# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=477

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 478

---

## [Add some default data to ES when docker first run](https://discuss.elastic.co/t/add-some-default-data-to-es-when-docker-first-run/338701)

<div class="topic-metadata">

**Author:** [@TranTruongMMCII](https://discuss.elastic.co/u/TranTruongMMCII)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 2:30am UTC](https://discuss.elastic.co/t/add-some-default-data-to-es-when-docker-first-run/338701 "2023-07-19T02:30:28Z")

</div>

Dear all, I am new to ES. Now I want to create a docker to run ES, but I faced some errors. Firstly, I can create a docker to run ES and can interact with it. But I want to add some default data to index when docker fir…

---

## [Set top\_hits size dynamically for each bucket based on its doc\_count with a script](https://discuss.elastic.co/t/set-top-hits-size-dynamically-for-each-bucket-based-on-its-doc-count-with-a-script/338728)

<div class="topic-metadata">

**Author:** [@DMinovski](https://discuss.elastic.co/u/DMinovski)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 11:31pm UTC](https://discuss.elastic.co/t/set-top-hits-size-dynamically-for-each-bucket-based-on-its-doc-count-with-a-script/338728 "2023-07-18T23:31:51Z")

</div>

I use a query to find the duplicates in an index based on a field. Some documents have the same value in this field and they are duplicates. { "size": 0, "aggs": { "duplicate\_terms": { "terms…

---

## [Data streams stuck in frozen searchable\_snapshot phase (wait state inconsistent with indices status)](https://discuss.elastic.co/t/data-streams-stuck-in-frozen-searchable-snapshot-phase-wait-state-inconsistent-with-indices-status/338727)

<div class="topic-metadata">

**Author:** [@Adrien\_WATTEZ](https://discuss.elastic.co/u/Adrien_WATTEZ)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 10:51pm UTC](https://discuss.elastic.co/t/data-streams-stuck-in-frozen-searchable-snapshot-phase-wait-state-inconsistent-with-indices-status/338727 "2023-07-18T22:51:40Z")

</div>

This request follows a previous ticket that was never really answered. ES 8.8.2 - free trial in local - paid enterprise licence on other environment Same problem, I have created a data stream with ILM with phases rang…

---

## [Elasticsearch delete docs during the indexations](https://discuss.elastic.co/t/elasticsearch-delete-docs-during-the-indexations/338674)

<div class="topic-metadata">

**Author:** [@atombrownbear](https://discuss.elastic.co/u/atombrownbear)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 9:53pm UTC](https://discuss.elastic.co/t/elasticsearch-delete-docs-during-the-indexations/338674 "2023-07-18T21:53:06Z")

</div>

Hi all! When im do indexation, my backend app sends 1234 pages (for example). if I call /stats? by curl I will see that 1234 pages have been indexed and 234 pages have been deleted, although they should not be deleted. w…

---

## [Custom analyser for numeric string](https://discuss.elastic.co/t/custom-analyser-for-numeric-string/338529)

<div class="topic-metadata">

**Author:** [@hmkhitaryan](https://discuss.elastic.co/u/hmkhitaryan)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 8:32pm UTC](https://discuss.elastic.co/t/custom-analyser-for-numeric-string/338529 "2023-07-18T20:32:19Z")

</div>

Hi everyone. I have this kind of issue: I have a numeric string field, seperated with dots, like "1.1.2", "11.2.1", and the like. I have a requirement to do sorting by this field, and when I try to sort by that field, i…

---

## [Which configuration schemes are avaliable in 8.8 version of elastic clusterization?](https://discuss.elastic.co/t/which-configuration-schemes-are-avaliable-in-8-8-version-of-elastic-clusterization/338137)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 20\
**Last updated:** [July 18, 2023, 7:57pm UTC](https://discuss.elastic.co/t/which-configuration-schemes-are-avaliable-in-8-8-version-of-elastic-clusterization/338137 "2023-07-18T19:57:03Z")

</div>

which configuration schemes are avaliable in 8.8 version of slatic clusterization?

---

## [Setup filebeat to send different logs to different indexes (to elasticsearch)](https://discuss.elastic.co/t/setup-filebeat-to-send-different-logs-to-different-indexes-to-elasticsearch/338709)

<div class="topic-metadata">

**Author:** [@perfecto25](https://discuss.elastic.co/u/perfecto25)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 6:36pm UTC](https://discuss.elastic.co/t/setup-filebeat-to-send-different-logs-to-different-indexes-to-elasticsearch/338709 "2023-07-18T18:36:10Z")

</div>

Hello, I setup a filebeat 8.8.2 on redhat host and configured my filebeat.yml like this, Im sending all my log data to ES directly, filebeat.inputs: - type: filestream id: my\_id enabled: true paths: - /home/cu…

---

## [TSVB markdown with conditional values](https://discuss.elastic.co/t/tsvb-markdown-with-conditional-values/338582)

<div class="topic-metadata">

**Author:** [@hkhalil](https://discuss.elastic.co/u/hkhalil)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 4:25pm UTC](https://discuss.elastic.co/t/tsvb-markdown-with-conditional-values/338582 "2023-07-18T16:25:35Z")

</div>

Hi, We're looking to create in our dashboard a markdown using the TSVB control type. Our dashboard has controls for filtering purposes. We would like the markdown to display different predetermined numerical values bas…

---

## [Filter results in table](https://discuss.elastic.co/t/filter-results-in-table/338697)

<div class="topic-metadata">

**Author:** [@vils](https://discuss.elastic.co/u/vils)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 4:39pm UTC](https://discuss.elastic.co/t/filter-results-in-table/338697 "2023-07-18T16:39:50Z")

</div>

Hi all, I'm currently working with a Lens table where my values are displayed as percentages. I'm interested in filtering these results so that only certain percentage ranges are displayed - for example, I might want to…

---

## [Does Platinum Anomaly Detection Rule Work At All?](https://discuss.elastic.co/t/does-platinum-anomaly-detection-rule-work-at-all/338439)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 4:07pm UTC](https://discuss.elastic.co/t/does-platinum-anomaly-detection-rule-work-at-all/338439 "2023-07-18T16:07:54Z")

</div>

Hi all. Can anyone confirm that the Platinum Anomaly Detection Rule works? I know it says it's "beta". I've been beating my head against this wall for two days! I do have a different kind of Rule that works, and send…

---

## [Fast Vector Highlighting is not working stable on Synonym based fields](https://discuss.elastic.co/t/fast-vector-highlighting-is-not-working-stable-on-synonym-based-fields/338673)

<div class="topic-metadata">

**Author:** [@Pavithra2014](https://discuss.elastic.co/u/Pavithra2014)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 4:05pm UTC](https://discuss.elastic.co/t/fast-vector-highlighting-is-not-working-stable-on-synonym-based-fields/338673 "2023-07-18T16:05:20Z")

</div>

Here , we are using Fast Vector highlight on a field where it has the copy field for synonym . for some records FVH highlights properly but for some it is not. Field mapping: title: { type: "text", term\_vector: "with\_p…

---

## [\*I am working with wireshark pcaps inside of SO kibana and hunt. Seems like the timestamps do not match?](https://discuss.elastic.co/t/i-am-working-with-wireshark-pcaps-inside-of-so-kibana-and-hunt-seems-like-the-timestamps-do-not-match/338612)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 3:32pm UTC](https://discuss.elastic.co/t/i-am-working-with-wireshark-pcaps-inside-of-so-kibana-and-hunt-seems-like-the-timestamps-do-not-match/338612 "2023-07-18T15:32:27Z")

</div>

Hi, I am using windows 11, SO, winlogbeat and logstash output.logstash: The Logstash hosts hosts: \["192.168.1.226:5044"\] I have saved a wireshark session as a pcap. I moved the pcap from my windows 10 machine with win…

---

## [Substract value of one attribute from the previous day value in ELasticsearch for Kibana Visualization](https://discuss.elastic.co/t/substract-value-of-one-attribute-from-the-previous-day-value-in-elasticsearch-for-kibana-visualization/337184)

<div class="topic-metadata">

**Author:** [@gauravpks](https://discuss.elastic.co/u/gauravpks)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 3:17pm UTC](https://discuss.elastic.co/t/substract-value-of-one-attribute-from-the-previous-day-value-in-elasticsearch-for-kibana-visualization/337184 "2023-07-18T15:17:25Z")

</div>

My elastic index has 3 attributes: - accountNumber, timestamp and score. I want to calculate the difference in score from today to the previous day (or the last value) for each account and build visualizations for the di…

---

## [Facing permission issues on running up \`elastic-package stack up\`](https://discuss.elastic.co/t/facing-permission-issues-on-running-up-elastic-package-stack-up/338566)

<div class="topic-metadata">

**Author:** [@hari\_ibm](https://discuss.elastic.co/u/hari_ibm)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 3:08pm UTC](https://discuss.elastic.co/t/facing-permission-issues-on-running-up-elastic-package-stack-up/338566 "2023-07-18T15:08:16Z")

</div>

Getting the below exception on running elastic-package stack up ERROR: Elasticsearch exited unexpectedly java.nio.file.AccessDeniedException: /usr/share/elasticsearch/config/certs at java.base/sun.nio.fs.UnixException.…

---

## [ECS version is different](https://discuss.elastic.co/t/ecs-version-is-different/338630)

<div class="topic-metadata">

**Author:** [@Nishant\_Chauhan](https://discuss.elastic.co/u/Nishant_Chauhan)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 3:06pm UTC](https://discuss.elastic.co/t/ecs-version-is-different/338630 "2023-07-18T15:06:37Z")

</div>

We are getting below error in our Kibana logs 8.7.1 and Elasticsearch version is also same 8.7.1 why ECS version is 8.6.0 ? is it ok , if wrong how we can correct it? {"service":{"node":{"roles":\["background\_tasks","u…

---

## [Configuration scheme issue](https://discuss.elastic.co/t/configuration-scheme-issue/338110)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 1:52pm UTC](https://discuss.elastic.co/t/configuration-scheme-issue/338110 "2023-07-11T13:52:08Z")

</div>

i have to cofigure a clúster with 5Teras data ingest per day in 4 data nodes the thing is, if I installed elastisearch 8.8 which configuration is the best for these schema, single node configuration with the voting s…

---

## [Duplicate Data Views being Created when Copying Dashboard to another Space](https://discuss.elastic.co/t/duplicate-data-views-being-created-when-copying-dashboard-to-another-space/338136)

<div class="topic-metadata">

**Author:** [@m-sarmento](https://discuss.elastic.co/u/m-sarmento)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 2:56pm UTC](https://discuss.elastic.co/t/duplicate-data-views-being-created-when-copying-dashboard-to-another-space/338136 "2023-07-18T14:56:09Z")

</div>

When copying a dashboard from one space to another it looks like a copy of the data view used in that dashboard is being created in the space it was copied into. What is the best way to go about copying dashboards to …

---

## [Kibana - Every user gets their own space](https://discuss.elastic.co/t/kibana-every-user-gets-their-own-space/338375)

<div class="topic-metadata">

**Author:** [@sc6698](https://discuss.elastic.co/u/sc6698)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 2:51pm UTC](https://discuss.elastic.co/t/kibana-every-user-gets-their-own-space/338375 "2023-07-18T14:51:57Z")

</div>

Hi, How am I going to achieve this by allowing every logged in user to have their own space and saved objects? All users are allowed to see their own space but not others. I understand that it could be done by creating…

---

## [Manually Enrolling Kibana](https://discuss.elastic.co/t/manually-enrolling-kibana/338451)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 2:41pm UTC](https://discuss.elastic.co/t/manually-enrolling-kibana/338451 "2023-07-18T14:41:29Z")

</div>

Hi there, I am trying to enroll Kibana manually (meaning without the enrollment token.) Basically what I am doing is- Starting elasticsearch and then setting the password for kibana\_system and then entering these cre…

---

## [Kibana returns "statusCode": 404 in simple docker stack](https://discuss.elastic.co/t/kibana-returns-statuscode-404-in-simple-docker-stack/338545)

<div class="topic-metadata">

**Author:** [@vojtech-cerveny](https://discuss.elastic.co/u/vojtech-cerveny)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 2:34pm UTC](https://discuss.elastic.co/t/kibana-returns-statuscode-404-in-simple-docker-stack/338545 "2023-07-18T14:34:31Z")

</div>

Hey, I have this simple stack of Elasticsearch + Kibana + Nginx for SSL. And I am not sure why Kibana returns on example.com:4444/kibana this response: { "statusCode": 404, "error": "Not Found", "message": "Not Found" …

---

## [求助kibana执行yarn build --skip-os-packages报错](https://discuss.elastic.co/t/kibana-yarn-build-skip-os-packages/338554)

<div class="topic-metadata">

**Author:** [@gao](https://discuss.elastic.co/u/gao)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 2:27pm UTC](https://discuss.elastic.co/t/kibana-yarn-build-skip-os-packages/338554 "2023-07-18T14:27:39Z")

</div>

yarn run v1.21.1 $ node scripts/build --all-platforms --skip-os-packages Browserslist: caniuse-lite is outdated. Please run: npx browserslist@latest --update-db Why you should do it regularly: GitHub - browserslist/b…

---

## [Add\_host\_metadata not collecting host details](https://discuss.elastic.co/t/add-host-metadata-not-collecting-host-details/338053)

<div class="topic-metadata">

**Author:** [@vijay\_kaali](https://discuss.elastic.co/u/vijay_kaali)\
**Replies:** 5\
**Last updated:** [July 18, 2023, 2:24pm UTC](https://discuss.elastic.co/t/add-host-metadata-not-collecting-host-details/338053 "2023-07-18T14:24:54Z")

</div>

Hi i am using 6.8 metricbeat and server is 7.12 . a. add host metricset and got error , so enable add\_host\_metadata : ~ b . as per documentation . add\_host\_metadata it should collect "host":{ "architecture":"x86\_64"…

---

## [Filebeat multiple modules on single input syslog port](https://discuss.elastic.co/t/filebeat-multiple-modules-on-single-input-syslog-port/338691)

<div class="topic-metadata">

**Author:** [@Amol\_Sahare](https://discuss.elastic.co/u/Amol_Sahare)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 2:17pm UTC](https://discuss.elastic.co/t/filebeat-multiple-modules-on-single-input-syslog-port/338691 "2023-07-18T14:17:27Z")

</div>

Hi All, I have installed filebeat Syslog input and received logs from multiple devices like Vmware Esx, Firewall, Unix, VCenter, Antivirus, etc. Filebeat Yml file: fields\_under\_root: true fields.collector\_node\_id: ${…

---

## [Elasticsearch error when trying to run bin/elasticsearch-setup-passwords](https://discuss.elastic.co/t/elasticsearch-error-when-trying-to-run-bin-elasticsearch-setup-passwords/338625)

<div class="topic-metadata">

**Author:** [@Kris\_U](https://discuss.elastic.co/u/Kris_U)\
**Replies:** 5\
**Last updated:** [July 18, 2023, 2:14pm UTC](https://discuss.elastic.co/t/elasticsearch-error-when-trying-to-run-bin-elasticsearch-setup-passwords/338625 "2023-07-18T14:14:12Z")

</div>

I am setting up Elasticsearch version 7.17.11 on Ubuntu 20.04. It will be a single instance of Elasticsearch but I will have separate instances for Kibana and Logstash. I am trying to recreate our setup in another cloud …

---

## [How to set the static range's in vertical axis for time-series graph in Kibana](https://discuss.elastic.co/t/how-to-set-the-static-ranges-in-vertical-axis-for-time-series-graph-in-kibana/338295)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 2:13pm UTC](https://discuss.elastic.co/t/how-to-set-the-static-ranges-in-vertical-axis-for-time-series-graph-in-kibana/338295 "2023-07-18T14:13:18Z")

</div>

I am trying to create time-series graph. I have 6 fields with random numbers(max 2000). How can we set the y-axis ranges (like 0,400, 1000, 1500, 2000) instead of dynamic. I am using ELK 8.2.3 version.

---

## [Custom 3rd party integration for outgoing connectors](https://discuss.elastic.co/t/custom-3rd-party-integration-for-outgoing-connectors/338675)

<div class="topic-metadata">

**Author:** [@mha1](https://discuss.elastic.co/u/mha1)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 1:43pm UTC](https://discuss.elastic.co/t/custom-3rd-party-integration-for-outgoing-connectors/338675 "2023-07-18T13:43:28Z")

</div>

Is there an update about the development of custom alerting connectors? I saw this question was asked twice in 2021. Add custom connectors to 3rd party Kibana Plugin Idea: Custom Alert Connector Any updates? I´ll als…

---

## [Optimize logstash tcp input plugin](https://discuss.elastic.co/t/optimize-logstash-tcp-input-plugin/337847)

<div class="topic-metadata">

**Author:** [@true64gurus](https://discuss.elastic.co/u/true64gurus)\
**Replies:** 7\
**Last updated:** [July 18, 2023, 1:33pm UTC](https://discuss.elastic.co/t/optimize-logstash-tcp-input-plugin/337847 "2023-07-18T13:33:26Z")

</div>

Hello, I have 10 Kubernetes clusters forward their logs to logstash VM (k8s fluentd ---\> logstash port 7000) . Logstash gets to a point where logs are being missed and source pods doing retries to get logs through . (…

---

## [Logstash not showing field with null values](https://discuss.elastic.co/t/logstash-not-showing-field-with-null-values/338648)

<div class="topic-metadata">

**Author:** [@Mohit\_Gupta2](https://discuss.elastic.co/u/Mohit_Gupta2)\
**Replies:** 5\
**Last updated:** [July 18, 2023, 12:44pm UTC](https://discuss.elastic.co/t/logstash-not-showing-field-with-null-values/338648 "2023-07-18T12:44:26Z")

</div>

I am indexing elasticsearch via logstash but it is showing only document's fields with not null values. Earlier I used to do this through transporter and it returns the null values as well. Also the mapping in both case…

---

## [How to add labels in apm for python lamda to reflect in kibana](https://discuss.elastic.co/t/how-to-add-labels-in-apm-for-python-lamda-to-reflect-in-kibana/338665)

<div class="topic-metadata">

**Author:** [@sairam\_kadakuntla](https://discuss.elastic.co/u/sairam_kadakuntla)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 11:51am UTC](https://discuss.elastic.co/t/how-to-add-labels-in-apm-for-python-lamda-to-reflect-in-kibana/338665 "2023-07-18T11:51:13Z")

</div>

i have created a elastic apm object like client = Client({ 'SERVICE\_NAME': os.environ.get("ELASTIC\_APM\_SERVICE\_NAME"), 'SERVER\_URL': os.environ.get("ELASTIC\_APM\_LAMBDA\_APM\_SERVER") }) starting with client.begin\_trans…

---

## [In data table visualization i have 5 columns but in one column, only one data is coming](https://discuss.elastic.co/t/in-data-table-visualization-i-have-5-columns-but-in-one-column-only-one-data-is-coming/338421)

<div class="topic-metadata">

**Author:** [@Malikmamta](https://discuss.elastic.co/u/Malikmamta)\
**Replies:** 4\
**Last updated:** [July 18, 2023, 10:11am UTC](https://discuss.elastic.co/t/in-data-table-visualization-i-have-5-columns-but-in-one-column-only-one-data-is-coming/338421 "2023-07-18T10:11:35Z")

</div>

in data table visualization, I have 5 columns but in one column, only one row is missing instead of 10 rows. in that column multiline are there. In discover, i can see complete data but for that one column, only single …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=476)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=478)
