# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=480

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 481

---

## [I have 2 aggregation in my query for Dau, Mau. how to combine them to find the ratio. have tried with bucket\_script, scripted metric. nothing works,](https://discuss.elastic.co/t/i-have-2-aggregation-in-my-query-for-dau-mau-how-to-combine-them-to-find-the-ratio-have-tried-with-bucket-script-scripted-metric-nothing-works/338373)

<div class="topic-metadata">

**Author:** [@Dev\_Profile](https://discuss.elastic.co/u/Dev_Profile)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 6:58am UTC](https://discuss.elastic.co/t/i-have-2-aggregation-in-my-query-for-dau-mau-how-to-combine-them-to-find-the-ratio-have-tried-with-bucket-script-scripted-metric-nothing-works/338373 "2023-07-17T06:58:28Z")

</div>

Below is my query. is there any way to access multi-buckets value to manipulate n return the results. { "\_source": false, "aggs": { "nested\_dau": { "nested": { "path": "dau" }, "aggs": …

---

## [I want to render only kibana dashboard screen in python application,,how can I do that?](https://discuss.elastic.co/t/i-want-to-render-only-kibana-dashboard-screen-in-python-application-how-can-i-do-that/338173)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 6:46am UTC](https://discuss.elastic.co/t/i-want-to-render-only-kibana-dashboard-screen-in-python-application-how-can-i-do-that/338173 "2023-07-17T06:46:26Z")

</div>

I want to render only Kibana dashboard screen in python application for user purpose only they don't have access for modification. User want's to only read permission. I am new on elasticsearch so please help for that, …

---

## [Filebeat module ingest pipeline not working in logstash](https://discuss.elastic.co/t/filebeat-module-ingest-pipeline-not-working-in-logstash/338500)

<div class="topic-metadata">

**Author:** [@nbindal](https://discuss.elastic.co/u/nbindal)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 5:55am UTC](https://discuss.elastic.co/t/filebeat-module-ingest-pipeline-not-working-in-logstash/338500 "2023-07-17T05:55:43Z")

</div>

Hi Team, I am using apache module and fileset in Beats+ELK stack where Filebeat is sending logs to logstash, logstash is using Ingest pipeline(we get module ingest pipeline - filebeat-8.7.1-apache-access-pipeline) , but…

---

## [How to sort my data in elasticsearch](https://discuss.elastic.co/t/how-to-sort-my-data-in-elasticsearch/338072)

<div class="topic-metadata">

**Author:** [@lz840408](https://discuss.elastic.co/u/lz840408)\
**Replies:** 8\
**Last updated:** [July 17, 2023, 5:13am UTC](https://discuss.elastic.co/t/how-to-sort-my-data-in-elasticsearch/338072 "2023-07-17T05:13:38Z")

</div>

how to sort by asc in logstash? i want new add field,it's self increment column,and insert dest index,how make it?

---

## [Getting logstasg error in rhel 8 and not running in logstash in rhel 8](https://discuss.elastic.co/t/getting-logstasg-error-in-rhel-8-and-not-running-in-logstash-in-rhel-8/338480)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 4:28am UTC](https://discuss.elastic.co/t/getting-logstasg-error-in-rhel-8-and-not-running-in-logstash-in-rhel-8/338480 "2023-07-17T04:28:47Z")

</div>

Logstash is not running in rhel 8 and getting error while start logstash. logstash version :- 7.4.3 \[ERROR\] 2023-07-15 18:52:56.228 \[main\] Logstash - java.lang.IllegalStateException: Logstash stopped processing because…

---

## [Logstash output by condition](https://discuss.elastic.co/t/logstash-output-by-condition/338376)

<div class="topic-metadata">

**Author:** [@tbs575](https://discuss.elastic.co/u/tbs575)\
**Replies:** 6\
**Last updated:** [July 17, 2023, 2:19am UTC](https://discuss.elastic.co/t/logstash-output-by-condition/338376 "2023-07-17T02:19:05Z")

</div>

Hi Guys, I setup logstash with influxdb plugin, and can send metric to influxdb successfully. But now I meet question with output by condition. run two filebeat instance onto two pc to capture two different log files, …

---

## [Own Output for SNMP Get Values in Logstash](https://discuss.elastic.co/t/own-output-for-snmp-get-values-in-logstash/338440)

<div class="topic-metadata">

**Author:** [@hitman22](https://discuss.elastic.co/u/hitman22)\
**Replies:** 2\
**Last updated:** [July 16, 2023, 10:33pm UTC](https://discuss.elastic.co/t/own-output-for-snmp-get-values-in-logstash/338440 "2023-07-16T22:33:56Z")

</div>

Hello, I have the following Logstash config input { snmp { tags =\> \[ "snmp" \] get =\> \[".1.3.6.1.4.1.9.9.48.1.1.1.5.2",".1.3.6.1.4.1.9.9.109.1.1.1.1.5.1",".1.3.6.1.4.1.9.9.48.1.1.1.5.1"\] hosts =\> \[{host =\> …

---

## [How to install custom plugin (dashboard) elastic stack 8.3](https://discuss.elastic.co/t/how-to-install-custom-plugin-dashboard-elastic-stack-8-3/338453)

<div class="topic-metadata">

**Author:** [@ARm1110](https://discuss.elastic.co/u/ARm1110)\
**Replies:** 1\
**Last updated:** [July 16, 2023, 1:40pm UTC](https://discuss.elastic.co/t/how-to-install-custom-plugin-dashboard-elastic-stack-8-3/338453 "2023-07-16T13:40:45Z")

</div>

hello my stack version 8.3.3 and OS ubuntu 22.04 I wanted to install a plugin from Github, but I'm working on the Debian thread for it, no matter what I did, it didn't install. link custom plugin directory kibana /u…

---

## [Collection and storage of information from netflow sources](https://discuss.elastic.co/t/collection-and-storage-of-information-from-netflow-sources/335759)

<div class="topic-metadata">

**Author:** [@BugS](https://discuss.elastic.co/u/BugS)\
**Replies:** 12\
**Last updated:** [July 16, 2023, 12:22pm UTC](https://discuss.elastic.co/t/collection-and-storage-of-information-from-netflow-sources/335759 "2023-07-16T12:22:10Z")

</div>

Hello everyone. Maybe it's a newbie question, but I have limited experience with ELK. Currently, I'm trying to use it as a netflow collector. I've configured everything according to the documentation, but I'm a bit conce…

---

## [Unkown Key in Elasticsearch Template (elastic stack 8.3.3)](https://discuss.elastic.co/t/unkown-key-in-elasticsearch-template-elastic-stack-8-3-3/338100)

<div class="topic-metadata">

**Author:** [@ARm1110](https://discuss.elastic.co/u/ARm1110)\
**Replies:** 4\
**Last updated:** [July 16, 2023, 4:41am UTC](https://discuss.elastic.co/t/unkown-key-in-elasticsearch-template-elastic-stack-8-3-3/338100 "2023-07-16T04:41:16Z")

</div>

elastic stack(filebeat,elasticsearch,kibana,elastic-agent,logstash) =\> 8.3.3 OS: Ubuntu 22.04 Agents: linux base I wanted to run Wazuh manager with Elastic 8.3.3, the Wazuh plugin can't be installed with elastic, I ma…

---

## [DBeaver to Elasticsearch connectivity is OK but fails on listing tables](https://discuss.elastic.co/t/dbeaver-to-elasticsearch-connectivity-is-ok-but-fails-on-listing-tables/338444)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 3\
**Last updated:** [July 16, 2023, 12:50am UTC](https://discuss.elastic.co/t/dbeaver-to-elasticsearch-connectivity-is-ok-but-fails-on-listing-tables/338444 "2023-07-16T00:50:26Z")

</div>

On DBeaver v23.1.0, we created a connection to an instance of Elasticsearch v8.6.1. The connectivity test, and logging in are OK. However, when clicking on the icons to expand the "Tables", it got an error saying, ... T…

---

## [Logstash 8.8.2 not sending filebeat 8.8.2 logs to eleasticsearch 8.8.2 database](https://discuss.elastic.co/t/logstash-8-8-2-not-sending-filebeat-8-8-2-logs-to-eleasticsearch-8-8-2-database/338459)

<div class="topic-metadata">

**Author:** [@Kiran\_K](https://discuss.elastic.co/u/Kiran_K)\
**Replies:** 2\
**Last updated:** [July 16, 2023, 12:40am UTC](https://discuss.elastic.co/t/logstash-8-8-2-not-sending-filebeat-8-8-2-logs-to-eleasticsearch-8-8-2-database/338459 "2023-07-16T00:40:12Z")

</div>

Dear Team, Our scenario is network devices send logs to filebeat. Filebeat send those logs to logstash and logstash send logs to elasticsearch database but we are receive below warning in logstash logs and we didn't rec…

---

## [Logs not being sent to filebeats and logstash](https://discuss.elastic.co/t/logs-not-being-sent-to-filebeats-and-logstash/338284)

<div class="topic-metadata">

**Author:** [@nikokyu](https://discuss.elastic.co/u/nikokyu)\
**Replies:** 2\
**Last updated:** [July 15, 2023, 10:12pm UTC](https://discuss.elastic.co/t/logs-not-being-sent-to-filebeats-and-logstash/338284 "2023-07-15T22:12:59Z")

</div>

Currently trying to set up Filebeats to try and connect to Logstash to send logs from cisco network syslogs and tacacs logs to a logstash server to be sent to elastic and then displayed on kibana. However, I have not be…

---

## [Filebeat and Logstash not connecting](https://discuss.elastic.co/t/filebeat-and-logstash-not-connecting/338302)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 4\
**Last updated:** [July 15, 2023, 1:55pm UTC](https://discuss.elastic.co/t/filebeat-and-logstash-not-connecting/338302 "2023-07-15T13:55:09Z")

</div>

I am reaching out to seek your expertise and guidance regarding an issue I am facing with transferring logs from Filebeat to Logstash. I have a setup where Filebeat is installed on 'Server1', which sends logs to Logstash…

---

## [Inaccessibility of Artifact Link for Elasticsearch Versions 2.x and 5.x: Seeking Clarification](https://discuss.elastic.co/t/inaccessibility-of-artifact-link-for-elasticsearch-versions-2-x-and-5-x-seeking-clarification/338457)

<div class="topic-metadata">

**Author:** [@amit\_phulera](https://discuss.elastic.co/u/amit_phulera)\
**Replies:** 3\
**Last updated:** [July 15, 2023, 11:54am UTC](https://discuss.elastic.co/t/inaccessibility-of-artifact-link-for-elasticsearch-versions-2-x-and-5-x-seeking-clarification/338457 "2023-07-15T11:54:07Z")

</div>

We have been using the following artifact link (https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-{{ elasticsearch\_version }}-linux-x86\_64.tar.gz) to download and test various components on elasticsearch…

---

## [How do return exact term matching irrespective of order?](https://discuss.elastic.co/t/how-do-return-exact-term-matching-irrespective-of-order/338297)

<div class="topic-metadata">

**Author:** [@at\_ohn](https://discuss.elastic.co/u/at_ohn)\
**Replies:** 3\
**Last updated:** [July 15, 2023, 6:30am UTC](https://discuss.elastic.co/t/how-do-return-exact-term-matching-irrespective-of-order/338297 "2023-07-15T06:30:12Z")

</div>

Hi community, appreciate if anyone has any insights on this. We want to return only exact matches irrespective of the order of the terms, and disregard any terms that are not in the query. For example, if we search "Ne…

---

## [How can we connect local kibana to elastic cloud elasticsearch](https://discuss.elastic.co/t/how-can-we-connect-local-kibana-to-elastic-cloud-elasticsearch/338379)

<div class="topic-metadata">

**Author:** [@Nishant\_Chauhan](https://discuss.elastic.co/u/Nishant_Chauhan)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 11:29pm UTC](https://discuss.elastic.co/t/how-can-we-connect-local-kibana-to-elastic-cloud-elasticsearch/338379 "2023-07-14T23:29:07Z")

</div>

how can we connect local kibana to elastic cloud elasticsearch, like how we can get token. I tried this. GET /\_security/enroll/kibana { "error": { "root\_cause": \[ { "type": "security\_exception", …

---

## [TSVB Table, is it possible to remove rows where the count value is zero](https://discuss.elastic.co/t/tsvb-table-is-it-possible-to-remove-rows-where-the-count-value-is-zero/338424)

<div class="topic-metadata">

**Author:** [@azulgrana](https://discuss.elastic.co/u/azulgrana)\
**Replies:** 3\
**Last updated:** [July 14, 2023, 10:42pm UTC](https://discuss.elastic.co/t/tsvb-table-is-it-possible-to-remove-rows-where-the-count-value-is-zero/338424 "2023-07-14T22:42:03Z")

</div>

Hi there! I have a TSVB table that displays the most recent version value (Last Value) over the last 31 days for the devices in the environment. Each device creates multiple records a day as we perform the automatic che…

---

## [Machine Learning - Anomaly Detection Jobs](https://discuss.elastic.co/t/machine-learning-anomaly-detection-jobs/338433)

<div class="topic-metadata">

**Author:** [@Jhonfechavez](https://discuss.elastic.co/u/Jhonfechavez)\
**Replies:** 2\
**Last updated:** [July 14, 2023, 10:09pm UTC](https://discuss.elastic.co/t/machine-learning-anomaly-detection-jobs/338433 "2023-07-14T22:09:10Z")

</div>

We have a Job in order to monitor our APM services using the following detectors: Yesterday we restarted the Job (Stop - start datafeed) and we are getting the following error: "Datafeed is encountering errors extra…

---

## [Using scripts with aggregation](https://discuss.elastic.co/t/using-scripts-with-aggregation/338378)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 9:13pm UTC](https://discuss.elastic.co/t/using-scripts-with-aggregation/338378 "2023-07-14T21:13:38Z")

</div>

Hi, I have a use case where the value of a field name signal can be 0, 1, or 2. I have to perform aggregation on this field but there are few records in the index without the field. For the field not\_exist, I need to as…

---

## [Logstash gets stuck in pipelines](https://discuss.elastic.co/t/logstash-gets-stuck-in-pipelines/337247)

<div class="topic-metadata">

**Author:** [@Tony\_K](https://discuss.elastic.co/u/Tony_K)\
**Replies:** 4\
**Last updated:** [July 14, 2023, 9:00pm UTC](https://discuss.elastic.co/t/logstash-gets-stuck-in-pipelines/337247 "2023-07-14T21:00:16Z")

</div>

I have a simple csv file where i like to upload to elasticsearch. My sample csv file contains 2 records. it gets stuck at pipelines. Please see below. I am running this on windows 11 Thank you for your helo. uploa…

---

## [Ingest pipeline: copy all fields that contains a word to a single new field](https://discuss.elastic.co/t/ingest-pipeline-copy-all-fields-that-contains-a-word-to-a-single-new-field/338432)

<div class="topic-metadata">

**Author:** [@drjz](https://discuss.elastic.co/u/drjz)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 8:48pm UTC](https://discuss.elastic.co/t/ingest-pipeline-copy-all-fields-that-contains-a-word-to-a-single-new-field/338432 "2023-07-14T20:48:02Z")

</div>

Hi all, I am puzzling with the Script processor in an Ingest pipeline to copy all fields to a single new field. This is the same idea as using the copy\_to in the mapping, but instead of creating the copy in the index, we…

---

## [Kibana Dashbaords into UI Mobile application](https://discuss.elastic.co/t/kibana-dashbaords-into-ui-mobile-application/338438)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 8:02pm UTC](https://discuss.elastic.co/t/kibana-dashbaords-into-ui-mobile-application/338438 "2023-07-14T20:02:09Z")

</div>

Hi, I have created a dashboard for my organization to track supply chain traceability. We have a mobile application UI also and we want to have the dashboard in that also. Can you please guide me, on how to embed it into…

---

## [Elastic Search 7.17.9 ClusterFormationFailure](https://discuss.elastic.co/t/elastic-search-7-17-9-clusterformationfailure/337963)

<div class="topic-metadata">

**Author:** [@SSRR](https://discuss.elastic.co/u/SSRR)\
**Replies:** 5\
**Last updated:** [July 14, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elastic-search-7-17-9-clusterformationfailure/337963 "2023-07-14T18:29:09Z")

</div>

I am facing some issues in my elasticsearch cluster related to Cluster Formation with 2 nodes. I'm trying to upgrade from elasticsearch from 7.17.0 to 7.17.9. Node1 is set as master and Node2 is not. I stopped elastics…

---

## [Simple? Where's the URL to query elastic cloud instance?](https://discuss.elastic.co/t/simple-wheres-the-url-to-query-elastic-cloud-instance/338318)

<div class="topic-metadata">

**Author:** [@midi-man](https://discuss.elastic.co/u/midi-man)\
**Replies:** 4\
**Last updated:** [July 14, 2023, 6:20pm UTC](https://discuss.elastic.co/t/simple-wheres-the-url-to-query-elastic-cloud-instance/338318 "2023-07-14T18:20:33Z")

</div>

A hopefully simple question: Where is the URL to query an elastic cloud instance for a given deployment? The docs say to always use api dot elastic-cloud dot com/api/v1/deployments but this doesn't appear to work for…

---

## [Making a field hidden in search \_source](https://discuss.elastic.co/t/making-a-field-hidden-in-search-source/338418)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 3\
**Last updated:** [July 14, 2023, 5:48pm UTC](https://discuss.elastic.co/t/making-a-field-hidden-in-search-source/338418 "2023-07-14T17:48:05Z")

</div>

I have a index which has TBs of data now I am adding a new field to it say foo using ingest pipeline http://localhost:9200/\_ingest/pipeline/add { "processors" : \[{ "set": { "field" : "foo", …

---

## [Aggregation Query filtering on results](https://discuss.elastic.co/t/aggregation-query-filtering-on-results/338343)

<div class="topic-metadata">

**Author:** [@lakhr034](https://discuss.elastic.co/u/lakhr034)\
**Replies:** 8\
**Last updated:** [July 14, 2023, 5:11pm UTC](https://discuss.elastic.co/t/aggregation-query-filtering-on-results/338343 "2023-07-14T17:11:12Z")

</div>

I have this query: GET user\_info,user\_auth\_cards\_info/\_search { "size": 0, "aggs": { "sorted\_user\_id": { "terms": { "field": "user\_id", "size": 15 }, "aggs": { "filtered…

---

## [Version conflict - no document found on update-by-query](https://discuss.elastic.co/t/version-conflict-no-document-found-on-update-by-query/338262)

<div class="topic-metadata">

**Author:** [@Balagopal\_Kanattil](https://discuss.elastic.co/u/Balagopal_Kanattil)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 3:40pm UTC](https://discuss.elastic.co/t/version-conflict-no-document-found-on-update-by-query/338262 "2023-07-14T15:40:24Z")

</div>

Hi, I am running a self hosted ES cluster with version 6.8.1. I am trying to update some docs using update-by-query API. It fails for some documents with following error: version\_conflict\_engine\_exception version con…

---

## [KIBANA - STATE POP-UP DISPLAYS AMOUNT ONLY IN REGION MAP](https://discuss.elastic.co/t/kibana-state-pop-up-displays-amount-only-in-region-map/338384)

<div class="topic-metadata">

**Author:** [@Sinchana\_P](https://discuss.elastic.co/u/Sinchana_P)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 3:35pm UTC](https://discuss.elastic.co/t/kibana-state-pop-up-displays-amount-only-in-region-map/338384 "2023-07-14T15:35:14Z")

</div>

KIBANA - STATE POP-UP DISPLAYS AMOUNT ONLY IN REGION MAP First time when the region map visualization is loaded, only amount is displayed. If any filter is applied on the map, then it starts showing state name as well. …

---

## [Phase out VM from cluster](https://discuss.elastic.co/t/phase-out-vm-from-cluster/338422)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 2\
**Last updated:** [July 14, 2023, 2:50pm UTC](https://discuss.elastic.co/t/phase-out-vm-from-cluster/338422 "2023-07-14T14:50:57Z")

</div>

Hi, I have an issue where one of my hot nodes has a larger disk than needed. Since I can't downsize the disk and due to the volume of data, I can't simply copy over to a smaller disk. So I thought it'd be the easiest (…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=479)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=481)
