# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=470

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 471

---

## [Multiline Filter : How to group error logs with stacktrace to elastic search using logstash?](https://discuss.elastic.co/t/multiline-filter-how-to-group-error-logs-with-stacktrace-to-elastic-search-using-logstash/338952)

<div class="topic-metadata">

**Author:** [@karthi.charles](https://discuss.elastic.co/u/karthi.charles)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 11:57am UTC](https://discuss.elastic.co/t/multiline-filter-how-to-group-error-logs-with-stacktrace-to-elastic-search-using-logstash/338952 "2023-07-26T11:57:45Z")

</div>

I am trying to group Error logs which having stacktrace information using multiline filter. Not sure how to set pattern correctly. Kindly help me to config the correct pattern. This is my logging pattern, INFO | 2023-…

---

## [Install elasticsearch 8.8](https://discuss.elastic.co/t/install-elasticsearch-8-8/339304)

<div class="topic-metadata">

**Author:** [@abntkpi](https://discuss.elastic.co/u/abntkpi)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 11:54am UTC](https://discuss.elastic.co/t/install-elasticsearch-8-8/339304 "2023-07-26T11:54:44Z")

</div>

Hello, I intend to install Elasticsearch 8.8 on an Ubuntu 22.04 server following the link below: Install Elasticsearch with Debian Package | Elasticsearch Guide \[8.9\] | Elastic The server has internet access, and the a…

---

## [Why comments field not being displayed](https://discuss.elastic.co/t/why-comments-field-not-being-displayed/338228)

<div class="topic-metadata">

**Author:** [@Dana\_Pavaday](https://discuss.elastic.co/u/Dana_Pavaday)\
**Replies:** 8\
**Last updated:** [July 26, 2023, 11:16am UTC](https://discuss.elastic.co/t/why-comments-field-not-being-displayed/338228 "2023-07-26T11:16:40Z")

</div>

Why is the comment field not being displayed for some Affected Services field values (Memory, CPU) in the Dashboard when they are already being displayed in Discover? Is this an issue with the logstash? What should be d…

---

## [Incorrect links in Kibana plugin documentation](https://discuss.elastic.co/t/incorrect-links-in-kibana-plugin-documentation/339097)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 3\
**Last updated:** [July 26, 2023, 10:28am UTC](https://discuss.elastic.co/t/incorrect-links-in-kibana-plugin-documentation/339097 "2023-07-26T10:28:02Z")

</div>

Hi, Please update documentation for plugin development. There is very little/vague documentation, out of which most of them contains incorrect links to examples and github. This is just an example(Elasticsearch servic…

---

## [when bumped up beats version from 7.16 to 8.6.2, indices are not created](https://discuss.elastic.co/t/when-bumped-up-beats-version-from-7-16-to-8-6-2-indices-are-not-created/339282)

<div class="topic-metadata">

**Author:** [@skumarya](https://discuss.elastic.co/u/skumarya)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 9:20am UTC](https://discuss.elastic.co/t/when-bumped-up-beats-version-from-7-16-to-8-6-2-indices-are-not-created/339282 "2023-07-26T09:20:05Z")

</div>

we were using Elasticsearch version 7.16 earlier since we have bumped up the version to 8.6.2 for elasticsearch, kibana and filebeat indices are not created. we are using Helm version 3.12.2 Kubernetes version 1.25.4/1…

---

## [Charts plugin or @elastic/charts](https://discuss.elastic.co/t/charts-plugin-or-elastic-charts/339033)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 6\
**Last updated:** [July 26, 2023, 8:16am UTC](https://discuss.elastic.co/t/charts-plugin-or-elastic-charts/339033 "2023-07-26T08:16:11Z")

</div>

Hi, I am creating an external plugin in Kibana 8.8.1 using React. I want to create charts inside my plugin. I expect them to be clickable and also just like in Kibana, when I click on a particular chart item (like bar …

---

## [How to see audit log in for my deployment in elastic cloud](https://discuss.elastic.co/t/how-to-see-audit-log-in-for-my-deployment-in-elastic-cloud/339257)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 7:17am UTC](https://discuss.elastic.co/t/how-to-see-audit-log-in-for-my-deployment-in-elastic-cloud/339257 "2023-07-26T07:17:42Z")

</div>

I have run the insert the data in Elasticsearch through rest call and once I went to Log and metrics inside the elastic cloud GUI ,I am unable to find audit logs , only I am getting server log, Please guide me regarding…

---

## [Date Filter](https://discuss.elastic.co/t/date-filter/337023)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 3\
**Last updated:** [July 26, 2023, 7:11am UTC](https://discuss.elastic.co/t/date-filter/337023 "2023-07-26T07:11:23Z")

</div>

I am trying to see how many count of items named from the data index has expiry date less than 30 days from now and also the count of items having expiry date till the next 30 days. I have tried a lot in TSVB with three …

---

## [Process logs of different formats to JSON](https://discuss.elastic.co/t/process-logs-of-different-formats-to-json/339258)

<div class="topic-metadata">

**Author:** [@Chel\_Db](https://discuss.elastic.co/u/Chel_Db)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 6:45am UTC](https://discuss.elastic.co/t/process-logs-of-different-formats-to-json/339258 "2023-07-26T06:45:43Z")

</div>

I'm pretty new to ELK and I'm trying to push few of our service's logs to ES. Log funneling flow is --\> \` Fluentd --\> Logstash --\> ES --\> Kibana. \` A thing to note is that, each service has its own log format. Attach…

---

## [Write data to Elasticsearch through plugin](https://discuss.elastic.co/t/write-data-to-elasticsearch-through-plugin/339260)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 6:55am UTC](https://discuss.elastic.co/t/write-data-to-elasticsearch-through-plugin/339260 "2023-07-26T06:55:28Z")

</div>

Hi, I am creating an external plugin in Kibana 8.8.1 using React. I want to write data to an Elasticsearch index on a button click inside the plugin. I presume I will have to use the Elasticsearch service provided by …

---

## [I don't know , how to solve this errorr.. , while try to reset the passcode in terminul](https://discuss.elastic.co/t/i-dont-know-how-to-solve-this-errorr-while-try-to-reset-the-passcode-in-terminul/339242)

<div class="topic-metadata">

**Author:** [@hari\_prabhu](https://discuss.elastic.co/u/hari_prabhu)\
**Replies:** 4\
**Last updated:** [July 26, 2023, 5:07am UTC](https://discuss.elastic.co/t/i-dont-know-how-to-solve-this-errorr-while-try-to-reset-the-passcode-in-terminul/339242 "2023-07-26T05:07:17Z")

</div>

./elasticsearch-env: line 86: cd: /etc/elasticsearch: Permission denied \`\`\` 86th line : \`\`\` ES\_PATH\_CONF = "cd" "$ES\_PATH\_CONF" ; \`pwd\` \`\`\`

---

## [When using the index settings with auto\_expand\_replicas set to "0-all," an issue arises where primary shards are concentrated on specific nodes](https://discuss.elastic.co/t/when-using-the-index-settings-with-auto-expand-replicas-set-to-0-all-an-issue-arises-where-primary-shards-are-concentrated-on-specific-nodes/339185)

<div class="topic-metadata">

**Author:** [@wedul\_chul](https://discuss.elastic.co/u/wedul_chul)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 4:31am UTC](https://discuss.elastic.co/t/when-using-the-index-settings-with-auto-expand-replicas-set-to-0-all-an-issue-arises-where-primary-shards-are-concentrated-on-specific-nodes/339185 "2023-07-26T04:31:01Z")

</div>

Due to the service requirements, the setting "auto\_expand\_replicas" is configured as "0-all," enabling replica shards to be present on all nodes. However, there is an issue where primary shards are concentrated on a spec…

---

## [Heartbeat auto reload configuration file](https://discuss.elastic.co/t/heartbeat-auto-reload-configuration-file/339163)

<div class="topic-metadata">

**Author:** [@michael31](https://discuss.elastic.co/u/michael31)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 4:25am UTC](https://discuss.elastic.co/t/heartbeat-auto-reload-configuration-file/339163 "2023-07-26T04:25:41Z")

</div>

Hello, I am setting up heartbeat with auto reload configuration files under the monitor.d path. It works fine and loads new config files but the problem is that it loads only for new files, if I edit an existing file an…

---

## [Search error rate 100](https://discuss.elastic.co/t/search-error-rate-100/339235)

<div class="topic-metadata">

**Author:** [@maximiliano\_carrasco](https://discuss.elastic.co/u/maximiliano_carrasco)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 12:41am UTC](https://discuss.elastic.co/t/search-error-rate-100/339235 "2023-07-26T00:41:48Z")

</div>

I am trying to run a simple track with search operation but I keep getting 100 error rate, This is my track {% import "rally.helpers" as rally with context %} { "version": 2, "description": "Tracker-generated track…

---

## [Need advice on using Elasticsearch in a transaction processing application](https://discuss.elastic.co/t/need-advice-on-using-elasticsearch-in-a-transaction-processing-application/338265)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 11:13pm UTC](https://discuss.elastic.co/t/need-advice-on-using-elasticsearch-in-a-transaction-processing-application/338265 "2023-07-25T23:13:04Z")

</div>

We develop and maintain an ecommerce back-office fulfillment system. So, it has the transaction processing function to capture fulfillment requests from an ecommerce website, and the reporting, listing, and business fu…

---

## [How to overcome the two-billion limitation on the number of Elasticsearch records?](https://discuss.elastic.co/t/how-to-overcome-the-two-billion-limitation-on-the-number-of-elasticsearch-records/339232)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 11:01pm UTC](https://discuss.elastic.co/t/how-to-overcome-the-two-billion-limitation-on-the-number-of-elasticsearch-records/339232 "2023-07-25T23:01:55Z")

</div>

As explained in the below quoted post on StackOverflow, Elasticsearch has a limit of two billion documents. Yes there is limit to the number of docs per shard of 2 billion, which is a hard lucene limit. There is a max…

---

## [401 error when setting up filebeat google\_workspace integration](https://discuss.elastic.co/t/401-error-when-setting-up-filebeat-google-workspace-integration/338417)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 7\
**Last updated:** [July 25, 2023, 10:12pm UTC](https://discuss.elastic.co/t/401-error-when-setting-up-filebeat-google-workspace-integration/338417 "2023-07-25T22:12:52Z")

</div>

Hi All, I'm using filebeat (7.17.9) and trying to setup google workspace integration. I've followed all the steps in: I've got a json credential file: { "type": "service\_account", "project\_id": "gwm-168856537013…

---

## [Getting started - Kibana - ElasticSearch - logstash](https://discuss.elastic.co/t/getting-started-kibana-elasticsearch-logstash/339204)

<div class="topic-metadata">

**Author:** [@rajdevworks](https://discuss.elastic.co/u/rajdevworks)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 10:09pm UTC](https://discuss.elastic.co/t/getting-started-kibana-elasticsearch-logstash/339204 "2023-07-25T22:09:08Z")

</div>

Hello, I have different json files which I would like to visualize into Kibana after ingesting them to Elasticsearch. Where can I get started and do I need to define input/output filters?

---

## [We are seeing the issue on SonarQube with elasticsearch. Elastic search is not coming up preventing the sonarqube to be up and running](https://discuss.elastic.co/t/we-are-seeing-the-issue-on-sonarqube-with-elasticsearch-elastic-search-is-not-coming-up-preventing-the-sonarqube-to-be-up-and-running/339229)

<div class="topic-metadata">

**Author:** [@bipin23](https://discuss.elastic.co/u/bipin23)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 9:56pm UTC](https://discuss.elastic.co/t/we-are-seeing-the-issue-on-sonarqube-with-elasticsearch-elastic-search-is-not-coming-up-preventing-the-sonarqube-to-be-up-and-running/339229 "2023-07-25T21:56:47Z")

</div>

Sonarqube version - 10.0.0 OS : RHEL 8 Java - opendfk 17 Here are the logs: 2023.07.25 21:03:47 ERROR es\[o.e.b.Elasticsearch\] fatal exception while booting Elasticsearch java.lang.ExceptionInInitializerError: null …

---

## [AlmaLinux OS 9](https://discuss.elastic.co/t/almalinux-os-9/338910)

<div class="topic-metadata">

**Author:** [@Nirjonadda](https://discuss.elastic.co/u/Nirjonadda)\
**Replies:** 4\
**Last updated:** [July 25, 2023, 8:27pm UTC](https://discuss.elastic.co/t/almalinux-os-9/338910 "2023-07-25T20:27:12Z")

</div>

Do you have any plan add support for AlmaLinux OS 9? Can not install Elasticsearch in AlmaLinux OS 9 because RPM signing key is invalid. rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch warning: Signature…

---

## [Combine term and bucket range query](https://discuss.elastic.co/t/combine-term-and-bucket-range-query/339215)

<div class="topic-metadata">

**Author:** [@aelam](https://discuss.elastic.co/u/aelam)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 8:09pm UTC](https://discuss.elastic.co/t/combine-term-and-bucket-range-query/339215 "2023-07-25T20:09:43Z")

</div>

I'm attempting to extract records of http success/failure data per user using an elasticsearch aggregation. I'm looking at two fields, "user.name" and "http.response.status\_code". My goal is to use a keyed range bucket …

---

## [Enable xpack.security but not password authentication](https://discuss.elastic.co/t/enable-xpack-security-but-not-password-authentication/338917)

<div class="topic-metadata">

**Author:** [@darshanypatel](https://discuss.elastic.co/u/darshanypatel)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 8:00pm UTC](https://discuss.elastic.co/t/enable-xpack-security-but-not-password-authentication/338917 "2023-07-25T20:00:11Z")

</div>

I have an ES 7.16.2 cluster running with TLS set up. I haven't set the xpack.security.enabled setting in my elasticsearch.yml file. I'm using the BASIC license. So it should have used the default value of false for that …

---

## [How to set up 3 dedicate master + 4 data nodes also master elegible](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 15\
**Last updated:** [July 25, 2023, 7:05pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887 "2023-07-25T19:05:02Z")

</div>

i need to set up 3 master node dedicate and 4 data node and master elegibles this is my yml configuration path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch bootstrap.memory\_lock: true cluster.name: C…

---

## [Aligning array elements with parent in table visualization](https://discuss.elastic.co/t/aligning-array-elements-with-parent-in-table-visualization/338962)

<div class="topic-metadata">

**Author:** [@Thomas.c](https://discuss.elastic.co/u/Thomas.c)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 7:16pm UTC](https://discuss.elastic.co/t/aligning-array-elements-with-parent-in-table-visualization/338962 "2023-07-25T19:16:53Z")

</div>

I'm trying to create a table visualization in Kibana. My data structure is like this: Vehicle{ Vehicle Number Vehicle make Vehicle model Vehicle year} Each record can have multiple vehicles in it, so the parent Veh…

---

## [Completely remove mapping check](https://discuss.elastic.co/t/completely-remove-mapping-check/339198)

<div class="topic-metadata">

**Author:** [@dastial](https://discuss.elastic.co/u/dastial)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 6:15pm UTC](https://discuss.elastic.co/t/completely-remove-mapping-check/339198 "2023-07-25T18:15:23Z")

</div>

I'm using ES8+ to store a lot of different document, but I've encountered some problems with property mapping. I am working with documents, each of which has hundreds of different fields, many of them with the same name.…

---

## [Join two searches with nested field](https://discuss.elastic.co/t/join-two-searches-with-nested-field/339213)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 5:23pm UTC](https://discuss.elastic.co/t/join-two-searches-with-nested-field/339213 "2023-07-25T17:23:05Z")

</div>

hello , I have been trying to join those two searches , but I didnt managed . I want to do this - SELECT user-data WHERE company.id = 1 AND timestamp BETWEEEN 2023-05-04 - 2023-06-05 // RESULT 100 GET /user-data/\_se…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/339009)

<div class="topic-metadata">

**Author:** [@SUNA](https://discuss.elastic.co/u/SUNA)\
**Replies:** 9\
**Last updated:** [July 25, 2023, 4:27pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/339009 "2023-07-25T16:27:43Z")

</div>

Hi Team, My ELK cluster running in one node. while clearing Queue, I had restarted kibana and elk services. from now my URL is stuck with below error. Kibana server is not ready yet In order to fix this i have restar…

---

## [Multiple pipelines bug with pipe-to-pipe config and CEF codec](https://discuss.elastic.co/t/multiple-pipelines-bug-with-pipe-to-pipe-config-and-cef-codec/338889)

<div class="topic-metadata">

**Author:** [@Markenstein](https://discuss.elastic.co/u/Markenstein)\
**Replies:** 23\
**Last updated:** [July 25, 2023, 3:52pm UTC](https://discuss.elastic.co/t/multiple-pipelines-bug-with-pipe-to-pipe-config-and-cef-codec/338889 "2023-07-25T15:52:09Z")

</div>

Hi, everyone! I have faced with such problem: several CEF strings pushed into the following pipelines configuration causing \_cefparseerror in result cause to incorrect string in the input. It's break original message in…

---

## [Kibana cuts HH:mm:ss off date in Table visualization](https://discuss.elastic.co/t/kibana-cuts-hhss-off-date-in-table-visualization/339195)

<div class="topic-metadata">

**Author:** [@OrangeBanana](https://discuss.elastic.co/u/OrangeBanana)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 3:23pm UTC](https://discuss.elastic.co/t/kibana-cuts-hhss-off-date-in-table-visualization/339195 "2023-07-25T15:23:50Z")

</div>

In Elasticsearch I have dates saved in the yyyy-MM-ddTHH:mm:ssZ format. However in my Kibana Table visualization only the yyyy-MM-dd part is shown. When I click on the data field in Kibana the date format is also shown a…

---

## [Filtering messages from Logstash codec rubydebug output](https://discuss.elastic.co/t/filtering-messages-from-logstash-codec-rubydebug-output/339212)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 0\
**Last updated:** [July 25, 2023, 3:15pm UTC](https://discuss.elastic.co/t/filtering-messages-from-logstash-codec-rubydebug-output/339212 "2023-07-25T15:15:06Z")

</div>

Our logtsash conf file is using tcp input plugin to ingest messages from different ports. The output part is as follows: output { if \[@metadata\]\[indexPrefix\] { file { path =\> "/opt/total/l…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=469)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=471)
