# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=452

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 453

---

## [What is best node configuration in 5 node](https://discuss.elastic.co/t/what-is-best-node-configuration-in-5-node/340709)

<div class="topic-metadata">

**Author:** [@hyungsun\_lim](https://discuss.elastic.co/u/hyungsun_lim)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 9:08am UTC](https://discuss.elastic.co/t/what-is-best-node-configuration-in-5-node/340709 "2023-08-14T09:08:06Z")

</div>

I have 5 nodes for elasticsearch. When i use 3 nodes, i just use them as default mode. Is it okay to use default mode for 5 nodes? Or is there any good options to set role for 5 nodes?

---

## [Uptime Page Error - Failed to execute 'btoa' on 'Window'](https://discuss.elastic.co/t/uptime-page-error-failed-to-execute-btoa-on-window/340630)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 9:05am UTC](https://discuss.elastic.co/t/uptime-page-error-failed-to-execute-btoa-on-window/340630 "2023-08-14T09:05:52Z")

</div>

Hello, We are monitoring around 1500 endpoints using Heartbeat. While pagination we are getting this strange error. Is it something related to character on the ID or NAME using in the heartbeat configurations ??? Pleas…

---

## [Awslog driver docker](https://discuss.elastic.co/t/awslog-driver-docker/340723)

<div class="topic-metadata">

**Author:** [@Ryan5](https://discuss.elastic.co/u/Ryan5)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 8:42am UTC](https://discuss.elastic.co/t/awslog-driver-docker/340723 "2023-08-14T08:42:30Z")

</div>

We are using AWS ECS EC2 with the awslog docker driver however, the issue is that the awslog driver outputs a binary file with all the .json log lines beginning with stderr and some unicode. Beats seems to crash when the…

---

## [Grok pattern failing for apache custom logs](https://discuss.elastic.co/t/grok-pattern-failing-for-apache-custom-logs/340529)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 7\
**Last updated:** [August 14, 2023, 6:24am UTC](https://discuss.elastic.co/t/grok-pattern-failing-for-apache-custom-logs/340529 "2023-08-14T06:24:28Z")

</div>

i am facing issue for my grok is failing for the apache custom logs as beolw 10.52.245.67 - - \[12/Jul/2023:08:08:51 +0800\] uibau1a "GET /login/runtime.6b0e772316ccb94a9291.js HTTP/1.1" 200 2289bytes "10.168.224.18, 10.5…

---

## [Encryption in Elasticsearch](https://discuss.elastic.co/t/encryption-in-elasticsearch/340711)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 6:17am UTC](https://discuss.elastic.co/t/encryption-in-elasticsearch/340711 "2023-08-14T06:17:05Z")

</div>

Just wanted to get some idea from the folks here regarding Elasticsearch data encryption. So, I am aware about 2 ways we can get our data encrypt in Elasticsearch:- Using some encyption/tokenization on data before ing…

---

## [Logstash parsing](https://discuss.elastic.co/t/logstash-parsing/339929)

<div class="topic-metadata">

**Author:** [@dilipchiru](https://discuss.elastic.co/u/dilipchiru)\
**Replies:** 4\
**Last updated:** [August 14, 2023, 5:44am UTC](https://discuss.elastic.co/t/logstash-parsing/339929 "2023-08-14T05:44:21Z")

</div>

Hi Team, I have 2 Fields which is From and TO which contains set of values which is comma separated. For example: "from" : "Loin, Elephant, cat, movie, John" "to" : "Loin, Elephant, cat, movie, John, USA " Now we wo…

---

## [ILM policy to rollover data from hot to frozen without replica shards](https://discuss.elastic.co/t/ilm-policy-to-rollover-data-from-hot-to-frozen-without-replica-shards/340518)

<div class="topic-metadata">

**Author:** [@sajjad\_akram](https://discuss.elastic.co/u/sajjad_akram)\
**Replies:** 2\
**Last updated:** [August 14, 2023, 5:06am UTC](https://discuss.elastic.co/t/ilm-policy-to-rollover-data-from-hot-to-frozen-without-replica-shards/340518 "2023-08-14T05:06:34Z")

</div>

Hi, My indices in hot phase is configured to have 2primary and 2replica shards. I want to have an ilm policy to rollover data from hot phase to frozen phase daily but without the replicas . i see that there is an optio…

---

## [Ingest Pipeline Stats - Processor \`if\` (conditional) measurement](https://discuss.elastic.co/t/ingest-pipeline-stats-processor-if-conditional-measurement/340707)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [August 13, 2023, 8:18pm UTC](https://discuss.elastic.co/t/ingest-pipeline-stats-processor-if-conditional-measurement/340707 "2023-08-13T20:18:52Z")

</div>

Hi All, I have a question related to the Ingest Pipeline stats that are part of the node stats api. The API returns the time it takes to process a doc for a given processor, but what isn't clear to me is does the time …

---

## [Error log "Couldn't index event to elastic"](https://discuss.elastic.co/t/error-log-couldnt-index-event-to-elastic/340704)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 1\
**Last updated:** [August 13, 2023, 6:22pm UTC](https://discuss.elastic.co/t/error-log-couldnt-index-event-to-elastic/340704 "2023-08-13T18:22:07Z")

</div>

Hi there, I want to confirm, if I got "Could not index event to elasticsearch" error, will it be retried if the reason that log has been resolved? I got this error and the reason shows me it caused by "Limit total field…

---

## [Moment.js Vulnerability](https://discuss.elastic.co/t/moment-js-vulnerability/340688)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 1\
**Last updated:** [August 13, 2023, 6:14pm UTC](https://discuss.elastic.co/t/moment-js-vulnerability/340688 "2023-08-13T18:14:54Z")

</div>

Hello, I am using Elasticsearch-Kibana version 7.10.2. In the security tests, it was observed that there was a vulnerability in moment.js software. moment.js 2.28.0 --\> CVE-2022-24785 Can I update this software, does…

---

## [Excessive 4673 events due to chromium](https://discuss.elastic.co/t/excessive-4673-events-due-to-chromium/340643)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 2:20pm UTC](https://discuss.elastic.co/t/excessive-4673-events-due-to-chromium/340643 "2023-08-11T14:20:45Z")

</div>

Hi All, We're seeing excessive 4673 events which appear to be linked to the chromium issue causing failures against SeProfileSingleProcessPrivilege; this appears to be well know by Microsoft. Ideally we would like to e…

---

## [Converting relative date like "now-30d" to absolute date/time format](https://discuss.elastic.co/t/converting-relative-date-like-now-30d-to-absolute-date-time-format/340701)

<div class="topic-metadata">

**Author:** [@Mohammad\_Rezaei](https://discuss.elastic.co/u/Mohammad_Rezaei)\
**Replies:** 0\
**Last updated:** [August 13, 2023, 9:08am UTC](https://discuss.elastic.co/t/converting-relative-date-like-now-30d-to-absolute-date-time-format/340701 "2023-08-13T09:08:33Z")

</div>

I am writing a plugin for Kibana. I want to display a chart: \<Chart\> \<Axis id="bottom" title={dateFormatter(startDate)} position={Position.Bottom} tickFormat={dateFormatter} /\> \<Axis id="left" …

---

## [Visualization: Controls - Not refreshing new values in options-list](https://discuss.elastic.co/t/visualization-controls-not-refreshing-new-values-in-options-list/340697)

<div class="topic-metadata">

**Author:** [@Kumbum](https://discuss.elastic.co/u/Kumbum)\
**Replies:** 0\
**Last updated:** [August 13, 2023, 4:18am UTC](https://discuss.elastic.co/t/visualization-controls-not-refreshing-new-values-in-options-list/340697 "2023-08-13T04:18:33Z")

</div>

Hi, I have an issue with control visualization; I am unable to see new values in the drop-down field of the options list. Please let me know how to fix this.

---

## [Updating enrich index for pipeline](https://discuss.elastic.co/t/updating-enrich-index-for-pipeline/339732)

<div class="topic-metadata">

**Author:** [@veryelastic](https://discuss.elastic.co/u/veryelastic)\
**Replies:** 7\
**Last updated:** [August 12, 2023, 7:50pm UTC](https://discuss.elastic.co/t/updating-enrich-index-for-pipeline/339732 "2023-08-12T19:50:27Z")

</div>

Hello, I have an 8.8.1 cluster, and am running documents through a series of ingest pipelines. One of these pipelines is an enrich stage. This data which is used to enrich the documents is sourced from an index via an…

---

## [Regarding tenants](https://discuss.elastic.co/t/regarding-tenants/340234)

<div class="topic-metadata">

**Author:** [@Ajay\_Kumar.S](https://discuss.elastic.co/u/Ajay_Kumar.S)\
**Replies:** 3\
**Last updated:** [August 12, 2023, 3:03pm UTC](https://discuss.elastic.co/t/regarding-tenants/340234 "2023-08-12T15:03:09Z")

</div>

Hello community How can I create a tenant in ELK 8.9.0 version?

---

## [How to query Elasticsearch datasource in Grafana?](https://discuss.elastic.co/t/how-to-query-elasticsearch-datasource-in-grafana/340682)

<div class="topic-metadata">

**Author:** [@ZahraZare](https://discuss.elastic.co/u/ZahraZare)\
**Replies:** 0\
**Last updated:** [August 12, 2023, 10:49am UTC](https://discuss.elastic.co/t/how-to-query-elasticsearch-datasource-in-grafana/340682 "2023-08-12T10:49:39Z")

</div>

I want to use an index in Elasticsearch as a data source in Grafana. But I can't query it and extract a specific field from it. I want to have only the data of the fields I want as output from among several fields in thi…

---

## [Handle retries for bulk api](https://discuss.elastic.co/t/handle-retries-for-bulk-api/340640)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 1\
**Last updated:** [August 12, 2023, 9:20am UTC](https://discuss.elastic.co/t/handle-retries-for-bulk-api/340640 "2023-08-12T09:20:51Z")

</div>

Hi, I am trying to make a bulk request using BulkRequest in java. I am not finding any documentation to retry the failed requests. Is there any inbuilt functionality in the java client api to handle retries or do I need…

---

## [Why query result cannot be generated all data (csv) of specific days in Elastic Search](https://discuss.elastic.co/t/why-query-result-cannot-be-generated-all-data-csv-of-specific-days-in-elastic-search/340674)

<div class="topic-metadata">

**Author:** [@jt2023](https://discuss.elastic.co/u/jt2023)\
**Replies:** 9\
**Last updated:** [August 12, 2023, 9:14am UTC](https://discuss.elastic.co/t/why-query-result-cannot-be-generated-all-data-csv-of-specific-days-in-elastic-search/340674 "2023-08-12T09:14:11Z")

</div>

why query result cannot be generated all data (csv) of specific days in Elastic Search. For example, i searched for 15,16,17 July data, but only 17July can be generated and displayed in csv file

---

## [Query Precision/Recall vs Sort](https://discuss.elastic.co/t/query-precision-recall-vs-sort/340667)

<div class="topic-metadata">

**Author:** [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Replies:** 1\
**Last updated:** [August 12, 2023, 7:59am UTC](https://discuss.elastic.co/t/query-precision-recall-vs-sort/340667 "2023-08-12T07:59:55Z")

</div>

I have a catalog of products and I'm facing some problems when I try to sort the results by other criteria than by relevance. Today I can sort the results in order: most recent and most rated. My query has the characte…

---

## [Log.file.path with grok condition issue with multiple log files](https://discuss.elastic.co/t/log-file-path-with-grok-condition-issue-with-multiple-log-files/339600)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 2\
**Last updated:** [August 12, 2023, 6:45am UTC](https://discuss.elastic.co/t/log-file-path-with-grok-condition-issue-with-multiple-log-files/339600 "2023-08-12T06:45:48Z")

</div>

Hi Team, Am I trying to create the index using log.file.path field in the grok if condition. Actually am I including the multiple file path. so while doing this the index was not creating. but if I include only one, the…

---

## [Extract date from filename, time from log line](https://discuss.elastic.co/t/extract-date-from-filename-time-from-log-line/339251)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 3\
**Last updated:** [August 12, 2023, 6:00am UTC](https://discuss.elastic.co/t/extract-date-from-filename-time-from-log-line/339251 "2023-08-12T06:00:17Z")

</div>

Hi on logstash need to use file as input, output as http. here is the string must be send: mymeasure,tag=mytag field="myfield" 1689682934 this part "1689682934" is timestamp. now question is how can i extract date f…

---

## [Transport errors between elasticsearch nodes](https://discuss.elastic.co/t/transport-errors-between-elasticsearch-nodes/336685)

<div class="topic-metadata">

**Author:** [@Josselin](https://discuss.elastic.co/u/Josselin)\
**Replies:** 10\
**Last updated:** [August 12, 2023, 5:38am UTC](https://discuss.elastic.co/t/transport-errors-between-elasticsearch-nodes/336685 "2023-08-12T05:38:57Z")

</div>

Hi ! I am creating this topic to seek help about a major issues on our Elasticsearch cluster. We have a cluster with nearly 150 nodes (quite a bit :wink: ) We are sometime encountering a big issues, some nodes start t…

---

## [Is is possible to have elasticsearch status return "running" but to get "no alive nodes found in cluster" for the same app?](https://discuss.elastic.co/t/is-is-possible-to-have-elasticsearch-status-return-running-but-to-get-no-alive-nodes-found-in-cluster-for-the-same-app/340670)

<div class="topic-metadata">

**Author:** [@nfanh](https://discuss.elastic.co/u/nfanh)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 11:01pm UTC](https://discuss.elastic.co/t/is-is-possible-to-have-elasticsearch-status-return-running-but-to-get-no-alive-nodes-found-in-cluster-for-the-same-app/340670 "2023-08-11T23:01:39Z")

</div>

is is possible to have elasticsearch status return "running" but to get "no alive nodes found in cluster" for the same app?

---

## [Discover Results Do Not Match Visualization Results](https://discuss.elastic.co/t/discover-results-do-not-match-visualization-results/339845)

<div class="topic-metadata">

**Author:** [@codewriterguy](https://discuss.elastic.co/u/codewriterguy)\
**Replies:** 6\
**Last updated:** [August 11, 2023, 9:55pm UTC](https://discuss.elastic.co/t/discover-results-do-not-match-visualization-results/339845 "2023-08-11T21:55:38Z")

</div>

Hi, Querying in Discover gives some number of results: The same query in a visualization isn't giving any results: Do both of these use the index pattern, and shouldn't both get the same query results for the sa…

---

## [Access Elasticsearch with HTTPs and HTTP](https://discuss.elastic.co/t/access-elasticsearch-with-https-and-http/340661)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 7:53pm UTC](https://discuss.elastic.co/t/access-elasticsearch-with-https-and-http/340661 "2023-08-11T19:53:03Z")

</div>

I configured my Elasticsearch server to be secure, using a proprietary certificate. Similar to the configuration below: # security settings xpack.security.enabled: true xpack.security.autoconfiguration.enabled: false #…

---

## [Security Rules execution error](https://discuss.elastic.co/t/security-rules-execution-error/338484)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 7:36pm UTC](https://discuss.elastic.co/t/security-rules-execution-error/338484 "2023-08-11T19:36:00Z")

</div>

Hello, Kibana shows errors for some built in rules, the error says: \[security\_exception\] Reason: missing authentication credentials for REST request \[/\_security/user/\_has\_privileges\], caused by: "" and my master node …

---

## [In Kibana dashboard graph, what is unit of value format being selected as default? I have attached the snapshot below](https://discuss.elastic.co/t/in-kibana-dashboard-graph-what-is-unit-of-value-format-being-selected-as-default-i-have-attached-the-snapshot-below/340242)

<div class="topic-metadata">

**Author:** [@Abhinav\_Sharma](https://discuss.elastic.co/u/Abhinav_Sharma)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 6:38pm UTC](https://discuss.elastic.co/t/in-kibana-dashboard-graph-what-is-unit-of-value-format-being-selected-as-default-i-have-attached-the-snapshot-below/340242 "2023-08-11T18:38:12Z")

</div>

---

## [\[Filebeat\]\[httpconf\] AuthenticationMissingOrInvalid](https://discuss.elastic.co/t/filebeat-httpconf-authenticationmissingorinvalid/340269)

<div class="topic-metadata">

**Author:** [@Mohammed\_Amine\_El\_ha](https://discuss.elastic.co/u/Mohammed_Amine_El_ha)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 6:35pm UTC](https://discuss.elastic.co/t/filebeat-httpconf-authenticationmissingorinvalid/340269 "2023-08-11T18:35:36Z")

</div>

Hi, I need to get logs from a rest API, I tried this config in My filebeat.yml: filebeat.inputs: type: httpjson request.url: ---------------------------------- request.transforms: set: target: header.Authorizatio…

---

## [Split One Lined "Message" field information](https://discuss.elastic.co/t/split-one-lined-message-field-information/340281)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 6:32pm UTC](https://discuss.elastic.co/t/split-one-lined-message-field-information/340281 "2023-08-11T18:32:58Z")

</div>

Hi, In my dynamic syslogs in eleasticsearch, A fields called "messages" has over 7 lines of data, I need to split that single line into different field. I have a special character "\\r\\n" before required split informatio…

---

## [Script\_field](https://discuss.elastic.co/t/script-field/340660)

<div class="topic-metadata">

**Author:** [@poonamd](https://discuss.elastic.co/u/poonamd)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:21pm UTC](https://discuss.elastic.co/t/script-field/340660 "2023-08-11T17:21:16Z")

</div>

I am trying to return a date from a painless script and then use that date in the query -\> bool -\> filter range query. But this does not seem to work. How should I access the first element of the newVal array? Is the S…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=451)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=453)
