# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=430

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 431

---

## [Install Elastic Search](https://discuss.elastic.co/t/install-elastic-search/342320)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 14\
**Last updated:** [September 7, 2023, 11:39am UTC](https://discuss.elastic.co/t/install-elastic-search/342320 "2023-09-07T11:39:54Z")

</div>

Hi Team, I had a requirement to create elasticsearch cluster with three nodes . I had install the elasticsearch binaries on these three nodes individually and updated the elasticsearch.yml file with node information bu…

---

## [IP match failed](https://discuss.elastic.co/t/ip-match-failed/342475)

<div class="topic-metadata">

**Author:** [@javierelastic](https://discuss.elastic.co/u/javierelastic)\
**Replies:** 4\
**Last updated:** [September 7, 2023, 11:27am UTC](https://discuss.elastic.co/t/ip-match-failed/342475 "2023-09-07T11:27:38Z")

</div>

Hi everyone! Something strange happens to me. I'm trying to see if a source ip matches a pattern I indicate. The ip is 100.44.1.128 and it tells me that it matches "^10.\*" How is it possible? if \[IPorigen\] =~ "^10.\*"…

---

## [Hybrid Search aggregations count mismatch on filters](https://discuss.elastic.co/t/hybrid-search-aggregations-count-mismatch-on-filters/342496)

<div class="topic-metadata">

**Author:** [@Ramgopalbhat10](https://discuss.elastic.co/u/Ramgopalbhat10)\
**Replies:** 1\
**Last updated:** [September 7, 2023, 11:23am UTC](https://discuss.elastic.co/t/hybrid-search-aggregations-count-mismatch-on-filters/342496 "2023-09-07T11:23:27Z")

</div>

I want to use aggregations on the hybrid search (query + knn), which will give me some facets that I can select in the UI and use as filters for subsequent queries. I'm using num\_candidates=100 and k=20. I read in the d…

---

## [Winlogbeat "ignore\_older" rule not working](https://discuss.elastic.co/t/winlogbeat-ignore-older-rule-not-working/342454)

<div class="topic-metadata">

**Author:** [@cesq](https://discuss.elastic.co/u/cesq)\
**Replies:** 6\
**Last updated:** [September 7, 2023, 10:12am UTC](https://discuss.elastic.co/t/winlogbeat-ignore-older-rule-not-working/342454 "2023-09-07T10:12:12Z")

</div>

I've been deploying winlogbeat with graylog-sidecar and for some reason the "ignore\_older" option does not work for me. I am using the latest graylog-sidecar version as well as winlogbeat. In my configuration I have spe…

---

## [Export Teleport Audit Events to the Elastic Stack](https://discuss.elastic.co/t/export-teleport-audit-events-to-the-elastic-stack/340997)

<div class="topic-metadata">

**Author:** [@jana1](https://discuss.elastic.co/u/jana1)\
**Replies:** 1\
**Last updated:** [September 7, 2023, 10:02am UTC](https://discuss.elastic.co/t/export-teleport-audit-events-to-the-elastic-stack/340997 "2023-09-07T10:02:44Z")

</div>

i need help with Exporting Teleport Audit logs to the Elastic Stack - KIbana i am beginner on everything thats way i faced a problem in each step . i need help on explaining how to do all that the things that i did i…

---

## [Where are memories go?](https://discuss.elastic.co/t/where-are-memories-go/342338)

<div class="topic-metadata">

**Author:** [@huajun\_qi](https://discuss.elastic.co/u/huajun_qi)\
**Replies:** 3\
**Last updated:** [September 7, 2023, 9:42am UTC](https://discuss.elastic.co/t/where-are-memories-go/342338 "2023-09-07T09:42:44Z")

</div>

Our clients encountered errors below recently when performing index and query requests: org.elasticsearch.client.ResponseException: org.elasticsearch.client.ResponseException: method \[POST\], host \[http://192.168.12.171:…

---

## [Adding an app plugin inside a dashboard](https://discuss.elastic.co/t/adding-an-app-plugin-inside-a-dashboard/342515)

<div class="topic-metadata">

**Author:** [@Javier\_Mazario\_Picaz](https://discuss.elastic.co/u/Javier_Mazario_Picaz)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 9:45am UTC](https://discuss.elastic.co/t/adding-an-app-plugin-inside-a-dashboard/342515 "2023-09-07T09:45:06Z")

</div>

I have generated an app Kibana plugin with the script generate\_plugin in Kibana 7.17 and I want to use my plugin in a dashboard. It is possible? I think I have to change the plugin.ts file but I don't know exactly how. …

---

## [Alternative grok with API](https://discuss.elastic.co/t/alternative-grok-with-api/342265)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 3\
**Last updated:** [September 7, 2023, 9:11am UTC](https://discuss.elastic.co/t/alternative-grok-with-api/342265 "2023-09-07T09:11:30Z")

</div>

Hello, I've some pipeline which use grok to parse logs and apply some modifications. As i collect in input data from Elastic index, make some modifications and send it directly data transformed in an Elastic index, is …

---

## [Logstash 8.9.0](https://discuss.elastic.co/t/logstash-8-9-0/342362)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 2\
**Last updated:** [September 7, 2023, 8:53am UTC](https://discuss.elastic.co/t/logstash-8-9-0/342362 "2023-09-07T08:53:59Z")

</div>

Please help me. I m running logstash 8.9.0. I recieve the below error in the pod logs. \[2023-09-05T16:25:32,904\]\[ERROR\]\[logstash.javapipeline \]\[main\]\[d9383b2c5e755b975c5f06446fd24ec66c0265c309ed53bd78ed6e05939579ec\] …

---

## [Count only sum value of ID on their last date](https://discuss.elastic.co/t/count-only-sum-value-of-id-on-their-last-date/342227)

<div class="topic-metadata">

**Author:** [@Guillaume\_V](https://discuss.elastic.co/u/Guillaume_V)\
**Replies:** 6\
**Last updated:** [September 7, 2023, 8:23am UTC](https://discuss.elastic.co/t/count-only-sum-value-of-id-on-their-last-date/342227 "2023-09-07T08:23:27Z")

</div>

Hi, I have a problem i would like to share you. This is my data And my table in Dashboard look like this : Level descending | Count 1 | 4 0 …

---

## [Cannot configure grok pipeline to processors in the elastic agent](https://discuss.elastic.co/t/cannot-configure-grok-pipeline-to-processors-in-the-elastic-agent/341933)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 8\
**Last updated:** [September 7, 2023, 6:45am UTC](https://discuss.elastic.co/t/cannot-configure-grok-pipeline-to-processors-in-the-elastic-agent/341933 "2023-09-07T06:45:03Z")

</div>

Hi everyone! I completed and successful configure grok debuger log format of haproxy. And next I was added code grok pattens to pipeline Finally step I have added pipeline to processors in the elastic agent but …

---

## [Creating custom grok pattern](https://discuss.elastic.co/t/creating-custom-grok-pattern/342303)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 4\
**Last updated:** [September 7, 2023, 6:30am UTC](https://discuss.elastic.co/t/creating-custom-grok-pattern/342303 "2023-09-07T06:30:00Z")

</div>

I was working with Logstash to structure the following types of logs: 2023-09-05 11:53:25 (152.32.73.6)-Logistics Request Approved: {"id":7355,"lr\_number":"LR-M006108","lr\_type":"2","lr\_type\_list":"1","lr\_type\_others":n…

---

## [Logstash lumberjack output kept on using IP instead of hostname](https://discuss.elastic.co/t/logstash-lumberjack-output-kept-on-using-ip-instead-of-hostname/342493)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 3:20am UTC](https://discuss.elastic.co/t/logstash-lumberjack-output-kept-on-using-ip-instead-of-hostname/342493 "2023-09-07T03:20:14Z")

</div>

Hello, i currently have a logstash in openshift exposed through openshift route with beats input. I tried to send some logs using powershell with logstash for windows: bin/logstash -e 'input { generator { count =\> 5 } }…

---

## [I want to get the total number of keyword hits for each document in the query results](https://discuss.elastic.co/t/i-want-to-get-the-total-number-of-keyword-hits-for-each-document-in-the-query-results/342490)

<div class="topic-metadata">

**Author:** [@z\_Henry](https://discuss.elastic.co/u/z_Henry)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 2:12am UTC](https://discuss.elastic.co/t/i-want-to-get-the-total-number-of-keyword-hits-for-each-document-in-the-query-results/342490 "2023-09-07T02:12:11Z")

</div>

My field mapping settings are as follows "functionPoint": { "type": "text", "index": true, "analyzer": "ik\_smart", "search\_analyzer": "ik\_smart", "fielddata": true, "fielddata\_frequency\_filter": { "min":…

---

## [Please help me Install Elasticsearch in EC2](https://discuss.elastic.co/t/please-help-me-install-elasticsearch-in-ec2/342487)

<div class="topic-metadata">

**Author:** [@chobo](https://discuss.elastic.co/u/chobo)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 1:26am UTC](https://discuss.elastic.co/t/please-help-me-install-elasticsearch-in-ec2/342487 "2023-09-07T01:26:51Z")

</div>

Hello I'm installing Elasticsearch in EC2 environment and setting elasticsearch.yml file, but I keep getting the following error fatal exception while booting Elasticsearch org.elasticsearch.transport.BindTransportExce…

---

## [Reset Kibana to blank state](https://discuss.elastic.co/t/reset-kibana-to-blank-state/342376)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 2\
**Last updated:** [September 7, 2023, 1:32am UTC](https://discuss.elastic.co/t/reset-kibana-to-blank-state/342376 "2023-09-07T01:32:32Z")

</div>

On startup Kibana creates configuration in ES, and that config accumulates with web UI config changes, I believe. Is there a way to zero out the Kibana config to start fresh? Or do I have to find every change and delet…

---

## [Error creating rule via API](https://discuss.elastic.co/t/error-creating-rule-via-api/342381)

<div class="topic-metadata">

**Author:** [@Gabriel\_Camara](https://discuss.elastic.co/u/Gabriel_Camara)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 11:45pm UTC](https://discuss.elastic.co/t/error-creating-rule-via-api/342381 "2023-09-06T23:45:00Z")

</div>

Hello, I'm trying to explain the example of creating a rule via API that is in the documentation, but I've been getting this error: {"statusCode":400,"error":"Bad Request","message":"Error creating rule: could not creat…

---

## [Does the Elasticsearch Ruby gem support both http and https hosts?](https://discuss.elastic.co/t/does-the-elasticsearch-ruby-gem-support-both-http-and-https-hosts/342477)

<div class="topic-metadata">

**Author:** [@ddzz](https://discuss.elastic.co/u/ddzz)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 9:38pm UTC](https://discuss.elastic.co/t/does-the-elasticsearch-ruby-gem-support-both-http-and-https-hosts/342477 "2023-09-06T21:38:57Z")

</div>

I want to transition a cluster of ES nodes from HTTP to HTTPS. When the list of hosts I pass in to the ES client is either all http or https, it works fine. But when it's a mix I run into a variety of errors. Does the ge…

---

## [What is actually causing these shard snapshot failures?](https://discuss.elastic.co/t/what-is-actually-causing-these-shard-snapshot-failures/342203)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 7\
**Last updated:** [September 6, 2023, 9:35pm UTC](https://discuss.elastic.co/t/what-is-actually-causing-these-shard-snapshot-failures/342203 "2023-09-06T21:35:59Z")

</div>

And how do I fix them ; ) I have 7 shards failing with a message of the form: INTERNAL\_SERVER\_ERROR: NoSuchFileException\[/data/elasticsearch/backups/daily/indices/L0OEoJ\_DSqOk8aNpntkxqQ/0/index-MD1wjtsmTBuEPMY\_zenaaQ\] I…

---

## [PFsense integration not working](https://discuss.elastic.co/t/pfsense-integration-not-working/342388)

<div class="topic-metadata">

**Author:** [@Rob\_wylde](https://discuss.elastic.co/u/Rob_wylde)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 8:30pm UTC](https://discuss.elastic.co/t/pfsense-integration-not-working/342388 "2023-09-06T20:30:11Z")

</div>

I have configured pfsense to send UDP logs to a Linux host with the pfense integration added to the policy. I have confirmed that pfsense is sending logs to the desired destination via nc -ul 9001, and I can see the plai…

---

## [Detecting specific event sequences in data streams](https://discuss.elastic.co/t/detecting-specific-event-sequences-in-data-streams/342469)

<div class="topic-metadata">

**Author:** [@Kargo](https://discuss.elastic.co/u/Kargo)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 7:40pm UTC](https://discuss.elastic.co/t/detecting-specific-event-sequences-in-data-streams/342469 "2023-09-06T19:40:14Z")

</div>

Hey there. I have a datastream in Elasticsearch with mappings similar to this: { "mappings": { "properties": { "@timestamp": {"type": "date"}, "event-type": {"type": "keyword"}, "session": {"…

---

## [Metricbeat illegal\_argument\_exception error](https://discuss.elastic.co/t/metricbeat-illegal-argument-exception-error/341919)

<div class="topic-metadata">

**Author:** [@wleight](https://discuss.elastic.co/u/wleight)\
**Replies:** 1\
**Last updated:** [September 6, 2023, 6:28pm UTC](https://discuss.elastic.co/t/metricbeat-illegal-argument-exception-error/341919 "2023-09-06T18:28:18Z")

</div>

Hi, I'm trying to set up Metricbeat -\> Elastic (8.9.0 on Ubuntu) using the HTTP JSON metricset, and had no problems at first, but then the output that is retrieved changed and now Metricbeat tells me "Cannot index event…

---

## [Anomaly Detection buckets over time?](https://discuss.elastic.co/t/anomaly-detection-buckets-over-time/340836)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 5:50pm UTC](https://discuss.elastic.co/t/anomaly-detection-buckets-over-time/340836 "2023-09-06T17:50:52Z")

</div>

Hi all. I have an Anomaly Job running with hourly buckets. The values rise and fall once per day. It seems to work great in tracking that pattern, and learning about weekends. But I have a newbie question. When ML i…

---

## [Modify sort mechanism of elasticsearch by counting matched elements in array properties](https://discuss.elastic.co/t/modify-sort-mechanism-of-elasticsearch-by-counting-matched-elements-in-array-properties/342466)

<div class="topic-metadata">

**Author:** [@Ben\_Berizovsky](https://discuss.elastic.co/u/Ben_Berizovsky)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 5:22pm UTC](https://discuss.elastic.co/t/modify-sort-mechanism-of-elasticsearch-by-counting-matched-elements-in-array-properties/342466 "2023-09-06T17:22:56Z")

</div>

Hello, I am trying to achieve a "Best Match" strategy for the results in my platform that uses Elasticsearch 7.15. Basically, there are the rules on how it should work: Every property that you match with a query\_strin…

---

## [Rally race crushes right after start](https://discuss.elastic.co/t/rally-race-crushes-right-after-start/342254)

<div class="topic-metadata">

**Author:** [@lokinehn](https://discuss.elastic.co/u/lokinehn)\
**Replies:** 10\
**Last updated:** [September 6, 2023, 4:32pm UTC](https://discuss.elastic.co/t/rally-race-crushes-right-after-start/342254 "2023-09-06T16:32:09Z")

</div>

I want to run a benchmark for my existing 8.9.0 cluster (honestly I've already run tests on that cluster earlier, and everything was great) and i get error right after start. Command i execute: esrally race --track=sql…

---

## [\[DOCUMENTATION\] ElasticSearch and Kibana documentation in .pdf/.epub/.azw format?](https://discuss.elastic.co/t/documentation-elasticsearch-and-kibana-documentation-in-pdf-epub-azw-format/341584)

<div class="topic-metadata">

**Author:** [@CodeTradition](https://discuss.elastic.co/u/CodeTradition)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 4:08pm UTC](https://discuss.elastic.co/t/documentation-elasticsearch-and-kibana-documentation-in-pdf-epub-azw-format/341584 "2023-09-06T16:08:42Z")

</div>

Hello guys, This might be a strange request for you but I was wondering if there was a documentation of Elasticsearch and Kibana in .pdf/.epub/.azw format ? I have been using Elasticsearch and Kibana since approximatel…

---

## [Build metric for a status of a rollout](https://discuss.elastic.co/t/build-metric-for-a-status-of-a-rollout/342429)

<div class="topic-metadata">

**Author:** [@jp1992ger](https://discuss.elastic.co/u/jp1992ger)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 2:22pm UTC](https://discuss.elastic.co/t/build-metric-for-a-status-of-a-rollout/342429 "2023-09-06T14:22:16Z")

</div>

Hello everyone, I currently want to build a metric to track a rollout. So what I want to do is check if a field with a specific value does exist once per host, count these host and match them against hosts where this fi…

---

## [Export data from kibana dashboard in CSV/Excel](https://discuss.elastic.co/t/export-data-from-kibana-dashboard-in-csv-excel/342106)

<div class="topic-metadata">

**Author:** [@HiteshSingh](https://discuss.elastic.co/u/HiteshSingh)\
**Replies:** 8\
**Last updated:** [September 6, 2023, 2:21pm UTC](https://discuss.elastic.co/t/export-data-from-kibana-dashboard-in-csv-excel/342106 "2023-09-06T14:21:25Z")

</div>

I want to export the records from the kibana dashboard in CSV/Excel. I have added a table in the dashboard from discover which contains millions of records. I want to download/export these records into CSV/Excel. Let m…

---

## [Kibana7.17.10 log rotation](https://discuss.elastic.co/t/kibana7-17-10-log-rotation/342313)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 7\
**Last updated:** [September 6, 2023, 1:54pm UTC](https://discuss.elastic.co/t/kibana7-17-10-log-rotation/342313 "2023-09-06T13:54:47Z")

</div>

Hi Kibana version-7.17.10 OS - 22.04 ubuntu I want to log rotation daily basis in kibana for kibana log file Can you help here?

---

## [How to customize navigation bar in kibana 8.9 interface?](https://discuss.elastic.co/t/how-to-customize-navigation-bar-in-kibana-8-9-interface/341683)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [September 6, 2023, 1:29pm UTC](https://discuss.elastic.co/t/how-to-customize-navigation-bar-in-kibana-8-9-interface/341683 "2023-09-06T13:29:06Z")

</div>

I want to change the color of the navigation bar of kiaban interface . Which file should I modify to change the color, and which parameter should I change?

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=429)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=431)
