# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=479

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 480

---

## [Indices have lifecycle errors](https://discuss.elastic.co/t/indices-have-lifecycle-errors/338524)

<div class="topic-metadata">

**Author:** [@Nde](https://discuss.elastic.co/u/Nde)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 9:41am UTC](https://discuss.elastic.co/t/indices-have-lifecycle-errors/338524 "2023-07-17T09:41:41Z")

</div>

Hello, In Index Management in Kabana I got some indices with lifecycle errors. The error of these indices is about the rollover\_alias not pointed into an index. i've tried the /\_reindex method and add the alias to t…

---

## [Subtraction of Sum Aggregate Values in one Index from Sum Aggregate Values in Another Index](https://discuss.elastic.co/t/subtraction-of-sum-aggregate-values-in-one-index-from-sum-aggregate-values-in-another-index/338442)

<div class="topic-metadata">

**Author:** [@nickbarry](https://discuss.elastic.co/u/nickbarry)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 3:58pm UTC](https://discuss.elastic.co/t/subtraction-of-sum-aggregate-values-in-one-index-from-sum-aggregate-values-in-another-index/338442 "2023-07-17T15:58:26Z")

</div>

I have two indices within a single data view that track 'compute cycles' in some unit like 'cycle-hours per month'. One of the indices is the total max available cycle-hours for each computer in the company's data cente…

---

## [Kafka input plugin cannot parse key or value due to message keys](https://discuss.elastic.co/t/kafka-input-plugin-cannot-parse-key-or-value-due-to-message-keys/338560)

<div class="topic-metadata">

**Author:** [@kohlbecker](https://discuss.elastic.co/u/kohlbecker)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 3:38pm UTC](https://discuss.elastic.co/t/kafka-input-plugin-cannot-parse-key-or-value-due-to-message-keys/338560 "2023-07-17T15:38:03Z")

</div>

Key and value of the topic messages consumed by the Kafka input plugin are prefixed with the message ids, which causes the json parser to fail: Here an example from the logstash log with decorate\_events =\> "extended" pr…

---

## [Need help with Elastic agent installation](https://discuss.elastic.co/t/need-help-with-elastic-agent-installation/338570)

<div class="topic-metadata">

**Author:** [@Retrogamer](https://discuss.elastic.co/u/Retrogamer)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 2:25pm UTC](https://discuss.elastic.co/t/need-help-with-elastic-agent-installation/338570 "2023-07-17T14:25:27Z")

</div>

It has been a few days that I am going through all documentations to install Elastic-agent either with Fleet Server or Stand-alone, but still, I have not been able to understand how each components works, what is the pre…

---

## [Unable to launch Kibana Dashboard outside the Network Host](https://discuss.elastic.co/t/unable-to-launch-kibana-dashboard-outside-the-network-host/336426)

<div class="topic-metadata">

**Author:** [@rohit.tps123](https://discuss.elastic.co/u/rohit.tps123)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 2:21pm UTC](https://discuss.elastic.co/t/unable-to-launch-kibana-dashboard-outside-the-network-host/336426 "2023-07-17T14:21:13Z")

</div>

Hello, I have installed Elastic Search and Kibana on one Network Host (Docker Env) While checking via curl commands. I am getting proper respone for Elastic Search and No response for Kibana I am not able to access t…

---

## [Bytes value wraps to negative value](https://discuss.elastic.co/t/bytes-value-wraps-to-negative-value/338533)

<div class="topic-metadata">

**Author:** [@eddie4](https://discuss.elastic.co/u/eddie4)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 1:48pm UTC](https://discuss.elastic.co/t/bytes-value-wraps-to-negative-value/338533 "2023-07-17T13:48:14Z")

</div>

Hello, Am attempting to multiply the number of bytes from netflow by 100. This is to offset the sampling rate. The pipeline has the following script: { "script": { "source": "ctx.network.true\_bytes2 = ctx.…

---

## [Implement proxy-protocol support for beats inputs](https://discuss.elastic.co/t/implement-proxy-protocol-support-for-beats-inputs/338561)

<div class="topic-metadata">

**Author:** [@bilel\_meddeb](https://discuss.elastic.co/u/bilel_meddeb)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 1:14pm UTC](https://discuss.elastic.co/t/implement-proxy-protocol-support-for-beats-inputs/338561 "2023-07-17T13:14:41Z")

</div>

Hello :wave:t4: Would it be possible to support proxy-protocol for beats inputs ? I send logs from winlogbeat to logstash and i have Haproxy between them. without proxy and with this configuration of logstash, i got …

---

## [Using sql query with parameters in dotnet client](https://discuss.elastic.co/t/using-sql-query-with-parameters-in-dotnet-client/338553)

<div class="topic-metadata">

**Author:** [@darooman](https://discuss.elastic.co/u/darooman)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 12:32pm UTC](https://discuss.elastic.co/t/using-sql-query-with-parameters-in-dotnet-client/338553 "2023-07-17T12:32:22Z")

</div>

When using the .net nuget package Elastic.Clients.Elasticsearch (version 8.1.3) to connect to an elastic cloud instance (running elastic v8.7.1), I am trying to use the sql query but I am struggling with the Params prope…

---

## [How to automatically delete index data after a few days or after certain size limit](https://discuss.elastic.co/t/how-to-automatically-delete-index-data-after-a-few-days-or-after-certain-size-limit/338511)

<div class="topic-metadata">

**Author:** [@akash-asthana](https://discuss.elastic.co/u/akash-asthana)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 12:14pm UTC](https://discuss.elastic.co/t/how-to-automatically-delete-index-data-after-a-few-days-or-after-certain-size-limit/338511 "2023-07-17T12:14:49Z")

</div>

Hello, I have a scenario where i need to clean up the index data after a given number of days or after a certain storage size is occupied. Is there any way of achieving this without deleting the actual index? Thanks

---

## [Elasticsearch License Expired](https://discuss.elastic.co/t/elasticsearch-license-expired/338546)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 12:11pm UTC](https://discuss.elastic.co/t/elasticsearch-license-expired/338546 "2023-07-17T12:11:17Z")

</div>

Hi What happens when the Elasticsearch license expired? Currently, the cluster has assigned a commercial license and it will expire soon, so what will happen once the assigned date expired?

---

## [After K8s cluster was turned off for night Kibna "Username or password is incorrect"](https://discuss.elastic.co/t/after-k8s-cluster-was-turned-off-for-night-kibna-username-or-password-is-incorrect/337123)

<div class="topic-metadata">

**Author:** [@Bogdan\_Boyko](https://discuss.elastic.co/u/Bogdan_Boyko)\
**Replies:** 9\
**Last updated:** [July 17, 2023, 11:30am UTC](https://discuss.elastic.co/t/after-k8s-cluster-was-turned-off-for-night-kibna-username-or-password-is-incorrect/337123 "2023-07-17T11:30:23Z")

</div>

I have a problem with Kibana, when my Kubernetes cluster shuts down in the evening and turns back on in the morning, then I can't log in with the credentials that were valid yesterday. And when I delete the pod and it is…

---

## [Prevent Functionbeat from deleting log groups](https://discuss.elastic.co/t/prevent-functionbeat-from-deleting-log-groups/338538)

<div class="topic-metadata">

**Author:** [@shlant](https://discuss.elastic.co/u/shlant)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 10:49am UTC](https://discuss.elastic.co/t/prevent-functionbeat-from-deleting-log-groups/338538 "2023-07-17T10:49:26Z")

</div>

So I am wanting to stream logs from a number of existing cloudwatch log groups to my ELK stack. I seem to have the setup basically ready but I noticed during the debugging of the setup process that when I deleted the Clo…

---

## [Autofocus lose while typing in SearchBox](https://discuss.elastic.co/t/autofocus-lose-while-typing-in-searchbox/338091)

<div class="topic-metadata">

**Author:** [@raj22](https://discuss.elastic.co/u/raj22)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 10:06am UTC](https://discuss.elastic.co/t/autofocus-lose-while-typing-in-searchbox/338091 "2023-07-17T10:06:22Z")

</div>

Hello, I have component from \> @elastic/react-search-ui . For searchbox desing customization used inputView. But when I started typing suddenly autofocus is losing , so I need to enter cusor again into input element …

---

## [Unable to create Custom index for metricbeat](https://discuss.elastic.co/t/unable-to-create-custom-index-for-metricbeat/336887)

<div class="topic-metadata">

**Author:** [@lalchand\_rajak](https://discuss.elastic.co/u/lalchand_rajak)\
**Replies:** 5\
**Last updated:** [July 17, 2023, 9:59am UTC](https://discuss.elastic.co/t/unable-to-create-custom-index-for-metricbeat/336887 "2023-07-17T09:59:18Z")

</div>

Hello, I am trying to create the custom index for metricbeat with same template as metricbeat but not able to create the index using below configs. ###################### Metricbeat Configuration Example ##############…

---

## [Filebeat: Index not getting created at Elasticsearch](https://discuss.elastic.co/t/filebeat-index-not-getting-created-at-elasticsearch/338530)

<div class="topic-metadata">

**Author:** [@mohammad\_messiah](https://discuss.elastic.co/u/mohammad_messiah)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 9:54am UTC](https://discuss.elastic.co/t/filebeat-index-not-getting-created-at-elasticsearch/338530 "2023-07-17T09:54:32Z")

</div>

Hi All, I have installed filebeat on few servers but somehow logs are not getting created tried reinstalling the filebeat didn't worked. For previously configured servers index are getting created on daily basis Please …

---

## [Import dashboard on elk 8.5.3](https://discuss.elastic.co/t/import-dashboard-on-elk-8-5-3/338236)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 6\
**Last updated:** [July 17, 2023, 9:54am UTC](https://discuss.elastic.co/t/import-dashboard-on-elk-8-5-3/338236 "2023-07-17T09:54:30Z")

</div>

hi can anyone help me i create dashboard on elk version 8.6.2 and i want to import them in elk version 8.5.3 but i get this warning in kibana UI The file could not be processed due to error: "Unprocessable Entity: Doc…

---

## [Search by script with field range + docs without exesting fields](https://discuss.elastic.co/t/search-by-script-with-field-range-docs-without-exesting-fields/338403)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 9:54am UTC](https://discuss.elastic.co/t/search-by-script-with-field-range-docs-without-exesting-fields/338403 "2023-07-17T09:54:24Z")

</div>

Hi, I try to make a query using template. Here are docs in my index: { "\_index" : "instruments", "\_type" : "\_doc", "\_id" : "721905", "\_score" : null, "\_source" : { "sess…

---

## [Is there a way to make the query string fuzzy by default?](https://discuss.elastic.co/t/is-there-a-way-to-make-the-query-string-fuzzy-by-default/338150)

<div class="topic-metadata">

**Author:** [@johnrodey](https://discuss.elastic.co/u/johnrodey)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 9:50am UTC](https://discuss.elastic.co/t/is-there-a-way-to-make-the-query-string-fuzzy-by-default/338150 "2023-07-17T09:50:37Z")

</div>

I submit a query string via Java Rest API (QueryStringQueryBuilder). Right now I pass in whatever the user enters and use that as my query string however I would like to automatically apply fuzzy searching, when it make…

---

## [Adding multiple client to the ELK centralised logging system](https://discuss.elastic.co/t/adding-multiple-client-to-the-elk-centralised-logging-system/338526)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar\_Jaiswal](https://discuss.elastic.co/u/Rahul_Kumar_Jaiswal)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 9:43am UTC](https://discuss.elastic.co/t/adding-multiple-client-to-the-elk-centralised-logging-system/338526 "2023-07-17T09:43:44Z")

</div>

How to add multiple clients to the ELK centralised logging system so that we can visualise their logs. I have already installed filebeat on the client nodes and configure the filebeat.yml file too. But, not able to see t…

---

## [Aggregation return data that do not match query](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184)

<div class="topic-metadata">

**Author:** [@Edyta\_Szkiladz](https://discuss.elastic.co/u/Edyta_Szkiladz)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 9:42am UTC](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184 "2023-07-17T09:42:32Z")

</div>

I am trying to do aggregation on documents which contains categories field. Categories is an array of strings. Sample document: { "\_index": "test-v11", "\_type": "\_doc", "\_id": "954961", "\_version": 4, "\_score"…

---

## [Curl error when connecting with ElasticSearch running from docker - Windows](https://discuss.elastic.co/t/curl-error-when-connecting-with-elasticsearch-running-from-docker-windows/338525)

<div class="topic-metadata">

**Author:** [@Chaitanya\_Kanth](https://discuss.elastic.co/u/Chaitanya_Kanth)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 9:41am UTC](https://discuss.elastic.co/t/curl-error-when-connecting-with-elasticsearch-running-from-docker-windows/338525 "2023-07-17T09:41:50Z")

</div>

I installed Elasticsearch docker image on windows 10 machine. Docker v4.21.1 and elasticsearch v8.2.2. I downloaded the cert file and running the curl command from same location where file is downloaded. Running below co…

---

## [Ruby into file](https://discuss.elastic.co/t/ruby-into-file/338102)

<div class="topic-metadata">

**Author:** [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 9:27am UTC](https://discuss.elastic.co/t/ruby-into-file/338102 "2023-07-17T09:27:23Z")

</div>

Hello, I read the documentation about the ruby script and I did not correctly understand the conversion of the ruby script into a file. If I have a converted ruby script into a file, do I have to rewrite the script int…

---

## [Add resiliency on .security-7 index](https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121)

<div class="topic-metadata">

**Author:** [@Josselin](https://discuss.elastic.co/u/Josselin)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 9:23am UTC](https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121 "2023-07-17T09:23:39Z")

</div>

Hi, During multiple incident with cluster restart we lost the nodes where the index .security-7 was stored. It had a huge impact and we want to avoid as much as possible this situation to occur again. We have seen on t…

---

## [Connect oracle to elastic / kibana](https://discuss.elastic.co/t/connect-oracle-to-elastic-kibana/338436)

<div class="topic-metadata">

**Author:** [@Oytoch](https://discuss.elastic.co/u/Oytoch)\
**Replies:** 5\
**Last updated:** [July 17, 2023, 9:03am UTC](https://discuss.elastic.co/t/connect-oracle-to-elastic-kibana/338436 "2023-07-17T09:03:53Z")

</div>

Hi, I try to understand kibana / Elasticsearch to interface my oracle database in order to make dashboard with kibana ( BI) I work with an "on premise" version First question, is it possible to do that with kibana ? …

---

## [How to use Search templates in collate for phrase suggester](https://discuss.elastic.co/t/how-to-use-search-templates-in-collate-for-phrase-suggester/338515)

<div class="topic-metadata">

**Author:** [@To\_Noroozi](https://discuss.elastic.co/u/To_Noroozi)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 8:33am UTC](https://discuss.elastic.co/t/how-to-use-search-templates-in-collate-for-phrase-suggester/338515 "2023-07-17T08:33:38Z")

</div>

Hi guys, according to the this link for collate: Suggesters | Elasticsearch Guide \[8.8\] | Elastic we can use our custom search template to use more complex query. i create sample search template and it is ok with name …

---

## [Persistent data support for logstash in ECK 2.8?](https://discuss.elastic.co/t/persistent-data-support-for-logstash-in-eck-2-8/338514)

<div class="topic-metadata">

**Author:** [@Claudio\_Tassini](https://discuss.elastic.co/u/Claudio_Tassini)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 8:30am UTC](https://discuss.elastic.co/t/persistent-data-support-for-logstash-in-eck-2-8/338514 "2023-07-17T08:30:44Z")

</div>

Hi all! I'm trying to deploy an ECK cluster composed of elasticsearch, kibana, beats and a logstash instance. The only problem I'm facing is that the logstash CRD does not seem to support the definition of a volumeclaim…

---

## [ES fails to restart after reboot](https://discuss.elastic.co/t/es-fails-to-restart-after-reboot/338465)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 8:21am UTC](https://discuss.elastic.co/t/es-fails-to-restart-after-reboot/338465 "2023-07-17T08:21:20Z")

</div>

version 7.17.1 running on ubuntu -- started from systemctl When ever the server is rebooted ES fails to restart properly. Subsequent manual restart works just fine. \[2023-07-16T01:37:33,109\]\[INFO \]\[o.e.p.PluginsServic…

---

## [How does elastic react with x-pack crack](https://discuss.elastic.co/t/how-does-elastic-react-with-x-pack-crack/338503)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 8:13am UTC](https://discuss.elastic.co/t/how-does-elastic-react-with-x-pack-crack/338503 "2023-07-17T08:13:55Z")

</div>

I'm researching on ESTC stock and wondering how does elastic react with x-pack crack? If SMB modifies Elastic code and builds it on-premise, it seems ESTC will lost much revenue

---

## [Create Backup of all Kibana Objects](https://discuss.elastic.co/t/create-backup-of-all-kibana-objects/338226)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 5\
**Last updated:** [July 17, 2023, 7:47am UTC](https://discuss.elastic.co/t/create-backup-of-all-kibana-objects/338226 "2023-07-17T07:47:38Z")

</div>

I would like to make sure that I'm able to restore all objects maintained by Kibana (Visualisations, Pipelines, Transformjobs, Dashboards, Templates, Fleet Settings and and and) from a snapshot. How can I achive that? I…

---

## [How to define time range Connection Graph](https://discuss.elastic.co/t/how-to-define-time-range-connection-graph/338485)

<div class="topic-metadata">

**Author:** [@leesever](https://discuss.elastic.co/u/leesever)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 7:12am UTC](https://discuss.elastic.co/t/how-to-define-time-range-connection-graph/338485 "2023-07-17T07:12:05Z")

</div>

Hi, we using the graph for centrality analysis to identify the most central nodes in our platform (links between users). I wish to emphasize that I am not a programer or something as such and mostly use Kibana for fraud…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=478)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=480)
