# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=472

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 473

---

## [Kibana can't sign in](https://discuss.elastic.co/t/kibana-cant-sign-in/339131)

<div class="topic-metadata">

**Author:** [@dro](https://discuss.elastic.co/u/dro)\
**Replies:** 2\
**Last updated:** [July 24, 2023, 10:35pm UTC](https://discuss.elastic.co/t/kibana-cant-sign-in/339131 "2023-07-24T22:35:39Z")

</div>

Kibana is not accepting the default elasticsearch-master-credentials The following ELK stack configuration is all version 8.5.1 running in a single node cluster: pod/elasticsearch-master-0 1/1 Running 0 …

---

## [Find all numbers in a text with](https://discuss.elastic.co/t/find-all-numbers-in-a-text-with/339020)

<div class="topic-metadata">

**Author:** [@kbfifi](https://discuss.elastic.co/u/kbfifi)\
**Replies:** 2\
**Last updated:** [July 24, 2023, 8:39pm UTC](https://discuss.elastic.co/t/find-all-numbers-in-a-text-with/339020 "2023-07-24T20:39:33Z")

</div>

I'm a newbe and trying to find all numbers in text with GROK. I'm using GROK debugger. My sample text: "Sample content with date 11 22 2022 and entity California and another date 1 1 1999 2-3-2024" I hope to get an ar…

---

## [No autorizated for monitoring error](https://discuss.elastic.co/t/no-autorizated-for-monitoring-error/338968)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 2\
**Last updated:** [July 24, 2023, 7:30pm UTC](https://discuss.elastic.co/t/no-autorizated-for-monitoring-error/338968 "2023-07-24T19:30:34Z")

</div>

You are not authorized to access Monitoring. To use Monitoring, you need the privileges granted by both the \`kibana\_admin\` and \`monitoring\_user \` roles. If you are attempting to access a dedicated monitoring cluster, th…

---

## [Kibana Data Path / Chromium Files](https://discuss.elastic.co/t/kibana-data-path-chromium-files/338908)

<div class="topic-metadata">

**Author:** [@jokulicz](https://discuss.elastic.co/u/jokulicz)\
**Replies:** 4\
**Last updated:** [July 24, 2023, 7:16pm UTC](https://discuss.elastic.co/t/kibana-data-path-chromium-files/338908 "2023-07-24T19:16:47Z")

</div>

Hi! I am running the latest version of Kibana on Windows. I set the data.path variable in the config to change the location of the data and this works for the uuid file, but not for the chromium folders that are create…

---

## [Issues Running ElasticSearch on Kibana](https://discuss.elastic.co/t/issues-running-elasticsearch-on-kibana/339123)

<div class="topic-metadata">

**Author:** [@Emily\_Miller](https://discuss.elastic.co/u/Emily_Miller)\
**Replies:** 2\
**Last updated:** [July 24, 2023, 6:50pm UTC](https://discuss.elastic.co/t/issues-running-elasticsearch-on-kibana/339123 "2023-07-24T18:50:47Z")

</div>

Hey all. I'm brand new to running Kibana, and I'm using a software called GrimoireLab that runs off of it and docker. I used to not have any issues setting it up, but every time I try to open my localhost now it says ERR…

---

## [How to secure the Elasticsearch API?](https://discuss.elastic.co/t/how-to-secure-the-elasticsearch-api/339092)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 5:50pm UTC](https://discuss.elastic.co/t/how-to-secure-the-elasticsearch-api/339092 "2023-07-24T17:50:57Z")

</div>

Hello, I want to share the Elastic curl API to the application team so that they can consume the API to get the data from Elastic search. How do I provide the authorization to the application team to consume that API? …

---

## [Match query not returning results](https://discuss.elastic.co/t/match-query-not-returning-results/337815)

<div class="topic-metadata">

**Author:** [@senadk](https://discuss.elastic.co/u/senadk)\
**Replies:** 6\
**Last updated:** [July 24, 2023, 5:14pm UTC](https://discuss.elastic.co/t/match-query-not-returning-results/337815 "2023-07-24T17:14:06Z")

</div>

Hi everyone, I started today with Elastic Search and have been working on some endpoints to get and post data. I do get a problem when trying to get results back on a match query. This is my document: { exception: \[…

---

## [Logstash Create pipeline API: \[pipeline\] failed to parse object / json\_parse\_exception](https://discuss.elastic.co/t/logstash-create-pipeline-api-pipeline-failed-to-parse-object-json-parse-exception/339055)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 4:46pm UTC](https://discuss.elastic.co/t/logstash-create-pipeline-api-pipeline-failed-to-parse-object-json-parse-exception/339055 "2023-07-24T16:46:21Z")

</div>

Hello World! I'm trying to follow this: to duplicate an existing Logstash pipeline, however I'm running into following error: % export PIPELINE=$(curl --silent --request GET --insecure "https://elastic:$es\_password@…

---

## [Fleet Server not deploying in ECK operator](https://discuss.elastic.co/t/fleet-server-not-deploying-in-eck-operator/337110)

<div class="topic-metadata">

**Author:** [@conuoha1](https://discuss.elastic.co/u/conuoha1)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 2:14pm UTC](https://discuss.elastic.co/t/fleet-server-not-deploying-in-eck-operator/337110 "2023-07-24T14:14:45Z")

</div>

This is my fleet.yaml file , i cant seem to understand why im getting this error apiVersion: agent.k8s.elastic.co/v1alpha1 kind: Agent metadata: annotations: association.k8s.elastic.co/es-conf-3796208044: \>- …

---

## [RFE: SQL - Add listagg aggregate function](https://discuss.elastic.co/t/rfe-sql-add-listagg-aggregate-function/339111)

<div class="topic-metadata">

**Author:** [@t603](https://discuss.elastic.co/u/t603)\
**Replies:** 0\
**Last updated:** [July 24, 2023, 2:14pm UTC](https://discuss.elastic.co/t/rfe-sql-add-listagg-aggregate-function/339111 "2023-07-24T14:14:12Z")

</div>

Hello, may I ask You in SQL language module to add "listagg" function into the aggregate (group by...having) SQL queries? This would help me to identify unique type of logs using this style of aggregation of string col…

---

## [Shards are in ALLOCATION\_FAILED or CLUSTER\_RECOVERED](https://discuss.elastic.co/t/shards-are-in-allocation-failed-or-cluster-recovered/339100)

<div class="topic-metadata">

**Author:** [@Sathish22](https://discuss.elastic.co/u/Sathish22)\
**Replies:** 3\
**Last updated:** [July 24, 2023, 2:05pm UTC](https://discuss.elastic.co/t/shards-are-in-allocation-failed-or-cluster-recovered/339100 "2023-07-24T14:05:30Z")

</div>

Hi All, we have a 5 master and 41 node cluster, due to some storage hardware issue, Elasticsearch cluster was affected and after resolving hardware issue, some of the shards are showing as ALLOCATION\_FAILED or CLUSTER\_R…

---

## [Change log level for beats deployed by fleet managed elastic-agent](https://discuss.elastic.co/t/change-log-level-for-beats-deployed-by-fleet-managed-elastic-agent/338473)

<div class="topic-metadata">

**Author:** [@GibbsGreatly](https://discuss.elastic.co/u/GibbsGreatly)\
**Replies:** 2\
**Last updated:** [July 24, 2023, 2:04pm UTC](https://discuss.elastic.co/t/change-log-level-for-beats-deployed-by-fleet-managed-elastic-agent/338473 "2023-07-24T14:04:51Z")

</div>

I've set up Elasticsearch and Kibana on a couple of test VM's. These will be running on Raspberry Pi's once I have it all figured out. Hence, it's pretty important that I limit logging. I am trying really hard to find…

---

## [Elastic Agent Not Showing any Logs](https://discuss.elastic.co/t/elastic-agent-not-showing-any-logs/337636)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 1:50pm UTC](https://discuss.elastic.co/t/elastic-agent-not-showing-any-logs/337636 "2023-07-24T13:50:15Z")

</div>

We deployed ECE in an air-gap environment. There are around three deployments. In one of the deployments, we Installed and configured an agent through fleet and added a MySQL Integration just for testing purposes. Agent …

---

## [Trying to use Synthetics but it shows an error on enrollment](https://discuss.elastic.co/t/trying-to-use-synthetics-but-it-shows-an-error-on-enrollment/337915)

<div class="topic-metadata">

**Author:** [@igorhodan](https://discuss.elastic.co/u/igorhodan)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 1:34pm UTC](https://discuss.elastic.co/t/trying-to-use-synthetics-but-it-shows-an-error-on-enrollment/337915 "2023-07-24T13:34:03Z")

</div>

Hello, I am trying to use the complete agent as recommended by the docs, for use the browser synthetics, according this post: Also i have alredy everything configured fine and working, without issues, but its a normal…

---

## [ELK Monitoring Cluster - issue with indexes reaching](https://discuss.elastic.co/t/elk-monitoring-cluster-issue-with-indexes-reaching/339021)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 8\
**Last updated:** [July 24, 2023, 1:27pm UTC](https://discuss.elastic.co/t/elk-monitoring-cluster-issue-with-indexes-reaching/339021 "2023-07-24T13:27:04Z")

</div>

Hello, I have following issue. I created ELK Onenode cluster with self-monitoring enabled (as ELK Monitoring Cluster) I joined another ELK Cluster environment to Monitoring Cluster. From another ELK Cluster I configu…

---

## [Logstash is not getting Kubernetes Metadata for logs coming from S3](https://discuss.elastic.co/t/logstash-is-not-getting-kubernetes-metadata-for-logs-coming-from-s3/339102)

<div class="topic-metadata">

**Author:** [@akshayw](https://discuss.elastic.co/u/akshayw)\
**Replies:** 0\
**Last updated:** [July 24, 2023, 1:18pm UTC](https://discuss.elastic.co/t/logstash-is-not-getting-kubernetes-metadata-for-logs-coming-from-s3/339102 "2023-07-24T13:18:20Z")

</div>

Hi, I have setup ELK-FluentBit stack in Kubernetes cluster. I'm pushing my application logs in cluster to S3 using FluentBit and adding those logs to ELK using S3-input plugin of Logstash. \[App Logs --\> FluentBit --\> S3…

---

## [Use Elasticsearch service for retrieving data from ES](https://discuss.elastic.co/t/use-elasticsearch-service-for-retrieving-data-from-es/339099)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 0\
**Last updated:** [July 24, 2023, 12:43pm UTC](https://discuss.elastic.co/t/use-elasticsearch-service-for-retrieving-data-from-es/339099 "2023-07-24T12:43:17Z")

</div>

Hi, How to use Elasticsearch service inside plugin? I am developing an external plugin in Kibana 8.1.1 using React. I want to retrieve data from ES at server side using the Elasticsearch service. I couldn't find any d…

---

## [How to get unique documents with Search\_After](https://discuss.elastic.co/t/how-to-get-unique-documents-with-search-after/339098)

<div class="topic-metadata">

**Author:** [@FTOR](https://discuss.elastic.co/u/FTOR)\
**Replies:** 0\
**Last updated:** [July 24, 2023, 12:38pm UTC](https://discuss.elastic.co/t/how-to-get-unique-documents-with-search-after/339098 "2023-07-24T12:38:11Z")

</div>

Hello, I would like to get unique documents basing on a field (unique\_id\_field) and by using search\_after algorithm GET /my\_index/\_search { "query": { "match\_all": {} } "size": 10000, "search\_after": \[sort\_field\_v…

---

## [Filebeat Xml decoder linux](https://discuss.elastic.co/t/filebeat-xml-decoder-linux/339096)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 0\
**Last updated:** [July 24, 2023, 12:31pm UTC](https://discuss.elastic.co/t/filebeat-xml-decoder-linux/339096 "2023-07-24T12:31:32Z")

</div>

Hello Community, I have an issue in xml decoder, I’m trying to decode sysmon for linuxs logs i’m using filebeat to send the logs from ubuntu server to my graylog everything works great however filebeat is decoding the ke…

---

## [Deployment of ELK Operator failing with namespace-level permissions](https://discuss.elastic.co/t/deployment-of-elk-operator-failing-with-namespace-level-permissions/339088)

<div class="topic-metadata">

**Author:** [@Kavish\_Mehta](https://discuss.elastic.co/u/Kavish_Mehta)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 11:41am UTC](https://discuss.elastic.co/t/deployment-of-elk-operator-failing-with-namespace-level-permissions/339088 "2023-07-24T11:41:19Z")

</div>

Hi, I am trying to Deploy Elasticsearch on Kubernetes using ECK, I only have namespace-level permissions in my k8s cluster, But the operator requires Daemonset permissions which is cluster level, and is thowing error …

---

## [Where I can use Population , Categorization and Rare ML Option](https://discuss.elastic.co/t/where-i-can-use-population-categorization-and-rare-ml-option/339070)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 11:40am UTC](https://discuss.elastic.co/t/where-i-can-use-population-categorization-and-rare-ml-option/339070 "2023-07-24T11:40:09Z")

</div>

Hi Team, Kibana Machine Learning provides Population , Categorization and Rare options . We need to work on these also but we can't able to find use cases for these options. Can anyone please explain to me where we ca…

---

## [Scripting at Kibana visualization to achieve calculations on bucket aggregation count](https://discuss.elastic.co/t/scripting-at-kibana-visualization-to-achieve-calculations-on-bucket-aggregation-count/339017)

<div class="topic-metadata">

**Author:** [@Mangesh\_Mathe](https://discuss.elastic.co/u/Mangesh_Mathe)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 11:36am UTC](https://discuss.elastic.co/t/scripting-at-kibana-visualization-to-achieve-calculations-on-bucket-aggregation-count/339017 "2023-07-24T11:36:30Z")

</div>

Hello Elastic Team, :wave: Elastic and Kibana version : v 8.4.2 configured on: Azure elastic cloud We had one use case , where we wanted to calculate number of dropouts from each bucket aggregation. Our application i…

---

## [Elasticsearch upgrade](https://discuss.elastic.co/t/elasticsearch-upgrade/339084)

<div class="topic-metadata">

**Author:** [@Sudheet\_Sid](https://discuss.elastic.co/u/Sudheet_Sid)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 11:26am UTC](https://discuss.elastic.co/t/elasticsearch-upgrade/339084 "2023-07-24T11:26:30Z")

</div>

Hello Team, We have elasticsearch and kibana version 7.14.0 (docker) which is running on my Linux system with version "Ubuntu 20.04.2 LTS" Here have we upgrade our OS to latest OS after upgradation is it running as be…

---

## [Debug server side of plugin](https://discuss.elastic.co/t/debug-server-side-of-plugin/339073)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 0\
**Last updated:** [July 24, 2023, 10:27am UTC](https://discuss.elastic.co/t/debug-server-side-of-plugin/339073 "2023-07-24T10:27:59Z")

</div>

Hi, Whenever I make some code changes in the server side of the plugin, be it console.log(), I have to restart the development server with yarn start every time for the changes to get updated (I donot see any changes in…

---

## [Reindex error in version6 after upgrading it from ESv5](https://discuss.elastic.co/t/reindex-error-in-version6-after-upgrading-it-from-esv5/336529)

<div class="topic-metadata">

**Author:** [@sonujatav35](https://discuss.elastic.co/u/sonujatav35)\
**Replies:** 7\
**Last updated:** [July 24, 2023, 10:27am UTC](https://discuss.elastic.co/t/reindex-error-in-version6-after-upgrading-it-from-esv5/336529 "2023-07-24T10:27:03Z")

</div>

Hi ES Community, I need some advice, I have to perform reindexing operation after upgrading the ES from v5 to v6. But while doing the reindexing i am getting the some mapping error. I am not very much sure which part s…

---

## [Designing a Kibana Dashboard to Display Only the "Time" Value](https://discuss.elastic.co/t/designing-a-kibana-dashboard-to-display-only-the-time-value/337599)

<div class="topic-metadata">

**Author:** [@abntkpi](https://discuss.elastic.co/u/abntkpi)\
**Replies:** 7\
**Last updated:** [July 24, 2023, 10:09am UTC](https://discuss.elastic.co/t/designing-a-kibana-dashboard-to-display-only-the-time-value/337599 "2023-07-24T10:09:50Z")

</div>

Hello and good time to you all. I receive the following log in Kibana: 64 bytes from 4.2.2.4: icmp\_seq=3 ttl=46 time=116 ms I want to design a dashboard that only displays the value of "time". I was able to easily acco…

---

## [I have installed ELK 7.17.9 and Kibana 7.17.9 , i would want to make the kibana url as https](https://discuss.elastic.co/t/i-have-installed-elk-7-17-9-and-kibana-7-17-9-i-would-want-to-make-the-kibana-url-as-https/339065)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 10:03am UTC](https://discuss.elastic.co/t/i-have-installed-elk-7-17-9-and-kibana-7-17-9-i-would-want-to-make-the-kibana-url-as-https/339065 "2023-07-24T10:03:14Z")

</div>

Hi Team, I have installed ELK 7.17.9 and all other components related to it. the cluster is up and working fine. I would want to make the kibana url as https. how can i do it . there are some questions regarding it. E…

---

## [Metricbeat windows module not working as expected](https://discuss.elastic.co/t/metricbeat-windows-module-not-working-as-expected/339061)

<div class="topic-metadata">

**Author:** [@p\_vimal](https://discuss.elastic.co/u/p_vimal)\
**Replies:** 0\
**Last updated:** [July 24, 2023, 9:19am UTC](https://discuss.elastic.co/t/metricbeat-windows-module-not-working-as-expected/339061 "2023-07-24T09:19:47Z")

</div>

Im trying to find the status of specfic service running on our windows machine. We are trying to get service information using windows Module from metricbeat, but modules doesnt sent any information of about service.. I…

---

## [Sankey Visualization plugin installation](https://discuss.elastic.co/t/sankey-visualization-plugin-installation/337752)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 9\
**Last updated:** [July 24, 2023, 8:55am UTC](https://discuss.elastic.co/t/sankey-visualization-plugin-installation/337752 "2023-07-24T08:55:24Z")

</div>

Hi, I am trying to install Sankey visualization plugin in kibana. following the instructions mentioned here When i run the yarn start i am getting the following error yarn run v1.22.19 $ cd ../.. && node scripts/ki…

---

## [Storage utilization - indices spread across multiple storage devices attached to the same node](https://discuss.elastic.co/t/storage-utilization-indices-spread-across-multiple-storage-devices-attached-to-the-same-node/339053)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 1\
**Last updated:** [July 24, 2023, 8:54am UTC](https://discuss.elastic.co/t/storage-utilization-indices-spread-across-multiple-storage-devices-attached-to-the-same-node/339053 "2023-07-24T08:54:06Z")

</div>

Hi, We are running a 3 node cluster (Elasticsearch 8.8.2) running on 3 identical physical machines. Each machine has 2 onboard SSD storage devices. As of now, only one of the two SSDs is in use. It has the OS(Ubuntu) an…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=471)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=473)
