# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=444

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 445

---

## [Security exception for remote cluster calls](https://discuss.elastic.co/t/security-exception-for-remote-cluster-calls/341395)

<div class="topic-metadata">

**Author:** [@darshanypatel](https://discuss.elastic.co/u/darshanypatel)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 12:07pm UTC](https://discuss.elastic.co/t/security-exception-for-remote-cluster-calls/341395 "2023-08-23T12:07:41Z")

</div>

I have a local & a remote cluster running on the same host (localhost) to be used by the integration tests. It is basically a sidecar container running ES. These tests were passing for ES version 7.16.2, but when I tried…

---

## [Insert data into a field where data contains some text between dollar and flower brackets](https://discuss.elastic.co/t/insert-data-into-a-field-where-data-contains-some-text-between-dollar-and-flower-brackets/341444)

<div class="topic-metadata">

**Author:** [@Madhuri\_Desai](https://discuss.elastic.co/u/Madhuri_Desai)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 10:57am UTC](https://discuss.elastic.co/t/insert-data-into-a-field-where-data-contains-some-text-between-dollar-and-flower-brackets/341444 "2023-08-23T10:57:11Z")

</div>

I need help with an issue that I am facing while inserting data into one of elastic index. Im trying to insert data from a log file into elastic and that file contains some text within dollar and flower brackets. Examp…

---

## [How to disable client certificate checks?](https://discuss.elastic.co/t/how-to-disable-client-certificate-checks/341365)

<div class="topic-metadata">

**Author:** [@nick\_harper1](https://discuss.elastic.co/u/nick_harper1)\
**Replies:** 3\
**Last updated:** [August 23, 2023, 10:54am UTC](https://discuss.elastic.co/t/how-to-disable-client-certificate-checks/341365 "2023-08-23T10:54:39Z")

</div>

Is it possible to disable the server from checking the clients? Even when I have this set: xpack.security.http.ssl.client\_authentication: none When I try to import anything using a script I get this: at java.lang.Thr…

---

## [Improve Snapshot/Backup capabilities for Air Gapped deployments via direct downloads or allowing individuals to push snapshots to repositories such as GitLab, Nexus or Artifactory](https://discuss.elastic.co/t/improve-snapshot-backup-capabilities-for-air-gapped-deployments-via-direct-downloads-or-allowing-individuals-to-push-snapshots-to-repositories-such-as-gitlab-nexus-or-artifactory/340599)

<div class="topic-metadata">

**Author:** [@sheldon.mcclung](https://discuss.elastic.co/u/sheldon.mcclung)\
**Replies:** 4\
**Last updated:** [August 23, 2023, 10:47am UTC](https://discuss.elastic.co/t/improve-snapshot-backup-capabilities-for-air-gapped-deployments-via-direct-downloads-or-allowing-individuals-to-push-snapshots-to-repositories-such-as-gitlab-nexus-or-artifactory/340599 "2023-08-23T10:47:09Z")

</div>

The below image shows the docs with the current snapshot repository options. For an environment that is air gapped, there are not many options available as far as registries to backup the elastic data. I propose that…

---

## [Nested Aggregation not returning document count](https://discuss.elastic.co/t/nested-aggregation-not-returning-document-count/341454)

<div class="topic-metadata">

**Author:** [@Raju\_Yadav](https://discuss.elastic.co/u/Raju_Yadav)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 9:49am UTC](https://discuss.elastic.co/t/nested-aggregation-not-returning-document-count/341454 "2023-08-23T09:49:56Z")

</div>

i have a product document and that product is published into various eCommerce website like amazon , flipkart as shown in location field. The product published is a nested field in Elasticsearch. now i want to aggregate …

---

## [Why is fast bulk than single indexing in elasticsearch](https://discuss.elastic.co/t/why-is-fast-bulk-than-single-indexing-in-elasticsearch/341339)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 11\
**Last updated:** [August 23, 2023, 9:42am UTC](https://discuss.elastic.co/t/why-is-fast-bulk-than-single-indexing-in-elasticsearch/341339 "2023-08-23T09:42:00Z")

</div>

I wonder why bulk indexing is faster than single indexing. I'm curious from the point of view of elasticsearch, other than being connected and closed and network communication problems. Based on the default refresh tim…

---

## [Runtime Fields](https://discuss.elastic.co/t/runtime-fields/341270)

<div class="topic-metadata">

**Author:** [@MOHIT\_SHARMA4](https://discuss.elastic.co/u/MOHIT_SHARMA4)\
**Replies:** 5\
**Last updated:** [August 23, 2023, 9:37am UTC](https://discuss.elastic.co/t/runtime-fields/341270 "2023-08-23T09:37:14Z")

</div>

Hey, I wanted to know what is the difference between defining runtime\_field in mapping v/s and doing so in the query itself. For this, I tried running the following requests to observe if there occurs any changes in int…

---

## [Unable to change bar width in a canvas when x-axis is with timestamp](https://discuss.elastic.co/t/unable-to-change-bar-width-in-a-canvas-when-x-axis-is-with-timestamp/341372)

<div class="topic-metadata">

**Author:** [@KLM](https://discuss.elastic.co/u/KLM)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 9:14am UTC](https://discuss.elastic.co/t/unable-to-change-bar-width-in-a-canvas-when-x-axis-is-with-timestamp/341372 "2023-08-23T09:14:51Z")

</div>

It is not changing the bar width of a bar chart when x-axis show time. follows the code used to generate the graph filters | essql query="SELECT HISTOGRAM("@timestamp", INTERVAL 10 MINUTES) as timestamp, count(\*) …

---

## [Indices are not generating through logstash to see the logs](https://discuss.elastic.co/t/indices-are-not-generating-through-logstash-to-see-the-logs/341394)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 4:26pm UTC](https://discuss.elastic.co/t/indices-are-not-generating-through-logstash-to-see-the-logs/341394 "2023-08-22T16:26:34Z")

</div>

Hi, I have implemented logstash but in my index management I am not able to see Indices of logstash but Ingest pipeline is created as shown in image. I want to push my mule application logs to logstash.How can I do …

---

## [Font Size and Null Values](https://discuss.elastic.co/t/font-size-and-null-values/340940)

<div class="topic-metadata">

**Author:** [@bishnoib](https://discuss.elastic.co/u/bishnoib)\
**Replies:** 3\
**Last updated:** [August 23, 2023, 8:05am UTC](https://discuss.elastic.co/t/font-size-and-null-values/340940 "2023-08-23T08:05:49Z")

</div>

Hi i am using Kibana 8.9.0 and I am creating a vertical bar chart with three categories. I wanted to change the font size of the labels and some of the columns have null/empty values I want to show them in the bar but th…

---

## [How to configure loadbalancer to accsess kibana installed on bare metal kubernetes with helm chart](https://discuss.elastic.co/t/how-to-configure-loadbalancer-to-accsess-kibana-installed-on-bare-metal-kubernetes-with-helm-chart/341439)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 7:50am UTC](https://discuss.elastic.co/t/how-to-configure-loadbalancer-to-accsess-kibana-installed-on-bare-metal-kubernetes-with-helm-chart/341439 "2023-08-23T07:50:42Z")

</div>

here is my helm chart for kibana with ssl and tls enabled.I have access to port 5601 with assined cluter ip (i have telnet throw port 5601)but not access throw loadbalancer(with assigned ip) but other apps working proper…

---

## [ROTATE ML INDEXES](https://discuss.elastic.co/t/rotate-ml-indexes/339286)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 7:02am UTC](https://discuss.elastic.co/t/rotate-ml-indexes/339286 "2023-08-23T07:02:43Z")

</div>

Hi to everyone! I was trying to apply an ILM to ML Job, but I couldn't found nothing related with ilm in machines learning job configuration Does someone how to do it?

---

## [Can't get the logs of process.name field](https://discuss.elastic.co/t/cant-get-the-logs-of-process-name-field/341431)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 6:38am UTC](https://discuss.elastic.co/t/cant-get-the-logs-of-process-name-field/341431 "2023-08-23T06:38:58Z")

</div>

Hello, can someone tell me what is wrong why I can't get the logs on field:process.name ? I just following the instruction here https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-system.html and …

---

## [Logstash runs forever but no index got created](https://discuss.elastic.co/t/logstash-runs-forever-but-no-index-got-created/341428)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 6:13am UTC](https://discuss.elastic.co/t/logstash-runs-forever-but-no-index-got-created/341428 "2023-08-23T06:13:30Z")

</div>

Hi All, I'm using the below configuration in logstash to populate the data on Elasticsearch 7.17.11 from logstash 7.17.12. It shows pipeline started but no index got created . input { jdbc { jdbc\_driver\_li…

---

## [Huge Segments filling up heap](https://discuss.elastic.co/t/huge-segments-filling-up-heap/341317)

<div class="topic-metadata">

**Author:** [@sreekanth\_makam](https://discuss.elastic.co/u/sreekanth_makam)\
**Replies:** 3\
**Last updated:** [August 23, 2023, 5:25am UTC](https://discuss.elastic.co/t/huge-segments-filling-up-heap/341317 "2023-08-23T05:25:34Z")

</div>

In our cluster, We have 6 node each with 30GB heap. We have around 30 indices each with few Millions of docs. Index structure is very very small with just 10 fileds. Each index size is hardly 5GB. Issue: After ingestin…

---

## [Stacked bar graph](https://discuss.elastic.co/t/stacked-bar-graph/341203)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 11\
**Last updated:** [August 23, 2023, 4:24am UTC](https://discuss.elastic.co/t/stacked-bar-graph/341203 "2023-08-23T04:24:48Z")

</div>

Hi i am working on a stacked bar graph, As shown in the image, on x axis i have time on y i have sum of bytes and breakdown by service name. so basically in logs in every entry there is a service name, bytes and time…

---

## [Cannot write Filebeat output to Elastic running on Docker Container on my MAC](https://discuss.elastic.co/t/cannot-write-filebeat-output-to-elastic-running-on-docker-container-on-my-mac/339970)

<div class="topic-metadata">

**Author:** [@bigdaddy0918](https://discuss.elastic.co/u/bigdaddy0918)\
**Replies:** 5\
**Last updated:** [August 22, 2023, 11:24pm UTC](https://discuss.elastic.co/t/cannot-write-filebeat-output-to-elastic-running-on-docker-container-on-my-mac/339970 "2023-08-22T23:24:16Z")

</div>

I have created a 3 node Elastic Docker Container using the instructions from Elastic 8.2.3, and upgraded it to 8.7.1. I am able to successfully create objects in the Elastic database, and the docker-compose command succ…

---

## [Metricbeat Perfmon Counters Stop Ingesting](https://discuss.elastic.co/t/metricbeat-perfmon-counters-stop-ingesting/341412)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 10:11pm UTC](https://discuss.elastic.co/t/metricbeat-perfmon-counters-stop-ingesting/341412 "2023-08-22T22:11:51Z")

</div>

Hello, Need help understanding why perfmon works but eventually stops working after awhile, Using Elastic Agent - Windows Integration to collect windows perfmon counters, the data comes in but then stops ingesting afte…

---

## [Elasticsearch Interface not loading](https://discuss.elastic.co/t/elasticsearch-interface-not-loading/341399)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 9:02pm UTC](https://discuss.elastic.co/t/elasticsearch-interface-not-loading/341399 "2023-08-22T21:02:31Z")

</div>

Cluster is green, all nodes are green but yet i cannot open up the interface, it stays as a blank screen, anyone ever run into this ? if I go to the monitoring node, and view the main cluster it loads fine , looks fine

---

## [We couldn't log you in. Please try again - Elastc/Kibana](https://discuss.elastic.co/t/we-couldnt-log-you-in-please-try-again-elastc-kibana/341384)

<div class="topic-metadata">

**Author:** [@Giancarlo\_Huapaya\_Ra](https://discuss.elastic.co/u/Giancarlo_Huapaya_Ra)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 8:39pm UTC](https://discuss.elastic.co/t/we-couldnt-log-you-in-please-try-again-elastc-kibana/341384 "2023-08-22T20:39:21Z")

</div>

Hi, I am trying to log in to my kibana but I get the following message: I have logged in to the server and I get the following error in the log: \[ERROR\]\[plugins.securitySolution.endpoint:user-artifact-packager:1.0.0…

---

## [File beat - handle too big registry file](https://discuss.elastic.co/t/file-beat-handle-too-big-registry-file/340719)

<div class="topic-metadata">

**Author:** [@sean\_kotler](https://discuss.elastic.co/u/sean_kotler)\
**Replies:** 4\
**Last updated:** [August 22, 2023, 8:32pm UTC](https://discuss.elastic.co/t/file-beat-handle-too-big-registry-file/340719 "2023-08-22T20:32:53Z")

</div>

Hi Team, I would like to understand how to handle filebeat too big registry file when logs files needs to be process only once (old logs(logs that are already in my logs folder, before my filebeat service will be in use…

---

## [Which is the best way to work with two different parameters bound to the legend?](https://discuss.elastic.co/t/which-is-the-best-way-to-work-with-two-different-parameters-bound-to-the-legend/341124)

<div class="topic-metadata">

**Author:** [@EdRayQO](https://discuss.elastic.co/u/EdRayQO)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 7:57pm UTC](https://discuss.elastic.co/t/which-is-the-best-way-to-work-with-two-different-parameters-bound-to-the-legend/341124 "2023-08-22T19:57:33Z")

</div>

Hi everyone, I'm reposting this from this discussion in vega-lite's github in case someone can help me. I have a line chart and I want to group the lines using different fields. I've achieved this using a selection para…

---

## [Unable to start logstash - Tried to load a plugin's code, but failed. {:exception=\>#\<LoadError: no such file to load -- logstash/outputs/microsoft-logstash-output-azure-loganalytics](https://discuss.elastic.co/t/unable-to-start-logstash-tried-to-load-a-plugins-code-but-failed-exception-loaderror-no-such-file-to-load-logstash-outputs-microsoft-logstash-output-azure-loganalytics/341403)

<div class="topic-metadata">

**Author:** [@pavank](https://discuss.elastic.co/u/pavank)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 7:15pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-tried-to-load-a-plugins-code-but-failed-exception-loaderror-no-such-file-to-load-logstash-outputs-microsoft-logstash-output-azure-loganalytics/341403 "2023-08-22T19:15:37Z")

</div>

Hi We are trying to install the microsoft-logstash-output-azure-loganalytics output plugin to send logs to Azure Log analytics, but getting the following error in Logstash start-up and the Logstash service keeps restart…

---

## [Get most frequent combinations of nested docs](https://discuss.elastic.co/t/get-most-frequent-combinations-of-nested-docs/341397)

<div class="topic-metadata">

**Author:** [@JsRg](https://discuss.elastic.co/u/JsRg)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 4:41pm UTC](https://discuss.elastic.co/t/get-most-frequent-combinations-of-nested-docs/341397 "2023-08-22T16:41:46Z")

</div>

I have a elasticsearch index with nested documents (colors). I would like to have a query with an aggregation, which shows the most frequent combinations of colors. An example: I have three documents \[ { "name": "D…

---

## [Modify the Font Styles for Discover tables](https://discuss.elastic.co/t/modify-the-font-styles-for-discover-tables/341127)

<div class="topic-metadata">

**Author:** [@Rajkumar\_M](https://discuss.elastic.co/u/Rajkumar_M)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 4:22pm UTC](https://discuss.elastic.co/t/modify-the-font-styles-for-discover-tables/341127 "2023-08-22T16:22:36Z")

</div>

I need to update the Font styles (color, size, ..) in the Kibana Discover Table. Please let me know the options to do that in Kibana UI.

---

## [Facing issue adding fleet server](https://discuss.elastic.co/t/facing-issue-adding-fleet-server/340803)

<div class="topic-metadata">

**Author:** [@TirathS](https://discuss.elastic.co/u/TirathS)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 10:59am UTC](https://discuss.elastic.co/t/facing-issue-adding-fleet-server/340803 "2023-08-22T10:59:21Z")

</div>

Hello All, I am fairly new to entire elk stack and right now trying to setup a home lab. I am facing a weird issue while adding a fleet server. I am using the official guide to install and whenever i am doing: sudo ./…

---

## [Elasticsearch 8.9.1 - How to extract the self-signed CA and server cert](https://discuss.elastic.co/t/elasticsearch-8-9-1-how-to-extract-the-self-signed-ca-and-server-cert/341304)

<div class="topic-metadata">

**Author:** [@saltspreader](https://discuss.elastic.co/u/saltspreader)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 3:06pm UTC](https://discuss.elastic.co/t/elasticsearch-8-9-1-how-to-extract-the-self-signed-ca-and-server-cert/341304 "2023-08-22T15:06:46Z")

</div>

Hi there, Elasticsearch v 8.9.1 installed via ES apt repo on ubuntu 22.04. I need to extract the self-signed CA and https cert from my elasticsearch 8.9.1 setup to copy to a gitlab instance for https connections. I've …

---

## [Tooltip position in vega is wrong](https://discuss.elastic.co/t/tooltip-position-in-vega-is-wrong/341128)

<div class="topic-metadata">

**Author:** [@karlanakamura](https://discuss.elastic.co/u/karlanakamura)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 3:12pm UTC](https://discuss.elastic.co/t/tooltip-position-in-vega-is-wrong/341128 "2023-08-22T15:12:44Z")

</div>

Hello, I'm using version 8.6.0 in elastic cloud. I would like to know what I can do so that the tooltip is in the correct position. I noticed that this bug often happens when I use a mark of type group. The code below …

---

## [Upgrading elastic to 8.8 has resulted in a master node sending out 5 megabytes a second](https://discuss.elastic.co/t/upgrading-elastic-to-8-8-has-resulted-in-a-master-node-sending-out-5-megabytes-a-second/341299)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 2:19pm UTC](https://discuss.elastic.co/t/upgrading-elastic-to-8-8-has-resulted-in-a-master-node-sending-out-5-megabytes-a-second/341299 "2023-08-22T14:19:08Z")

</div>

Usually elastic master nodes send out 100 kilobytes a second of data. But after upgrading the active master is sending out 5 megabytes. There's no known issue but this doesn't seem healthy. It's role is only master.

---

## [Trial License ECK Issues](https://discuss.elastic.co/t/trial-license-eck-issues/341381)

<div class="topic-metadata">

**Author:** [@walberss](https://discuss.elastic.co/u/walberss)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 2:04pm UTC](https://discuss.elastic.co/t/trial-license-eck-issues/341381 "2023-08-22T14:04:16Z")

</div>

Hi guys I'm trying make tests with ldap integration on kubernetes eck and i can change de license from basic to trial, after few seconds the license come back to basic, Has anyone already caught this behavior? {"type":…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=443)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=445)
