# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=429

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 430

---

## [Filebeat Setup error: Couldn't load template](https://discuss.elastic.co/t/filebeat-setup-error-couldnt-load-template/342268)

<div class="topic-metadata">

**Author:** [@JNWL](https://discuss.elastic.co/u/JNWL)\
**Replies:** 3\
**Last updated:** [September 8, 2023, 11:02am UTC](https://discuss.elastic.co/t/filebeat-setup-error-couldnt-load-template/342268 "2023-09-08T11:02:43Z")

</div>

Hi All Years ago I set up a Zeek host with filebeat shipping logs to ELK, this worked fine... Trying to replicate it on a new host years later, and a lot has changed! I'm getting the below error: sudo filebeat setup …

---

## [Canvas filter visualization based on some other timestamp field](https://discuss.elastic.co/t/canvas-filter-visualization-based-on-some-other-timestamp-field/342601)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 10:24am UTC](https://discuss.elastic.co/t/canvas-filter-visualization-based-on-some-other-timestamp-field/342601 "2023-09-08T10:24:29Z")

</div>

Team, i am trying to use canvas and i have placed a time filter which is using column modified\_date as column. Now i am creating a metric visualization and it is not showcasing anything when above column is selected …

---

## [Connecting to Tableau: Tableau could not generate a query to perform this operation](https://discuss.elastic.co/t/connecting-to-tableau-tableau-could-not-generate-a-query-to-perform-this-operation/342517)

<div class="topic-metadata">

**Author:** [@Krikkits](https://discuss.elastic.co/u/Krikkits)\
**Replies:** 4\
**Last updated:** [September 8, 2023, 10:17am UTC](https://discuss.elastic.co/t/connecting-to-tableau-tableau-could-not-generate-a-query-to-perform-this-operation/342517 "2023-09-08T10:17:06Z")

</div>

I have Elasticsearch 7.17.3 and the latest Tableau Desktop (trial version). I followed the documentation (v. 7.17.3 connectors as well) on how to connect them and it works. However, even though the tables are shown withi…

---

## [Metricbeat running but didn't appear in monitoring](https://discuss.elastic.co/t/metricbeat-running-but-didnt-appear-in-monitoring/342562)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 4\
**Last updated:** [September 8, 2023, 9:37am UTC](https://discuss.elastic.co/t/metricbeat-running-but-didnt-appear-in-monitoring/342562 "2023-09-08T09:37:14Z")

</div>

Hello there I found a strange situation here. so I added some logstash nodes to my cluster and used metricbeat to monitor them. but after the metricbeat was running, I checked in my monitoring node, and I found not all …

---

## [The principle of sorting queries](https://discuss.elastic.co/t/the-principle-of-sorting-queries/342508)

<div class="topic-metadata">

**Author:** [@Ceilzcx](https://discuss.elastic.co/u/Ceilzcx)\
**Replies:** 6\
**Last updated:** [September 8, 2023, 9:27am UTC](https://discuss.elastic.co/t/the-principle-of-sorting-queries/342508 "2023-09-08T09:27:03Z")

</div>

I simulated some discrete queries using esrally，and found something that confused me. the first picture is not use sort, and the second use sort. search qps is same. 【99.9th percentile service time】not use sort is smal…

---

## [I m running logstash in a container](https://discuss.elastic.co/t/i-m-running-logstash-in-a-container/342564)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 9\
**Last updated:** [September 8, 2023, 9:07am UTC](https://discuss.elastic.co/t/i-m-running-logstash-in-a-container/342564 "2023-09-08T09:07:26Z")

</div>

Why does this runs pipelines.yml. while passing the configuration using -f. I use startup.sh which in turn calls the /usr/share/logstash/bin/logstash -f /usr/share/logstash/conf.d/ -w 2 Within the container I see 2 pro…

---

## [Colors on different threshold values](https://discuss.elastic.co/t/colors-on-different-threshold-values/342502)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 4\
**Last updated:** [September 8, 2023, 8:50am UTC](https://discuss.elastic.co/t/colors-on-different-threshold-values/342502 "2023-09-08T08:50:09Z")

</div>

We are having one index called resources, which consist of timeseries data i.e. each and every document is having value with timestamp. I want to show this timeseries data in table view with following column: name times…

---

## [ELK index being deleted for a certain period without index lifecycle](https://discuss.elastic.co/t/elk-index-being-deleted-for-a-certain-period-without-index-lifecycle/342189)

<div class="topic-metadata">

**Author:** [@Juan\_Paulo\_Serrano1](https://discuss.elastic.co/u/Juan_Paulo_Serrano1)\
**Replies:** 8\
**Last updated:** [September 8, 2023, 8:38am UTC](https://discuss.elastic.co/t/elk-index-being-deleted-for-a-certain-period-without-index-lifecycle/342189 "2023-09-08T08:38:18Z")

</div>

Hi, I'm having an issue where certain index is being deleted after 28 days, I already removed the lifecycle policy which has 60 days delete phase and it is still being deleted after 28 days. Does anyone has experience on…

---

## [Esrally queries guesses of bottlenecks during pressure measurements](https://discuss.elastic.co/t/esrally-queries-guesses-of-bottlenecks-during-pressure-measurements/342584)

<div class="topic-metadata">

**Author:** [@Ceilzcx](https://discuss.elastic.co/u/Ceilzcx)\
**Replies:** 2\
**Last updated:** [September 8, 2023, 8:07am UTC](https://discuss.elastic.co/t/esrally-queries-guesses-of-bottlenecks-during-pressure-measurements/342584 "2023-09-08T08:07:26Z")

</div>

I use esrally. when i setting throughout to 100 or 200, the Median Throughput are about 100 or 200. but i setting throughout parm more, the mediam throughput still about 240. when i watch the monitor, the load less than …

---

## [Can synonym analyzer or Fuzzy queries return the token that it got matched to from document?](https://discuss.elastic.co/t/can-synonym-analyzer-or-fuzzy-queries-return-the-token-that-it-got-matched-to-from-document/342575)

<div class="topic-metadata">

**Author:** [@aashini](https://discuss.elastic.co/u/aashini)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 6:22am UTC](https://discuss.elastic.co/t/can-synonym-analyzer-or-fuzzy-queries-return-the-token-that-it-got-matched-to-from-document/342575 "2023-09-08T06:22:38Z")

</div>

I am using search-time synonyms in my Index. I am also using fuzzy queries to correct the spelling mistakes of user input in making search. For example, My Index has a field named Trade which can have value "Plumbing". …

---

## [How to configure metricbeat k8s to use ssl connection to ES](https://discuss.elastic.co/t/how-to-configure-metricbeat-k8s-to-use-ssl-connection-to-es/342538)

<div class="topic-metadata">

**Author:** [@Mihai-CMM](https://discuss.elastic.co/u/Mihai-CMM)\
**Replies:** 2\
**Last updated:** [September 8, 2023, 6:50am UTC](https://discuss.elastic.co/t/how-to-configure-metricbeat-k8s-to-use-ssl-connection-to-es/342538 "2023-09-08T06:50:31Z")

</div>

Per title i find it impssobile to configure metricbeat and ES on k8s env. Can i please get a full working env for metricbeat? https://raw.githubusercontent.com/elastic/beats/8.9/deploy/kubernetes/metricbeat-kubernetes.…

---

## [Issue with Kibana rules and alerts](https://discuss.elastic.co/t/issue-with-kibana-rules-and-alerts/342578)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 6:49am UTC](https://discuss.elastic.co/t/issue-with-kibana-rules-and-alerts/342578 "2023-09-08T06:49:12Z")

</div>

Hello, I created a rule in Kibana for Disk alerts and I have configured it to notify (email) once in a day (Below snapshot for your reference). But it is triggering the alerts more than once in a day. Is there anything…

---

## [Outputing Logstash logs to Elastic Index fails](https://discuss.elastic.co/t/outputing-logstash-logs-to-elastic-index-fails/341774)

<div class="topic-metadata">

**Author:** [@aashini](https://discuss.elastic.co/u/aashini)\
**Replies:** 4\
**Last updated:** [September 8, 2023, 5:41am UTC](https://discuss.elastic.co/t/outputing-logstash-logs-to-elastic-index-fails/341774 "2023-09-08T05:41:55Z")

</div>

I am using Logstash version 7.11 and and trying to output logs from logstash pipeline to Elastic version 8.\*. I am using hosts, index, api\_key, ssl and action params with ssl =\> true and action =\> "create" . output { …

---

## [Php agent laravel jobs](https://discuss.elastic.co/t/php-agent-laravel-jobs/342571)

<div class="topic-metadata">

**Author:** [@Vidyanath\_Vemula](https://discuss.elastic.co/u/Vidyanath_Vemula)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 5:39am UTC](https://discuss.elastic.co/t/php-agent-laravel-jobs/342571 "2023-09-08T05:39:04Z")

</div>

Hello, APM does not seem to gather execution statistics of our laravel jobs. We have configured apm agent in php cli and our jobs are executed using supervisor. Manual invocations of php -version does trigger apm stats…

---

## [Receiving messages from remote syslog using logstash](https://discuss.elastic.co/t/receiving-messages-from-remote-syslog-using-logstash/342559)

<div class="topic-metadata">

**Author:** [@d14](https://discuss.elastic.co/u/d14)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 1:47am UTC](https://discuss.elastic.co/t/receiving-messages-from-remote-syslog-using-logstash/342559 "2023-09-08T01:47:47Z")

</div>

I am trying to receive data from a remote syslog server using logstash and the syslog input plugin but unsure how it works. I have a custom domain I want to use for this communication, do I use the custom IP/domain in t…

---

## [Can I omit ES\_USERNAME, ES\_PASSWORD, KIBANA\_FLEET\_USERNAME, KIBANA\_FLEET\_PASSWORD from elastic-agent Kubernetes daemonset?](https://discuss.elastic.co/t/can-i-omit-es-username-es-password-kibana-fleet-username-kibana-fleet-password-from-elastic-agent-kubernetes-daemonset/342558)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 3\
**Last updated:** [September 8, 2023, 12:58am UTC](https://discuss.elastic.co/t/can-i-omit-es-username-es-password-kibana-fleet-username-kibana-fleet-password-from-elastic-agent-kubernetes-daemonset/342558 "2023-09-08T00:58:12Z")

</div>

In the Fleet UI, when specifying the installation method for a Kubernetes cluster, ES\_USERNAME and ES\_PASSWORD are specified as environment variables which are passed down to the docker.elastic.co/beats/elastic-agent c…

---

## [Has anyone come up with a maintainable way to set index.number\_of\_replicas cluster wide?](https://discuss.elastic.co/t/has-anyone-come-up-with-a-maintainable-way-to-set-index-number-of-replicas-cluster-wide/341288)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 7\
**Last updated:** [September 7, 2023, 11:09pm UTC](https://discuss.elastic.co/t/has-anyone-come-up-with-a-maintainable-way-to-set-index-number-of-replicas-cluster-wide/341288 "2023-09-07T23:09:03Z")

</div>

Thanks to budget issues, I'm trying to slim down the footprint of my Elastic stack. While not ideal, running in single-node mode would make things easier to manage. But, as far as I can tell, Elastic Agent creates ever…

---

## [Disable geo lookup in logstash](https://discuss.elastic.co/t/disable-geo-lookup-in-logstash/342557)

<div class="topic-metadata">

**Author:** [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Replies:** 1\
**Last updated:** [September 7, 2023, 10:57pm UTC](https://discuss.elastic.co/t/disable-geo-lookup-in-logstash/342557 "2023-09-07T22:57:39Z")

</div>

I am parsing firewall logs and I don't want logstash to try and do geo parsing. My firewall logs already have the geo information. How can I disable geo parsing so I stop getting \_geoip\_lookup\_failure?

---

## [Enhanced respone to fsnotify queue overflow errors](https://discuss.elastic.co/t/enhanced-respone-to-fsnotify-queue-overflow-errors/342555)

<div class="topic-metadata">

**Author:** [@James\_Nelson1](https://discuss.elastic.co/u/James_Nelson1)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 9:19pm UTC](https://discuss.elastic.co/t/enhanced-respone-to-fsnotify-queue-overflow-errors/342555 "2023-09-07T21:19:51Z")

</div>

Hi Auditbeat folks. I'm considering a feature request, or maybe even a PR to enhance Auditbeat's file\_integrity behavior on Linux platforms when the "fsnotify queue overflow" message is encountered. See eventreader\_fsnot…

---

## [Whats the difference between Tencent Elasticsearch Service and Elastic Cloud?](https://discuss.elastic.co/t/whats-the-difference-between-tencent-elasticsearch-service-and-elastic-cloud/342172)

<div class="topic-metadata">

**Author:** [@heermaas3](https://discuss.elastic.co/u/heermaas3)\
**Replies:** 5\
**Last updated:** [September 7, 2023, 8:20pm UTC](https://discuss.elastic.co/t/whats-the-difference-between-tencent-elasticsearch-service-and-elastic-cloud/342172 "2023-09-07T20:20:43Z")

</div>

I have seen there are 3 different cloud providers for the Elastic Cloud, but I have also seen Elasticsearch is available as a Service on Tencent and Alibaba too, which has nothing to do with the Elastic Cloud, right? Bu…

---

## [Ingest dns queries into elk from dozens of bind9 server](https://discuss.elastic.co/t/ingest-dns-queries-into-elk-from-dozens-of-bind9-server/342546)

<div class="topic-metadata">

**Author:** [@Poubelle\_Dirty](https://discuss.elastic.co/u/Poubelle_Dirty)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 7:20pm UTC](https://discuss.elastic.co/t/ingest-dns-queries-into-elk-from-dozens-of-bind9-server/342546 "2023-09-07T19:20:09Z")

</div>

Hello everyone. I'm looking for the best way (if there is !) for ingesting dns queries from bind9 servers. The environment is composed of about 15 "cluster" of dns servers (1 master and 3 slaves per cluster) that are a…

---

## [How to avoid field\_value\_factor on 'must' clause](https://discuss.elastic.co/t/how-to-avoid-field-value-factor-on-must-clause/342449)

<div class="topic-metadata">

**Author:** [@blinker1](https://discuss.elastic.co/u/blinker1)\
**Replies:** 5\
**Last updated:** [September 7, 2023, 6:28pm UTC](https://discuss.elastic.co/t/how-to-avoid-field-value-factor-on-must-clause/342449 "2023-09-07T18:28:26Z")

</div>

Hi, running the ELK stack on the Elastic cloud, I've defined a search template that has the following query: "query": { "function\_score": { "functions": \[ { "field\_value\_factor": { "field":…

---

## [Delete old back indexes from alias](https://discuss.elastic.co/t/delete-old-back-indexes-from-alias/342439)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 11\
**Last updated:** [September 7, 2023, 5:32pm UTC](https://discuss.elastic.co/t/delete-old-back-indexes-from-alias/342439 "2023-09-07T17:32:45Z")

</div>

Hello! I use data streams for store data. And I have data stream alias. How I can automatically delete back indexes older 7 days from alias?

---

## [Cannot reduce number of segments during indexing](https://discuss.elastic.co/t/cannot-reduce-number-of-segments-during-indexing/342199)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 2\
**Last updated:** [September 7, 2023, 4:15pm UTC](https://discuss.elastic.co/t/cannot-reduce-number-of-segments-during-indexing/342199 "2023-09-07T16:15:53Z")

</div>

I have followed the advice in the aKNN tuning guide: But no matter the settings, the indexing process still creates a huge tail of tiny segments. Setup: New dev deployment Zero search traffic 64GB, CPU optimized "in…

---

## [How do you move all data from one tier to another?](https://discuss.elastic.co/t/how-do-you-move-all-data-from-one-tier-to-another/342535)

<div class="topic-metadata">

**Author:** [@feo13](https://discuss.elastic.co/u/feo13)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 3:15pm UTC](https://discuss.elastic.co/t/how-do-you-move-all-data-from-one-tier-to-another/342535 "2023-09-07T15:15:03Z")

</div>

Hi there, Sorry if this isn't the right place for this question but I'm not sure where else to ask. I currently have an Elastic Cloud deployment with hot, warm, and frozen tiers. Our warm tier blew up in size (and cost…

---

## [Limited score precision for a big score hierarchy](https://discuss.elastic.co/t/limited-score-precision-for-a-big-score-hierarchy/340759)

<div class="topic-metadata">

**Author:** [@Grisha](https://discuss.elastic.co/u/Grisha)\
**Replies:** 14\
**Last updated:** [September 7, 2023, 3:02pm UTC](https://discuss.elastic.co/t/limited-score-precision-for-a-big-score-hierarchy/340759 "2023-09-07T15:02:20Z")

</div>

Hi, I'm trying to implement a kind of score hierarchy using different boosts for different fields (there are multiple fields and type of search (full match, fuzzy, etc.)). Simplified example of boosts: field\_1 fuzzy b…

---

## [JSON Parsing issue with elasticsearch ingest pipeline](https://discuss.elastic.co/t/json-parsing-issue-with-elasticsearch-ingest-pipeline/342519)

<div class="topic-metadata">

**Author:** [@Jobin\_James](https://discuss.elastic.co/u/Jobin_James)\
**Replies:** 4\
**Last updated:** [September 7, 2023, 1:51pm UTC](https://discuss.elastic.co/t/json-parsing-issue-with-elasticsearch-ingest-pipeline/342519 "2023-09-07T13:51:55Z")

</div>

Hello, I am building an Elasticsearch cluster to aggregate and monitor application logs. I am using ECK for deploying and managing the cluster in k8s and fleet-managed elastic agent deployed across multiple clusters to …

---

## [Question elk](https://discuss.elastic.co/t/question-elk/342529)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 1:49pm UTC](https://discuss.elastic.co/t/question-elk/342529 "2023-09-07T13:49:46Z")

</div>

Bonjour ,je voulais dans cette cas supprimer seulement la premier numero comme par exemple ici "create\_uid" : \[ 1, "Support" \], je voudrais supprimer 1 dans le champs create\_uid comment je peux faire ca

---

## [Watcher to send email alerts when Windows Defender detects malware](https://discuss.elastic.co/t/watcher-to-send-email-alerts-when-windows-defender-detects-malware/342528)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 1:28pm UTC](https://discuss.elastic.co/t/watcher-to-send-email-alerts-when-windows-defender-detects-malware/342528 "2023-09-07T13:28:47Z")

</div>

I created a Watcher in Kibana to send email notification when malware is detected on one of the monitored hosts. Maleware detection event has a Windows Event Log ID 1116 and it is generated by Winlog channel "Microsoft-…

---

## [How does cluster.auto\_shrink\_voting\_configuration prevent split brain?](https://discuss.elastic.co/t/how-does-cluster-auto-shrink-voting-configuration-prevent-split-brain/342418)

<div class="topic-metadata">

**Author:** [@etki](https://discuss.elastic.co/u/etki)\
**Replies:** 9\
**Last updated:** [September 7, 2023, 11:31am UTC](https://discuss.elastic.co/t/how-does-cluster-auto-shrink-voting-configuration-prevent-split-brain/342418 "2023-09-07T11:31:15Z")

</div>

We have some docs telling that it's not possible, but they don't explain much, just stating some things. How is the following situation avoided? A cluster has voting configuration of 5 nodes. A network partition occurs…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=428)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=430)
