# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=471

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 472

---

## [Expired ca.crt/nodes certificates - how to renew such certificates?](https://discuss.elastic.co/t/expired-ca-crt-nodes-certificates-how-to-renew-such-certificates/339114)

<div class="topic-metadata">

**Author:** [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Replies:** 4\
**Last updated:** [July 25, 2023, 2:39pm UTC](https://discuss.elastic.co/t/expired-ca-crt-nodes-certificates-how-to-renew-such-certificates/339114 "2023-07-25T14:39:40Z")

</div>

Dears, To secure our ELK cluster we are using self-signed certificates generated by elasticsearch-certutil tool. Our ca.crt and certificates of nodes expired. I would like to mention that many external filebeats connec…

---

## [Kibana alert with index connector: indexing {{context}} as JSON](https://discuss.elastic.co/t/kibana-alert-with-index-connector-indexing-context-as-json/339205)

<div class="topic-metadata">

**Author:** [@dmcarmen](https://discuss.elastic.co/u/dmcarmen)\
**Replies:** 0\
**Last updated:** [July 25, 2023, 2:04pm UTC](https://discuss.elastic.co/t/kibana-alert-with-index-connector-indexing-context-as-json/339205 "2023-07-25T14:04:48Z")

</div>

Hi, I am trying to setup an ES query alert using an index connector. I would like to have a similar behavior to the predefined alert index, but my ELK version is 7.12 and that index was not available for that version. I…

---

## [Is it possible modify query results before aggregations](https://discuss.elastic.co/t/is-it-possible-modify-query-results-before-aggregations/339136)

<div class="topic-metadata">

**Author:** [@Dalin](https://discuss.elastic.co/u/Dalin)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 1:57pm UTC](https://discuss.elastic.co/t/is-it-possible-modify-query-results-before-aggregations/339136 "2023-07-25T13:57:46Z")

</div>

I need to modify Elasticsearch query results based on user permissions determined by an external authorizer, before the results are used for aggregations. Anyone know if it's possible to intercept the query results, modi…

---

## [Elasticsearch index pattern in Tableau](https://discuss.elastic.co/t/elasticsearch-index-pattern-in-tableau/339183)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 1:52pm UTC](https://discuss.elastic.co/t/elasticsearch-index-pattern-in-tableau/339183 "2023-07-25T13:52:25Z")

</div>

Hello, I am trying to create a visualization in Tableau with Elasticsearch as the data source. I am able to connect Tableau and Elasticsearch successfully . But the problem is I can't select the index pattern in Tablea…

---

## [I cant search nested](https://discuss.elastic.co/t/i-cant-search-nested/339187)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 12:52pm UTC](https://discuss.elastic.co/t/i-cant-search-nested/339187 "2023-07-25T12:52:16Z")

</div>

hello , I am trying to search nested . I dont know what I am doing wrong . MY MAPPING { "user-data-info": { "mappings": { "dynamic": "false", "properties": { "company": { "type": "…

---

## [Native Language Translation (not analyzers)](https://discuss.elastic.co/t/native-language-translation-not-analyzers/336906)

<div class="topic-metadata">

**Author:** [@Yossi11](https://discuss.elastic.co/u/Yossi11)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 12:46pm UTC](https://discuss.elastic.co/t/native-language-translation-not-analyzers/336906 "2023-07-25T12:46:59Z")

</div>

Hello, My name is Yossi. I'm pretty new to elastic. Just stated using it a few months. I work a lot of different languages - English, German, Arabic (different dialects), French, Hebrew, Spanish and more. I'm using Dav…

---

## [There was problem checking fleet permission](https://discuss.elastic.co/t/there-was-problem-checking-fleet-permission/339192)

<div class="topic-metadata">

**Author:** [@Nirmal](https://discuss.elastic.co/u/Nirmal)\
**Replies:** 0\
**Last updated:** [July 25, 2023, 12:18pm UTC](https://discuss.elastic.co/t/there-was-problem-checking-fleet-permission/339192 "2023-07-25T12:18:28Z")

</div>

I am trying to setup fleet server, but I am facing this issue. Please anybody knows what I am missing here.

---

## [Nested sorting differs between ES7 and ES8?](https://discuss.elastic.co/t/nested-sorting-differs-between-es7-and-es8/337904)

<div class="topic-metadata">

**Author:** [@MarynaCherniavska](https://discuss.elastic.co/u/MarynaCherniavska)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 12:17pm UTC](https://discuss.elastic.co/t/nested-sorting-differs-between-es7-and-es8/337904 "2023-07-25T12:17:59Z")

</div>

Dear team, we're moving from 7.17 to 8.7 (I know, big jump) and as part of the move, we have been running the e2e tests of the application on the new cluster, before actually switching the application to it. Some tests, …

---

## [Snapshot policy will continue to backup fail when the backup jumps out of shard error](https://discuss.elastic.co/t/snapshot-policy-will-continue-to-backup-fail-when-the-backup-jumps-out-of-shard-error/337738)

<div class="topic-metadata">

**Author:** [@Lily1](https://discuss.elastic.co/u/Lily1)\
**Replies:** 6\
**Last updated:** [July 25, 2023, 12:16pm UTC](https://discuss.elastic.co/t/snapshot-policy-will-continue-to-backup-fail-when-the-backup-jumps-out-of-shard-error/337738 "2023-07-25T12:16:26Z")

</div>

Version: Elasticsearch 7.16.2 S3 Storage Classes: new file saving S3 Standard, after month turn to S3 Glacier Regularly back up the index of the same Aliases to s3 every day. Recently, the following error suddenly po…

---

## [Ingest pipeline with conditions runs tests correct but no documents are processed](https://discuss.elastic.co/t/ingest-pipeline-with-conditions-runs-tests-correct-but-no-documents-are-processed/339150)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 4\
**Last updated:** [July 25, 2023, 11:55am UTC](https://discuss.elastic.co/t/ingest-pipeline-with-conditions-runs-tests-correct-but-no-documents-are-processed/339150 "2023-07-25T11:55:45Z")

</div>

Hi; Elasticsearch version: 8.6.2 Logstash version: 8.6.2 I have created and tested at simple ingest pipeline, which adds an event.ingested field to Filebeat documents, which do not already have this field set b…

---

## [Fleet server agent output not supported](https://discuss.elastic.co/t/fleet-server-agent-output-not-supported/339174)

<div class="topic-metadata">

**Author:** [@quic22](https://discuss.elastic.co/u/quic22)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 11:54am UTC](https://discuss.elastic.co/t/fleet-server-agent-output-not-supported/339174 "2023-07-25T11:54:04Z")

</div>

Hello, I just installed elastic stack (with fleet server on the same host) with logstash as output in fleet settings and that was working until I rebooted. Everything seems to work only is the server not listening on por…

---

## [Log4j framework can no longer reconnect because the security manager on logstash restart](https://discuss.elastic.co/t/log4j-framework-can-no-longer-reconnect-because-the-security-manager-on-logstash-restart/339115)

<div class="topic-metadata">

**Author:** [@ansk98](https://discuss.elastic.co/u/ansk98)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 11:54am UTC](https://discuss.elastic.co/t/log4j-framework-can-no-longer-reconnect-because-the-security-manager-on-logstash-restart/339115 "2023-07-25T11:54:01Z")

</div>

Hi all, For the logging of the Elasticsearch processes, the log4j2 was configured to log server, slowlog indexing, and slowlog search information to logstash by adding a socket appender that sends relevant logs to the r…

---

## [Option to search matching phrase with post fix and prefix while maintaining the order in Elasticsearch 7.x](https://discuss.elastic.co/t/option-to-search-matching-phrase-with-post-fix-and-prefix-while-maintaining-the-order-in-elasticsearch-7-x/339161)

<div class="topic-metadata">

**Author:** [@Vithu](https://discuss.elastic.co/u/Vithu)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 11:35am UTC](https://discuss.elastic.co/t/option-to-search-matching-phrase-with-post-fix-and-prefix-while-maintaining-the-order-in-elasticsearch-7-x/339161 "2023-07-25T11:35:56Z")

</div>

I have a requirement to modify Elasticsearch query from 1.x to 7.x. The 1.x query is given below: { "query": { "filtered": { "filter": { "and": { "filters": \[ { "t…

---

## [How to get details of fleet server](https://discuss.elastic.co/t/how-to-get-details-of-fleet-server/338868)

<div class="topic-metadata">

**Author:** [@Nishant\_Chauhan](https://discuss.elastic.co/u/Nishant_Chauhan)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 10:00am UTC](https://discuss.elastic.co/t/how-to-get-details-of-fleet-server/338868 "2023-07-25T10:00:49Z")

</div>

How can I list number/name of hosts connected to any specific Fleet server.

---

## [Integrations not updating and fleet server page not loading](https://discuss.elastic.co/t/integrations-not-updating-and-fleet-server-page-not-loading/338517)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 4\
**Last updated:** [July 25, 2023, 9:43am UTC](https://discuss.elastic.co/t/integrations-not-updating-and-fleet-server-page-not-loading/338517 "2023-07-25T09:43:16Z")

</div>

Integrations are not updating and the fleet server page is not loading. Using ELK 8.8.1

---

## [Elastic Search Unclear Mapper Parsing Exception](https://discuss.elastic.co/t/elastic-search-unclear-mapper-parsing-exception/339108)

<div class="topic-metadata">

**Author:** [@optimaX](https://discuss.elastic.co/u/optimaX)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 9:25am UTC](https://discuss.elastic.co/t/elastic-search-unclear-mapper-parsing-exception/339108 "2023-07-25T09:25:30Z")

</div>

Incident: I'm currently working on a log pipeline which forwards the logs from an API - of our Anti-Virus solution - to Graylog and therefore Elasticsearch behind that. However, I encountered a very strange mapper-parsi…

---

## [NOOB, Elastic Stack (Search/Logstash) Netflow Cisco SD-WAN](https://discuss.elastic.co/t/noob-elastic-stack-search-logstash-netflow-cisco-sd-wan/338687)

<div class="topic-metadata">

**Author:** [@mhollingsworth1](https://discuss.elastic.co/u/mhollingsworth1)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 2:01pm UTC](https://discuss.elastic.co/t/noob-elastic-stack-search-logstash-netflow-cisco-sd-wan/338687 "2023-07-18T14:01:36Z")

</div>

I've been using an ELK stack for Netflow collection for roughly 1.5yr with my Cisco environment. Recently I've migrated onto SD-WAN and am sending my netflow data to the collector but for whatever reason all I'm seeing i…

---

## [Rebuild builtin indices](https://discuss.elastic.co/t/rebuild-builtin-indices/337098)

<div class="topic-metadata">

**Author:** [@rokka](https://discuss.elastic.co/u/rokka)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 9:19am UTC](https://discuss.elastic.co/t/rebuild-builtin-indices/337098 "2023-07-25T09:19:12Z")

</div>

Hi, for an unkown reason some builtin indices like ".geoip\_databases" or ".kibana\_7.16.2\_001" are corrupt in my ES instance. Is there a way to rebuilt them? Greetings Andre

---

## [Masters not joining the cluster](https://discuss.elastic.co/t/masters-not-joining-the-cluster/339158)

<div class="topic-metadata">

**Author:** [@ORIAN\_MENASHE](https://discuss.elastic.co/u/ORIAN_MENASHE)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 9:11am UTC](https://discuss.elastic.co/t/masters-not-joining-the-cluster/339158 "2023-07-25T09:11:32Z")

</div>

Hi I have 3 masters that not joining my cluster One of the is up but don’t have cluster uuid Can you help me?

---

## [Merge records into one table](https://discuss.elastic.co/t/merge-records-into-one-table/339067)

<div class="topic-metadata">

**Author:** [@akeelow](https://discuss.elastic.co/u/akeelow)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 8:50am UTC](https://discuss.elastic.co/t/merge-records-into-one-table/339067 "2023-07-25T08:50:41Z")

</div>

Hello! cisco gateway sends 4 log entries for one voip call. All four records have a common id. Is it possible to create such a query in the Kibana interface to create a table where each row will contain the following fie…

---

## [Getting the error after upgrading from v6 to v7](https://discuss.elastic.co/t/getting-the-error-after-upgrading-from-v6-to-v7/339034)

<div class="topic-metadata">

**Author:** [@sonujatav35](https://discuss.elastic.co/u/sonujatav35)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 8:44am UTC](https://discuss.elastic.co/t/getting-the-error-after-upgrading-from-v6-to-v7/339034 "2023-07-25T08:44:31Z")

</div>

Hi ES community, I have one question recently i have done reindexing then ES up-gradation from v6.8.23 to v7.17.9. After this operation i noticed some error in elastic-search. Text fields are not optimised for operatio…

---

## [Get Unique Values for Elastic UI Donut Charts](https://discuss.elastic.co/t/get-unique-values-for-elastic-ui-donut-charts/339087)

<div class="topic-metadata">

**Author:** [@cyrildaniel](https://discuss.elastic.co/u/cyrildaniel)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 7:44am UTC](https://discuss.elastic.co/t/get-unique-values-for-elastic-ui-donut-charts/339087 "2023-07-25T07:44:36Z")

</div>

I would like to show the total unique count of vendors in the middle of the donut chart, but by default the total count comes. Is there a way to show the unique number of vendors? In the below image instead of 98 it sho…

---

## [Syntax is overwriting when using .NET Elastic.Clients.ElasticSearch package](https://discuss.elastic.co/t/syntax-is-overwriting-when-using-net-elastic-clients-elasticsearch-package/339050)

<div class="topic-metadata">

**Author:** [@Rottonscope](https://discuss.elastic.co/u/Rottonscope)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 7:34am UTC](https://discuss.elastic.co/t/syntax-is-overwriting-when-using-net-elastic-clients-elasticsearch-package/339050 "2023-07-25T07:34:52Z")

</div>

Hello! I'm new to using Elasticsearch and trying to get my head around the Query DSL for the .NET package: Elastic.Clients.Elasticsearch. I have a basic query set-up as such: Ids excludeIds = new Ids(new List\<I…

---

## [Number of concurrent search requests on ElasticSearch cluster](https://discuss.elastic.co/t/number-of-concurrent-search-requests-on-elasticsearch-cluster/339144)

<div class="topic-metadata">

**Author:** [@Mohit\_Munjal](https://discuss.elastic.co/u/Mohit_Munjal)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 6:22am UTC](https://discuss.elastic.co/t/number-of-concurrent-search-requests-on-elasticsearch-cluster/339144 "2023-07-25T06:22:35Z")

</div>

My objective is to calculate 2 things Q1: how many search requests can a elasticsearch cluster can work on at once Q2: how many search requests can a elasticsearch cluster hold in it's queue before starting rejecting i…

---

## [Stuck in preparing for race](https://discuss.elastic.co/t/stuck-in-preparing-for-race/339143)

<div class="topic-metadata">

**Author:** [@maximiliano\_carrasco](https://discuss.elastic.co/u/maximiliano_carrasco)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 6:09am UTC](https://discuss.elastic.co/t/stuck-in-preparing-for-race/339143 "2023-07-25T06:09:21Z")

</div>

I am trying to use esrally but it keeps stuck in "preparing for race..." I create a track with: esrally create-track --track=test --target-hosts=host --client-options="use\_ssl:true,verify\_certs:true,basic\_auth\_user:…

---

## [LDAP Integration Not Working](https://discuss.elastic.co/t/ldap-integration-not-working/338865)

<div class="topic-metadata">

**Author:** [@forabraham1](https://discuss.elastic.co/u/forabraham1)\
**Replies:** 6\
**Last updated:** [July 25, 2023, 4:53am UTC](https://discuss.elastic.co/t/ldap-integration-not-working/338865 "2023-07-25T04:53:31Z")

</div>

We're running inhouse platinum version of ELK stack 7.16. We've tried to use AD for user authentication, but it is not working and ends throwing invalid credential error. We're 100% sure that it is valid password. This …

---

## [How to configure multi-pipeline configuration in logstash 8.6.1?](https://discuss.elastic.co/t/how-to-configure-multi-pipeline-configuration-in-logstash-8-6-1/339071)

<div class="topic-metadata">

**Author:** [@Koele](https://discuss.elastic.co/u/Koele)\
**Replies:** 4\
**Last updated:** [July 25, 2023, 3:26am UTC](https://discuss.elastic.co/t/how-to-configure-multi-pipeline-configuration-in-logstash-8-6-1/339071 "2023-07-25T03:26:59Z")

</div>

Basic Information logstash version: 8.6.1 Logstash installation method: tar.gz logstash installation directory: /opt OS: CentOS 7 ogstash.yml configuration file node.name: logstash01 path.data: /data/logstash01 pipe…

---

## [Metricbeat missing dashboards](https://discuss.elastic.co/t/metricbeat-missing-dashboards/339139)

<div class="topic-metadata">

**Author:** [@Ryaninsolencee](https://discuss.elastic.co/u/Ryaninsolencee)\
**Replies:** 0\
**Last updated:** [July 25, 2023, 3:17am UTC](https://discuss.elastic.co/t/metricbeat-missing-dashboards/339139 "2023-07-25T03:17:16Z")

</div>

As i configured my elasticsearch to https, i changed all the necessary .yml files to include the https for elastic. but now my metricbeat doesnt work anymore and im also missing the dashboard fields elasticsearch and ki…

---

## [Problem to access Elastic portal https://local.host:12443/deployments](https://discuss.elastic.co/t/problem-to-access-elastic-portal-https-local-host-12443-deployments/339137)

<div class="topic-metadata">

**Author:** [@Cleber\_Carvalho](https://discuss.elastic.co/u/Cleber_Carvalho)\
**Replies:** 0\
**Last updated:** [July 25, 2023, 1:09am UTC](https://discuss.elastic.co/t/problem-to-access-elastic-portal-https-local-host-12443-deployments/339137 "2023-07-25T01:09:02Z")

</div>

When I try access the link to my ECE installation I receive the following error: 'Error: Service Unavailable' 'at y (https://local.host:12443/app.ac60c57da441fe117e33.js:2:252916)' 'at m (https://local.host:12443/app.…

---

## [Not able to download all rows of data in CSV](https://discuss.elastic.co/t/not-able-to-download-all-rows-of-data-in-csv/338638)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 13\
**Last updated:** [July 24, 2023, 10:53pm UTC](https://discuss.elastic.co/t/not-able-to-download-all-rows-of-data-in-csv/338638 "2023-07-24T22:53:12Z")

</div>

Hi, I have a query that generated 25 hits, and I have selected a few columns to display in the tabular format. When I tried to export the results by generating a CSV report, I'm only able to export 15 rows, not all 25 r…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=470)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=472)
