# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=426

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 427

---

## [Elasticsearch using bundled JDK instead of the one at JAVA\_HOME](https://discuss.elastic.co/t/elasticsearch-using-bundled-jdk-instead-of-the-one-at-java-home/342797)

<div class="topic-metadata">

**Author:** [@martha889](https://discuss.elastic.co/u/martha889)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 1:06pm UTC](https://discuss.elastic.co/t/elasticsearch-using-bundled-jdk-instead-of-the-one-at-java-home/342797 "2023-09-12T13:06:30Z")

</div>

Seeing this error while trying to run elasticsearch on redhat docker container. Any idea why elasticserach is not using the JDK present in JAVA\_HOME or how to fix this error? root@5196a84b088b:/var/lib/avi/logs# JAVA\_HO…

---

## [Input jdbc error handling](https://discuss.elastic.co/t/input-jdbc-error-handling/342836)

<div class="topic-metadata">

**Author:** [@inbeom\_cho](https://discuss.elastic.co/u/inbeom_cho)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 1:03pm UTC](https://discuss.elastic.co/t/input-jdbc-error-handling/342836 "2023-09-12T13:03:16Z")

</div>

hi all this is my input jdbc input { jdbc { jdbc\_driver\_library =\> "/usr/share/java/postgresql.jar" jdbc\_driver\_class =\> "org.postgresql.Driver" jdbc\_connection\_string =\> "jdbc:postgresql://\*.\*.\*.\*/databa…

---

## [Stack monitoring not visible in Kibana UI 8.8.2 version](https://discuss.elastic.co/t/stack-monitoring-not-visible-in-kibana-ui-8-8-2-version/342831)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 12:31pm UTC](https://discuss.elastic.co/t/stack-monitoring-not-visible-in-kibana-ui-8-8-2-version/342831 "2023-09-12T12:31:55Z")

</div>

Hello All, I am using Enterprise license of kibana and migrated from 7.9.1 to 8.8.2 version. Earlier it used to show STACK MONITORING OPTION in kibana now its not showing in 8.8.2 version. How to enable? , I tried belo…

---

## [After upgrading logstash to version 8.9.1, it disconnects from the DB2 database after a few days](https://discuss.elastic.co/t/after-upgrading-logstash-to-version-8-9-1-it-disconnects-from-the-db2-database-after-a-few-days/342830)

<div class="topic-metadata">

**Author:** [@Lukas\_Hrcka](https://discuss.elastic.co/u/Lukas_Hrcka)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 12:20pm UTC](https://discuss.elastic.co/t/after-upgrading-logstash-to-version-8-9-1-it-disconnects-from-the-db2-database-after-a-few-days/342830 "2023-09-12T12:20:33Z")

</div>

Hello, after upgrading logstash to version 8.9.1 from 7.17.x, I have problems with the automatic loss of connection to the DB2 database (DB2 ver. 11.5 Mod 7). The previous version of ELK 7.17.x had no problem, the conne…

---

## [The metric beat index size is incrasing rapidly.can we remove some of the fields present in the index](https://discuss.elastic.co/t/the-metric-beat-index-size-is-incrasing-rapidly-can-we-remove-some-of-the-fields-present-in-the-index/342804)

<div class="topic-metadata">

**Author:** [@Ambikaguntu](https://discuss.elastic.co/u/Ambikaguntu)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 12:10pm UTC](https://discuss.elastic.co/t/the-metric-beat-index-size-is-incrasing-rapidly-can-we-remove-some-of-the-fields-present-in-the-index/342804 "2023-09-12T12:10:42Z")

</div>

My metricbeat default field brings in too much unnecessary data. Can i remove the fields in the index what I need. I have removed the Metricbeat processor to drop fields in the metricbeat configuaration .Still there are…

---

## [Comparison of data at a kibana dashboard](https://discuss.elastic.co/t/comparison-of-data-at-a-kibana-dashboard/342805)

<div class="topic-metadata">

**Author:** [@Voula\_Mikr](https://discuss.elastic.co/u/Voula_Mikr)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 12:09pm UTC](https://discuss.elastic.co/t/comparison-of-data-at-a-kibana-dashboard/342805 "2023-09-12T12:09:37Z")

</div>

Hi , I have the below kind of data counter1: { "name":"name1", "vnf\_type":"ZTS", "counter":"cpu", "value":"10", "event\_time\_stamp":"2021-02-15T02:44:19Z" } I would like to compare the value "value" of t…

---

## [Kibana Stack Monitoring: Elasticsearch node status offline](https://discuss.elastic.co/t/kibana-stack-monitoring-elasticsearch-node-status-offline/342779)

<div class="topic-metadata">

**Author:** [@phu\_phat](https://discuss.elastic.co/u/phu_phat)\
**Replies:** 3\
**Last updated:** [September 12, 2023, 12:08pm UTC](https://discuss.elastic.co/t/kibana-stack-monitoring-elasticsearch-node-status-offline/342779 "2023-09-12T12:08:47Z")

</div>

After upgrade ELK Stack (ES, Kibana, Metricbeat, Logstash) from 7.17 to 8.9.2 all node in cluster status offline without elasticsearch in same kibana node In index management Before upgrade to 8.9.2 Data insert to .mo…

---

## [Rolling restart triggers primary-replica resync leading to write unavailability](https://discuss.elastic.co/t/rolling-restart-triggers-primary-replica-resync-leading-to-write-unavailability/339301)

<div class="topic-metadata">

**Author:** [@devoxel](https://discuss.elastic.co/u/devoxel)\
**Replies:** 10\
**Last updated:** [September 12, 2023, 10:54am UTC](https://discuss.elastic.co/t/rolling-restart-triggers-primary-replica-resync-leading-to-write-unavailability/339301 "2023-09-12T10:54:13Z")

</div>

When a node is shutdown during a normal rolling restart, we end up in a loss of write availability for a period of 10 mins. We're using ECK operator to manage the cluster. It's 7.17 and the operator is the latest versio…

---

## [Kibana maintenance window question](https://discuss.elastic.co/t/kibana-maintenance-window-question/342786)

<div class="topic-metadata">

**Author:** [@mkf1](https://discuss.elastic.co/u/mkf1)\
**Replies:** 3\
**Last updated:** [September 12, 2023, 10:37am UTC](https://discuss.elastic.co/t/kibana-maintenance-window-question/342786 "2023-09-12T10:37:34Z")

</div>

Hi, I couldn't see much in the documentation so I though I would ask my question here. It might be a dumb question, but in the Maintenance Window settings, I'm a bit confused on the timezone setting. For example if I s…

---

## [Use new dataview in an existing dashboard](https://discuss.elastic.co/t/use-new-dataview-in-an-existing-dashboard/342656)

<div class="topic-metadata">

**Author:** [@javierelastic](https://discuss.elastic.co/u/javierelastic)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 9:38am UTC](https://discuss.elastic.co/t/use-new-dataview-in-an-existing-dashboard/342656 "2023-09-12T09:38:25Z")

</div>

Hi. I have a dashboard created with a set of data that I passed through logstash to elasticsearch. But now I have created a new index and a new dataview with similar data. And I want to use the complete dashboard with t…

---

## [Failed to fetch https://artifacts.elastic.co/packages/7.x/apt/dists/stable/InRelease 403 Forbidden \[IP: 2600:1901:0:1d7:: 443\]](https://discuss.elastic.co/t/failed-to-fetch-https-artifacts-elastic-co-packages-7-x-apt-dists-stable-inrelease-403-forbidden-ip-26000-443/341442)

<div class="topic-metadata">

**Author:** [@Andi0r](https://discuss.elastic.co/u/Andi0r)\
**Replies:** 8\
**Last updated:** [September 12, 2023, 9:35am UTC](https://discuss.elastic.co/t/failed-to-fetch-https-artifacts-elastic-co-packages-7-x-apt-dists-stable-inrelease-403-forbidden-ip-26000-443/341442 "2023-09-12T09:35:06Z")

</div>

Hi, i am trying to install Elastic Search but i am getting the error: Failed to fetch https://artifacts.elastic.co/packages/7.x/apt/dists/stable/InRelease 403 Forbidden \[IP: 2600:1901:0:1d7:: 443\] Could it be that y…

---

## [Is it possible to get only the types of fields I want from metricbeat?](https://discuss.elastic.co/t/is-it-possible-to-get-only-the-types-of-fields-i-want-from-metricbeat/342770)

<div class="topic-metadata">

**Author:** [@20wjsdudtj](https://discuss.elastic.co/u/20wjsdudtj)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 9:12am UTC](https://discuss.elastic.co/t/is-it-possible-to-get-only-the-types-of-fields-i-want-from-metricbeat/342770 "2023-09-12T09:12:43Z")

</div>

My metricbeat default field brings in too much unnecessary data. (For example, kubernetes. Kubernetes-related data such as pod.name, uid, namespace.., etc. There are only a few data I need. Can I specify and import this?…

---

## [Is Is watcher is free in elastic search? if paid than what is the cost?](https://discuss.elastic.co/t/is-is-watcher-is-free-in-elastic-search-if-paid-than-what-is-the-cost/342785)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 9:05am UTC](https://discuss.elastic.co/t/is-is-watcher-is-free-in-elastic-search-if-paid-than-what-is-the-cost/342785 "2023-09-12T09:05:03Z")

</div>

Is watcher is free in Elasticsearch? if paid than what is the cost?

---

## [I need to use search\_after sort by \_score and \_id in a rescore query](https://discuss.elastic.co/t/i-need-to-use-search-after-sort-by-score-and-id-in-a-rescore-query/342789)

<div class="topic-metadata">

**Author:** [@George\_Githinji](https://discuss.elastic.co/u/George_Githinji)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 8:20am UTC](https://discuss.elastic.co/t/i-need-to-use-search-after-sort-by-score-and-id-in-a-rescore-query/342789 "2023-09-12T08:20:03Z")

</div>

I want to implement the search\_after pagination technique, I want to sort out the data using \_score and \_id. The problem I am facing is that I have built my query using rescore and you can't use the sort and rescore at t…

---

## [Error pipeline/output.go:180 failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/error-pipeline-output-go-180-failed-to-publish-events-temporary-bulk-send-failure/342788)

<div class="topic-metadata">

**Author:** [@Sevde\_Nur\_Canli](https://discuss.elastic.co/u/Sevde_Nur_Canli)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 8:09am UTC](https://discuss.elastic.co/t/error-pipeline-output-go-180-failed-to-publish-events-temporary-bulk-send-failure/342788 "2023-09-12T08:09:56Z")

</div>

Hello I recently got the following error, pipeline/output.go:180 failed to publish events: temporary bulk send failure I tried everything to solve this problem and look every info in the internet but no solution still. …

---

## [Generating term vectors on the fly](https://discuss.elastic.co/t/generating-term-vectors-on-the-fly/342784)

<div class="topic-metadata">

**Author:** [@d\_u](https://discuss.elastic.co/u/d_u)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 6:47am UTC](https://discuss.elastic.co/t/generating-term-vectors-on-the-fly/342784 "2023-09-12T06:47:54Z")

</div>

Suppose, I have more than 1mil documents where I have a text field lets say "Contents". We have not enabled termvector for the index. Now when we want to find count of occurrence of a word lets say "data" in "Contents" …

---

## [Kibana data view containing runtime composite fields](https://discuss.elastic.co/t/kibana-data-view-containing-runtime-composite-fields/341586)

<div class="topic-metadata">

**Author:** [@i.raisr](https://discuss.elastic.co/u/i.raisr)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 6:23am UTC](https://discuss.elastic.co/t/kibana-data-view-containing-runtime-composite-fields/341586 "2023-09-12T06:23:13Z")

</div>

Kibana data views. Cool stuff and thank you for them! For some stupid reason I cannot figure out how to use "composite" fields in the runtime mapping. Consider the following simple example: { "data\_view": { "id"…

---

## [How to get metrics on telegraf endpoint](https://discuss.elastic.co/t/how-to-get-metrics-on-telegraf-endpoint/341092)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 6:04am UTC](https://discuss.elastic.co/t/how-to-get-metrics-on-telegraf-endpoint/341092 "2023-09-12T06:04:22Z")

</div>

Hi, I'm trying to use metricbeat to read from a server that has exposed host:9050/metrics, in one of the metrics looks like \[...\] # HELP mongodb\_active\_reads Telegraf collected metric # TYPE mongodb\_active\_reads untype…

---

## [Change text mapping from text to integer](https://discuss.elastic.co/t/change-text-mapping-from-text-to-integer/342484)

<div class="topic-metadata">

**Author:** [@Geeboy](https://discuss.elastic.co/u/Geeboy)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 3:21am UTC](https://discuss.elastic.co/t/change-text-mapping-from-text-to-integer/342484 "2023-09-12T03:21:08Z")

</div>

Good day! Im creating new index, when I add this to "data views", it was tagged as TEXT type. I need it to be integer. do you have step by step guide for this case? my temporary solution is this command -\> emit (Intege…

---

## [File /run/elastic-agent.sock no such file and directory when i finished installing the agent on linux](https://discuss.elastic.co/t/file-run-elastic-agent-sock-no-such-file-and-directory-when-i-finished-installing-the-agent-on-linux/342775)

<div class="topic-metadata">

**Author:** [@Yanuar\_Ahmad\_Adhari](https://discuss.elastic.co/u/Yanuar_Ahmad_Adhari)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 3:15am UTC](https://discuss.elastic.co/t/file-run-elastic-agent-sock-no-such-file-and-directory-when-i-finished-installing-the-agent-on-linux/342775 "2023-09-12T03:15:48Z")

</div>

Error: failed to communicate with Elastic Agent daemon: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial unix /run/elastic-agent.sock: connect: no such file or directory"…

---

## [Grok patterns for nginx](https://discuss.elastic.co/t/grok-patterns-for-nginx/342692)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 3:24am UTC](https://discuss.elastic.co/t/grok-patterns-for-nginx/342692 "2023-09-11T03:24:40Z")

</div>

Today I have text log format about nginx\_access {"timestamp": "2023-09-07T03:03:33+00:00", "remote\_addr": "10.0.x.x", "remote\_user": "-", "request\_time": "0.002 s", "status\_request": "200", "request\_Size": "510", "requ…

---

## [GET api by doc\_id returns different result whenever i try](https://discuss.elastic.co/t/get-api-by-doc-id-returns-different-result-whenever-i-try/342293)

<div class="topic-metadata">

**Author:** [@ycice](https://discuss.elastic.co/u/ycice)\
**Replies:** 7\
**Last updated:** [September 12, 2023, 1:53am UTC](https://discuss.elastic.co/t/get-api-by-doc-id-returns-different-result-whenever-i-try/342293 "2023-09-12T01:53:49Z")

</div>

Hi, i manage more than 100 ES clusters in my company for 3 years But at last week, I faced very strange issue. I think it is not possible... Could you carefully check this? ES version : 6.8.2 Cluster health : Green G…

---

## [Alerting on Run Failures](https://discuss.elastic.co/t/alerting-on-run-failures/342623)

<div class="topic-metadata">

**Author:** [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 11:46pm UTC](https://discuss.elastic.co/t/alerting-on-run-failures/342623 "2023-09-11T23:46:06Z")

</div>

We have a scheduled app that performs a nightly processing job across several different target "markets". I'm trying to figure out how to fire off an alert when a market fails to run. So, let's say I typically see the …

---

## [Custom URL not directing to correct ML job in Anomaly Explorer from email alert](https://discuss.elastic.co/t/custom-url-not-directing-to-correct-ml-job-in-anomaly-explorer-from-email-alert/342763)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 11:32pm UTC](https://discuss.elastic.co/t/custom-url-not-directing-to-correct-ml-job-in-anomaly-explorer-from-email-alert/342763 "2023-09-11T23:32:58Z")

</div>

Hello, I generated a few rules to alert on a severity threshold for different Anomaly Detection jobs. Whenever I click the url to open the job in anomaly explorer, it takes me to the same unrelated ML job. I'm using ({{…

---

## [How to build docker image from local clone copy of source](https://discuss.elastic.co/t/how-to-build-docker-image-from-local-clone-copy-of-source/342767)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 0\
**Last updated:** [September 11, 2023, 9:57pm UTC](https://discuss.elastic.co/t/how-to-build-docker-image-from-local-clone-copy-of-source/342767 "2023-09-11T21:57:27Z")

</div>

i have an enlistment of logstash, would like to build a docker image, what is my command for this

---

## [How to build docker images for logstash, kibana, elastic](https://discuss.elastic.co/t/how-to-build-docker-images-for-logstash-kibana-elastic/342754)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 3\
**Last updated:** [September 11, 2023, 9:00pm UTC](https://discuss.elastic.co/t/how-to-build-docker-images-for-logstash-kibana-elastic/342754 "2023-09-11T21:00:51Z")

</div>

i am trying to learn elastic, kibana, logstash. i have cloned source copies. what are the steps to build docker images, can someone point me to link/video which helps me in installing dependencies and build docker image

---

## [No logs from /var/containers/\* in kubernetes integration](https://discuss.elastic.co/t/no-logs-from-var-containers-in-kubernetes-integration/342671)

<div class="topic-metadata">

**Author:** [@georgi.hristov](https://discuss.elastic.co/u/georgi.hristov)\
**Replies:** 0\
**Last updated:** [September 10, 2023, 7:34am UTC](https://discuss.elastic.co/t/no-logs-from-var-containers-in-kubernetes-integration/342671 "2023-09-10T07:34:30Z")

</div>

Hello guys, I have been trying to setup ECK lately as a monitoring solution for our local K8s cluster. I have used the examples provided in the official documentation for Fleet-managed Elastic Agent on ECK with system …

---

## [Kind:Elasticsearch Kind:Kibana not creating any nodes in K8s why?](https://discuss.elastic.co/t/kind-elasticsearch-kind-kibana-not-creating-any-nodes-in-k8s-why/342758)

<div class="topic-metadata">

**Author:** [@Esakki](https://discuss.elastic.co/u/Esakki)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 5:32pm UTC](https://discuss.elastic.co/t/kind-elasticsearch-kind-kibana-not-creating-any-nodes-in-k8s-why/342758 "2023-09-11T17:32:12Z")

</div>

Hi All, I had elasticsearch and kibana deployed in my on-prem K8s cluster, due to some config issue I deleted both deployments (I deployed, deployments, svc, and secrets) in my cluster and trying to re-deploy but it's n…

---

## [Netflow gigamon - Flowset id error](https://discuss.elastic.co/t/netflow-gigamon-flowset-id-error/342747)

<div class="topic-metadata">

**Author:** [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Replies:** 0\
**Last updated:** [September 11, 2023, 2:40pm UTC](https://discuss.elastic.co/t/netflow-gigamon-flowset-id-error/342747 "2023-09-11T14:40:42Z")

</div>

Hi everybody. I still have a problem about neflow gigamon. I used netflow codec for parsing logs received from gigamon however I continuous received flowset error. My logstash is 8.4.3 version. Netflow codec versio…

---

## [Failed to authenticate user 'elastic' against https://192.168.xx.xx:9200/\_security/\_authenticate?pretty](https://discuss.elastic.co/t/failed-to-authenticate-user-elastic-against-https-192-168-xx-xx-9200-security-authenticate-pretty/342654)

<div class="topic-metadata">

**Author:** [@uli67](https://discuss.elastic.co/u/uli67)\
**Replies:** 3\
**Last updated:** [September 11, 2023, 2:00pm UTC](https://discuss.elastic.co/t/failed-to-authenticate-user-elastic-against-https-192-168-xx-xx-9200-security-authenticate-pretty/342654 "2023-09-11T14:00:33Z")

</div>

Hi fellows, your help is needed. I have installed elasticsearch for the first time on my Alma-Linux9. That worked so far elastisearch runs on port 9200 tcp6 0 0 :::9200 :::\* …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=425)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=427)
