# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=468

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 469

---

## [How to Create a list of Buttons (with link) when specific selected button is clicked there is a new set of sub buttons (links) that user can click in Mardown Visualisation?](https://discuss.elastic.co/t/how-to-create-a-list-of-buttons-with-link-when-specific-selected-button-is-clicked-there-is-a-new-set-of-sub-buttons-links-that-user-can-click-in-mardown-visualisation/339275)

<div class="topic-metadata">

**Author:** [@SHAIK\_ASMA\_ZABI\_18BB](https://discuss.elastic.co/u/SHAIK_ASMA_ZABI_18BB)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 3:58pm UTC](https://discuss.elastic.co/t/how-to-create-a-list-of-buttons-with-link-when-specific-selected-button-is-clicked-there-is-a-new-set-of-sub-buttons-links-that-user-can-click-in-mardown-visualisation/339275 "2023-07-27T15:58:51Z")

</div>

I am using Markdown Visualization in which there are 5 buttons which have individual dashboard loading links. From those dashboard links there are sub buttons coming up which have their own dashboard loading links. How d…

---

## [Upgrading from 7.11.1 to 7.17 with only one node in the Cluster](https://discuss.elastic.co/t/upgrading-from-7-11-1-to-7-17-with-only-one-node-in-the-cluster/339455)

<div class="topic-metadata">

**Author:** [@getmoin](https://discuss.elastic.co/u/getmoin)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 2:51pm UTC](https://discuss.elastic.co/t/upgrading-from-7-11-1-to-7-17-with-only-one-node-in-the-cluster/339455 "2023-07-27T14:51:55Z")

</div>

Hi everyone, I have an Elastic search in prod, hosting on GCP. The present version of the Elastic search is 7.11.1 and its in yellow (EOL) in the dashboard.I want to upgrade it to the 7.17.12. And then to the 8.x I hav…

---

## [Kibana 8.9.0 plugin build failure](https://discuss.elastic.co/t/kibana-8-9-0-plugin-build-failure/339351)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 3\
**Last updated:** [July 27, 2023, 2:47pm UTC](https://discuss.elastic.co/t/kibana-8-9-0-plugin-build-failure/339351 "2023-07-27T14:47:36Z")

</div>

Hi we have updated our plugin from 8.8.1 to 8.9.0 and are hitting this error yarn bootstrap yarn run v1.22.19 $ yarn kbn bootstrap && yarn install $ node ../../scripts/kbn bootstrap \[bazel\] INFO: Invocation ID: 63a2c789…

---

## [Elastic memmory size](https://discuss.elastic.co/t/elastic-memmory-size/339450)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 2\
**Last updated:** [July 27, 2023, 2:45pm UTC](https://discuss.elastic.co/t/elastic-memmory-size/339450 "2023-07-27T14:45:40Z")

</div>

Hi i have this error when i ingest my nodes with logstsh data the thing is that the nodes were block because the memory what to small for the size of data but i change the path data to another that has 5 Teras o f memor…

---

## [ES SQL against index pattern](https://discuss.elastic.co/t/es-sql-against-index-pattern/339447)

<div class="topic-metadata">

**Author:** [@tangkalo](https://discuss.elastic.co/u/tangkalo)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 2:45pm UTC](https://discuss.elastic.co/t/es-sql-against-index-pattern/339447 "2023-07-27T14:45:27Z")

</div>

Hi, one of my ES SQL in a Canvas workpad runs against an index pattern(i.e. some-index-name\* ) which cannot be found in the dropdown list of Kibana Discover's dropdown list. Could this be a permission issue in Kibana? I…

---

## [Customize security exception error message](https://discuss.elastic.co/t/customize-security-exception-error-message/339191)

<div class="topic-metadata">

**Author:** [@Juan\_Heredia\_Heredia](https://discuss.elastic.co/u/Juan_Heredia_Heredia)\
**Replies:** 0\
**Last updated:** [July 25, 2023, 12:15pm UTC](https://discuss.elastic.co/t/customize-security-exception-error-message/339191 "2023-07-25T12:15:27Z")

</div>

Hello everyone! I am novice in Kibana and this is my first topic in the group. Thanks in advance. It is possible to customize the error messages in Dev Tools Console? I need not shows the user and backend\_roles sec…

---

## [Best way to check if a database (postgres and mssql) is up and running using metricbeat?](https://discuss.elastic.co/t/best-way-to-check-if-a-database-postgres-and-mssql-is-up-and-running-using-metricbeat/339336)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 2:24pm UTC](https://discuss.elastic.co/t/best-way-to-check-if-a-database-postgres-and-mssql-is-up-and-running-using-metricbeat/339336 "2023-07-27T14:24:23Z")

</div>

Hi, what whould the best way to check if a database (postgres and mssql) is up and running using metricbeat? I need to create alerts if a database is down, in kibana "Alerts an Insights -\> rules" there is an option to a…

---

## [Does adding a custom endpoint alias retain the original random URL?](https://discuss.elastic.co/t/does-adding-a-custom-endpoint-alias-retain-the-original-random-url/339449)

<div class="topic-metadata">

**Author:** [@sparrowt](https://discuss.elastic.co/u/sparrowt)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 2:21pm UTC](https://discuss.elastic.co/t/does-adding-a-custom-endpoint-alias-retain-the-original-random-url/339449 "2023-07-27T14:21:31Z")

</div>

If you create a 'custom endpoint alias' as described here, how long will the existing, original, random URL endpoints keep working for? For example with an existing Elastic Cloud deployment with Deployment ID Stringwith…

---

## [How to hide 3 dots on the top right of the pane](https://discuss.elastic.co/t/how-to-hide-3-dots-on-the-top-right-of-the-pane/339287)

<div class="topic-metadata">

**Author:** [@Jvv\_Satya](https://discuss.elastic.co/u/Jvv_Satya)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 2:04pm UTC](https://discuss.elastic.co/t/how-to-hide-3-dots-on-the-top-right-of-the-pane/339287 "2023-07-27T14:04:27Z")

</div>

I am using Kibana 8.6.2. I have developed a dashboard and embedded the URL in an iFrame in my application. However, I see the 3 dots on the top right of every pane. Is it possible to disable it. Also, can we hide the (…

---

## [What's the number of Elser parameter?](https://discuss.elastic.co/t/whats-the-number-of-elser-parameter/339446)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 1:40pm UTC](https://discuss.elastic.co/t/whats-the-number-of-elser-parameter/339446 "2023-07-27T13:40:58Z")

</div>

The model binary is 400M in size. Looks like BERT. But I believe Elser must be quantized or distilled, since it took much more time to run in my laptop

---

## [Is it always necessary to use size attribute in DSL query?](https://discuss.elastic.co/t/is-it-always-necessary-to-use-size-attribute-in-dsl-query/339377)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 3\
**Last updated:** [July 27, 2023, 1:23pm UTC](https://discuss.elastic.co/t/is-it-always-necessary-to-use-size-attribute-in-dsl-query/339377 "2023-07-27T13:23:26Z")

</div>

Hi, Is it always necessary to use the size attribute in Elasticsearch DSL query? What if there are many documents and I do not know the exact no of documents that I would need? I am trying to get the last poll data fr…

---

## [Elastic Enterprise Pricing](https://discuss.elastic.co/t/elastic-enterprise-pricing/339439)

<div class="topic-metadata">

**Author:** [@mahan\_masih](https://discuss.elastic.co/u/mahan_masih)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 1:06pm UTC](https://discuss.elastic.co/t/elastic-enterprise-pricing/339439 "2023-07-27T13:06:24Z")

</div>

Hi, How is Elastic licensing priced? Is it per node, per eps, which parameter affects the price? This is for an on-prem cluster. Does anybody have an idea of the Enterprise license price? This is for an 8 nodes clust…

---

## [Does Elasticsearch capture audit logs for Query DSL, EQL and SQL or Not?](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 12\
**Last updated:** [July 27, 2023, 12:43pm UTC](https://discuss.elastic.co/t/does-elasticsearch-capture-audit-logs-for-query-dsl-eql-and-sql-or-not/339398 "2023-07-27T12:43:41Z")

</div>

Does Elasticsearch capture audit logs for Query DSL, EQL and SQL or Not???

---

## [How to switch y-axis to x-axis](https://discuss.elastic.co/t/how-to-switch-y-axis-to-x-axis/339393)

<div class="topic-metadata">

**Author:** [@hananz](https://discuss.elastic.co/u/hananz)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 11:23am UTC](https://discuss.elastic.co/t/how-to-switch-y-axis-to-x-axis/339393 "2023-07-27T11:23:51Z")

</div>

Hi using Kibana 8.8 and lens my data is series of sample points (CSV file), trying to show a line graph: X-axis as counter and Y-axis as the data points. the best result is a graph with the axis in the wrong positions…

---

## [I have install elasticsearch 8.5.3 in K8s, the pods are not getting up, shows error\[failed to bind service\]](https://discuss.elastic.co/t/i-have-install-elasticsearch-8-5-3-in-k8s-the-pods-are-not-getting-up-shows-error-failed-to-bind-service/339421)

<div class="topic-metadata">

**Author:** [@Rahul\_madugula](https://discuss.elastic.co/u/Rahul_madugula)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 10:37am UTC](https://discuss.elastic.co/t/i-have-install-elasticsearch-8-5-3-in-k8s-the-pods-are-not-getting-up-shows-error-failed-to-bind-service/339421 "2023-07-27T10:37:13Z")

</div>

---

## [How to loop over the ctx results, so as to send the extracted details in email alert?](https://discuss.elastic.co/t/how-to-loop-over-the-ctx-results-so-as-to-send-the-extracted-details-in-email-alert/339419)

<div class="topic-metadata">

**Author:** [@Divya\_Thaore](https://discuss.elastic.co/u/Divya_Thaore)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 10:17am UTC](https://discuss.elastic.co/t/how-to-loop-over-the-ctx-results-so-as-to-send-the-extracted-details-in-email-alert/339419 "2023-07-27T10:17:58Z")

</div>

The result set for example is : { "\_shards": { "total": 14, "failed": 0, "successful": 14, "skipped": 0 }, "hits": { "hits": \[ { "\_index": "logs-cfsyslog-2023.07.26", "\_type": "\_doc", "\_source": { "msg": "-…

---

## [How to download platinum and enterprise version of elasticsearch for free trail](https://discuss.elastic.co/t/how-to-download-platinum-and-enterprise-version-of-elasticsearch-for-free-trail/339256)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 19\
**Last updated:** [July 27, 2023, 10:23am UTC](https://discuss.elastic.co/t/how-to-download-platinum-and-enterprise-version-of-elasticsearch-for-free-trail/339256 "2023-07-27T10:23:59Z")

</div>

Please provide the link for download platinum or enterprise version of elasticsearch for free trail in Linux and rpm system.

---

## [Elasticsearch not capturing audit logs while I am executing index creation queries, SQL queries mention in ELASTICSEARCH documentation](https://discuss.elastic.co/t/elasticsearch-not-capturing-audit-logs-while-i-am-executing-index-creation-queries-sql-queries-mention-in-elasticsearch-documentation/339381)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 10:22am UTC](https://discuss.elastic.co/t/elasticsearch-not-capturing-audit-logs-while-i-am-executing-index-creation-queries-sql-queries-mention-in-elasticsearch-documentation/339381 "2023-07-27T10:22:00Z")

</div>

I am executing index creation queries and SQL queries mention in ELASTICSEARCH documentation, but I am not getting audit logs regarding these queries. Can anyone tell me which kind audit logs only we can get while execu…

---

## [Can't start elastic elasticsearch-8.9.0](https://discuss.elastic.co/t/cant-start-elastic-elasticsearch-8-9-0/339299)

<div class="topic-metadata">

**Author:** [@choilee](https://discuss.elastic.co/u/choilee)\
**Replies:** 10\
**Last updated:** [July 27, 2023, 10:00am UTC](https://discuss.elastic.co/t/cant-start-elastic-elasticsearch-8-9-0/339299 "2023-07-27T10:00:10Z")

</div>

I installed elasticsearch-8.9.0 on root account in centos 7 But couldn't start. i use this command "systemctl start elasticsearch.service" And i couldn't find any wrong Permission....help please...ㅠㅠ Jul 26 20:06:43 S…

---

## [Elastic Agent error out with log\_group\_arn, log\_group\_name and log\_group\_name\_prefix config cannot all be empty](https://discuss.elastic.co/t/elastic-agent-error-out-with-log-group-arn-log-group-name-and-log-group-name-prefix-config-cannot-all-be-empty/339414)

<div class="topic-metadata">

**Author:** [@The2](https://discuss.elastic.co/u/The2)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 9:56am UTC](https://discuss.elastic.co/t/elastic-agent-error-out-with-log-group-arn-log-group-name-and-log-group-name-prefix-config-cannot-all-be-empty/339414 "2023-07-27T09:56:01Z")

</div>

Hello, I'm trying to use elastic-agent to integrate with AWS to fetch cloudwatch logs. However i'm facing this issue: Unit state changed aws-cloudwatch-default-aws-cloudwatch-cloudwatch-481de7b4-7c2d-4fbf-9156-3acdd53…

---

## [decayDateGauss gives different results depending on the amount of hits](https://discuss.elastic.co/t/decaydategauss-gives-different-results-depending-on-the-amount-of-hits/339415)

<div class="topic-metadata">

**Author:** [@Massimo\_Redaelli](https://discuss.elastic.co/u/Massimo_Redaelli)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 9:56am UTC](https://discuss.elastic.co/t/decaydategauss-gives-different-results-depending-on-the-amount-of-hits/339415 "2023-07-27T09:56:27Z")

</div>

I'm using a script\_score query where the score script is this: double decay = params.decays.getOrDefault(doc\['spider'\].value, 0.1); def ts = doc\['last\_update'\].size()!=0 ? doc\['last\_update'\].value : doc\['timestamp'\].va…

---

## [Kibana - No results match your search criteria](https://discuss.elastic.co/t/kibana-no-results-match-your-search-criteria/339319)

<div class="topic-metadata">

**Author:** [@jsingleton71](https://discuss.elastic.co/u/jsingleton71)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 9:38am UTC](https://discuss.elastic.co/t/kibana-no-results-match-your-search-criteria/339319 "2023-07-27T09:38:26Z")

</div>

All, I have more than 1000 IIS access logs ingested into Elasticsearch 8.8.1. This amounts to around 100GB in actual storage. I can query the data from a Jupyter Notebook and get results using the same indexes. I have c…

---

## [Cannot read properties of undefined (reading 'hapi')"](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-hapi/339403)

<div class="topic-metadata">

**Author:** [@chep](https://discuss.elastic.co/u/chep)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 8:45am UTC](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-hapi/339403 "2023-07-27T08:45:29Z")

</div>

curl -X POST "KIbana URL/api/detection\_engine/rules/\_import" -H 'Content-Type: application/json' -u offsec:student -H 'kbn-xsrf: true' -H 'Content-Type: multipart/form-data' --form "file=@/home/bourne/Downloads/rules\_exp…

---

## [Elastic agent showing disable in windows services. How to resolved this issue](https://discuss.elastic.co/t/elastic-agent-showing-disable-in-windows-services-how-to-resolved-this-issue/339401)

<div class="topic-metadata">

**Author:** [@Tushar02](https://discuss.elastic.co/u/Tushar02)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 8:28am UTC](https://discuss.elastic.co/t/elastic-agent-showing-disable-in-windows-services-how-to-resolved-this-issue/339401 "2023-07-27T08:28:59Z")

</div>

elastic agent showing disable in windows services. How to resolved this issue

---

## [Char\_filter doesn't work properly](https://discuss.elastic.co/t/char-filter-doesnt-work-properly/339218)

<div class="topic-metadata">

**Author:** [@Vladimir\_Talabko](https://discuss.elastic.co/u/Vladimir_Talabko)\
**Replies:** 12\
**Last updated:** [July 27, 2023, 8:01am UTC](https://discuss.elastic.co/t/char-filter-doesnt-work-properly/339218 "2023-07-27T08:01:25Z")

</div>

Hello! I have an index with a char\_filter for avoiding special symbols like "-\_.": curl -X PUT "localhost:9200/test\_index?pretty" -H 'Content-Type: application/json' -d' { "settings": { "analysis": { …

---

## [Give wildcard for fieldname in emit() when creating Runtime field throws error](https://discuss.elastic.co/t/give-wildcard-for-fieldname-in-emit-when-creating-runtime-field-throws-error/339394)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 7:35am UTC](https://discuss.elastic.co/t/give-wildcard-for-fieldname-in-emit-when-creating-runtime-field-throws-error/339394 "2023-07-27T07:35:08Z")

</div>

Hi, I have a field, say macAddress in all my documents, but with different names. Like in some documents, it is host.macAddress, while in some it is machine.mac and so on. I want to create a runtime field called macAdd…

---

## [How to get the fleet server backup and restore](https://discuss.elastic.co/t/how-to-get-the-fleet-server-backup-and-restore/339384)

<div class="topic-metadata">

**Author:** [@ankitha\_sn](https://discuss.elastic.co/u/ankitha_sn)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 7:03am UTC](https://discuss.elastic.co/t/how-to-get-the-fleet-server-backup-and-restore/339384 "2023-07-27T07:03:10Z")

</div>

Hi Team, Need help in getting the fleet server backup and how to restore it. Thanks, Ankitha

---

## [Exception while attempting Migration from AWS OSS 1.3 to Elasticsearch 7.17](https://discuss.elastic.co/t/exception-while-attempting-migration-from-aws-oss-1-3-to-elasticsearch-7-17/337797)

<div class="topic-metadata">

**Author:** [@gaurav\_jain](https://discuss.elastic.co/u/gaurav_jain)\
**Replies:** 6\
**Last updated:** [July 25, 2023, 12:29pm UTC](https://discuss.elastic.co/t/exception-while-attempting-migration-from-aws-oss-1-3-to-elasticsearch-7-17/337797 "2023-07-25T12:29:12Z")

</div>

Hello. We are planning to migrate existing elastic cluster from AWS opensearch service 1.1 to Elastic Cloud: 7.17 with some indexes of ~50GB in size First, I launched an elastic cloud cluster : 7.17. Data migration e…

---

## [How to read indexed binary field data from doc values (in custom Query plugin)](https://discuss.elastic.co/t/how-to-read-indexed-binary-field-data-from-doc-values-in-custom-query-plugin/339387)

<div class="topic-metadata">

**Author:** [@Pyppe](https://discuss.elastic.co/u/Pyppe)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 6:19am UTC](https://discuss.elastic.co/t/how-to-read-indexed-binary-field-data-from-doc-values-in-custom-query-plugin/339387 "2023-07-27T06:19:40Z")

</div>

Hi! We're trying to write a custom query-plugin for Elasticsearch where we would use binary data for calculating scores (disclaimer: I've never written one before). Each document can have multiple vectors, so we cannot …

---

## [Extract fields from a field and add the total count](https://discuss.elastic.co/t/extract-fields-from-a-field-and-add-the-total-count/339386)

<div class="topic-metadata">

**Author:** [@joshuskarki](https://discuss.elastic.co/u/joshuskarki)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 6:09am UTC](https://discuss.elastic.co/t/extract-fields-from-a-field-and-add-the-total-count/339386 "2023-07-27T06:09:12Z")

</div>

I have this logs (json format) imported into elastic via logstash. "fields.models": "{'msp': '1', 'tcl': '1'}", with logstash, how do we extract the model name and calculate the total count The desired output should a…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=467)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=469)
