# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=478

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 479

---

## [How to change the kibana jvm memory](https://discuss.elastic.co/t/how-to-change-the-kibana-jvm-memory/338647)

<div class="topic-metadata">

**Author:** [@tan\_minkee](https://discuss.elastic.co/u/tan_minkee)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 10:00am UTC](https://discuss.elastic.co/t/how-to-change-the-kibana-jvm-memory/338647 "2023-07-18T10:00:13Z")

</div>

I would like to set the kibana jvm memory to 8Gb instead of default value, May I know how to do that? What I have done is edit the field "--max-old-space-size=8192" in the node.options under /etc/kibana but I am not sur…

---

## [How to change the axis to Dynamic in LENS](https://discuss.elastic.co/t/how-to-change-the-axis-to-dynamic-in-lens/338319)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 9:44am UTC](https://discuss.elastic.co/t/how-to-change-the-axis-to-dynamic-in-lens/338319 "2023-07-18T09:44:45Z")

</div>

Hello Team, Can you help to make the axis Dynamic for LENS as the lowest values shown here is 0.....whereas axis may start from 300000

---

## [How to create email alerts in kibana](https://discuss.elastic.co/t/how-to-create-email-alerts-in-kibana/338219)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 11\
**Last updated:** [July 18, 2023, 9:37am UTC](https://discuss.elastic.co/t/how-to-create-email-alerts-in-kibana/338219 "2023-07-18T09:37:00Z")

</div>

how can i create email alert for logs in elasticsearch and how can i create connectors in kibana UI

---

## [Elasticsearch performance degrades after upgrading from 6.7 to 7.10](https://discuss.elastic.co/t/elasticsearch-performance-degrades-after-upgrading-from-6-7-to-7-10/338640)

<div class="topic-metadata">

**Author:** [@teanoon](https://discuss.elastic.co/u/teanoon)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 9:28am UTC](https://discuss.elastic.co/t/elasticsearch-performance-degrades-after-upgrading-from-6-7-to-7-10/338640 "2023-07-18T09:28:59Z")

</div>

We are trying to migrate the elasticsearch from 6.7 to 7.10. The indices are reindexed in the new elasticsearch cluster. And did some comparisons. simple load test is slow A simple load test indicates that the same se…

---

## [Elastic Agent by Docker Image](https://discuss.elastic.co/t/elastic-agent-by-docker-image/338636)

<div class="topic-metadata">

**Author:** [@Retrogamer](https://discuss.elastic.co/u/Retrogamer)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 8:56am UTC](https://discuss.elastic.co/t/elastic-agent-by-docker-image/338636 "2023-07-18T08:56:05Z")

</div>

I want to deploy Stand-alone Elastic Agent using Docker image. I followed the instruction in this page but, I am not sure which environment variables I should use to deploy the Agent as Stand-alone. Elastic Search and Ki…

---

## [I/O wait is increasing after many reindexing](https://discuss.elastic.co/t/i-o-wait-is-increasing-after-many-reindexing/337695)

<div class="topic-metadata">

**Author:** [@yannlef](https://discuss.elastic.co/u/yannlef)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 8:21am UTC](https://discuss.elastic.co/t/i-o-wait-is-increasing-after-many-reindexing/337695 "2023-07-18T08:21:13Z")

</div>

Hello, I'm trying to find some response here, since I think I exhausted all my solutions on that problem. I'm also totally new with this subject. I am working on an old ELK (5.5), hosted on a docker in a dedicated VM …

---

## [Running multiple pipelines and a single pipeline triggered with shell script simultaneously](https://discuss.elastic.co/t/running-multiple-pipelines-and-a-single-pipeline-triggered-with-shell-script-simultaneously/338441)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 7:48am UTC](https://discuss.elastic.co/t/running-multiple-pipelines-and-a-single-pipeline-triggered-with-shell-script-simultaneously/338441 "2023-07-18T07:48:22Z")

</div>

Hi. I have 5 pipelines already running on linux server. The conf files are listed in a pipeline.yml and it has already been started with sudo systemctl start logstash, up and running. I created another single pipeline…

---

## [Can't send data to elastic after upgrade the version](https://discuss.elastic.co/t/cant-send-data-to-elastic-after-upgrade-the-version/338634)

<div class="topic-metadata">

**Author:** [@zerratriani](https://discuss.elastic.co/u/zerratriani)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 7:41am UTC](https://discuss.elastic.co/t/cant-send-data-to-elastic-after-upgrade-the-version/338634 "2023-07-18T07:41:36Z")

</div>

Hi, previously we used Elastic & Logstash version 7.15 to store data. But after we upgraded to version 8 the data could not be sent. We used the same Logstash configuration and added a few things that changed in version …

---

## [Elasticsearch failed to start 8.8](https://discuss.elastic.co/t/elasticsearch-failed-to-start-8-8/338616)

<div class="topic-metadata">

**Author:** [@Aditya\_Bollam](https://discuss.elastic.co/u/Aditya_Bollam)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 7:35am UTC](https://discuss.elastic.co/t/elasticsearch-failed-to-start-8-8/338616 "2023-07-18T07:35:41Z")

</div>

I am not able to start the service

---

## [Can I find out why is my elastic node has a high read rate every 12 hours](https://discuss.elastic.co/t/can-i-find-out-why-is-my-elastic-node-has-a-high-read-rate-every-12-hours/338194)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 5\
**Last updated:** [July 18, 2023, 7:34am UTC](https://discuss.elastic.co/t/can-i-find-out-why-is-my-elastic-node-has-a-high-read-rate-every-12-hours/338194 "2023-07-18T07:34:08Z")

</div>

Hi, Above is my elastic 3 days IO rate chart, it does have a special pattern between every 12 hours, the read will reach to a peak, but I am not sure what is the thing that can potentially cause this happens... is there…

---

## [Rackaware good practises](https://discuss.elastic.co/t/rackaware-good-practises/338632)

<div class="topic-metadata">

**Author:** [@bombovy](https://discuss.elastic.co/u/bombovy)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 6:43am UTC](https://discuss.elastic.co/t/rackaware-good-practises/338632 "2023-07-18T06:43:44Z")

</div>

Hello, We have really big log elastic cluster hosted on EKS in AWS. We are generating 17TB of logs each day. Also we are using data tiers for savings. The big costs issue that we are struggling now is the Data Transfer …

---

## [I want to add the custom control in the dashboard where i need to enter new data in the control which should reflect on the dashboard is there anything like that?](https://discuss.elastic.co/t/i-want-to-add-the-custom-control-in-the-dashboard-where-i-need-to-enter-new-data-in-the-control-which-should-reflect-on-the-dashboard-is-there-anything-like-that/338396)

<div class="topic-metadata">

**Author:** [@Aditya\_Patidar](https://discuss.elastic.co/u/Aditya_Patidar)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 4:59am UTC](https://discuss.elastic.co/t/i-want-to-add-the-custom-control-in-the-dashboard-where-i-need-to-enter-new-data-in-the-control-which-should-reflect-on-the-dashboard-is-there-anything-like-that/338396 "2023-07-18T04:59:07Z")

</div>

I want to add the custom control in the dashboard where i need to enter new data in the control which should reflect on the dashboard is there anything like that?

---

## [java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit](https://discuss.elastic.co/t/java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/338620)

<div class="topic-metadata">

**Author:** [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 3:18am UTC](https://discuss.elastic.co/t/java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/338620 "2023-07-18T03:18:52Z")

</div>

Please help me!

---

## [ExecStart=/usr/share/kibana/bin/kibana (code=exited, status=78)](https://discuss.elastic.co/t/execstart-usr-share-kibana-bin-kibana-code-exited-status-78/338474)

<div class="topic-metadata">

**Author:** [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 2:31am UTC](https://discuss.elastic.co/t/execstart-usr-share-kibana-bin-kibana-code-exited-status-78/338474 "2023-07-18T02:31:02Z")

</div>

Please help me!

---

## [ECK 8.8.0 error.message":"javax.net.ssl.SSLHandshakeException: Received fatal alert: bad\_certificate](https://discuss.elastic.co/t/eck-8-8-0-error-message-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/338619)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 1:53am UTC](https://discuss.elastic.co/t/eck-8-8-0-error-message-javax-net-ssl-sslhandshakeexception-received-fatal-alert-bad-certificate/338619 "2023-07-18T01:53:48Z")

</div>

\[my-es-master-0 elasticsearch\] {"@timestamp":"2023-07-18T01:52:00.183Z", "log.level": "WARN", "message":"caught exception while handling client http traffic, closing connection Netty4HttpChannel{localAddress=/10.0.81.0:9…

---

## [How to delete system indices?](https://discuss.elastic.co/t/how-to-delete-system-indices/338510)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 1:37am UTC](https://discuss.elastic.co/t/how-to-delete-system-indices/338510 "2023-07-18T01:37:09Z")

</div>

Hi all, My current cluster is an upgraded cluster from version 7.x to 8.x It has alot of system indices that nolonger require in the cluster but whenever i tried to delete it. I got this message { "error": { "ro…

---

## [Truststore does not contain any trusted certificate entries](https://discuss.elastic.co/t/truststore-does-not-contain-any-trusted-certificate-entries/338610)

<div class="topic-metadata">

**Author:** [@sslgeorge](https://discuss.elastic.co/u/sslgeorge)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 11:36pm UTC](https://discuss.elastic.co/t/truststore-does-not-contain-any-trusted-certificate-entries/338610 "2023-07-17T23:36:57Z")

</div>

I used openssl to generate self signed certs for elasticsearch, but I am unable to use this certs to start elasticsearch. I keep getting the below error \[2023-07-16T19:42:22,649\]\[ERROR\]\[o.e.b.Elasticsearch \] \[Mac…

---

## [Composite aggregation returns after\_key even when there are no more buckets](https://discuss.elastic.co/t/composite-aggregation-returns-after-key-even-when-there-are-no-more-buckets/338606)

<div class="topic-metadata">

**Author:** [@cdhowie](https://discuss.elastic.co/u/cdhowie)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 10:00pm UTC](https://discuss.elastic.co/t/composite-aggregation-returns-after-key-even-when-there-are-no-more-buckets/338606 "2023-07-17T22:00:35Z")

</div>

I've been working on a query that performs a composite aggregation with a large number of buckets. When I set the aggregation size to 50,000, all buckets fit in the response. However, after\_key is still present in the re…

---

## [General Log Warning Question](https://discuss.elastic.co/t/general-log-warning-question/338443)

<div class="topic-metadata">

**Author:** [@Ray3](https://discuss.elastic.co/u/Ray3)\
**Replies:** 6\
**Last updated:** [July 17, 2023, 8:38pm UTC](https://discuss.elastic.co/t/general-log-warning-question/338443 "2023-07-17T20:38:36Z")

</div>

I deployed metricbeat to a node. Unless I use superuser role, I will get warnings in the log, that it cannot take certain actions as the api key used is unauthorized. I do see data reported in kibana, it appears metric…

---

## [Installer Claims Version is Already Installed](https://discuss.elastic.co/t/installer-claims-version-is-already-installed/338603)

<div class="topic-metadata">

**Author:** [@mreeg](https://discuss.elastic.co/u/mreeg)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 7:21pm UTC](https://discuss.elastic.co/t/installer-claims-version-is-already-installed/338603 "2023-07-17T19:21:45Z")

</div>

Hello, I'm trying to Install a piece of software that utilizes Elasticsearch, and includes the Elasticsearch install as part of the installation process. Due to other errors, I had to uninstall the software (includin…

---

## [Logstash HTTP code 400 {:response\_code=\>400}](https://discuss.elastic.co/t/logstash-http-code-400-response-code-400/338501)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 7:19pm UTC](https://discuss.elastic.co/t/logstash-http-code-400-response-code-400/338501 "2023-07-17T19:19:13Z")

</div>

Hi when i try to send data with logstash to influxdb return this error: \[ERROR\] 2023-07-17 09:21:36.133 \[\[main\]\>worker1\] http - Encountered non-2xx HTTP code 400 {:response\_code=\>400, :url=\>"http://192.168.1.2:8086/api…

---

## [99th Percentile of index rate](https://discuss.elastic.co/t/99th-percentile-of-index-rate/338569)

<div class="topic-metadata">

**Author:** [@veryelastic](https://discuss.elastic.co/u/veryelastic)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 6:57pm UTC](https://discuss.elastic.co/t/99th-percentile-of-index-rate/338569 "2023-07-17T18:57:34Z")

</div>

Hello, I have an Elastic 8.8.1 cluster up and running, and being monitored via Metricbeat feeding into stack monitoring, and I can see a chart of index rate. I'd like to visualise the 99th percentile index rate across …

---

## [How to delete docs.deleted from ELK?](https://discuss.elastic.co/t/how-to-delete-docs-deleted-from-elk/338597)

<div class="topic-metadata">

**Author:** [@Yuri\_Pires](https://discuss.elastic.co/u/Yuri_Pires)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 6:50pm UTC](https://discuss.elastic.co/t/how-to-delete-docs-deleted-from-elk/338597 "2023-07-17T18:50:01Z")

</div>

Hello, in this logstash index I used the delete\_by\_query endpoint to clean old logs from storage, I was successful in this step, but I found that the docs are still on the HD and I want to delete them to free up space. h…

---

## [Is there an API to return Anomaly Detection Job results? (Not a Rule)](https://discuss.elastic.co/t/is-there-an-api-to-return-anomaly-detection-job-results-not-a-rule/338599)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 6:24pm UTC](https://discuss.elastic.co/t/is-there-an-api-to-return-anomaly-detection-job-results-not-a-rule/338599 "2023-07-17T18:24:29Z")

</div>

Hi all. Is there an API (or some way) to programmatically return the results displayed on this page? I can do without the chart. I just need some way to know there's some score over 90, for instance. I know about…

---

## [Getting this on opening the UI Cannot connect to the Elasticsearch cluster See the Kibana logs for details and try reloading the page](https://discuss.elastic.co/t/getting-this-on-opening-the-ui-cannot-connect-to-the-elasticsearch-cluster-see-the-kibana-logs-for-details-and-try-reloading-the-page/338595)

<div class="topic-metadata">

**Author:** [@Mamoon\_Qazi](https://discuss.elastic.co/u/Mamoon_Qazi)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 5:46pm UTC](https://discuss.elastic.co/t/getting-this-on-opening-the-ui-cannot-connect-to-the-elasticsearch-cluster-see-the-kibana-logs-for-details-and-try-reloading-the-page/338595 "2023-07-17T17:46:28Z")

</div>

On opening the Kibana UI i get this message "Cannot connect to the Elasticsearch cluster See the Kibana logs for details and try reloading the page." on checking the kibana logs i see this {"type":"log","@timestamp":"2…

---

## [Return only last message based on a specific field](https://discuss.elastic.co/t/return-only-last-message-based-on-a-specific-field/336560)

<div class="topic-metadata">

**Author:** [@WimM](https://discuss.elastic.co/u/WimM)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 5:27pm UTC](https://discuss.elastic.co/t/return-only-last-message-based-on-a-specific-field/336560 "2023-07-17T17:27:13Z")

</div>

Hi I work for a telco company and we are currently reporting on tests done by the technician at the customers location I have currently a graph showing the count on all tests in total (off course with some filters appl…

---

## [Does DBeaver client translate SQL queries to API calls?](https://discuss.elastic.co/t/does-dbeaver-client-translate-sql-queries-to-api-calls/338445)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 5:08pm UTC](https://discuss.elastic.co/t/does-dbeaver-client-translate-sql-queries-to-api-calls/338445 "2023-07-17T17:08:01Z")

</div>

Following this document we have created a DBeaver connection to a testing Elasticsearch instance running the 30-day trial license. We tried SQL queries like select \* from "my-index-000001" limit 10; and the DBeaver clie…

---

## [Stack Monitoring with Metricbeat 8 -- No Cluster Found](https://discuss.elastic.co/t/stack-monitoring-with-metricbeat-8-no-cluster-found/336104)

<div class="topic-metadata">

**Author:** [@Evesy](https://discuss.elastic.co/u/Evesy)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 4:52pm UTC](https://discuss.elastic.co/t/stack-monitoring-with-metricbeat-8-no-cluster-found/336104 "2023-07-17T16:52:38Z")

</div>

Kibana cannot find stack monitoring data when using Metricbeat to collect Elasticsearch/Kibana/Logstash metrics on 8.x I have the below configurations: Kibana (8.8.0) No explicit settings in regards to monitoring etc. …

---

## [Auditing Kibana's user events](https://discuss.elastic.co/t/auditing-kibanas-user-events/338395)

<div class="topic-metadata">

**Author:** [@IsItPossible](https://discuss.elastic.co/u/IsItPossible)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 4:18pm UTC](https://discuss.elastic.co/t/auditing-kibanas-user-events/338395 "2023-07-17T16:18:33Z")

</div>

Hello, I have some questions about monitoring access/events done by Kibana's users. Here are some examples of events im interested in: Create/Delete/Update/Enable/Disable rules Create/Update/Close cases Close/Delete a…

---

## [Help ingesting Data](https://discuss.elastic.co/t/help-ingesting-data/338580)

<div class="topic-metadata">

**Author:** [@Tom\_Dixon](https://discuss.elastic.co/u/Tom_Dixon)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 4:14pm UTC](https://discuss.elastic.co/t/help-ingesting-data/338580 "2023-07-17T16:14:42Z")

</div>

Hi all, I'm new to Elastic and Logstash. I have a source of event data which I'm having problems ingesting. I think it is because the data itself, but being new to Logstash it could also be me, so I'm not sure where the …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=477)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=479)
