# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=482

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 483

---

## [My ELK CLuster health is showing yellow](https://discuss.elastic.co/t/my-elk-cluster-health-is-showing-yellow/338292)

<div class="topic-metadata">

**Author:** [@bbkunbi](https://discuss.elastic.co/u/bbkunbi)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 8:39am UTC](https://discuss.elastic.co/t/my-elk-cluster-health-is-showing-yellow/338292 "2023-07-13T08:39:55Z")

</div>

My ELK Cluster health is showing yellow. Missing replica shards. i am creating index using python code es.index , in that where i have to define replica shard. image is attached.

---

## [Do we need to install nginx to bypass authentication of kibana dashboards when embeded in an external application?](https://discuss.elastic.co/t/do-we-need-to-install-nginx-to-bypass-authentication-of-kibana-dashboards-when-embeded-in-an-external-application/338168)

<div class="topic-metadata">

**Author:** [@Jvv\_Satya](https://discuss.elastic.co/u/Jvv_Satya)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 8:39am UTC](https://discuss.elastic.co/t/do-we-need-to-install-nginx-to-bypass-authentication-of-kibana-dashboards-when-embeded-in-an-external-application/338168 "2023-07-13T08:39:19Z")

</div>

I have created Kibana Dashboards and embedded the iFrame URL in an application. It is asking to enter the username/password inside iFrame. So, how can we bypass and get rid of the login. The kibana version i am uisng is …

---

## [Fleet Server](https://discuss.elastic.co/t/fleet-server/337475)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 8:38am UTC](https://discuss.elastic.co/t/fleet-server/337475 "2023-07-13T08:38:25Z")

</div>

Hello everyone, when trying to enroll my fleet server (which is on the same time and IP as the elasticsearch and kibana) i encounter the following errors. know that this sits behind a proxy so could potentially be that …

---

## [Issue with logstash](https://discuss.elastic.co/t/issue-with-logstash/338290)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 8:15am UTC](https://discuss.elastic.co/t/issue-with-logstash/338290 "2023-07-13T08:15:05Z")

</div>

Hello, I have a question: when you have two different configuration files in the logstash conf.d directory, does this cause a problem when importing them into elasticsearch?

---

## [GeoIp based on custom field source.ip](https://discuss.elastic.co/t/geoip-based-on-custom-field-source-ip/338088)

<div class="topic-metadata">

**Author:** [@vasile](https://discuss.elastic.co/u/vasile)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 7:27am UTC](https://discuss.elastic.co/t/geoip-based-on-custom-field-source-ip/338088 "2023-07-13T07:27:41Z")

</div>

Hi all, I am trying to parse a log message. The original log looks like this: Jul 10 08:51:10 prometheus sshd\[19074\]: Accepted password for my\_user from 1.1.1.1 port 1111 ssh2 My filebeat conf is bellow: --- filebeat…

---

## [Want to create technical support case in Elastic Search](https://discuss.elastic.co/t/want-to-create-technical-support-case-in-elastic-search/338277)

<div class="topic-metadata">

**Author:** [@swapnalimag](https://discuss.elastic.co/u/swapnalimag)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 7:02am UTC](https://discuss.elastic.co/t/want-to-create-technical-support-case-in-elastic-search/338277 "2023-07-13T07:02:44Z")

</div>

I want access to the technical support in Elastic Search. I am Organisational owner but not able to access to the technical support. I have only access to account or billing.

---

## [Need assistance for Uninstalling fleet agent on multiple workstation remotely](https://discuss.elastic.co/t/need-assistance-for-uninstalling-fleet-agent-on-multiple-workstation-remotely/338282)

<div class="topic-metadata">

**Author:** [@swapnalimag](https://discuss.elastic.co/u/swapnalimag)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 6:06am UTC](https://discuss.elastic.co/t/need-assistance-for-uninstalling-fleet-agent-on-multiple-workstation-remotely/338282 "2023-07-13T06:06:24Z")

</div>

Hello, Recently we have deployed fleet agent on windows workstations remotely through GPO. Some of the workstations are facing high CPU usage issue. For That we need assistance for uninstalling the agents remotely. I ca…

---

## [Is leader sync cluster state to node when new node join cluster?](https://discuss.elastic.co/t/is-leader-sync-cluster-state-to-node-when-new-node-join-cluster/338185)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 5:54am UTC](https://discuss.elastic.co/t/is-leader-sync-cluster-state-to-node-when-new-node-join-cluster/338185 "2023-07-13T05:54:58Z")

</div>

When a new node or a previously joined node that was later expelled joins a stable cluster, will the leader synchronize the latest cluster status with them? If so, who can tell me where to find this functionality? I have…

---

## [Action over webhook status](https://discuss.elastic.co/t/action-over-webhook-status/338278)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 5:45am UTC](https://discuss.elastic.co/t/action-over-webhook-status/338278 "2023-07-13T05:45:20Z")

</div>

Hi, I have a watcher with webhook action in it. Is it possible to make another action based on webhook response status? Something like that actions: { webhook\_action: { webhook: { scheme: host: …

---

## [LogStash::Json::ParserError: Unexpected character (':' (code 58))](https://discuss.elastic.co/t/logstash-unexpected-character-code-58/337864)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 5:17am UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-58/337864 "2023-07-13T05:17:49Z")

</div>

i am facing the unexpected character error code 58 in my json data. even after validation of the data the logstash is reporting the errors . below is the sample data , can anyone help why logstash reporting an error here…

---

## [Elasticsearch 8.8: Master not discovered or elected yet, an election requires at least 2 nodes with ids from \[..\]](https://discuss.elastic.co/t/elasticsearch-8-8-master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-with-ids-from/338034)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 5:17am UTC](https://discuss.elastic.co/t/elasticsearch-8-8-master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-with-ids-from/338034 "2023-07-13T05:17:48Z")

</div>

I am creating a multinode cluster (3 Master Nodes), having the configuration like xpack.ml.enabled: false xpack.security.enabled: false network.host: \[\_local\_, \_site\_\] path.data: /data/esdata path.logs: /data/logs xpack…

---

## [Calculate Unix timestamp difference in kibana](https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241)

<div class="topic-metadata">

**Author:** [@Babu72](https://discuss.elastic.co/u/Babu72)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 5:13am UTC](https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241 "2023-07-13T05:13:49Z")

</div>

Hi All, I need help for new scripted field to calculate Unix timestamp difference in kibana as a Metric stop\_timestamp : start\_timestamp : output: hh:mm:ss:SS:SS 1 = 1 Nanosecond 1000 = 1 Microsecond 1000000 = 1 Milli…

---

## [Uploading ML Models into Elasticsearch](https://discuss.elastic.co/t/uploading-ml-models-into-elasticsearch/338195)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 15\
**Last updated:** [July 13, 2023, 5:04am UTC](https://discuss.elastic.co/t/uploading-ml-models-into-elasticsearch/338195 "2023-07-13T05:04:09Z")

</div>

I am trying to upload ML Model into elasticsearch using the eland script provided in the documentation. Installed Python, eland & Pytorch but still unable to upload. python version : Python 3.7.9 Eland version : 8.3…

---

## [Documentation on running our own elastic package storage](https://discuss.elastic.co/t/documentation-on-running-our-own-elastic-package-storage/338274)

<div class="topic-metadata">

**Author:** [@hari\_ibm](https://discuss.elastic.co/u/hari_ibm)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 4:43am UTC](https://discuss.elastic.co/t/documentation-on-running-our-own-elastic-package-storage/338274 "2023-07-13T04:43:09Z")

</div>

Documentation on running our own elastic package storage I have build custom integration and also have setup our own elastic package registry? I couldn't able to find documentation on pushing the package to my registry

---

## [Is elastic Ingest pipelines resource intensive?](https://discuss.elastic.co/t/is-elastic-ingest-pipelines-resource-intensive/338049)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 7\
**Last updated:** [July 13, 2023, 4:30am UTC](https://discuss.elastic.co/t/is-elastic-ingest-pipelines-resource-intensive/338049 "2023-07-13T04:30:05Z")

</div>

Hi, I am currently using injest pipelines to enrich my document before it wrote into index. I am wondering if this process would have a potenial hugh resouce(heap ram or cpu) comsumed for my Elasticsearch node behind …

---

## [Hostname/IP does not match certificate's altnames](https://discuss.elastic.co/t/hostname-ip-does-not-match-certificates-altnames/338234)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 3:11am UTC](https://discuss.elastic.co/t/hostname-ip-does-not-match-certificates-altnames/338234 "2023-07-13T03:11:36Z")

</div>

Hi there, I am trying to enroll kibana with elasticsearch cluster. Here is my deployment detail. I have deployed an Elasticsearch cluster on an EC2 instance using docker and, I am able to access it using the publicI…

---

## [Index template failing with "reason": "unknown key \[index\_patterns\] for create index"](https://discuss.elastic.co/t/index-template-failing-with-reason-unknown-key-index-patterns-for-create-index/338270)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 3:04am UTC](https://discuss.elastic.co/t/index-template-failing-with-reason-unknown-key-index-patterns-for-create-index/338270 "2023-07-13T03:04:51Z")

</div>

I am facing the unknown key for my index template creation time, "reason": "unknown key \[index\_patterns\] for create index" below is the top heading of my template { "index\_patterns" : \[ "data\_center-…

---

## [Enroll Kibana using the Elasticsearch "\_security/enroll/kibana" API](https://discuss.elastic.co/t/enroll-kibana-using-the-elasticsearch-security-enroll-kibana-api/338117)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 3:02am UTC](https://discuss.elastic.co/t/enroll-kibana-using-the-elasticsearch-security-enroll-kibana-api/338117 "2023-07-13T03:02:46Z")

</div>

Hi, I am generating an enrollment token using curl -k https://username:password@address:9200/\_security/enroll/kibana Now, If I am using the token in Kibana enrollment token pagafter starting, am getting error as:- En…

---

## [When I installed the ELASTICSEARCH 8.8.1, I am not able to change the number of replicas of .security and .security-profile index](https://discuss.elastic.co/t/when-i-installed-the-elasticsearch-8-8-1-i-am-not-able-to-change-the-number-of-replicas-of-security-and-security-profile-index/337597)

<div class="topic-metadata">

**Author:** [@KunwarAkanksha](https://discuss.elastic.co/u/KunwarAkanksha)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 12:10am UTC](https://discuss.elastic.co/t/when-i-installed-the-elasticsearch-8-8-1-i-am-not-able-to-change-the-number-of-replicas-of-security-and-security-profile-index/337597 "2023-07-13T00:10:49Z")

</div>

If the Node having the .security index goes down the whole cluster is not functioning. And superuser elastic is unable to edit the setting of this .security index

---

## [Action over webhook status](https://discuss.elastic.co/t/action-over-webhook-status/338055)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 12:02am UTC](https://discuss.elastic.co/t/action-over-webhook-status/338055 "2023-07-13T00:02:56Z")

</div>

Hi, I have a watcher with webhook action in it. Is it possible to make another action based on webhook response status? Something like that actions: { webhook\_action: { webhook: { scheme: host: …

---

## [Rollover of indices doesn't work any more](https://discuss.elastic.co/t/rollover-of-indices-doesnt-work-any-more/338075)

<div class="topic-metadata">

**Author:** [@ronin667](https://discuss.elastic.co/u/ronin667)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 11:54pm UTC](https://discuss.elastic.co/t/rollover-of-indices-doesnt-work-any-more/338075 "2023-07-12T23:54:46Z")

</div>

Hi community, we're running an Elastic Cloud cluster with Elasticsearch and Kibana that has been giving us some trouble in the last few weeks. After our cluster ran out of storage a few weeks ago, the cluster stopped a…

---

## [Multiple events processing and runtime fields](https://discuss.elastic.co/t/multiple-events-processing-and-runtime-fields/338115)

<div class="topic-metadata">

**Author:** [@Thibadu](https://discuss.elastic.co/u/Thibadu)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 11:23pm UTC](https://discuss.elastic.co/t/multiple-events-processing-and-runtime-fields/338115 "2023-07-12T23:23:45Z")

</div>

Hello there, I am currently working on how to raise an alert in Kibana in case a field's value is identical across two different events. Here's how my setup is configured : Network traffic -\> Suricata -\> log file -\> F…

---

## [How do I get unique keys counts, not unique values per key?](https://discuss.elastic.co/t/how-do-i-get-unique-keys-counts-not-unique-values-per-key/338044)

<div class="topic-metadata">

**Author:** [@ecc256](https://discuss.elastic.co/u/ecc256)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 10:48pm UTC](https://discuss.elastic.co/t/how-do-i-get-unique-keys-counts-not-unique-values-per-key/338044 "2023-07-12T22:48:00Z")

</div>

I have a collections of documents. What query can produce unique keys counts (for a time interval), not unique values per key? It might be too simple to do and not mentioned anywhere... thus I cannot find it?

---

## [Elastic Search / ILM / Snapshots S3/Minio](https://discuss.elastic.co/t/elastic-search-ilm-snapshots-s3-minio/338263)

<div class="topic-metadata">

**Author:** [@datencio](https://discuss.elastic.co/u/datencio)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 10:42pm UTC](https://discuss.elastic.co/t/elastic-search-ilm-snapshots-s3-minio/338263 "2023-07-12T22:42:59Z")

</div>

I have been asked to do a POC to see how to properly configure our systems so that ILM will before it deletes an indice will take a snapshot of the indice and store it into S3/Minio. I have successfully updated the clust…

---

## [Dashboard which automatically selects today's index](https://discuss.elastic.co/t/dashboard-which-automatically-selects-todays-index/338142)

<div class="topic-metadata">

**Author:** [@Sam\_Estes](https://discuss.elastic.co/u/Sam_Estes)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 10:35pm UTC](https://discuss.elastic.co/t/dashboard-which-automatically-selects-todays-index/338142 "2023-07-12T22:35:39Z")

</div>

Hello, I have a database with an index for each day. I would like to create a dashboard with visualizations using data from today's index. Each day, we create a new index so I would like the dashboard to automatically u…

---

## [Sometimes I fail to start up and the error message is as follows.](https://discuss.elastic.co/t/sometimes-i-fail-to-start-up-and-the-error-message-is-as-follows/338174)

<div class="topic-metadata">

**Author:** [@pl02206984](https://discuss.elastic.co/u/pl02206984)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 9:46pm UTC](https://discuss.elastic.co/t/sometimes-i-fail-to-start-up-and-the-error-message-is-as-follows/338174 "2023-07-12T21:46:54Z")

</div>

Sometimes I fail to start up and the error message is as follows. \[2023-07-12T10:50:36,815\]\[ERROR\]\[logstash.config.sourceloader\] No configuration found in the configured sources. \[2023-07-12T10:50:36,932\]\[INFO \]\[logstas…

---

## [In ElasticSearch8.5.1, sorted by longitude and latitude](https://discuss.elastic.co/t/in-elasticsearch8-5-1-sorted-by-longitude-and-latitude/338187)

<div class="topic-metadata">

**Author:** [@maoqingjue](https://discuss.elastic.co/u/maoqingjue)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 8:44pm UTC](https://discuss.elastic.co/t/in-elasticsearch8-5-1-sorted-by-longitude-and-latitude/338187 "2023-07-12T20:44:08Z")

</div>

In Elasticsearch8.5.1, sorted by longitude and latitude, my data format is: Post\_info\_address\_index:\[ { LatALng:{ Lat: 37.520804, Lon: 121.219555 } }, { LatALng:{ Lat: 37.520496, Lon: 121.220644 } } \] I us…

---

## [Node repurpose from data to master made primary shard unavailable. How to reset the cluster as API not working](https://discuss.elastic.co/t/node-repurpose-from-data-to-master-made-primary-shard-unavailable-how-to-reset-the-cluster-as-api-not-working/338258)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 8:12pm UTC](https://discuss.elastic.co/t/node-repurpose-from-data-to-master-made-primary-shard-unavailable-how-to-reset-the-cluster-as-api-not-working/338258 "2023-07-12T20:12:31Z")

</div>

node repurpose from data to master made primary shard unavailable. How to reset the cluster as API not working. I am ok to loose the data but not able to start the cluster a fresh. Please suggest.

---

## [How to make Visualization x axis terms in certain order](https://discuss.elastic.co/t/how-to-make-visualization-x-axis-terms-in-certain-order/338038)

<div class="topic-metadata">

**Author:** [@grace\_Li](https://discuss.elastic.co/u/grace_Li)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 7:49pm UTC](https://discuss.elastic.co/t/how-to-make-visualization-x-axis-terms-in-certain-order/338038 "2023-07-12T19:49:02Z")

</div>

Hi, I'm trying to build a visualization with some text type terms as x-axis. Is there a way to put these text value in a given order instead of by alphabetical? For example I'd like to have the response time as Y-axis…

---

## [Sending request to one index, writing to multiple indices](https://discuss.elastic.co/t/sending-request-to-one-index-writing-to-multiple-indices/338079)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 23\
**Last updated:** [July 12, 2023, 7:19pm UTC](https://discuss.elastic.co/t/sending-request-to-one-index-writing-to-multiple-indices/338079 "2023-07-12T19:19:13Z")

</div>

I have a index named index1. I want to configure it such that any write/update request that comes to index1 gets written to both index1 and index2 but any search request still uses index1. Is this possible with some exis…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=481)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=483)
