# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=497

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 498

---

## [Unable to access kibana despite creating azure elastic ISV service with owner subscription](https://discuss.elastic.co/t/unable-to-access-kibana-despite-creating-azure-elastic-isv-service-with-owner-subscription/336916)

<div class="topic-metadata">

**Author:** [@Francis\_Salvin](https://discuss.elastic.co/u/Francis_Salvin)\
**Replies:** 4\
**Last updated:** [June 27, 2023, 8:14pm UTC](https://discuss.elastic.co/t/unable-to-access-kibana-despite-creating-azure-elastic-isv-service-with-owner-subscription/336916 "2023-06-27T20:14:04Z")

</div>

I am working on deploying azure elastic ISV service and using it with apps deployed in AKS cluster. Deployed successfully, but any elastic task I do after that is prompted for approval from admin (like accessing kibana) …

---

## [Making API POST request in Kibana plugin](https://discuss.elastic.co/t/making-api-post-request-in-kibana-plugin/337003)

<div class="topic-metadata">

**Author:** [@trosagnant](https://discuss.elastic.co/u/trosagnant)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 7:32pm UTC](https://discuss.elastic.co/t/making-api-post-request-in-kibana-plugin/337003 "2023-06-27T19:32:49Z")

</div>

Hello everyone, I'm trying to create a simple Kibana plugin which should send \_update\_by\_query request to elasticsearch, with values to updated provided by GUI in said plugin, but I can't quite grasp how making API call…

---

## [Gathering Top Values Through Elk API](https://discuss.elastic.co/t/gathering-top-values-through-elk-api/337019)

<div class="topic-metadata">

**Author:** [@hi\_xavier](https://discuss.elastic.co/u/hi_xavier)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 6:52pm UTC](https://discuss.elastic.co/t/gathering-top-values-through-elk-api/337019 "2023-06-27T18:52:15Z")

</div>

Hi, Is it possible, with the combination of Elk API and Aggregations , to gather top values. For example, the top 5 error messages from a set of results?

---

## [Which nodes to have logstash send to cluster](https://discuss.elastic.co/t/which-nodes-to-have-logstash-send-to-cluster/337018)

<div class="topic-metadata">

**Author:** [@eh2021-elastic](https://discuss.elastic.co/u/eh2021-elastic)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 6:37pm UTC](https://discuss.elastic.co/t/which-nodes-to-have-logstash-send-to-cluster/337018 "2023-06-27T18:37:00Z")

</div>

I have an elastic 7.16 cluster that consist of 4 dedicated masterand 16 data nodes. I have logstash sending syslog data from various network systems, firewalls, etc and just noticed the logstash config on some devices di…

---

## [Pipeline error "pipeline-id" :exception=\>#\<Psych::DisallowedClass: Tried to load unspecified class: Time](https://discuss.elastic.co/t/pipeline-error-pipeline-id-exception-psych-tried-to-load-unspecified-class-time/336786)

<div class="topic-metadata">

**Author:** [@Gelinski](https://discuss.elastic.co/u/Gelinski)\
**Replies:** 2\
**Last updated:** [June 27, 2023, 6:29pm UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-exception-psych-tried-to-load-unspecified-class-time/336786 "2023-06-27T18:29:20Z")

</div>

Hello folks, I have a logstash pipeline that is using a jdbc input and is configured with a schedule (0/1 \* \* \* \*) and after change its schedule to any other schedule the following error starts to happen: \[2023-06-23T…

---

## [Configure limit.conf for ElasticSearch server](https://discuss.elastic.co/t/configure-limit-conf-for-elasticsearch-server/336930)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 3\
**Last updated:** [June 27, 2023, 12:43pm UTC](https://discuss.elastic.co/t/configure-limit-conf-for-elasticsearch-server/336930 "2023-06-27T12:43:19Z")

</div>

The Elasticsearch documentation says that I should configure nofile and nproc for better performance. But the documentation is a bit confusing. First, do I set it to the "elastic" user that was created by Elasticsearch…

---

## [Potential memory leak issue with filebeat and metricbeat](https://discuss.elastic.co/t/potential-memory-leak-issue-with-filebeat-and-metricbeat/334353)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 8\
**Last updated:** [June 27, 2023, 4:01pm UTC](https://discuss.elastic.co/t/potential-memory-leak-issue-with-filebeat-and-metricbeat/334353 "2023-06-27T16:01:27Z")

</div>

Since upgrading from ELK 7.17.1 to ELK 8.6.2 (and even with ELK 8.7.1) we are experiencing OOMKilled on filebeat and metricbeat pods. We had no issues with ELK 7.17.1. Increasing the resources allocations does not resolv…

---

## [BACnet - ingest data from field devices](https://discuss.elastic.co/t/bacnet-ingest-data-from-field-devices/337015)

<div class="topic-metadata">

**Author:** [@Ostaseski](https://discuss.elastic.co/u/Ostaseski)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 3:46pm UTC](https://discuss.elastic.co/t/bacnet-ingest-data-from-field-devices/337015 "2023-06-27T15:46:00Z")

</div>

I cannot read the responses on how to ingest data from field devices that talk Modbus TCP and BACnet IP to Elastic Logstash. Were there any suggestions or perhaps an update? Any help would be appreciated. Thanks

---

## ["target\_prefix" equivalent for ingest pipeline?](https://discuss.elastic.co/t/target-prefix-equivalent-for-ingest-pipeline/337009)

<div class="topic-metadata">

**Author:** [@andrew.klaassen](https://discuss.elastic.co/u/andrew.klaassen)\
**Replies:** 2\
**Last updated:** [June 27, 2023, 3:28pm UTC](https://discuss.elastic.co/t/target-prefix-equivalent-for-ingest-pipeline/337009 "2023-06-27T15:28:19Z")

</div>

The filebeat dissect processor has a handy "target\_prefix" option, which allows everything it extracts to be placed under a common prefix. Is there any equivalent for the dissect or grok processors in an ingest pipeline…

---

## [Enrich index with data found in another index](https://discuss.elastic.co/t/enrich-index-with-data-found-in-another-index/336966)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 2:50pm UTC](https://discuss.elastic.co/t/enrich-index-with-data-found-in-another-index/336966 "2023-06-27T14:50:29Z")

</div>

Hello, What is the best way to add a field to an existing indexm where the value is filled with data from an other index. E.g. most commont example you have an index with a name field amd you want to add an email addr…

---

## [Elastic search cluster red primary shards missing](https://discuss.elastic.co/t/elastic-search-cluster-red-primary-shards-missing/337004)

<div class="topic-metadata">

**Author:** [@Nilesh\_Jethwani](https://discuss.elastic.co/u/Nilesh_Jethwani)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 2:21pm UTC](https://discuss.elastic.co/t/elastic-search-cluster-red-primary-shards-missing/337004 "2023-06-27T14:21:31Z")

</div>

Kibana is showing elastic health as red primary shards missing I have single node cluster. How can i fix this red status ?

---

## [Dynamic instances of Elastic Agent](https://discuss.elastic.co/t/dynamic-instances-of-elastic-agent/337005)

<div class="topic-metadata">

**Author:** [@hti](https://discuss.elastic.co/u/hti)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 2:14pm UTC](https://discuss.elastic.co/t/dynamic-instances-of-elastic-agent/337005 "2023-06-27T14:14:11Z")

</div>

Hello, we are spawning multiple Windows Server instances from a golden image. These instances get destroyed and recreated daily. For log collection we installed and enrolled the Elastic Agent in the golden image. We do…

---

## [I have a problem with EL and Xenforo](https://discuss.elastic.co/t/i-have-a-problem-with-el-and-xenforo/336872)

<div class="topic-metadata">

**Author:** [@Hi\_Welt](https://discuss.elastic.co/u/Hi_Welt)\
**Replies:** 4\
**Last updated:** [June 27, 2023, 2:08pm UTC](https://discuss.elastic.co/t/i-have-a-problem-with-el-and-xenforo/336872 "2023-06-27T14:08:47Z")

</div>

HI I have been using EL in xenforo for a longtime but now I randomly starts shutingdown since updating from EL7 to EL8. cat /var/log/elasticsearch/elasticsearch.log \[2023-06-26T03:24:33,901\]\[INFO \]\[o.e.n.Node …

---

## [What are the ways to combine the scores of keyword search + vector search other than the RRF ranking recently used?](https://discuss.elastic.co/t/what-are-the-ways-to-combine-the-scores-of-keyword-search-vector-search-other-than-the-rrf-ranking-recently-used/336914)

<div class="topic-metadata">

**Author:** [@Rahul\_Agarwal1](https://discuss.elastic.co/u/Rahul_Agarwal1)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 1:27pm UTC](https://discuss.elastic.co/t/what-are-the-ways-to-combine-the-scores-of-keyword-search-vector-search-other-than-the-rrf-ranking-recently-used/336914 "2023-06-27T13:27:31Z")

</div>

I want to combine the scores of knn search + normal keyword search. What are the ways of doing it other than the RRF ranking recently added?

---

## [Stopping logstash](https://discuss.elastic.co/t/stopping-logstash/336586)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 13\
**Last updated:** [June 27, 2023, 1:06pm UTC](https://discuss.elastic.co/t/stopping-logstash/336586 "2023-06-27T13:06:11Z")

</div>

Hello, i'm currently working on logstash and i have a question. To launch my logtash script, i use this command: sudo /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/test.conf When I run it in my terminal, to…

---

## [8.1, some confusion about successfulShardExecution in AbstractSearchAsyncAction](https://discuss.elastic.co/t/8-1-some-confusion-about-successfulshardexecution-in-abstractsearchasyncaction/336987)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 12:32pm UTC](https://discuss.elastic.co/t/8-1-some-confusion-about-successfulshardexecution-in-abstractsearchasyncaction/336987 "2023-06-27T12:32:34Z")

</div>

"Every response of shard result will trigger the successfulShardExecution method of AbstractSearchAsyncAction. I am confused about why we use shardsIt.remaining() + 1 to calculate ops, shouldn't it be +1 for each shard?" …

---

## [Using the "docker.elastic.co" container registry behind a firewall](https://discuss.elastic.co/t/using-the-docker-elastic-co-container-registry-behind-a-firewall/336888)

<div class="topic-metadata">

**Author:** [@haseHH](https://discuss.elastic.co/u/haseHH)\
**Replies:** 2\
**Last updated:** [June 27, 2023, 11:42am UTC](https://discuss.elastic.co/t/using-the-docker-elastic-co-container-registry-behind-a-firewall/336888 "2023-06-27T11:42:49Z")

</div>

Hi everyone, I am looking for guidance on how to properly access the "docker.elastic.co" CR behind a corporate firewall. This question was already posed back in 2020, but never answered. Here's that original topic. Wha…

---

## [How to filter by "Count of records" within Kibana Lens](https://discuss.elastic.co/t/how-to-filter-by-count-of-records-within-kibana-lens/336197)

<div class="topic-metadata">

**Author:** [@fim](https://discuss.elastic.co/u/fim)\
**Replies:** 3\
**Last updated:** [June 27, 2023, 11:10am UTC](https://discuss.elastic.co/t/how-to-filter-by-count-of-records-within-kibana-lens/336197 "2023-06-27T11:10:35Z")

</div>

My goal is to filter by counts for a field "tracking\_no" where the value inside of the field is exactly similar. In Kibana Lens I created a simple table with a count aggregation. The table show exactly what I expect, bu…

---

## [Docs: reindex.remote.whitelist takes and array and not comma separated list](https://discuss.elastic.co/t/docs-reindex-remote-whitelist-takes-and-array-and-not-comma-separated-list/336976)

<div class="topic-metadata">

**Author:** [@adopauco](https://discuss.elastic.co/u/adopauco)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 10:49am UTC](https://discuss.elastic.co/t/docs-reindex-remote-whitelist-takes-and-array-and-not-comma-separated-list/336976 "2023-06-27T10:49:41Z")

</div>

According to this piece of documentation, I need to configure reindex.remote.whitelist to allow reindexing from a remote elastic cluster. It states that the value should be a string with comma separated list of allowed …

---

## [Elastic search upgrade from 7.16.2 to 7.17.7](https://discuss.elastic.co/t/elastic-search-upgrade-from-7-16-2-to-7-17-7/336579)

<div class="topic-metadata">

**Author:** [@Bibhutibhusan\_Sahoo](https://discuss.elastic.co/u/Bibhutibhusan_Sahoo)\
**Replies:** 2\
**Last updated:** [June 27, 2023, 10:25am UTC](https://discuss.elastic.co/t/elastic-search-upgrade-from-7-16-2-to-7-17-7/336579 "2023-06-27T10:25:52Z")

</div>

Hi Team, we are trying to upgrade Elasticsearch from 7.16.2 to 7.17.7 through rpm package and getting following error One or more requisite failed: service.elastic.elasticsearch.service, Can someone help here? What is …

---

## [Error fetching data for metricset logstash.node\_stats: error making http request: port 9600 connection refused](https://discuss.elastic.co/t/error-fetching-data-for-metricset-logstash-node-stats-error-making-http-request-port-9600-connection-refused/336965)

<div class="topic-metadata">

**Author:** [@deepier](https://discuss.elastic.co/u/deepier)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 9:48am UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-logstash-node-stats-error-making-http-request-port-9600-connection-refused/336965 "2023-06-27T09:48:45Z")

</div>

Hello Everyone, Good day, I already setup my elastic and metricbeat. I already enable some metricbeat modules like elasticsearch-xpack configured the yml. Now im tryng to add logstash via metricbeat but when i restart…

---

## [Unable to delete snapshot](https://discuss.elastic.co/t/unable-to-delete-snapshot/336952)

<div class="topic-metadata">

**Author:** [@rakesh08](https://discuss.elastic.co/u/rakesh08)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 8:31am UTC](https://discuss.elastic.co/t/unable-to-delete-snapshot/336952 "2023-06-27T08:31:12Z")

</div>

In our environment, having 2 different elasticsearch servers running on eks cluster and leveraging elasticsearch-curator tool to take periodic snapshot on AWS s3 bucket. On both the ES servers, the elasticsearch-curator…

---

## [How to generate the enrollment-token for another node with ssl?](https://discuss.elastic.co/t/how-to-generate-the-enrollment-token-for-another-node-with-ssl/336574)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 6\
**Last updated:** [June 27, 2023, 7:38am UTC](https://discuss.elastic.co/t/how-to-generate-the-enrollment-token-for-another-node-with-ssl/336574 "2023-06-27T07:38:20Z")

</div>

Unable to create enrollment token for scope\[node\] ERROR: Unable to create an enrollment token. Elasticsearch node HTTP layer ssl configuration Keystore doesn't contain any private entries where the associated certificat…

---

## [Elasticsearch-create-enrollment-token is not possible without a keystore ( aka with PEM certificates)](https://discuss.elastic.co/t/elasticsearch-create-enrollment-token-is-not-possible-without-a-keystore-aka-with-pem-certificates/336136)

<div class="topic-metadata">

**Author:** [@DavidDPD](https://discuss.elastic.co/u/DavidDPD)\
**Replies:** 3\
**Last updated:** [June 27, 2023, 7:33am UTC](https://discuss.elastic.co/t/elasticsearch-create-enrollment-token-is-not-possible-without-a-keystore-aka-with-pem-certificates/336136 "2023-06-27T07:33:58Z")

</div>

This has been posted a few times, but threads have been auto-closed without an explicit explanation. I'm posting this as this really either needs to be changed/fixed in Elasticsearch, or DOCUMENTED. It does not seem to…

---

## [Logstash HTTP filter shows ruby exception NoMethodError strip for nil class](https://discuss.elastic.co/t/logstash-http-filter-shows-ruby-exception-nomethoderror-strip-for-nil-class/336947)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 7:28am UTC](https://discuss.elastic.co/t/logstash-http-filter-shows-ruby-exception-nomethoderror-strip-for-nil-class/336947 "2023-06-27T07:28:30Z")

</div>

Hi Team, I am extracting contents of thousands of URLs using http filter. But some urls throws below error which is stopping pipeline. Pipeline worker error, the pipeline will be stopped {:pipeline\_id=\>"new-english-pd…

---

## [Need help in how to rebuild the node\_modules present in kibana source code with code changes](https://discuss.elastic.co/t/need-help-in-how-to-rebuild-the-node-modules-present-in-kibana-source-code-with-code-changes/335934)

<div class="topic-metadata">

**Author:** [@Ashigha\_JR](https://discuss.elastic.co/u/Ashigha_JR)\
**Replies:** 2\
**Last updated:** [June 27, 2023, 6:21am UTC](https://discuss.elastic.co/t/need-help-in-how-to-rebuild-the-node-modules-present-in-kibana-source-code-with-code-changes/335934 "2023-06-27T06:21:19Z")

</div>

I have changed some CSS properties like button color, text color etc.. present inside "kibana-8.1.1/node\_modules/@kbn/ui-shared-deps-npm/shared\_built\_assets/kibana-ui-shared-deps-npm.v8.light.css" file, that changes need…

---

## [Need help to how to customize the theme color of the kibana dashboard](https://discuss.elastic.co/t/need-help-to-how-to-customize-the-theme-color-of-the-kibana-dashboard/335824)

<div class="topic-metadata">

**Author:** [@Ashigha\_JR](https://discuss.elastic.co/u/Ashigha_JR)\
**Replies:** 5\
**Last updated:** [June 27, 2023, 6:20am UTC](https://discuss.elastic.co/t/need-help-to-how-to-customize-the-theme-color-of-the-kibana-dashboard/335824 "2023-06-27T06:20:50Z")

</div>

Is it possible to customize the theme color of the kibana dashboard apart from default light and dark theme. I need to change the kibana dashboard theme color into purple , also need to change the color of the time filt…

---

## [Attach two pipeline to a single index in kibana 6.7.0](https://discuss.elastic.co/t/attach-two-pipeline-to-a-single-index-in-kibana-6-7-0/336898)

<div class="topic-metadata">

**Author:** [@danialumer](https://discuss.elastic.co/u/danialumer)\
**Replies:** 3\
**Last updated:** [June 27, 2023, 6:00am UTC](https://discuss.elastic.co/t/attach-two-pipeline-to-a-single-index-in-kibana-6-7-0/336898 "2023-06-27T06:00:15Z")

</div>

I have an issue that i have written two pipelines using devtools in v6.7.0, but do not know how to attach them with index, Can someone please assist on this?

---

## [Elasticsearch Index management strategy](https://discuss.elastic.co/t/elasticsearch-index-management-strategy/336833)

<div class="topic-metadata">

**Author:** [@Narcissus666](https://discuss.elastic.co/u/Narcissus666)\
**Replies:** 4\
**Last updated:** [June 27, 2023, 5:28am UTC](https://discuss.elastic.co/t/elasticsearch-index-management-strategy/336833 "2023-06-27T05:28:10Z")

</div>

Does Elasticsearch have a mechanismr like docke for storing logs? Docker log management divides logs into many files, and during rolling updates, only the oldest log files are deleted, rather than deleting the entire in…

---

## [Nested queries that refer to an expression on the parent](https://discuss.elastic.co/t/nested-queries-that-refer-to-an-expression-on-the-parent/336938)

<div class="topic-metadata">

**Author:** [@DaveG](https://discuss.elastic.co/u/DaveG)\
**Replies:** 0\
**Last updated:** [June 27, 2023, 3:11am UTC](https://discuss.elastic.co/t/nested-queries-that-refer-to-an-expression-on-the-parent/336938 "2023-06-27T03:11:20Z")

</div>

Hi All, I wish to write a query on nested data where there are expressions on the parent data as wells as expressions on the nested data all mixed together. For example, get me all the records that have id = 1 and exis…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=496)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=498)
