# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=436

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 437

---

## [logstash Handling exception: io.netty.handler.codec.DecoderException:](https://discuss.elastic.co/t/logstash-handling-exception-io-netty-handler-codec-decoderexception/342054)

<div class="topic-metadata">

**Author:** [@zuoseven](https://discuss.elastic.co/u/zuoseven)\
**Replies:** 5\
**Last updated:** [September 1, 2023, 5:54am UTC](https://discuss.elastic.co/t/logstash-handling-exception-io-netty-handler-codec-decoderexception/342054 "2023-09-01T05:54:15Z")

</div>

Handling exception: io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: Empty server certificate chain (caused by: javax.net.ssl.SSLHandshakeException: Empty server certificate chain) \[2023-08-3…

---

## [Open SSL vulnerability in logstash directory](https://discuss.elastic.co/t/open-ssl-vulnerability-in-logstash-directory/341982)

<div class="topic-metadata">

**Author:** [@Supriyo](https://discuss.elastic.co/u/Supriyo)\
**Replies:** 4\
**Last updated:** [September 1, 2023, 5:01am UTC](https://discuss.elastic.co/t/open-ssl-vulnerability-in-logstash-directory/341982 "2023-09-01T05:01:56Z")

</div>

Security scans have found this open SSL vulnerability in logstash directory. We are trying to upgrade OpenSSL version 3.0.8 or later in the production server. The current version on the server is 3.0.3. Could you plea…

---

## [How to create boxes for particular field](https://discuss.elastic.co/t/how-to-create-boxes-for-particular-field/341075)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 2\
**Last updated:** [September 1, 2023, 3:52am UTC](https://discuss.elastic.co/t/how-to-create-boxes-for-particular-field/341075 "2023-09-01T03:52:05Z")

</div>

I want show some boxes which does not contain count for specific server. I am attach screenshot. In this picture i am trying too show that server but not their count,,, I want show only name for that particular serv…

---

## [Elasticsearch 2.2.4, issue with reindexing](https://discuss.elastic.co/t/elasticsearch-2-2-4-issue-with-reindexing/342089)

<div class="topic-metadata">

**Author:** [@Oeoeoey](https://discuss.elastic.co/u/Oeoeoey)\
**Replies:** 1\
**Last updated:** [September 1, 2023, 3:11am UTC](https://discuss.elastic.co/t/elasticsearch-2-2-4-issue-with-reindexing/342089 "2023-09-01T03:11:06Z")

</div>

I'm very new to elasticsearch and I just started working on some very old legacy code and the component I'm working on randomly stopped being able to reindex the indexes a couple of weeks ago. It used to be able to do a…

---

## [How can I creat the 'downloadable json file'?](https://discuss.elastic.co/t/how-can-i-creat-the-downloadable-json-file/340226)

<div class="topic-metadata">

**Author:** [@IANIAN](https://discuss.elastic.co/u/IANIAN)\
**Replies:** 1\
**Last updated:** [September 1, 2023, 12:20am UTC](https://discuss.elastic.co/t/how-can-i-creat-the-downloadable-json-file/340226 "2023-09-01T00:20:02Z")

</div>

Hi, I wanna demo this blog. How can I create the 'downlodable json file' ? It is at 'Step 4' from here

---

## [Is it possible to restore a single backing index for a data stream](https://discuss.elastic.co/t/is-it-possible-to-restore-a-single-backing-index-for-a-data-stream/341761)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 6\
**Last updated:** [August 31, 2023, 10:05pm UTC](https://discuss.elastic.co/t/is-it-possible-to-restore-a-single-backing-index-for-a-data-stream/341761 "2023-08-31T22:05:41Z")

</div>

we somehow lost both the a shard and its replica for the head of our datastream . I forced a rollover to get the datastream to accepting data again and removed the empty index (using api). I now want to restore that b…

---

## [Adding runtime fields referencing hash map elements to data view](https://discuss.elastic.co/t/adding-runtime-fields-referencing-hash-map-elements-to-data-view/342088)

<div class="topic-metadata">

**Author:** [@dstracha1](https://discuss.elastic.co/u/dstracha1)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 9:25pm UTC](https://discuss.elastic.co/t/adding-runtime-fields-referencing-hash-map-elements-to-data-view/342088 "2023-08-31T21:25:51Z")

</div>

Receiving painless script error when adding runtime field to a data view. The script references an element within a hash map in the document. I have a requirement to include a calculated field to a saved search that is …

---

## [Curator advancing ILM phase due to disk usage](https://discuss.elastic.co/t/curator-advancing-ilm-phase-due-to-disk-usage/342070)

<div class="topic-metadata">

**Author:** [@Pete\_Nelson](https://discuss.elastic.co/u/Pete_Nelson)\
**Replies:** 2\
**Last updated:** [August 31, 2023, 7:11pm UTC](https://discuss.elastic.co/t/curator-advancing-ilm-phase-due-to-disk-usage/342070 "2023-08-31T19:11:47Z")

</div>

This is a feature request for Curator. I know that Elastic's official stance is that clusters should be sized for retention time requirements, and I know the answer to exhausting disk space is to enable automatic scalin…

---

## [How to set \`bulk\_max\_size\` and \`compression\_level\`?](https://discuss.elastic.co/t/how-to-set-bulk-max-size-and-compression-level/341387)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 8\
**Last updated:** [August 31, 2023, 6:34pm UTC](https://discuss.elastic.co/t/how-to-set-bulk-max-size-and-compression-level/341387 "2023-08-31T18:34:19Z")

</div>

I have about 2000 Elastic agents (version 8.9.0) connected to a system with 3 Fleet servers (version 8.9.0). We have about 20 different agent policies, because the various Elastic agents are sending slightly different …

---

## [Reindex from AWS Opensearch to Elasticsearch 7.17](https://discuss.elastic.co/t/reindex-from-aws-opensearch-to-elasticsearch-7-17/342067)

<div class="topic-metadata">

**Author:** [@Chuck\_Reynolds](https://discuss.elastic.co/u/Chuck_Reynolds)\
**Replies:** 3\
**Last updated:** [August 31, 2023, 4:00pm UTC](https://discuss.elastic.co/t/reindex-from-aws-opensearch-to-elasticsearch-7-17/342067 "2023-08-31T16:00:55Z")

</div>

I'm trying to reindex from AWS OPensearch to Elasticsearch 7.17 but I get the following error. { "error" : { "root\_cause" : \[ { "type" : "status\_exception", "reason" : "body={\\"error\\":{\\"roo…

---

## [Inconsistent behaviour of search\_after when used along with Point in time Id for large data sets](https://discuss.elastic.co/t/inconsistent-behaviour-of-search-after-when-used-along-with-point-in-time-id-for-large-data-sets/342074)

<div class="topic-metadata">

**Author:** [@Pravin\_Mourya](https://discuss.elastic.co/u/Pravin_Mourya)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 3:59pm UTC](https://discuss.elastic.co/t/inconsistent-behaviour-of-search-after-when-used-along-with-point-in-time-id-for-large-data-sets/342074 "2023-08-31T15:59:48Z")

</div>

Hello, We have a requirement in our project to extract all the data from the Elasticsearch index and dump it into a relational DB. The volume of data in the index is quite high around 100 million. Also there are process…

---

## [How to use Machine Learning to track thousands of different error codes?](https://discuss.elastic.co/t/how-to-use-machine-learning-to-track-thousands-of-different-error-codes/342065)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 3:10pm UTC](https://discuss.elastic.co/t/how-to-use-machine-learning-to-track-thousands-of-different-error-codes/342065 "2023-08-31T15:10:58Z")

</div>

Hi all. I'm working with around 1,500 different types of error codes. I'd like to use ML to know when any of them individually goes way up. That's too many for Multi-Metric to handle. Could anyone advise how to work …

---

## [Json codec vs. json\_lines codec for collecting mongoexport output JSON?](https://discuss.elastic.co/t/json-codec-vs-json-lines-codec-for-collecting-mongoexport-output-json/341616)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 18\
**Last updated:** [August 31, 2023, 2:59pm UTC](https://discuss.elastic.co/t/json-codec-vs-json-lines-codec-for-collecting-mongoexport-output-json/341616 "2023-08-31T14:59:47Z")

</div>

I'm trying to get Logstash to ingest a JSON file created by a mongoexport call. The file looks like this: { "\_id": "3c51d008add94422abf107f0", "name": "Pulse Get SVN By ID", "type": "automation", "tasks": { "53…

---

## [I want to use udp to output logs to logstash](https://discuss.elastic.co/t/i-want-to-use-udp-to-output-logs-to-logstash/342052)

<div class="topic-metadata">

**Author:** [@manymany](https://discuss.elastic.co/u/manymany)\
**Replies:** 1\
**Last updated:** [August 31, 2023, 2:04pm UTC](https://discuss.elastic.co/t/i-want-to-use-udp-to-output-logs-to-logstash/342052 "2023-08-31T14:04:11Z")

</div>

Filebeat Version: 8.4.3 ERROR: unsupported network type udp.

---

## [Elasticsearch Reindexing error during upgrade in upgrade assistant](https://discuss.elastic.co/t/elasticsearch-reindexing-error-during-upgrade-in-upgrade-assistant/342044)

<div class="topic-metadata">

**Author:** [@agent47](https://discuss.elastic.co/u/agent47)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 12:04pm UTC](https://discuss.elastic.co/t/elasticsearch-reindexing-error-during-upgrade-in-upgrade-assistant/342044 "2023-08-31T12:04:11Z")

</div>

I am currently trying to upgrade my elasticsearch stack from 7.17.7 to 8.9 but I run in the error in the upgrade assistant while trying to fix the deprecation issues, I get the following error {"error":{"root\_cause":\[{"…

---

## [Unable to install 3rd party pluging using ES + Kibana 7.6.0](https://discuss.elastic.co/t/unable-to-install-3rd-party-pluging-using-es-kibana-7-6-0/341903)

<div class="topic-metadata">

**Author:** [@asad\_ali](https://discuss.elastic.co/u/asad_ali)\
**Replies:** 2\
**Last updated:** [August 31, 2023, 11:47am UTC](https://discuss.elastic.co/t/unable-to-install-3rd-party-pluging-using-es-kibana-7-6-0/341903 "2023-08-31T11:47:54Z")

</div>

Hello, I'm stuck in the situation where I'm to run a plugin which only support ES/Kibana 7.6.0 version, so I installed and run both services and they are working as expected. Problem comes when I attempt to install the …

---

## [Run arbitrary code at ingest that is too big for Painless script](https://discuss.elastic.co/t/run-arbitrary-code-at-ingest-that-is-too-big-for-painless-script/342032)

<div class="topic-metadata">

**Author:** [@jrihds](https://discuss.elastic.co/u/jrihds)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 10:08am UTC](https://discuss.elastic.co/t/run-arbitrary-code-at-ingest-that-is-too-big-for-painless-script/342032 "2023-08-31T10:08:16Z")

</div>

Hello, I have a simple algorithm I want to use as part of an ingest pipeline to derive a metric from a string field. For example: "this\_is\_my\_string" and from that we derive a new field for insertion into the index whic…

---

## [Active alert from a deleted rule](https://discuss.elastic.co/t/active-alert-from-a-deleted-rule/342019)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 7:14am UTC](https://discuss.elastic.co/t/active-alert-from-a-deleted-rule/342019 "2023-08-31T07:14:48Z")

</div>

Hello, I noticed 2 issues related to Kibana Alerts: In my Kibana, there are 2 active alerts for the same rule active all the time - even though one of them is from 3 months in the past and should be long recovered. A …

---

## [Snowflake to Elasticsearch Using Logtsash](https://discuss.elastic.co/t/snowflake-to-elasticsearch-using-logtsash/341785)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 3\
**Last updated:** [August 31, 2023, 7:01am UTC](https://discuss.elastic.co/t/snowflake-to-elasticsearch-using-logtsash/341785 "2023-08-31T07:01:17Z")

</div>

We are migrating data from Snowflake to Elasticsearch using the Logtsash driver. I took the logstash conf file template from \[Pull data from Snowflake with logstash | by Izek Chen | Medium\]. Below is the Logstash confi…

---

## [Table visualization in kibana](https://discuss.elastic.co/t/table-visualization-in-kibana/341946)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 3\
**Last updated:** [August 31, 2023, 5:31am UTC](https://discuss.elastic.co/t/table-visualization-in-kibana/341946 "2023-08-31T05:31:15Z")

</div>

I want to create a table visualization in kibana in which i want to display short\_date which is in date format for every entry the bytes and the duration as a separate row. If i select top values in the rows section it…

---

## [How to implement multi tenant environment in Elasticsearch](https://discuss.elastic.co/t/how-to-implement-multi-tenant-environment-in-elasticsearch/341606)

<div class="topic-metadata">

**Author:** [@HARSHAL\_CHAUDHARI](https://discuss.elastic.co/u/HARSHAL_CHAUDHARI)\
**Replies:** 18\
**Last updated:** [August 31, 2023, 4:38am UTC](https://discuss.elastic.co/t/how-to-implement-multi-tenant-environment-in-elasticsearch/341606 "2023-08-31T04:38:05Z")

</div>

What is the approach the Elasticsearch community recommends to use in a multi-tenant environment? Is one index Approach good? what are the pros and cons? Thanks, Harshal

---

## [Geoip log file](https://discuss.elastic.co/t/geoip-log-file/341901)

<div class="topic-metadata">

**Author:** [@AndyB](https://discuss.elastic.co/u/AndyB)\
**Replies:** 8\
**Last updated:** [August 31, 2023, 2:10am UTC](https://discuss.elastic.co/t/geoip-log-file/341901 "2023-08-31T02:10:50Z")

</div>

I would like to see if the geoip database is being downloaded. Getting information from Bard, it tells me that I need to create a file on my server here: /var/log/geoip/geoip.log I have done this but the geoip.log file…

---

## [Indexing buffer settings](https://discuss.elastic.co/t/indexing-buffer-settings/342006)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 1:25am UTC](https://discuss.elastic.co/t/indexing-buffer-settings/342006 "2023-08-31T01:25:47Z")

</div>

Are there any metrics when this buffer (indices.memory.index\_buffer\_size) is filled up? The refresh interval for my index is 5 seconds, but I think that due to the volume + document size, the buffer is filled up earlier …

---

## [Index with different document types](https://discuss.elastic.co/t/index-with-different-document-types/341984)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 3\
**Last updated:** [August 31, 2023, 1:21am UTC](https://discuss.elastic.co/t/index-with-different-document-types/341984 "2023-08-31T01:21:16Z")

</div>

Hello, Suppose I have in total 3000 mappings (mix of text, date, numerics) for an index and have documents using a subset of those mappings like this: doc1 { field\_1 ... field\_2 ... field\_3 ... } doc2 { field\_…

---

## [Latest rolled over data not searchable in Discover menu](https://discuss.elastic.co/t/latest-rolled-over-data-not-searchable-in-discover-menu/341937)

<div class="topic-metadata">

**Author:** [@Geeboy](https://discuss.elastic.co/u/Geeboy)\
**Replies:** 10\
**Last updated:** [August 31, 2023, 1:16am UTC](https://discuss.elastic.co/t/latest-rolled-over-data-not-searchable-in-discover-menu/341937 "2023-08-31T01:16:59Z")

</div>

Im new to ELK (Im using td-agent as log forwarder) I have created ILM rollover in my dev environment, my index was successfully rolling over, but I can't search the new index in the latest rollover in the discover. i hav…

---

## [Kibana - Cant apply NOT filter](https://discuss.elastic.co/t/kibana-cant-apply-not-filter/340486)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 2\
**Last updated:** [August 30, 2023, 11:28pm UTC](https://discuss.elastic.co/t/kibana-cant-apply-not-filter/340486 "2023-08-30T23:28:46Z")

</div>

Hello, I am trying to use wild card to filter output in Kibana. Please see below: I need to filter out host names containing "north" in the name. This does not work and output still shows hostnames with the word "…

---

## [Elastic Serverless Forwarder for AWS SSL Authentication?](https://discuss.elastic.co/t/elastic-serverless-forwarder-for-aws-ssl-authentication/340576)

<div class="topic-metadata">

**Author:** [@stabbotco1](https://discuss.elastic.co/u/stabbotco1)\
**Replies:** 2\
**Last updated:** [August 30, 2023, 11:09pm UTC](https://discuss.elastic.co/t/elastic-serverless-forwarder-for-aws-ssl-authentication/340576 "2023-08-30T23:09:46Z")

</div>

Hi All, we are looking to use the Elastic Serverless Forwarder for AWS, sending to logstash. We've got the initial setup and working, and are wondering if there is support for ssl authentication when sending data to lo…

---

## [Inconsistent definition of size field in ByteStreamOutput.java](https://discuss.elastic.co/t/inconsistent-definition-of-size-field-in-bytestreamoutput-java/341874)

<div class="topic-metadata">

**Author:** [@Paras\_Malik](https://discuss.elastic.co/u/Paras_Malik)\
**Replies:** 1\
**Last updated:** [August 30, 2023, 8:19pm UTC](https://discuss.elastic.co/t/inconsistent-definition-of-size-field-in-bytestreamoutput-java/341874 "2023-08-30T20:19:06Z")

</div>

The definition of Size field in ByteStreamOutput changes from size of store data at the initialisation of BigByteArray to capacity of the BigByteArray at the time of growing the Array. What is the correct definition of …

---

## [Adding a kibana variable in a email alert message](https://discuss.elastic.co/t/adding-a-kibana-variable-in-a-email-alert-message/341975)

<div class="topic-metadata">

**Author:** [@Reeta\_Gupta](https://discuss.elastic.co/u/Reeta_Gupta)\
**Replies:** 1\
**Last updated:** [August 30, 2023, 5:21pm UTC](https://discuss.elastic.co/t/adding-a-kibana-variable-in-a-email-alert-message/341975 "2023-08-30T17:21:55Z")

</div>

How to add a kibana variable in a email alert message

---

## [How to plot line graph in kibana having x-axis with time interval of 24 hrs as 2, 4, 6,](https://discuss.elastic.co/t/how-to-plot-line-graph-in-kibana-having-x-axis-with-time-interval-of-24-hrs-as-2-4-6/340883)

<div class="topic-metadata">

**Author:** [@Lahari\_Madhava\_Reddy](https://discuss.elastic.co/u/Lahari_Madhava_Reddy)\
**Replies:** 1\
**Last updated:** [August 30, 2023, 4:25pm UTC](https://discuss.elastic.co/t/how-to-plot-line-graph-in-kibana-having-x-axis-with-time-interval-of-24-hrs-as-2-4-6/340883 "2023-08-30T16:25:28Z")

</div>

As shown in the graph the x-axis represents 24 hours as intervals and y-axis shows the number of files at 2hrs of interval we need to show the number of files under 2 hrs and at 4 hr time interval we need to show numb…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=435)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=437)
