# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=489

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 490

---

## [Elastic Agent - Remove Unused Beats](https://discuss.elastic.co/t/elastic-agent-remove-unused-beats/337726)

<div class="topic-metadata">

**Author:** [@RichardH1](https://discuss.elastic.co/u/RichardH1)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:36pm UTC](https://discuss.elastic.co/t/elastic-agent-remove-unused-beats/337726 "2023-07-05T22:36:44Z")

</div>

Hi, We want to use Elastic Agent for our server deployments but the package size is larger than competing technologies. 90% of our servers just need Metricbeat installed so I'm wondering if we can strip out the other be…

---

## [Search UI - custom checkbox styling issue](https://discuss.elastic.co/t/search-ui-custom-checkbox-styling-issue/337725)

<div class="topic-metadata">

**Author:** [@JeroenAdam](https://discuss.elastic.co/u/JeroenAdam)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:28pm UTC](https://discuss.elastic.co/t/search-ui-custom-checkbox-styling-issue/337725 "2023-07-05T22:28:05Z")

</div>

Hi there, I'm developing an app using search UI and Elasticsearch, great experience so far. I 'm lacking in advanced React skills, I have no idea why my custom styled checkboxes won't reflect the correct state in the UI…

---

## [ILM not deleting index](https://discuss.elastic.co/t/ilm-not-deleting-index/337241)

<div class="topic-metadata">

**Author:** [@raymondmintz11](https://discuss.elastic.co/u/raymondmintz11)\
**Replies:** 22\
**Last updated:** [July 5, 2023, 10:12pm UTC](https://discuss.elastic.co/t/ilm-not-deleting-index/337241 "2023-07-05T22:12:11Z")

</div>

I am running a simple setup with ILM and small index. ILM should delete the index but instead its stuck at "step": "check-rollover-ready", here is my script to recreate the index #!/bin/bash echo -e "\\n update s…

---

## [Heartbeat auto-discover not working for AWS ELB](https://discuss.elastic.co/t/heartbeat-auto-discover-not-working-for-aws-elb/337187)

<div class="topic-metadata">

**Author:** [@michael31](https://discuss.elastic.co/u/michael31)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 9:31pm UTC](https://discuss.elastic.co/t/heartbeat-auto-discover-not-working-for-aws-elb/337187 "2023-07-05T21:31:47Z")

</div>

Hello, I am trying to set up heartbeat for AWS autodiscover ELB in 2 accounts (1 I did succesffully) and on the second with the exact same configuration I am getting the following errors. I configured everything as a far…

---

## [Wildcard search for a word](https://discuss.elastic.co/t/wildcard-search-for-a-word/337718)

<div class="topic-metadata">

**Author:** [@umesh\_choudary](https://discuss.elastic.co/u/umesh_choudary)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 9:03pm UTC](https://discuss.elastic.co/t/wildcard-search-for-a-word/337718 "2023-07-05T21:03:02Z")

</div>

How can i search for a word as contains while searching index. eg: if i search the index using books, i need to get the results which should contain book and books in the response..

---

## [Add a customizable ID for package policy](https://discuss.elastic.co/t/add-a-customizable-id-for-package-policy/337690)

<div class="topic-metadata">

**Author:** [@Bearloggs](https://discuss.elastic.co/u/Bearloggs)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 8:58pm UTC](https://discuss.elastic.co/t/add-a-customizable-id-for-package-policy/337690 "2023-07-05T20:58:05Z")

</div>

Hello, I am trying to create a policy package using the Kibana Dev Tools and I wondered if it was possible to apply a unique customizable ID. For example, I want to create osquery manager package policy with ID "osquer…

---

## [Change Timestamp to event.ingested](https://discuss.elastic.co/t/change-timestamp-to-event-ingested/337498)

<div class="topic-metadata">

**Author:** [@Xenial](https://discuss.elastic.co/u/Xenial)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 8:44pm UTC](https://discuss.elastic.co/t/change-timestamp-to-event-ingested/337498 "2023-07-05T20:44:29Z")

</div>

Hello Elastic Team, Can you help me , i want to change timestamp field to event.ingested on Kibana 8.8 and elasticsearch 8 Thankyou

---

## [Time since last response](https://discuss.elastic.co/t/time-since-last-response/337440)

<div class="topic-metadata">

**Author:** [@tomwood](https://discuss.elastic.co/u/tomwood)\
**Replies:** 4\
**Last updated:** [July 5, 2023, 8:35pm UTC](https://discuss.elastic.co/t/time-since-last-response/337440 "2023-07-05T20:35:46Z")

</div>

I'm trying to create a visualisation in Kibana dashboard that shows the UP Time of some API's and also shows when they last logged a response into Elastic. I want to colour each api's info green, amber or red, depending …

---

## [Vulnerability is not being allowed in event.category](https://discuss.elastic.co/t/vulnerability-is-not-being-allowed-in-event-category/337674)

<div class="topic-metadata">

**Author:** [@hodgepodge](https://discuss.elastic.co/u/hodgepodge)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 7:59pm UTC](https://discuss.elastic.co/t/vulnerability-is-not-being-allowed-in-event-category/337674 "2023-07-05T19:59:51Z")

</div>

I am seeing this failure while testing pipeline of integration: \[0\] parsing field value failed: field "event.category"'s value "vulnerability" is not one of the allowed values (authentication, configuration, database, d…

---

## [Deserializing Avro Records with different schemas](https://discuss.elastic.co/t/deserializing-avro-records-with-different-schemas/337701)

<div class="topic-metadata">

**Author:** [@fine\_porcupine](https://discuss.elastic.co/u/fine_porcupine)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 7:43pm UTC](https://discuss.elastic.co/t/deserializing-avro-records-with-different-schemas/337701 "2023-07-05T19:43:12Z")

</div>

I'm doing the due diligence on the Avro Codec Plugin and I'm wondering if it's possible to use this if there are different types of events in the same SQS queue? For example - SQS Queue contains serialized events with s…

---

## [Kibana: export option for table visualisations](https://discuss.elastic.co/t/kibana-export-option-for-table-visualisations/337592)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 7:38pm UTC](https://discuss.elastic.co/t/kibana-export-option-for-table-visualisations/337592 "2023-07-05T19:38:39Z")

</div>

ES/Kibana version 7.17.1 I want to be able to export data from aggregation table visualisations. I have some existing ones that have an export option: so far as I can tell these are not Lense but the original "Aggre…

---

## [Enrolling elastic-agent, the production-ready way?](https://discuss.elastic.co/t/enrolling-elastic-agent-the-production-ready-way/337697)

<div class="topic-metadata">

**Author:** [@UPPERCASE](https://discuss.elastic.co/u/UPPERCASE)\
**Replies:** 5\
**Last updated:** [July 5, 2023, 7:07pm UTC](https://discuss.elastic.co/t/enrolling-elastic-agent-the-production-ready-way/337697 "2023-07-05T19:07:39Z")

</div>

I want to use Fleet, but I have some doubts about the documented deployment method. I think it would've been better if it was possible to just install the elastic-agent as an RPM/DEB and then configure a yaml file, then …

---

## [Logs are getting parsed in messages field for M365 Defender Logs](https://discuss.elastic.co/t/logs-are-getting-parsed-in-messages-field-for-m365-defender-logs/337698)

<div class="topic-metadata">

**Author:** [@elastic12](https://discuss.elastic.co/u/elastic12)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 4:27pm UTC](https://discuss.elastic.co/t/logs-are-getting-parsed-in-messages-field-for-m365-defender-logs/337698 "2023-07-05T16:27:11Z")

</div>

The issue is with the logs in Microsoft 365 Defender. All of the logs are being stored in a single message field, instead of being stored in individual fields as shown in Elasticsearch documentation. Previously, the logs…

---

## [Vector search for large amount of data with limited RAM resources](https://discuss.elastic.co/t/vector-search-for-large-amount-of-data-with-limited-ram-resources/337681)

<div class="topic-metadata">

**Author:** [@louis\_sg](https://discuss.elastic.co/u/louis_sg)\
**Replies:** 3\
**Last updated:** [July 5, 2023, 4:03pm UTC](https://discuss.elastic.co/t/vector-search-for-large-amount-of-data-with-limited-ram-resources/337681 "2023-07-05T16:03:15Z")

</div>

Hi there, I am new here trying to use Elasticsearch for vector similarity search. My dataset is as large as 100M records, each containing a 384 dimensions vector and a string payload. I am building the HNSW index type…

---

## [Stacktrace logged by several lines in kibana](https://discuss.elastic.co/t/stacktrace-logged-by-several-lines-in-kibana/337539)

<div class="topic-metadata">

**Author:** [@ANARAN](https://discuss.elastic.co/u/ANARAN)\
**Replies:** 3\
**Last updated:** [July 5, 2023, 3:59pm UTC](https://discuss.elastic.co/t/stacktrace-logged-by-several-lines-in-kibana/337539 "2023-07-05T15:59:45Z")

</div>

Hello, I'm trying to improve the display of stacktraces for an application I'm working on. Now, the stacktrace look like this : I work with log4j (I know, it's deprecated) and logstash, but not filebeat. How can I…

---

## [Max retries exceeded with url: /pmc/documents.json.bz2 SSLCertVerificationError \[SSL: CERTIFICATE\_VERIFY\_FAILED\]](https://discuss.elastic.co/t/max-retries-exceeded-with-url-pmc-documents-json-bz2-sslcertverificationerror-ssl-certificate-verify-failed/335708)

<div class="topic-metadata">

**Author:** [@Swathi\_Kakumanu](https://discuss.elastic.co/u/Swathi_Kakumanu)\
**Replies:** 7\
**Last updated:** [July 5, 2023, 3:51pm UTC](https://discuss.elastic.co/t/max-retries-exceeded-with-url-pmc-documents-json-bz2-sslcertverificationerror-ssl-certificate-verify-failed/335708 "2023-07-05T15:51:39Z")

</div>

Hi, I am facing an issue with SSL Verification of esrally for rally-tracks.elastic.co', port=443 , however curl request and openssl works fine. FYI, internet works on the rally VM. Command used to run: esrally race -…

---

## [Text embedding different in elastic search and python library](https://discuss.elastic.co/t/text-embedding-different-in-elastic-search-and-python-library/329164)

<div class="topic-metadata">

**Author:** [@Roshan\_Kumar1](https://discuss.elastic.co/u/Roshan_Kumar1)\
**Replies:** 5\
**Last updated:** [July 5, 2023, 3:07pm UTC](https://discuss.elastic.co/t/text-embedding-different-in-elastic-search-and-python-library/329164 "2023-07-05T15:07:51Z")

</div>

Deploying sentence transformer model as provided in this blog, using eland on Elasticsearch returns only the embedding corresponding to the first token. However, while using the python implementation to encode the text r…

---

## [Api Search in Python - how to get bad return code](https://discuss.elastic.co/t/api-search-in-python-how-to-get-bad-return-code/337686)

<div class="topic-metadata">

**Author:** [@RickT](https://discuss.elastic.co/u/RickT)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 2:43pm UTC](https://discuss.elastic.co/t/api-search-in-python-how-to-get-bad-return-code/337686 "2023-07-05T14:43:47Z")

</div>

Hi, I'm using the search API running from Python to collect some documents. The request goes well as long as the connection is OK. However, when the connection is timeout, the Python script crashes and i can't used any…

---

## [Installation document for ELK 8.7](https://discuss.elastic.co/t/installation-document-for-elk-8-7/337635)

<div class="topic-metadata">

**Author:** [@SivaPrasadELK](https://discuss.elastic.co/u/SivaPrasadELK)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 1:59pm UTC](https://discuss.elastic.co/t/installation-document-for-elk-8-7/337635 "2023-07-05T13:59:40Z")

</div>

While trying to install the ELK 8.7 and its components such as file beat logstash kibana and Elasticsearch and trying to setup the ELK as below Filebeat =====\> Logstash ======\> elastic =======\>kibana keeping this workf…

---

## [Get and set Elasticsearch data via plugin](https://discuss.elastic.co/t/get-and-set-elasticsearch-data-via-plugin/337626)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 6\
**Last updated:** [July 5, 2023, 1:29pm UTC](https://discuss.elastic.co/t/get-and-set-elasticsearch-data-via-plugin/337626 "2023-07-05T13:29:39Z")

</div>

Hi, I am developing a custom plugin in Kibana using React, in Kibana 8.8.1. I want to set and get Elasticsearch data via the plugin. Which of the 2 is a better option? Elasticsearch service Elasticsearch service …

---

## [Is it possible to use encrypted elascticsearch instead of direct username, password in Output plugin of logstash?](https://discuss.elastic.co/t/is-it-possible-to-use-encrypted-elascticsearch-instead-of-direct-username-password-in-output-plugin-of-logstash/337647)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 1:24pm UTC](https://discuss.elastic.co/t/is-it-possible-to-use-encrypted-elascticsearch-instead-of-direct-username-password-in-output-plugin-of-logstash/337647 "2023-07-05T13:24:57Z")

</div>

I want to use encrypted elasticsearch, So I don't want to use directly username ,password of elasticsearch in logstash. Please provide the any answers.

---

## [Logstash build from Source failing](https://discuss.elastic.co/t/logstash-build-from-source-failing/337611)

<div class="topic-metadata">

**Author:** [@tejas7](https://discuss.elastic.co/u/tejas7)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 12:58pm UTC](https://discuss.elastic.co/t/logstash-build-from-source-failing/337611 "2023-07-05T12:58:49Z")

</div>

Hello Team , I am trying to build logstash from source code from the main branch. It is failing with the following error: \* Exception is: org.gradle.api.tasks.TaskExecutionException: Execution failed for task ':install…

---

## [SAML without Elasticsearch SSL (using Traefik as a reverse proxy)](https://discuss.elastic.co/t/saml-without-elasticsearch-ssl-using-traefik-as-a-reverse-proxy/336396)

<div class="topic-metadata">

**Author:** [@rushil791](https://discuss.elastic.co/u/rushil791)\
**Replies:** 4\
**Last updated:** [July 5, 2023, 12:50pm UTC](https://discuss.elastic.co/t/saml-without-elasticsearch-ssl-using-traefik-as-a-reverse-proxy/336396 "2023-07-05T12:50:00Z")

</div>

Hi there, I want to be able to use SAML with my Elasticsearch-Kibana setup in Docker, but I need to be able to use my organisation's CA cert. I do not have access to the CA's private key, so I can't use the certutil to …

---

## [Login Elasticsearch and Kibana](https://discuss.elastic.co/t/login-elasticsearch-and-kibana/337661)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 11:14am UTC](https://discuss.elastic.co/t/login-elasticsearch-and-kibana/337661 "2023-07-05T11:14:09Z")

</div>

Hi, Is it possible to generate a token on the elasticsearch API? A sort of login (username/password) and the same on kibana? Currently, there's no such thing on my elasticsearch and kibana instance, and anyone can make…

---

## [Is it possible to restore a specific index from a datastream to a datastream from snapshot](https://discuss.elastic.co/t/is-it-possible-to-restore-a-specific-index-from-a-datastream-to-a-datastream-from-snapshot/334710)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 3\
**Last updated:** [July 5, 2023, 10:50am UTC](https://discuss.elastic.co/t/is-it-possible-to-restore-a-specific-index-from-a-datastream-to-a-datastream-from-snapshot/334710 "2023-07-05T10:50:47Z")

</div>

Recently we migrated our elasticsearch cluster and used snapshot/restore to do this. Unfortunately we forgot about a change we made to the lifecycle policy of a the apm traces datastream. Which meant data older than 90 …

---

## [Elasticsearch 8.5.2 -- Restoring datastreams isn’t working as planned](https://discuss.elastic.co/t/elasticsearch-8-5-2-restoring-datastreams-isn-t-working-as-planned/337645)

<div class="topic-metadata">

**Author:** [@Gautier\_Franchini](https://discuss.elastic.co/u/Gautier_Franchini)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 10:48am UTC](https://discuss.elastic.co/t/elasticsearch-8-5-2-restoring-datastreams-isn-t-working-as-planned/337645 "2023-07-05T10:48:37Z")

</div>

Hello, I encountered an issue during a datastream restore this morning: What I want to achieve: restore the backuped indices from may 2023 in the same current working datastream ; I would like to avoid interruption of…

---

## [Cluster overshard issue](https://discuss.elastic.co/t/cluster-overshard-issue/337603)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 10:22am UTC](https://discuss.elastic.co/t/cluster-overshard-issue/337603 "2023-07-05T10:22:20Z")

</div>

Hi, I have question about how to solve the cluster overshard issue sot that things can get back to normal/ Currently, I am renting 2 node in 2 different zone. And, I've encountered oversharding issue, show in the b…

---

## [Cannot connect to elasticsearch, via functionbeat(using AWS Lambda)](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-via-functionbeat-using-aws-lambda/337657)

<div class="topic-metadata">

**Author:** [@Kavan\_Dalwadi](https://discuss.elastic.co/u/Kavan_Dalwadi)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:42am UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-via-functionbeat-using-aws-lambda/337657 "2023-07-05T10:42:39Z")

</div>

Currently I have deployed Elasticstack (ELK) on AWS EKS and Im using NodePort service for all the application My elasticsearch is running at- 54.2xx.xxx.xxx:30092/ (Which is the public IP address of EC2). I have lamb…

---

## [Error while performing snapshot and restore in 3 node elk cluster](https://discuss.elastic.co/t/error-while-performing-snapshot-and-restore-in-3-node-elk-cluster/337656)

<div class="topic-metadata">

**Author:** [@Raushan\_kumar](https://discuss.elastic.co/u/Raushan_kumar)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:40am UTC](https://discuss.elastic.co/t/error-while-performing-snapshot-and-restore-in-3-node-elk-cluster/337656 "2023-07-05T10:40:49Z")

</div>

so i am trying to perform snapshot and restore on 3 node cluster in elasticsearch 8.7 through nfs.but when i am putting the path.repo same path of shared directory so its giving me that this path.repo is not accessible.n…

---

## [Add id processor filebeat](https://discuss.elastic.co/t/add-id-processor-filebeat/337655)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:39am UTC](https://discuss.elastic.co/t/add-id-processor-filebeat/337655 "2023-07-05T10:39:00Z")

</div>

Hi there, just want to ask, i have configured filebeat as a container and the filebeat has been ingested millions of logs every minutes. first of all, this is my filebeat config precisely on processor part: as can y…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=488)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=490)
