# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=447

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 448

---

## [What is Query delay and bucket span](https://discuss.elastic.co/t/what-is-query-delay-and-bucket-span/340886)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 7:26am UTC](https://discuss.elastic.co/t/what-is-query-delay-and-bucket-span/340886 "2023-08-21T07:26:21Z")

</div>

Hi Team We are running two jobs of anomaly detection where for one job we are using 10 min of bucket span and for second one we are using 1 hour bucket span. Query delay is same for both jobs i.e. default value. For bo…

---

## [Logtash url is not working](https://discuss.elastic.co/t/logtash-url-is-not-working/341176)

<div class="topic-metadata">

**Author:** [@younus](https://discuss.elastic.co/u/younus)\
**Replies:** 2\
**Last updated:** [August 21, 2023, 7:20am UTC](https://discuss.elastic.co/t/logtash-url-is-not-working/341176 "2023-08-21T07:20:59Z")

</div>

Error: Address already in use: bind Exception: Java::JavaNet::BindException Stack: sun.nio.ch.Net.bind0(Native Method) sun.nio.ch.Net.bind(sun/nio/ch/Net.java:555) sun.nio.ch.ServerSocketChannelImpl.netBind(sun/nio/c…

---

## [How to configure Logstash pipeline to not OOM-Kill ElasticSearch](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949)

<div class="topic-metadata">

**Author:** [@amattice](https://discuss.elastic.co/u/amattice)\
**Replies:** 7\
**Last updated:** [August 21, 2023, 5:18am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949 "2023-08-21T05:18:59Z")

</div>

I'm very new here and to the ELK stack in general. I setup an Ubuntu VM in my Azure resource group and installed the latest Elasticsearch,LogStash, and Kibana. I have basic user authentication setup for kibana, and no SS…

---

## [Transforms from first principles](https://discuss.elastic.co/t/transforms-from-first-principles/340706)

<div class="topic-metadata">

**Author:** [@veryelastic](https://discuss.elastic.co/u/veryelastic)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 3:36am UTC](https://discuss.elastic.co/t/transforms-from-first-principles/340706 "2023-08-21T03:36:36Z")

</div>

Hi, I've got an 8.8.1 cluster which is functioning well and ingesting data into a hot/warm architecture. I have a number of users with some pretty heavy dashboards and, to lighten the load on the cluster, I thought it …

---

## [Need to remove the scientific notation on sum Aggregation](https://discuss.elastic.co/t/need-to-remove-the-scientific-notation-on-sum-aggregation/341193)

<div class="topic-metadata">

**Author:** [@Sakthi1](https://discuss.elastic.co/u/Sakthi1)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 1:16am UTC](https://discuss.elastic.co/t/need-to-remove-the-scientific-notation-on-sum-aggregation/341193 "2023-08-21T01:16:40Z")

</div>

My Index Mapping: "total"{ "type": :"double" "ignore\_malformaed": "true" } when i perform sum on this field i am getting the scientific notation. Query i triggered: POST /\_sql { "query": "select sum(total) from "…

---

## [Using jdbc\_static to build connectionstring that are used in later step](https://discuss.elastic.co/t/using-jdbc-static-to-build-connectionstring-that-are-used-in-later-step/341189)

<div class="topic-metadata">

**Author:** [@johanwallenborg](https://discuss.elastic.co/u/johanwallenborg)\
**Replies:** 2\
**Last updated:** [August 20, 2023, 7:17pm UTC](https://discuss.elastic.co/t/using-jdbc-static-to-build-connectionstring-that-are-used-in-later-step/341189 "2023-08-20T19:17:02Z")

</div>

I found and read about jdbc\_static and trying to get my head around. But I have some questions before i dive deeper into this one. Say that I have a database with a table with rows that contains i.e a identifier, datab…

---

## [How to show difference percentage between 2 lines](https://discuss.elastic.co/t/how-to-show-difference-percentage-between-2-lines/341062)

<div class="topic-metadata">

**Author:** [@grace\_Li](https://discuss.elastic.co/u/grace_Li)\
**Replies:** 1\
**Last updated:** [August 20, 2023, 6:09pm UTC](https://discuss.elastic.co/t/how-to-show-difference-percentage-between-2-lines/341062 "2023-08-20T18:09:12Z")

</div>

Hi, Now I have this graph. Is there a way to display how many percentage difference between the 2 lines at each data point?

---

## [KIBANA 8.7.1 kibana\_system password update](https://discuss.elastic.co/t/kibana-8-7-1-kibana-system-password-update/341137)

<div class="topic-metadata">

**Author:** [@sealove23](https://discuss.elastic.co/u/sealove23)\
**Replies:** 1\
**Last updated:** [August 20, 2023, 6:08pm UTC](https://discuss.elastic.co/t/kibana-8-7-1-kibana-system-password-update/341137 "2023-08-20T18:08:00Z")

</div>

Happy Friday, need help with KIBANA start using xxxxxxx:5601

---

## [Search related documents in kibana in single query](https://discuss.elastic.co/t/search-related-documents-in-kibana-in-single-query/341115)

<div class="topic-metadata">

**Author:** [@vignesh\_nayak](https://discuss.elastic.co/u/vignesh_nayak)\
**Replies:** 4\
**Last updated:** [August 20, 2023, 4:32pm UTC](https://discuss.elastic.co/t/search-related-documents-in-kibana-in-single-query/341115 "2023-08-20T16:32:38Z")

</div>

Hi, I have one scenario. I am pushing certain ID in thread context from application for each transaction along with individual log messages, which means all docs in kibana for that transaction will have same ID, Ex: Tra…

---

## [As part of elastic upgrade prerequisite deleted .reindexed-v6-watches-6 all watchers are gone](https://discuss.elastic.co/t/as-part-of-elastic-upgrade-prerequisite-deleted-reindexed-v6-watches-6-all-watchers-are-gone/341139)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 1\
**Last updated:** [August 20, 2023, 4:01pm UTC](https://discuss.elastic.co/t/as-part-of-elastic-upgrade-prerequisite-deleted-reindexed-v6-watches-6-all-watchers-are-gone/341139 "2023-08-20T16:01:06Z")

</div>

Hi All, We're currently on Elastic 7.17 and are preparing to upgrade to version 8.6. As part of the upgrade process, we were reviewing the breaking changes, specifically in relation to the indices created in version 6. …

---

## [Access a field's value in elastic search without indexing](https://discuss.elastic.co/t/access-a-fields-value-in-elastic-search-without-indexing/341150)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 3\
**Last updated:** [August 20, 2023, 1:26pm UTC](https://discuss.elastic.co/t/access-a-fields-value-in-elastic-search-without-indexing/341150 "2023-08-20T13:26:25Z")

</div>

Hi, I have a requirement to form a script query from java code where it has to formulate the final score after getting the elastic score plus referring a variable on the runtime. document is indexed like below { "ran…

---

## [Aggregation Path](https://discuss.elastic.co/t/aggregation-path/341172)

<div class="topic-metadata">

**Author:** [@noman13bd](https://discuss.elastic.co/u/noman13bd)\
**Replies:** 0\
**Last updated:** [August 20, 2023, 6:05am UTC](https://discuss.elastic.co/t/aggregation-path/341172 "2023-08-20T06:05:05Z")

</div>

I want to use global number of total docs in bucket script. But getting the error No aggregation found for path \[global\_total\_docs\>total\_docs\] can you please help me to identify the right aggregation path? GET bl\_log\_d…

---

## [Elasticsearch Keystore not being created](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 11\
**Last updated:** [August 20, 2023, 4:30am UTC](https://discuss.elastic.co/t/elasticsearch-keystore-not-being-created/341120 "2023-08-20T04:30:08Z")

</div>

Hi there, So, I am trying to run a simple ES single-node cluster. Here is the Dockerfile:- FROM elasticsearch:8.7.0 COPY . . #this copies the start\_es.sh ENTRYPOINT \["./start\_es.sh"\] The start\_es.sh contains noth…

---

## [How to Check which service/application is generating more logs?](https://discuss.elastic.co/t/how-to-check-which-service-application-is-generating-more-logs/340827)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 3\
**Last updated:** [August 20, 2023, 3:42am UTC](https://discuss.elastic.co/t/how-to-check-which-service-application-is-generating-more-logs/340827 "2023-08-20T03:42:08Z")

</div>

Is there a way to check which service/application is generating more logs? Kubernetes Cluster Centralised Elasticsearch and Kibana Fluentbit - different Kubernetes clusters which will send logs to centralised Elastics…

---

## [Is there a way to monitor changes to roles and username / passwords for builtin or created users](https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129)

<div class="topic-metadata">

**Author:** [@txmrlevine](https://discuss.elastic.co/u/txmrlevine)\
**Replies:** 6\
**Last updated:** [August 20, 2023, 12:25am UTC](https://discuss.elastic.co/t/is-there-a-way-to-monitor-changes-to-roles-and-username-passwords-for-builtin-or-created-users/341129 "2023-08-20T00:25:21Z")

</div>

Our Security team is looking for a way for them to use Carbon Black to monitor changes to users (add/ delete) , password changes for these adhoc users or built in users. we were looking for a file on disk. The only inf…

---

## [Logstash doesn't reads JSON file on Windows](https://discuss.elastic.co/t/logstash-doesnt-reads-json-file-on-windows/341156)

<div class="topic-metadata">

**Author:** [@VSKMurali](https://discuss.elastic.co/u/VSKMurali)\
**Replies:** 10\
**Last updated:** [August 19, 2023, 11:35pm UTC](https://discuss.elastic.co/t/logstash-doesnt-reads-json-file-on-windows/341156 "2023-08-19T23:35:17Z")

</div>

Hello, I am trying to configure a following setup on Windows machine. JSON file (creates every 5 mins with the same file name) and Elasticsearch should read the file and push to Index and this is my Logstash config fil…

---

## [Im having a firewall pushing logs towards a linux destination server with middle contains linux machine having logstash server](https://discuss.elastic.co/t/im-having-a-firewall-pushing-logs-towards-a-linux-destination-server-with-middle-contains-linux-machine-having-logstash-server/340511)

<div class="topic-metadata">

**Author:** [@sudharsanam132](https://discuss.elastic.co/u/sudharsanam132)\
**Replies:** 4\
**Last updated:** [August 19, 2023, 9:38am UTC](https://discuss.elastic.co/t/im-having-a-firewall-pushing-logs-towards-a-linux-destination-server-with-middle-contains-linux-machine-having-logstash-server/340511 "2023-08-19T09:38:35Z")

</div>

So firewall pushing logs towards logstash server in logstash i have mentioned in the output plugin to the destination server i need to filter my logs if for example:192.168.1.143 contains the ip in the message i need to …

---

## [Elastic Agent integration for Azure IoT log events forwarding to Elasticsearch](https://discuss.elastic.co/t/elastic-agent-integration-for-azure-iot-log-events-forwarding-to-elasticsearch/341144)

<div class="topic-metadata">

**Author:** [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Replies:** 0\
**Last updated:** [August 19, 2023, 7:36am UTC](https://discuss.elastic.co/t/elastic-agent-integration-for-azure-iot-log-events-forwarding-to-elasticsearch/341144 "2023-08-19T07:36:34Z")

</div>

Hello, everyone! Looking for some help. Need to forward Azure IoT Hub log events to Elasticsearch using Elastic Agent integration. Does anyone has any suggestion? For similar cases good solution is Diagnostic settings +…

---

## [Elasticsearch.service failed after restart](https://discuss.elastic.co/t/elasticsearch-service-failed-after-restart/341056)

<div class="topic-metadata">

**Author:** [@dirtdart666](https://discuss.elastic.co/u/dirtdart666)\
**Replies:** 2\
**Last updated:** [August 19, 2023, 3:01am UTC](https://discuss.elastic.co/t/elasticsearch-service-failed-after-restart/341056 "2023-08-19T03:01:55Z")

</div>

Hi everyone, I am attempitng to install Elasticsearch on an Ubuntu server 22.04. LTS VM but I am running into a few issues. After configuring /etc/elasticsearch/elasticsearch.yml saving and then running sudo systemctl …

---

## [How to Apply Custom Template to Logstash (8.x)](https://discuss.elastic.co/t/how-to-apply-custom-template-to-logstash-8-x/341110)

<div class="topic-metadata">

**Author:** [@inkweon7269](https://discuss.elastic.co/u/inkweon7269)\
**Replies:** 2\
**Last updated:** [August 18, 2023, 11:25pm UTC](https://discuss.elastic.co/t/how-to-apply-custom-template-to-logstash-8-x/341110 "2023-08-18T23:25:31Z")

</div>

I am studying Elasticsearch using Docker Compose and ELK. I am having an issue where the custom template is not being applied in logstash.conf. How can I fixed it? csv-template.json { "template": "csv", "order": "1"…

---

## [Disabling shard allocation not working as expected](https://discuss.elastic.co/t/disabling-shard-allocation-not-working-as-expected/341135)

<div class="topic-metadata">

**Author:** [@Brent\_Plummer](https://discuss.elastic.co/u/Brent_Plummer)\
**Replies:** 4\
**Last updated:** [August 18, 2023, 11:20pm UTC](https://discuss.elastic.co/t/disabling-shard-allocation-not-working-as-expected/341135 "2023-08-18T23:20:15Z")

</div>

One of my 6 Elasticsearch clusters at work is not respecting when i try to disable shard allocation prior to pull a node/server from the cluster. When I run the curl command below I get the "true" response you would exp…

---

## [ELK status Yellow to green](https://discuss.elastic.co/t/elk-status-yellow-to-green/341064)

<div class="topic-metadata">

**Author:** [@younus](https://discuss.elastic.co/u/younus)\
**Replies:** 1\
**Last updated:** [August 18, 2023, 7:47pm UTC](https://discuss.elastic.co/t/elk-status-yellow-to-green/341064 "2023-08-18T19:47:02Z")

</div>

ELK index is yellow . I want to change yellow to green . { "ace\_logs": { "settings": { "index": { "routing": { "allocation": { "include": { "\_tier\_preference": "data\_content" } } }, "number\_of\_shards": "1", …

---

## [Revert to Basic (Free) License - JDBC / ODBC Support?](https://discuss.elastic.co/t/revert-to-basic-free-license-jdbc-odbc-support/341125)

<div class="topic-metadata">

**Author:** [@lenny1](https://discuss.elastic.co/u/lenny1)\
**Replies:** 1\
**Last updated:** [August 18, 2023, 7:17pm UTC](https://discuss.elastic.co/t/revert-to-basic-free-license-jdbc-odbc-support/341125 "2023-08-18T19:17:39Z")

</div>

Hello, I deployed the ELK stack and used it in TRIAL license mode till now. I plan to revert to the basic (free) license, but I need the functionality to ingest MySQL database data into ELK stack via JDBC ingress pipeli…

---

## [Kibana : no handler found for uri](https://discuss.elastic.co/t/kibana-no-handler-found-for-uri/341123)

<div class="topic-metadata">

**Author:** [@rp346](https://discuss.elastic.co/u/rp346)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 6:27pm UTC](https://discuss.elastic.co/t/kibana-no-handler-found-for-uri/341123 "2023-08-18T18:27:52Z")

</div>

I tried to set xpack security for kibana by doing following bin/kibana-encryption-keys generate Copied the generated encryption keys to kibana.yml. xpack.encryptedSavedObjects.encryptionKey: #### xpack.reporti…

---

## [Kibana clock time different from Elasticsearch?](https://discuss.elastic.co/t/kibana-clock-time-different-from-elasticsearch/340960)

<div class="topic-metadata">

**Author:** [@Hannah\_Zhang](https://discuss.elastic.co/u/Hannah_Zhang)\
**Replies:** 2\
**Last updated:** [August 18, 2023, 6:42pm UTC](https://discuss.elastic.co/t/kibana-clock-time-different-from-elasticsearch/340960 "2023-08-18T18:42:51Z")

</div>

It seems the Kibana clock time setting is different from Elasticsearch, so when I posted index into Elasticsearch, I can see that immediately from Elasticsearch, but can't see it with Kibana "Discover" if I set time inte…

---

## [\[ERROR\]\[plugins.securitySolution.endpoint:user-artifact-packager:1.0.0\] EndpointError: Error scheduling task](https://discuss.elastic.co/t/error-plugins-securitysolution-endpoint1-0-0-endpointerror-error-scheduling-task/341121)

<div class="topic-metadata">

**Author:** [@Giancarlo\_Huapaya\_Ra](https://discuss.elastic.co/u/Giancarlo_Huapaya_Ra)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 6:01pm UTC](https://discuss.elastic.co/t/error-plugins-securitysolution-endpoint1-0-0-endpointerror-error-scheduling-task/341121 "2023-08-18T18:01:28Z")

</div>

Hi, I am trying to log in to my kibana but I get the following message: I have logged in to the server and I get the following error in the log: \[ERROR\]\[plugins.securitySolution.endpoint:user-artifact-packager:1.0.0…

---

## [Big index design](https://discuss.elastic.co/t/big-index-design/341118)

<div class="topic-metadata">

**Author:** [@maradev](https://discuss.elastic.co/u/maradev)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 5:19pm UTC](https://discuss.elastic.co/t/big-index-design/341118 "2023-08-18T17:19:59Z")

</div>

Hi, I'm working od designing and implementing search for my project, I'm not so experienced with Elastic and I'm afraid that I'll made wrong design decisions. Could you please share your thoughts about it? I have follow…

---

## [Logstash Output for Fleet Managed Elastic Agent](https://discuss.elastic.co/t/logstash-output-for-fleet-managed-elastic-agent/341117)

<div class="topic-metadata">

**Author:** [@elastic\_n00b](https://discuss.elastic.co/u/elastic_n00b)\
**Replies:** 0\
**Last updated:** [August 18, 2023, 5:08pm UTC](https://discuss.elastic.co/t/logstash-output-for-fleet-managed-elastic-agent/341117 "2023-08-18T17:08:22Z")

</div>

Configure SSL/TLS for the Logstash output | Fleet and Elastic Agent Guide \[8.8\] | Elastic I am looking at these instructions for configuring logstash as an output for elastic agent and I am a bit confused about the clien…

---

## [We couldn't log you in. Please try again](https://discuss.elastic.co/t/we-couldnt-log-you-in-please-try-again/340929)

<div class="topic-metadata">

**Author:** [@daniel\_quiroz](https://discuss.elastic.co/u/daniel_quiroz)\
**Replies:** 6\
**Last updated:** [August 18, 2023, 4:50pm UTC](https://discuss.elastic.co/t/we-couldnt-log-you-in-please-try-again/340929 "2023-08-18T16:50:13Z")

</div>

Hi Everyone, I'm install elastic and kibana on Centos 7. They was working but when I restart the server, the services now print "We couldn't log you in. Please try again." in Kibana's login. I look the service status a…

---

## [Gather Heartbeat Monitor Data from S3 Bucket](https://discuss.elastic.co/t/gather-heartbeat-monitor-data-from-s3-bucket/341058)

<div class="topic-metadata">

**Author:** [@szhao](https://discuss.elastic.co/u/szhao)\
**Replies:** 2\
**Last updated:** [August 18, 2023, 4:19pm UTC](https://discuss.elastic.co/t/gather-heartbeat-monitor-data-from-s3-bucket/341058 "2023-08-18T16:19:31Z")

</div>

Are you able to configure the heatbeat.config.monitors: path variable to be set to a S3 bucket? As of now, I would like to automatically generate the monitor .yaml files, store them in a S3 bucket, and then through anoth…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=446)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=448)
