# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=458

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 459

---

## [Issues Moving Elasticsearch and Kibana to new server (with all existing custom indexes and dashboards)](https://discuss.elastic.co/t/issues-moving-elasticsearch-and-kibana-to-new-server-with-all-existing-custom-indexes-and-dashboards/340189)

<div class="topic-metadata">

**Author:** [@Akjal](https://discuss.elastic.co/u/Akjal)\
**Replies:** 10\
**Last updated:** [August 7, 2023, 8:44pm UTC](https://discuss.elastic.co/t/issues-moving-elasticsearch-and-kibana-to-new-server-with-all-existing-custom-indexes-and-dashboards/340189 "2023-08-07T20:44:45Z")

</div>

Hello there, I am working on a large ec2 ubuntu instance where I manually downloaded and installed elasticsearch and kibana (I didn't use docker) . I connected my stack with external data sources and made a lot of custo…

---

## [Export connector using saved objects api](https://discuss.elastic.co/t/export-connector-using-saved-objects-api/338011)

<div class="topic-metadata">

**Author:** [@Bhrugu\_Sharma](https://discuss.elastic.co/u/Bhrugu_Sharma)\
**Replies:** 4\
**Last updated:** [August 7, 2023, 7:42pm UTC](https://discuss.elastic.co/t/export-connector-using-saved-objects-api/338011 "2023-08-07T19:42:20Z")

</div>

I am trying to export connectors from few of my spaces using saved objects api the request body looks like body ={ "type": "connector", "includeReferencesDeep": True } but when i do the request it says "statu…

---

## [Fetch substring from a string in logstash filter](https://discuss.elastic.co/t/fetch-substring-from-a-string-in-logstash-filter/340223)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 5:36pm UTC](https://discuss.elastic.co/t/fetch-substring-from-a-string-in-logstash-filter/340223 "2023-08-07T17:36:04Z")

</div>

Hi, I have a field called url in elasticsearch document. The sample value for the field is /3dpassport/login I want to extract only the first string before / that is 3dpassport and store it in a field. Tried this copy…

---

## [Logstash Twitter error - no address for stream.twitter.com](https://discuss.elastic.co/t/logstash-twitter-error-no-address-for-stream-twitter-com/340238)

<div class="topic-metadata">

**Author:** [@Yochai\_Ben-Chaim](https://discuss.elastic.co/u/Yochai_Ben-Chaim)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 5:27pm UTC](https://discuss.elastic.co/t/logstash-twitter-error-no-address-for-stream-twitter-com/340238 "2023-08-07T17:27:56Z")

</div>

I am trying to use the twitter plugin with the latest ELK stack (8.9.0). When I activate logstash -f myconf\_file.conf I am getting error messages messages : "no address for stream.twitter.com" My conf file is very bas…

---

## [Logstash unable to send network log to elastic search database but raw data successfully store in system](https://discuss.elastic.co/t/logstash-unable-to-send-network-log-to-elastic-search-database-but-raw-data-successfully-store-in-system/340243)

<div class="topic-metadata">

**Author:** [@Kiran\_K](https://discuss.elastic.co/u/Kiran_K)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 5:22pm UTC](https://discuss.elastic.co/t/logstash-unable-to-send-network-log-to-elastic-search-database-but-raw-data-successfully-store-in-system/340243 "2023-08-07T17:22:10Z")

</div>

\[WARN \] 2023-08-07 08:45:44.506 \[\[main\]-pipeline-manager\] elasticsearch - Detected a 6.x and above cluster: the type event field won't be used to determine the document \_type {:es\_version=\>8} \[INFO \] 2023-08-07 08:45:44…

---

## [Search for docs from last 24h on data field not timestamp](https://discuss.elastic.co/t/search-for-docs-from-last-24h-on-data-field-not-timestamp/338199)

<div class="topic-metadata">

**Author:** [@lemospt](https://discuss.elastic.co/u/lemospt)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 4:47pm UTC](https://discuss.elastic.co/t/search-for-docs-from-last-24h-on-data-field-not-timestamp/338199 "2023-08-07T16:47:39Z")

</div>

Hi, in my documents i have the field report\_last\_request, in kibana i need a query that get all documents that has the report\_last\_request date from last 24h. Hope is clear. Thanks in advance.

---

## [Slow query concerns, how to optimize?](https://discuss.elastic.co/t/slow-query-concerns-how-to-optimize/339902)

<div class="topic-metadata">

**Author:** [@chenlx594](https://discuss.elastic.co/u/chenlx594)\
**Replies:** 6\
**Last updated:** [August 7, 2023, 4:34pm UTC](https://discuss.elastic.co/t/slow-query-concerns-how-to-optimize/339902 "2023-08-07T16:34:44Z")

</div>

Originally, there was an index a1. Now, it's modified to have index a1 with alias A, and index a2 with alias A. When querying using alias A, the query speed increases from 7ms to 60ms compared to directly querying using …

---

## [Making complete row of data table clickable (Drilldown)](https://discuss.elastic.co/t/making-complete-row-of-data-table-clickable-drilldown/340288)

<div class="topic-metadata">

**Author:** [@hughes](https://discuss.elastic.co/u/hughes)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 4:22pm UTC](https://discuss.elastic.co/t/making-complete-row-of-data-table-clickable-drilldown/340288 "2023-08-07T16:22:52Z")

</div>

This is to further expand off of this post. I have the paid version of elastic, but still am unable to execute the drilldown from clicking the table row. There are three dots on the far right side of the row that I inst…

---

## [Metricbeat docker.network\_summary does not work from within a container?](https://discuss.elastic.co/t/metricbeat-docker-network-summary-does-not-work-from-within-a-container/339226)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 3:33pm UTC](https://discuss.elastic.co/t/metricbeat-docker-network-summary-does-not-work-from-within-a-container/339226 "2023-08-07T15:33:49Z")

</div>

So, judging from this error I've been getting today: lanewell-metricbeat-app | {"log.level":"error","@timestamp":"2023-07-25T20:06:51.398Z","log.origin":{"file.name":"module/wrapper.go","file.line":263},"message":"Erro…

---

## [Kibana canvas auto refresh dont' work and sets automaticcaly to manual](https://discuss.elastic.co/t/kibana-canvas-auto-refresh-dont-work-and-sets-automaticcaly-to-manual/339932)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 4\
**Last updated:** [August 7, 2023, 3:17pm UTC](https://discuss.elastic.co/t/kibana-canvas-auto-refresh-dont-work-and-sets-automaticcaly-to-manual/339932 "2023-08-07T15:17:16Z")

</div>

Hello All, I'm trying to embedd the kibana canvas in my custom webui as LIVE ALERTS for admins. The auto refresh interval dosen't seems to work correctly or has some bugs, not sure. Everytime I'm setting auto refresh …

---

## [Get \`Error: s is undefined\` when browsing to "Management-\>Data-\>Transforms"](https://discuss.elastic.co/t/get-error-s-is-undefined-when-browsing-to-management-data-transforms/340276)

<div class="topic-metadata">

**Author:** [@tolland](https://discuss.elastic.co/u/tolland)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 3:13pm UTC](https://discuss.elastic.co/t/get-error-s-is-undefined-when-browsing-to-management-data-transforms/340276 "2023-08-07T15:13:47Z")

</div>

I have a kibana / elasticsearch installed from rpms version 8.9.0 on rocky-8 linux. Security is disabled. When I browse to the Transforms menu: http://elasticsearch.lan:5601/app/management/data/transform I get the foll…

---

## [Kibana Message Parse](https://discuss.elastic.co/t/kibana-message-parse/339976)

<div class="topic-metadata">

**Author:** [@Kumbum](https://discuss.elastic.co/u/Kumbum)\
**Replies:** 10\
**Last updated:** [August 7, 2023, 3:09pm UTC](https://discuss.elastic.co/t/kibana-message-parse/339976 "2023-08-07T15:09:21Z")

</div>

I have a custom log file in a source machine and it comes as a single-line log through "message" attribute to the Dashboard message = \<INFO/ERROR/FATAL, etc\>, , , , , , I want this message gets split as below. messag…

---

## [Delete data stream and all it's index](https://discuss.elastic.co/t/delete-data-stream-and-all-its-index/340085)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [August 7, 2023, 3:03pm UTC](https://discuss.elastic.co/t/delete-data-stream-and-all-its-index/340085 "2023-08-07T15:03:12Z")

</div>

I have a test data stream. it works fine. But now I am trying to delete it and I can't When I do delete via command or via GUI it recreates it self DELETE /\_data\_stream/msyos1-log I can't delete index template as wel…

---

## [Wazuh template ILM policy resets to blank post-upgrade to 4.4.4](https://discuss.elastic.co/t/wazuh-template-ilm-policy-resets-to-blank-post-upgrade-to-4-4-4/340260)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 2:39pm UTC](https://discuss.elastic.co/t/wazuh-template-ilm-policy-resets-to-blank-post-upgrade-to-4-4-4/340260 "2023-08-07T14:39:58Z")

</div>

Hi, I use Wazuh with Elastic, and recently I performed an update of wazuh to 4.4.4. Since the upgrade the ILM policy on the Wazuh template reset to null and therefore indexes didn't roll over. I thought i fixed the ind…

---

## [Auto download Chromium in kibana](https://discuss.elastic.co/t/auto-download-chromium-in-kibana/336708)

<div class="topic-metadata">

**Author:** [@Suresh\_Ghatuwa](https://discuss.elastic.co/u/Suresh_Ghatuwa)\
**Replies:** 4\
**Last updated:** [August 7, 2023, 2:20pm UTC](https://discuss.elastic.co/t/auto-download-chromium-in-kibana/336708 "2023-08-07T14:20:30Z")

</div>

On starting Kibana 8.6.2, chromium browser was downloaded automatically internally for reporting purpose (i guess). Path: \<kibana\_path\>/x-pack/plugins/screenshotting/chromium/\* Can we disable auto download the chromium…

---

## [In MySQL to create a database we execute a query: CREATE DATABASE DEMODB, so can we create a DATABASE in Elasticsearch also?](https://discuss.elastic.co/t/in-mysql-to-create-a-database-we-execute-a-query-create-database-demodb-so-can-we-create-a-database-in-elasticsearch-also/340279)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 1:41pm UTC](https://discuss.elastic.co/t/in-mysql-to-create-a-database-we-execute-a-query-create-database-demodb-so-can-we-create-a-database-in-elasticsearch-also/340279 "2023-08-07T13:41:58Z")

</div>

If possible, give me reference link or Command here.

---

## [Security autoconfiguration information](https://discuss.elastic.co/t/security-autoconfiguration-information/340100)

<div class="topic-metadata">

**Author:** [@usman1](https://discuss.elastic.co/u/usman1)\
**Replies:** 6\
**Last updated:** [August 7, 2023, 1:33pm UTC](https://discuss.elastic.co/t/security-autoconfiguration-information/340100 "2023-08-07T13:33:15Z")

</div>

I have just installed the newest version of Elasticsearch using the official guide but did not come across 'Security autoconfiguration information' screen. Now when I try to start Elasticsearch using the following comman…

---

## [Custom plugins not working anymore](https://discuss.elastic.co/t/custom-plugins-not-working-anymore/339826)

<div class="topic-metadata">

**Author:** [@pchakour](https://discuss.elastic.co/u/pchakour)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 12:20pm UTC](https://discuss.elastic.co/t/custom-plugins-not-working-anymore/339826 "2023-08-07T12:20:30Z")

</div>

Hello everyone, I'm working on custom plugins migration and I'm facing a problem. My problem is also encountered and explained by somebody else in this thread : Kibana plugin development: Error when creating plugin in K…

---

## [Unexpected HTTP Error (503) when running Elasticsearch tools](https://discuss.elastic.co/t/unexpected-http-error-503-when-running-elasticsearch-tools/340263)

<div class="topic-metadata">

**Author:** [@General-Trident](https://discuss.elastic.co/u/General-Trident)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 11:09am UTC](https://discuss.elastic.co/t/unexpected-http-error-503-when-running-elasticsearch-tools/340263 "2023-08-07T11:09:09Z")

</div>

Need help on how to resolve issue at Elasticsearch tools not working All permissions on $ES\_HOME using command ls -ltr : \[root@localhost bin\]# ls -ltr total 3204 -rwxr-xr-x. 1 root root 353 Jul 19 21:46 elasticsear…

---

## [Multiline regexp](https://discuss.elastic.co/t/multiline-regexp/340257)

<div class="topic-metadata">

**Author:** [@Drewolf](https://discuss.elastic.co/u/Drewolf)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 10:41am UTC](https://discuss.elastic.co/t/multiline-regexp/340257 "2023-08-07T10:41:35Z")

</div>

background I want to write a regular expression that matches the line which contain "Exception" and does not contain "DebugModeException". In the following example, the first line contains "DebugModeException" and doe…

---

## [Hide Some Filters](https://discuss.elastic.co/t/hide-some-filters/340235)

<div class="topic-metadata">

**Author:** [@fenixon](https://discuss.elastic.co/u/fenixon)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 10:36am UTC](https://discuss.elastic.co/t/hide-some-filters/340235 "2023-08-07T10:36:58Z")

</div>

I want to hide some particular filters in kibana dashboard. Is it possible?

---

## [Runtime/cgo: pthread\_create failed: Operation not permitted SIGABRT: abort PC=0x7f46dd713a7c m=2 sigcode=18446744073709551610](https://discuss.elastic.co/t/runtime-cgo-pthread-create-failed-operation-not-permitted-sigabrt-abort-pc-0x7f46dd713a7c-m-2-sigcode-18446744073709551610/340253)

<div class="topic-metadata">

**Author:** [@linxx](https://discuss.elastic.co/u/linxx)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 10:11am UTC](https://discuss.elastic.co/t/runtime-cgo-pthread-create-failed-operation-not-permitted-sigabrt-abort-pc-0x7f46dd713a7c-m-2-sigcode-18446744073709551610/340253 "2023-08-07T10:11:06Z")

</div>

linxx@ubuntu:~/module/filebeat-6.8.13-linux-x86\_64$ ./filebeat -e 2023-08-07T11:29:18.205+0800 INFO instance/beat.go:611 Home path: \[/home/linxx/module/filebeat-6.8.13-linux-x86\_64\] Config path: \[/home/linxx/mo…

---

## [What is status of the logs in case of agents unavailability](https://discuss.elastic.co/t/what-is-status-of-the-logs-in-case-of-agents-unavailability/340111)

<div class="topic-metadata">

**Author:** [@ankitha\_sn](https://discuss.elastic.co/u/ankitha_sn)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 7:29am UTC](https://discuss.elastic.co/t/what-is-status-of-the-logs-in-case-of-agents-unavailability/340111 "2023-08-07T07:29:59Z")

</div>

Hi Team, I have some queries. If the agent is down, what is the status of the logs? Will it send the logs to Elastic DB once it is up? Here logs mean agent downtime logs. Thanks, Ankitha

---

## [Include logs with custom logs](https://discuss.elastic.co/t/include-logs-with-custom-logs/340231)

<div class="topic-metadata">

**Author:** [@shubham.s](https://discuss.elastic.co/u/shubham.s)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 7:01am UTC](https://discuss.elastic.co/t/include-logs-with-custom-logs/340231 "2023-08-07T07:01:33Z")

</div>

Hi, I have successfully integrated logs with the help of elastic-agent and integrated custom logs. Now I want elastic agent to process only logs from the file which contains specific keyword. I want elastic agent to exc…

---

## [KIBANA and ELASTICSEARCH 8.9X not working either SELFSIGNED or Custom SSL certs over WebBrowser](https://discuss.elastic.co/t/kibana-and-elasticsearch-8-9x-not-working-either-selfsigned-or-custom-ssl-certs-over-webbrowser/340229)

<div class="topic-metadata">

**Author:** [@Penchala\_Abhilash\_Mu](https://discuss.elastic.co/u/Penchala_Abhilash_Mu)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 6:54am UTC](https://discuss.elastic.co/t/kibana-and-elasticsearch-8-9x-not-working-either-selfsigned-or-custom-ssl-certs-over-webbrowser/340229 "2023-08-07T06:54:49Z")

</div>

Hi Team we were implemented Elasticsearch and KIBANA 8.9 over Single UBUNTU 20.4 VM. The service runs internally (locally over VM) but unable to resolved over WEB BROWSER unable to execute /resolve the domain. Tested Be…

---

## [In ELK stack can we know if how many users have logged in and logged out and how many dashboards they have accessed?](https://discuss.elastic.co/t/in-elk-stack-can-we-know-if-how-many-users-have-logged-in-and-logged-out-and-how-many-dashboards-they-have-accessed/339395)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 4\
**Last updated:** [August 7, 2023, 6:58am UTC](https://discuss.elastic.co/t/in-elk-stack-can-we-know-if-how-many-users-have-logged-in-and-logged-out-and-how-many-dashboards-they-have-accessed/339395 "2023-08-07T06:58:45Z")

</div>

Hi Team, In our ELK stack can we know if how many users have logged in and logged out and how many dashboards they have accessed? Thanks in Adavance.

---

## [Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create\<main\>, action\_result: false", :backtrace=\>nil](https://discuss.elastic.co/t/failed-to-execute-action-id-main-action-type-logstash-failedaction-message-could-not-execute-action-pipelineaction-create-main-action-result-false-backtrace-nil/340116)

<div class="topic-metadata">

**Author:** [@ItsGautam](https://discuss.elastic.co/u/ItsGautam)\
**Replies:** 3\
**Last updated:** [August 7, 2023, 5:30am UTC](https://discuss.elastic.co/t/failed-to-execute-action-id-main-action-type-logstash-failedaction-message-could-not-execute-action-pipelineaction-create-main-action-result-false-backtrace-nil/340116 "2023-08-07T05:30:44Z")

</div>

Hi, I am new to the elasticsearch. i ve tried to find the solution but ...... \[2023-08-04T13:09:08,778\]\[INFO \]\[logstash.javapipeline \]\[main\] Pipeline terminated {"pipeline.id"=\>"main"} \[2023-08-04T13:09:08,806\]\[ERR…

---

## [Cumulative Sum String field](https://discuss.elastic.co/t/cumulative-sum-string-field/340216)

<div class="topic-metadata">

**Author:** [@dro](https://discuss.elastic.co/u/dro)\
**Replies:** 4\
**Last updated:** [August 7, 2023, 3:19am UTC](https://discuss.elastic.co/t/cumulative-sum-string-field/340216 "2023-08-07T03:19:18Z")

</div>

I've tried searching on the forum, but haven't really found something similar. Is there a method to show a cumulative sum of a field of type string using Lens or TVSB? For example a field of data with string types YES …

---

## [Filebeat processors drop\_fields has no effect](https://discuss.elastic.co/t/filebeat-processors-drop-fields-has-no-effect/340213)

<div class="topic-metadata">

**Author:** [@Drewolf](https://discuss.elastic.co/u/Drewolf)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 3:14am UTC](https://discuss.elastic.co/t/filebeat-processors-drop-fields-has-no-effect/340213 "2023-08-07T03:14:00Z")

</div>

background this processors can not drop field "agent\_name" my filebeat config filebeat.inputs: - type: container paths: # - /var/log/containers/xgimi-launcher\*.log - /var/log/containers/\*.log processor…

---

## [Logstash always queue in multiple pipeline](https://discuss.elastic.co/t/logstash-always-queue-in-multiple-pipeline/340131)

<div class="topic-metadata">

**Author:** [@jact](https://discuss.elastic.co/u/jact)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 3:13am UTC](https://discuss.elastic.co/t/logstash-always-queue-in-multiple-pipeline/340131 "2023-08-07T03:13:45Z")

</div>

Hi Master, i'm using logstash 8.8 i'm on stuck in this condtion. after i created multiple pipeline like this - pipeline.id: beats path.config: "/etc/logstash/conf.d/beats.conf" pipeline.workers: 3 - pipeline.id: …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=457)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=459)
