# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=476

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 477

---

## [Error while using ./elasticsearch-node repurpose tool](https://discuss.elastic.co/t/error-while-using-elasticsearch-node-repurpose-tool/338807)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 3:43pm UTC](https://discuss.elastic.co/t/error-while-using-elasticsearch-node-repurpose-tool/338807 "2023-07-19T15:43:23Z")

</div>

i got this error while using /usr/share/elasticsearch/elasticsearch-node repurpose to set my master node only for master { "error" : { "root\_cause" : \[ { "type" : "security\_exception", "reas…

---

## [Lens is showing lines without values](https://discuss.elastic.co/t/lens-is-showing-lines-without-values/338702)

<div class="topic-metadata">

**Author:** [@johngregg](https://discuss.elastic.co/u/johngregg)\
**Replies:** 5\
**Last updated:** [July 19, 2023, 3:32pm UTC](https://discuss.elastic.co/t/lens-is-showing-lines-without-values/338702 "2023-07-19T15:32:50Z")

</div>

I have a lens that I'm using to show custom metrics from Elastic APM, like jvm.jmx.banana. I haven't found good docs explaining breakdown, but it appears to be similar to the SQL "group by" clause, which is what I want. …

---

## [Logstash stops treatment when database goes down](https://discuss.elastic.co/t/logstash-stops-treatment-when-database-goes-down/338806)

<div class="topic-metadata">

**Author:** [@thibaut\_a](https://discuss.elastic.co/u/thibaut_a)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 3:30pm UTC](https://discuss.elastic.co/t/logstash-stops-treatment-when-database-goes-down/338806 "2023-07-19T15:30:35Z")

</div>

Hi, I have multiple JDBC inputs waiting for PostgreSQL database lines each minute. The database has a problem and is down. Due to this mistake, I don't receive any log in Kibana. I tried to find some fields in the docum…

---

## [Improve performance for update\_by\_query relational updates](https://discuss.elastic.co/t/improve-performance-for-update-by-query-relational-updates/338415)

<div class="topic-metadata">

**Author:** [@rolfschmidt](https://discuss.elastic.co/u/rolfschmidt)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 3:30pm UTC](https://discuss.elastic.co/t/improve-performance-for-update-by-query-relational-updates/338415 "2023-07-19T15:30:24Z")

</div>

Hi, I would like to ask for advice because I'm not sure how to optimize my data structures or requests to get more performance out of my system. I have a Elasticsearch with 1.000.000 objects stored in it. Let's say I h…

---

## [Unassigned shards - cannot allocate because all found copies of the shard are either stale or corrupt](https://discuss.elastic.co/t/unassigned-shards-cannot-allocate-because-all-found-copies-of-the-shard-are-either-stale-or-corrupt/338804)

<div class="topic-metadata">

**Author:** [@karsai1993](https://discuss.elastic.co/u/karsai1993)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 3:11pm UTC](https://discuss.elastic.co/t/unassigned-shards-cannot-allocate-because-all-found-copies-of-the-shard-are-either-stale-or-corrupt/338804 "2023-07-19T15:11:55Z")

</div>

Hello there, We are facing a RED cluster. GET \_cluster/health { "cluster\_name": "my\_cluster", "status": "red", "timed\_out": false, "number\_of\_nodes": 20, "number\_of\_data\_nodes": 13, "active\_primary\_shards"…

---

## [Dynamically Link to external site in Kibana Visuals](https://discuss.elastic.co/t/dynamically-link-to-external-site-in-kibana-visuals/338797)

<div class="topic-metadata">

**Author:** [@breiter](https://discuss.elastic.co/u/breiter)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 2:33pm UTC](https://discuss.elastic.co/t/dynamically-link-to-external-site-in-kibana-visuals/338797 "2023-07-19T14:33:17Z")

</div>

What is the standard for dynamically linking to external sites in dashboards? I have a table of data from my database. I'm displaying entity's IDs. These entities can be accessed through unique URLs, for example: https:…

---

## [Access is denied](https://discuss.elastic.co/t/access-is-denied/338304)

<div class="topic-metadata">

**Author:** [@Step-Creeper](https://discuss.elastic.co/u/Step-Creeper)\
**Replies:** 5\
**Last updated:** [July 19, 2023, 2:30pm UTC](https://discuss.elastic.co/t/access-is-denied/338304 "2023-07-19T14:30:25Z")

</div>

I have my Elasticsearch running on the default port and am able to login, so that is running fine. I downloaded the kibana.zip from official elasticsearch site, extracted it to desktop, and tried running kibana.bat Thi…

---

## [BulkIngester index operation does not propagate pipeline if defined](https://discuss.elastic.co/t/bulkingester-index-operation-does-not-propagate-pipeline-if-defined/338781)

<div class="topic-metadata">

**Author:** [@ng.software.dev](https://discuss.elastic.co/u/ng.software.dev)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 2:22pm UTC](https://discuss.elastic.co/t/bulkingester-index-operation-does-not-propagate-pipeline-if-defined/338781 "2023-07-19T14:22:59Z")

</div>

I am using the BulkIngester utility in the Java API to stream index request to Elasticsearch. Consider the following snippet of code: bulkIngester.add(o -\> o.index(i -\> i .pipeline(pipeline) .index(index) .…

---

## [Pros and Cons of using Elastic as a vector database?](https://discuss.elastic.co/t/pros-and-cons-of-using-elastic-as-a-vector-database/338733)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 1:47pm UTC](https://discuss.elastic.co/t/pros-and-cons-of-using-elastic-as-a-vector-database/338733 "2023-07-19T13:47:28Z")

</div>

I'm comparing Elastic vs other pure vector databases vs Mongodb/redis offerings. Is anything wrong or supplemental? Thank you! Pros: It's an Elastic product, meaning high SLA and needless to buy other products when do…

---

## [Example Inputs logtash configuration](https://discuss.elastic.co/t/example-inputs-logtash-configuration/338792)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 1:39pm UTC](https://discuss.elastic.co/t/example-inputs-logtash-configuration/338792 "2023-07-19T13:39:45Z")

</div>

Hello, Can i get help with an input configuration for logstash please? I currently am using this as a curl to get my information, but i need this in yaml if possible \</\> \</\>curl -X GET 'https://192.168.3.21:9200/\_cat…

---

## [How can I pass kibana authentication credentials from python application?](https://discuss.elastic.co/t/how-can-i-pass-kibana-authentication-credentials-from-python-application/338504)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 6\
**Last updated:** [July 19, 2023, 1:25pm UTC](https://discuss.elastic.co/t/how-can-i-pass-kibana-authentication-credentials-from-python-application/338504 "2023-07-19T13:25:21Z")

</div>

Hello,, I have python application, In which I have iframe kibana dashboard . If I am log in that python app at same time log in iframe kibana dashboard as well. User not again log in kibana dashboard. How can I manage t…

---

## [How to send logs from IBM DataPower to logstash](https://discuss.elastic.co/t/how-to-send-logs-from-ibm-datapower-to-logstash/338715)

<div class="topic-metadata">

**Author:** [@ram\_mq](https://discuss.elastic.co/u/ram_mq)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 12:34pm UTC](https://discuss.elastic.co/t/how-to-send-logs-from-ibm-datapower-to-logstash/338715 "2023-07-19T12:34:08Z")

</div>

I would like to send logs from IBM DataPower to Logstash. Please advise how to send the logs?

---

## [How to fetch Ids from more than 10k records in single response](https://discuss.elastic.co/t/how-to-fetch-ids-from-more-than-10k-records-in-single-response/338749)

<div class="topic-metadata">

**Author:** [@Paras\_Rangani](https://discuss.elastic.co/u/Paras_Rangani)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-to-fetch-ids-from-more-than-10k-records-in-single-response/338749 "2023-07-19T11:21:20Z")

</div>

I have around 1 million documents , after applying the filters I get more than 10k records, but I do not want whole documents , instead I want the IDS of that records in a single call.How can I do that ?

---

## [Not able to index array in logstash](https://discuss.elastic.co/t/not-able-to-index-array-in-logstash/338774)

<div class="topic-metadata">

**Author:** [@Mohit\_Gupta2](https://discuss.elastic.co/u/Mohit_Gupta2)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 11:11am UTC](https://discuss.elastic.co/t/not-able-to-index-array-in-logstash/338774 "2023-07-19T11:11:40Z")

</div>

As it says, Logstash is not able to index array of strings or any kind of string for that matter. eg. - country :\["some\_name"\] is not mapped while country: '\["some\_name"\]' is indexed although it is showing the unmapped …

---

## [TopNavMenu filter bar not visible](https://discuss.elastic.co/t/topnavmenu-filter-bar-not-visible/338772)

<div class="topic-metadata">

**Author:** [@cyrildaniel](https://discuss.elastic.co/u/cyrildaniel)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 11:06am UTC](https://discuss.elastic.co/t/topnavmenu-filter-bar-not-visible/338772 "2023-07-19T11:06:44Z")

</div>

I am using the TopNavMenu provided by navigation.ui, everything else displays except for the filter bar as seen below. I have referred to the kibana examples - "third\_party\_maps\_source\_example" and "search\_examples" …

---

## [How to create container name specific indexes](https://discuss.elastic.co/t/how-to-create-container-name-specific-indexes/338766)

<div class="topic-metadata">

**Author:** [@Affan\_Mir](https://discuss.elastic.co/u/Affan_Mir)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 10:42am UTC](https://discuss.elastic.co/t/how-to-create-container-name-specific-indexes/338766 "2023-07-19T10:42:51Z")

</div>

I've deployed filebeat as a daemonset now for every container I need to access to their respective container names and read them from logstash so I can have indexes like 'container-name-YYYY-MM-DD' in my Elasticsearch. T…

---

## [Kibana metric help OR ( Bucket selector on a top metrics aggregation AND OR VEGA debug )](https://discuss.elastic.co/t/kibana-metric-help-or-bucket-selector-on-a-top-metrics-aggregation-and-or-vega-debug/336899)

<div class="topic-metadata">

**Author:** [@LucasE](https://discuss.elastic.co/u/LucasE)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 10:36am UTC](https://discuss.elastic.co/t/kibana-metric-help-or-bucket-selector-on-a-top-metrics-aggregation-and-or-vega-debug/336899 "2023-07-19T10:36:15Z")

</div>

Hello everyone, I stumbled across an issue I cannot resolve and I have no idea how to continue from here. My initial situation is simple : I have logs of 'problems' every minute in this format : ID|Status. Open logs …

---

## [Failed to run a query](https://discuss.elastic.co/t/failed-to-run-a-query/338678)

<div class="topic-metadata">

**Author:** [@leonid\_fayngold](https://discuss.elastic.co/u/leonid_fayngold)\
**Replies:** 3\
**Last updated:** [July 19, 2023, 10:27am UTC](https://discuss.elastic.co/t/failed-to-run-a-query/338678 "2023-07-19T10:27:01Z")

</div>

Failed to run the following query: select (date\_trunc('hour', my\_date) + interval date\_part('minute', my\_date)::int minutes) as group\_by\_name from table\_name where my\_date\>= '2023-07-12' having the following excepti…

---

## [ELSER deployments crash kibana and fail deployment](https://discuss.elastic.co/t/elser-deployments-crash-kibana-and-fail-deployment/337344)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 10:06am UTC](https://discuss.elastic.co/t/elser-deployments-crash-kibana-and-fail-deployment/337344 "2023-07-19T10:06:30Z")

</div>

Trying to test ELSER following this tutorial, but I cannot get past the very first step of deploying the ELSER model. I have a 4GB ML node, as specified. Every time I try to deploy the ELSER model, my Kibana node crashe…

---

## [Filter results by another query](https://discuss.elastic.co/t/filter-results-by-another-query/338763)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 10:01am UTC](https://discuss.elastic.co/t/filter-results-by-another-query/338763 "2023-07-19T10:01:07Z")

</div>

I have a usecase where I want to search for documents that do not have counterparts in the index. For example, consider the following: I have a document format like this: { "file": "myfile.ext", "classificatio…

---

## [Is it recommended to disable sniffer and always direct the requests to the k8s HTTP SVC instead?](https://discuss.elastic.co/t/is-it-recommended-to-disable-sniffer-and-always-direct-the-requests-to-the-k8s-http-svc-instead/338762)

<div class="topic-metadata">

**Author:** [@GustavoSantos](https://discuss.elastic.co/u/GustavoSantos)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 9:36am UTC](https://discuss.elastic.co/t/is-it-recommended-to-disable-sniffer-and-always-direct-the-requests-to-the-k8s-http-svc-instead/338762 "2023-07-19T09:36:04Z")

</div>

Hi all, Our ES clusters are deployed in k8s using the eck-operator and our application uses the Java client with sniffer enabled. We are currently struggling with an annoying issue when the cluster is restarted. By th…

---

## [Wrongly named the container of the master node](https://discuss.elastic.co/t/wrongly-named-the-container-of-the-master-node/338756)

<div class="topic-metadata">

**Author:** [@BogdanS](https://discuss.elastic.co/u/BogdanS)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 9:05am UTC](https://discuss.elastic.co/t/wrongly-named-the-container-of-the-master-node/338756 "2023-07-19T09:05:30Z")

</div>

Hi all. When I first created the Elasticsearch cluster in GKE with the ECK (1 master node, 32 data nodes), I gave a name to the container inside the master node - "elasticsearch-master". 6 months in, and 14 TB later, I …

---

## [Discect rule with a "+" sign in the message, can't escape it](https://discuss.elastic.co/t/discect-rule-with-a-sign-in-the-message-cant-escape-it/338661)

<div class="topic-metadata">

**Author:** [@UPPERCASE](https://discuss.elastic.co/u/UPPERCASE)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 8:36am UTC](https://discuss.elastic.co/t/discect-rule-with-a-sign-in-the-message-cant-escape-it/338661 "2023-07-19T08:36:05Z")

</div>

I have the following disect rule: %{timestamp} queries: info: client @%{dns\_client} %{source\_ip}#%{source\_port} (%{query}): query: %{query\_2} IN %{class} + (%{dns\_server}), which is from a BIND DNS server (querylog). Wh…

---

## [The connection between Logstash and Elasticsearch is not working](https://discuss.elastic.co/t/the-connection-between-logstash-and-elasticsearch-is-not-working/338750)

<div class="topic-metadata">

**Author:** [@chldnjs8899](https://discuss.elastic.co/u/chldnjs8899)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 8:14am UTC](https://discuss.elastic.co/t/the-connection-between-logstash-and-elasticsearch-is-not-working/338750 "2023-07-19T08:14:42Z")

</div>

The following content has been translated using ChatGPT. Thank you for your understanding. Hello, I'm currently learning Elasticsearch. I'm using Elasticsearch version 8.8.2. I have written the following pipeline in ord…

---

## [Visualize user journey on a website](https://discuss.elastic.co/t/visualize-user-journey-on-a-website/338060)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 4\
**Last updated:** [July 19, 2023, 7:52am UTC](https://discuss.elastic.co/t/visualize-user-journey-on-a-website/338060 "2023-07-19T07:52:59Z")

</div>

Hi , I want to visualize the various url visited by a spcific user along with the timestamp in a graph. i have the following data in es index, date: 11/Jul/2023:11:15:13.705 +0530 remote ip: 49.37.163.204 url: /3…

---

## [How to create security rule for Windows Authentication - Success from Public IPs Alert with KQL language?](https://discuss.elastic.co/t/how-to-create-security-rule-for-windows-authentication-success-from-public-ips-alert-with-kql-language/338588)

<div class="topic-metadata">

**Author:** [@aungsoemin](https://discuss.elastic.co/u/aungsoemin)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 7:27am UTC](https://discuss.elastic.co/t/how-to-create-security-rule-for-windows-authentication-success-from-public-ips-alert-with-kql-language/338588 "2023-07-19T07:27:01Z")

</div>

Hi, I'm trying to create the custom use case "Windows Authentication - Success from Public IPs Alert" with below informations. Event code = 4624 Action = Success IP Range = Any Public IP Here is my KQL query to cre…

---

## [ES node handshake failed](https://discuss.elastic.co/t/es-node-handshake-failed/338743)

<div class="topic-metadata">

**Author:** [@emmning](https://discuss.elastic.co/u/emmning)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 6:17am UTC](https://discuss.elastic.co/t/es-node-handshake-failed/338743 "2023-07-19T06:17:43Z")

</div>

Hi team, I am trying to start cluster on my MacBook. I got below error \[2023-07-19T14:16:03,014\]\[WARN \]\[o.e.d.HandshakingTransportAddressConnector\] \[node-2\] \[connectToRemoteMasterNode\[127.0.0.1:9301\]\] completed handsha…

---

## [How to connect Stand Alone Elastic Agent to SentinelOne and Logstash?](https://discuss.elastic.co/t/how-to-connect-stand-alone-elastic-agent-to-sentinelone-and-logstash/338726)

<div class="topic-metadata">

**Author:** [@toman](https://discuss.elastic.co/u/toman)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 4:29am UTC](https://discuss.elastic.co/t/how-to-connect-stand-alone-elastic-agent-to-sentinelone-and-logstash/338726 "2023-07-19T04:29:30Z")

</div>

I am trying to make a connection from our SentinelOne environment to our existing Logstash server where we process data. We do not use Fleet or Elasticsearch. It seems that we could use Elastic Agent for this connection…

---

## [Index rollover ealier than described in ILM index lifecycle management](https://discuss.elastic.co/t/index-rollover-ealier-than-described-in-ilm-index-lifecycle-management/337996)

<div class="topic-metadata">

**Author:** [@VietDuc](https://discuss.elastic.co/u/VietDuc)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 3:29am UTC](https://discuss.elastic.co/t/index-rollover-ealier-than-described-in-ilm-index-lifecycle-management/337996 "2023-07-19T03:29:22Z")

</div>

Hi everyone, I have setup a TSDS with following ILM in ES 8.8.2 GET .ds-micrometer-metrics-2023.07.08-000036/\_ilm/explain ".ds-micrometer-metrics-2023.07.08-000036": { "index": ".ds-micrometer-metrics-2023.07.0…

---

## [Elastic APM - Plotting traceID start and end timestamps](https://discuss.elastic.co/t/elastic-apm-plotting-traceid-start-and-end-timestamps/338703)

<div class="topic-metadata">

**Author:** [@sangramreddy](https://discuss.elastic.co/u/sangramreddy)\
**Replies:** 10\
**Last updated:** [July 19, 2023, 2:55am UTC](https://discuss.elastic.co/t/elastic-apm-plotting-traceid-start-and-end-timestamps/338703 "2023-07-19T02:55:06Z")

</div>

We have bunch of applications through which a trace ID passes. We would like to calculate total time taken by the trace and plot them. Elastic APM UI doesn't show this information out of the box for asynchronous applica…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=475)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=477)
