2023-09-13T12:53:29Z")

</div>

Hello, I want to figure out that is there any chances that the mapping of the index may change. As the ES queries n all was running fine on one env but sudden I'm getting error while searching. And I checked that and …

---

## [Substitute GROK by dissect: test of writing](https://discuss.elastic.co/t/substitute-grok-by-dissect-test-of-writing/342930)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 12:07pm UTC](https://discuss.elastic.co/t/substitute-grok-by-dissect-test-of-writing/342930 "2023-09-13T12:07:54Z")

</div>

hello, I want to substitute a grok filter by a dissect In a few words, i want replace this grok filter grok { match =\> { "\[raw\_syslog\_result\]\[syslog\_message\]" =\> \[ "THREAT,%{WORD:threat\_type},%{DATA:generate\_time},%…

---

## [How to ingest Squid proxy logs into elasticsearch and visualize on kibana?](https://discuss.elastic.co/t/how-to-ingest-squid-proxy-logs-into-elasticsearch-and-visualize-on-kibana/342906)

<div class="topic-metadata">

**Author:** [@irshadalam](https://discuss.elastic.co/u/irshadalam)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 11:49am UTC](https://discuss.elastic.co/t/how-to-ingest-squid-proxy-logs-into-elasticsearch-and-visualize-on-kibana/342906 "2023-09-13T11:49:07Z")

</div>

How to craete ingest-pipeline Squid proxy logs into elasticsearch and visualize on kibana ?

---

## [Elastic Security Issues](https://discuss.elastic.co/t/elastic-security-issues/342900)

<div class="topic-metadata">

**Author:** [@Phyo\_WaThone\_Win](https://discuss.elastic.co/u/Phyo_WaThone_Win)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 11:18am UTC](https://discuss.elastic.co/t/elastic-security-issues/342900 "2023-09-13T11:18:03Z")

</div>

Hello, Firslty, sorry for my english. In my elastic panel, I see this error In your Elasticsearch configuration (elasticsearch.yml), enable: Elasticsearch security(opens in a new tab or window). Set xpack.security.ena…

---

## [Elasticsearch cluster status is yellow](https://discuss.elastic.co/t/elasticsearch-cluster-status-is-yellow/342911)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 4\
**Last updated:** [September 13, 2023, 10:44am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-status-is-yellow/342911 "2023-09-13T10:44:20Z")

</div>

Hi, I have created elasticsearch,kibana and apm in a single node and all is working properly ,kibana and apm is healthy but elasticsearch status is yellow.I also want to say elasticsearch status was green before,but afte…

---

## [Use fleet-server integration without authority certificates](https://discuss.elastic.co/t/use-fleet-server-integration-without-authority-certificates/342933)

<div class="topic-metadata">

**Author:** [@Guillaume\_Cotral](https://discuss.elastic.co/u/Guillaume_Cotral)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 10:10am UTC](https://discuss.elastic.co/t/use-fleet-server-integration-without-authority-certificates/342933 "2023-09-13T10:10:24Z")

</div>

Hello everybody, I set up an ELK server running Docker with Elasticsearch and Kibana within my company as a test. I would like to know if it is possible to delete the authentication certificates so that the integrations…

---

## [Elastic search queue choking](https://discuss.elastic.co/t/elastic-search-queue-choking/342904)

<div class="topic-metadata">

**Author:** [@cosmos\_roeba](https://discuss.elastic.co/u/cosmos_roeba)\
**Replies:** 5\
**Last updated:** [September 13, 2023, 9:52am UTC](https://discuss.elastic.co/t/elastic-search-queue-choking/342904 "2023-09-13T09:52:59Z")

</div>

I am running a 2 node cluster with 2 core cpus. I have 2 indices with about 1 million docs each. They are flat documents and I need to enable search on title key stored both as text and keyword. Search text is minimum 3…

---

## [I cannot search the file name from path in Elasticsearch](https://discuss.elastic.co/t/i-cannot-search-the-file-name-from-path-in-elasticsearch/342812)

<div class="topic-metadata">

**Author:** [@Enes\_Can\_ISIK](https://discuss.elastic.co/u/Enes_Can_ISIK)\
**Replies:** 3\
**Last updated:** [September 13, 2023, 9:48am UTC](https://discuss.elastic.co/t/i-cannot-search-the-file-name-from-path-in-elasticsearch/342812 "2023-09-13T09:48:05Z")

</div>

I want to search filename from a path in Elasticsearch, but I cannot do it. I have documents consisting of "name" fields with paths. Example: Name "folder/folder1/test/folder2/folder/" "folder/folder1/test/folder2/f…

---

## [Doubt about cacerts file of Elasticsearch](https://discuss.elastic.co/t/doubt-about-cacerts-file-of-elasticsearch/342925)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 9:18am UTC](https://discuss.elastic.co/t/doubt-about-cacerts-file-of-elasticsearch/342925 "2023-09-13T09:18:34Z")

</div>

Hi, everyone I would like to know the purpose of cacerts file of Elasticsearch (/usr/share/elasticsearch/jdk/lib/security/cacerts). It has some certificates into, are they important? they could be removed? Thanks in a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=423)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=425)
