# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=499

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 500

---

## [Failed to start Elasticsearch | 'failed' state with result 'signal'](https://discuss.elastic.co/t/failed-to-start-elasticsearch-failed-state-with-result-signal/336849)

<div class="topic-metadata">

**Author:** [@Alex\_BeimDaddeln](https://discuss.elastic.co/u/Alex_BeimDaddeln)\
**Replies:** 12\
**Last updated:** [June 26, 2023, 9:25am UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch-failed-state-with-result-signal/336849 "2023-06-26T09:25:48Z")

</div>

Today I tried to install Elasticseatch on my new Ubuntu 22.04 server. The setup did not show any error. Nevertheless, at startup always comes this error: -- Support: \*\*\* -- The unit elasticsearch.service completed and…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/336653)

<div class="topic-metadata">

**Author:** [@sunainajain](https://discuss.elastic.co/u/sunainajain)\
**Replies:** 3\
**Last updated:** [June 26, 2023, 9:07am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/336653 "2023-06-26T09:07:10Z")

</div>

Hi Team, In Kibana UI , We are able to see error message as "Kibana server is not ready yet" but when we did status check for kibana and Elasticsearch using below command we were able to get below results. Status check…

---

## [Huge amount of SELinux messages due to Metricbeat & Filebeat](https://discuss.elastic.co/t/huge-amount-of-selinux-messages-due-to-metricbeat-filebeat/336882)

<div class="topic-metadata">

**Author:** [@adityasinghal26](https://discuss.elastic.co/u/adityasinghal26)\
**Replies:** 0\
**Last updated:** [June 26, 2023, 8:54am UTC](https://discuss.elastic.co/t/huge-amount-of-selinux-messages-due-to-metricbeat-filebeat/336882 "2023-06-26T08:54:30Z")

</div>

Hi Team, We are currently running Elasticsearch 8.6 and various beats (filebeat, metricbeat) of version 8.6 in Oracle Kubernetes Engine (OKE) nodes. As part of the implementation, we are seeing below error messages prin…

---

## [Kibana unable to connect to package registry after upgrade to 8.8.1](https://discuss.elastic.co/t/kibana-unable-to-connect-to-package-registry-after-upgrade-to-8-8-1/336317)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 16\
**Last updated:** [June 26, 2023, 8:44am UTC](https://discuss.elastic.co/t/kibana-unable-to-connect-to-package-registry-after-upgrade-to-8-8-1/336317 "2023-06-26T08:44:26Z")

</div>

Hi all I have a problems with kibana after upgrading from version 8.5.2 to version 8.8.1 All thing work normally but the intergration keep giving me this error Kibana cannot connect to the Elastic Package Registry, wh…

---

## [Circuit breaker on high throughput](https://discuss.elastic.co/t/circuit-breaker-on-high-throughput/335853)

<div class="topic-metadata">

**Author:** [@lasica](https://discuss.elastic.co/u/lasica)\
**Replies:** 3\
**Last updated:** [June 26, 2023, 8:20am UTC](https://discuss.elastic.co/t/circuit-breaker-on-high-throughput/335853 "2023-06-26T08:20:17Z")

</div>

Hi everyone, we have an elasticsearch-7.17 cluster with 4 nodes (master&data) 3x: (ELK) 1x AMD Ryzen 7 3700X, 8 cores, 3.6Ghz 64GB DDR4 ram 2xSSD, 2TB 1x: (APM + kibana) Inter i7-7700, 4 cores, 4.2Ghz 32GB ram 2xS…

---

## [How many days the data can be placed in the one index of ES?](https://discuss.elastic.co/t/how-many-days-the-data-can-be-placed-in-the-one-index-of-es/336641)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 6\
**Last updated:** [June 26, 2023, 7:57am UTC](https://discuss.elastic.co/t/how-many-days-the-data-can-be-placed-in-the-one-index-of-es/336641 "2023-06-26T07:57:36Z")

</div>

If per day 4gb size logs from logstash in one index then how many days it will be stored in ES?

---

## [I can't recoverd my cluster of elasticsearch on dev in 7.17](https://discuss.elastic.co/t/i-cant-recoverd-my-cluster-of-elasticsearch-on-dev-in-7-17/336857)

<div class="topic-metadata">

**Author:** [@Han2](https://discuss.elastic.co/u/Han2)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 7:45am UTC](https://discuss.elastic.co/t/i-cant-recoverd-my-cluster-of-elasticsearch-on-dev-in-7-17/336857 "2023-06-26T07:45:47Z")

</div>

I have a cluster, that statu is yellow .security-7 is UNASSIGNED when i use this order \_cluster/allocation/explain I encounter this error and i don't know how to do Some one can help me PLZ

---

## [How to display different days values in Lens](https://discuss.elastic.co/t/how-to-display-different-days-values-in-lens/336867)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 0\
**Last updated:** [June 26, 2023, 7:02am UTC](https://discuss.elastic.co/t/how-to-display-different-days-values-in-lens/336867 "2023-06-26T07:02:59Z")

</div>

Hello Team, Please help for the below query I want to display value of one variable in Lens, in below given format One line for Last Day sum of that variable Second line of (n-8)th Day Sum of that variable third lin…

---

## [数据节点因滞后而掉出集群](https://discuss.elastic.co/t/topic/336860)

<div class="topic-metadata">

**Author:** [@lianmeng0](https://discuss.elastic.co/u/lianmeng0)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 6:30am UTC](https://discuss.elastic.co/t/topic/336860 "2023-06-26T06:30:06Z")

</div>

\--------------------------------------------------- 数据节点日志 ------------------------------------------------------- \[2023-06-26T10:15:28,625\]\[WARN \]\[r.suppressed \] \[datanode-17\] path: /\_bulk, params: {timeout…

---

## [Using KQL in Filters on Kibana to match strings that "ends with"](https://discuss.elastic.co/t/using-kql-in-filters-on-kibana-to-match-strings-that-ends-with/336862)

<div class="topic-metadata">

**Author:** [@kashif\_shamaz](https://discuss.elastic.co/u/kashif_shamaz)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 6:17am UTC](https://discuss.elastic.co/t/using-kql-in-filters-on-kibana-to-match-strings-that-ends-with/336862 "2023-06-26T06:17:04Z")

</div>

Hi there, I have an indexed field called "uri\_path", on this field, I have following values: - /something/\*/ - /something/\*/a/ - /something/\*/b/ - /something/\*/c/ The \* indicates anything, and I want to create a searc…

---

## [Format field as Time in Color scripted field](https://discuss.elastic.co/t/format-field-as-time-in-color-scripted-field/336799)

<div class="topic-metadata">

**Author:** [@kimari](https://discuss.elastic.co/u/kimari)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 6:15am UTC](https://discuss.elastic.co/t/format-field-as-time-in-color-scripted-field/336799 "2023-06-26T06:15:04Z")

</div>

I have a scripted field that I need to use the color scripted for more than 13 minutes, but this field comes in seconds I want to use the format in 00:00:00 as well, since if i use the color format, I cannot use the numb…

---

## [Where do integer document IDs in highlighting error messages come from?](https://discuss.elastic.co/t/where-do-integer-document-ids-in-highlighting-error-messages-come-from/336602)

<div class="topic-metadata">

**Author:** [@nkleinbaer](https://discuss.elastic.co/u/nkleinbaer)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 5:58am UTC](https://discuss.elastic.co/t/where-do-integer-document-ids-in-highlighting-error-messages-come-from/336602 "2023-06-26T05:58:14Z")

</div>

Sometimes when searching in Kibana I will get a pop up about failed shards. Inspecting the response shows errors like this one: The length of \[message\] field of \[32\] doc of \[my-index\] index has exceeded \[1000000\] - maxi…

---

## [How to show and Export data along with simple date formate (MM-dd-YYYY HH:mm)](https://discuss.elastic.co/t/how-to-show-and-export-data-along-with-simple-date-formate-mm-dd-yyyy-hh-mm/336537)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 5:46am UTC](https://discuss.elastic.co/t/how-to-show-and-export-data-along-with-simple-date-formate-mm-dd-yyyy-hh-mm/336537 "2023-06-26T05:46:41Z")

</div>

Hi , How we can export the data with a simple date format currently it exporting with this format (Jun 19, 2023 @ 14:32:50.894) but we need this format (06-19-2023 14:32) please see the below snap for your reference. …

---

## [New Document Indexing Performance Troubleshooting](https://discuss.elastic.co/t/new-document-indexing-performance-troubleshooting/336854)

<div class="topic-metadata">

**Author:** [@mfalkenstein](https://discuss.elastic.co/u/mfalkenstein)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 4:43am UTC](https://discuss.elastic.co/t/new-document-indexing-performance-troubleshooting/336854 "2023-06-26T04:43:11Z")

</div>

So I've been trying to troubleshoot an issue with my Elasticsearch currently being used a production system. Our servers are hosted in AWS and the specs of each node are Standard D16s v3 (16 vcpus, 64 GiB memory, 1.5TB o…

---

## [Upgrade failed to 8.x](https://discuss.elastic.co/t/upgrade-failed-to-8-x/336665)

<div class="topic-metadata">

**Author:** [@Chel](https://discuss.elastic.co/u/Chel)\
**Replies:** 6\
**Last updated:** [June 26, 2023, 4:35am UTC](https://discuss.elastic.co/t/upgrade-failed-to-8-x/336665 "2023-06-26T04:35:16Z")

</div>

Error message: Upgrading the 7.17.4 ES version to 8.5.2 ES cluster getting the below message. We have checked the deprecation messages and upgrade assistant and nothing was reported. java.lang.IllegalStateException: ca…

---

## [Can I specify the index in a query search?](https://discuss.elastic.co/t/can-i-specify-the-index-in-a-query-search/336218)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 3:46am UTC](https://discuss.elastic.co/t/can-i-specify-the-index-in-a-query-search/336218 "2023-06-26T03:46:51Z")

</div>

I need to search multiple indexes on Elasticsearch, My problem is that on each index I have the same field name (is\_active), how do I specify that it's the field of the other index ? GET index-1,index-2/\_search { "que…

---

## [How to set up a cluster?](https://discuss.elastic.co/t/how-to-set-up-a-cluster/336790)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 2:00am UTC](https://discuss.elastic.co/t/how-to-set-up-a-cluster/336790 "2023-06-26T02:00:18Z")

</div>

Does Elasticsearch have any step-by-step tutorials on how to set up a 3-node cluster? I've seen the following docs \[1, 2\], but they are just concepts, they don't show which files to edit and which commands to run.

---

## [Encountered logstash error "Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"input\\", \\"filter\\", \\"output\\" at line 1, column 1 (byte 1)""](https://discuss.elastic.co/t/encountered-logstash-error-expected-one-of-t-r-n-input-filter-output-at-line-1-column-1-byte-1/336796)

<div class="topic-metadata">

**Author:** [@pdowma](https://discuss.elastic.co/u/pdowma)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 1:40am UTC](https://discuss.elastic.co/t/encountered-logstash-error-expected-one-of-t-r-n-input-filter-output-at-line-1-column-1-byte-1/336796 "2023-06-26T01:40:23Z")

</div>

Problem: When setting up a Docker-based Elastic Stack (Elasticsearch, Logstash, and Kibana) environment. The Logstash service was not able to start correctly and reported the following error message: \[2023-06-23T16:41:…

---

## [Trouble adding a new Kibana instance to an existing Elasticsearch Cluster](https://discuss.elastic.co/t/trouble-adding-a-new-kibana-instance-to-an-existing-elasticsearch-cluster/336695)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 1:36am UTC](https://discuss.elastic.co/t/trouble-adding-a-new-kibana-instance-to-an-existing-elasticsearch-cluster/336695 "2023-06-26T01:36:56Z")

</div>

We are running a 3 Node ES Cluster with basic security (inter-node TLS) enabled. We installed Kibana on one of the Nodes initially and are now trying to install it on a second node in the cluster. The /etc/kibana/kibana…

---

## [Is it possible to keep max 5GB for logs but to delete old continously?](https://discuss.elastic.co/t/is-it-possible-to-keep-max-5gb-for-logs-but-to-delete-old-continously/336832)

<div class="topic-metadata">

**Author:** [@HannesWaser](https://discuss.elastic.co/u/HannesWaser)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 12:22am UTC](https://discuss.elastic.co/t/is-it-possible-to-keep-max-5gb-for-logs-but-to-delete-old-continously/336832 "2023-06-26T00:22:14Z")

</div>

Dear all, I am a novice to Kibana. I made it run bit now I wonder how I can limit the storage kibana and elasticseach use for log data AND how I can delete old logs automatically so new ones can be added. The goal is to …

---

## [Manual refresh does not seem to take effect instantly](https://discuss.elastic.co/t/manual-refresh-does-not-seem-to-take-effect-instantly/336850)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 0\
**Last updated:** [June 25, 2023, 10:07pm UTC](https://discuss.elastic.co/t/manual-refresh-does-not-seem-to-take-effect-instantly/336850 "2023-06-25T22:07:38Z")

</div>

I have alot of unit tests that use an actual instance of elasticsearch. Currently between every test the index is deleted and recreated like this: await client.indices.delete({ index }); await client.indices.create({ in…

---

## [Changing ES Scheme to http](https://discuss.elastic.co/t/changing-es-scheme-to-http/336839)

<div class="topic-metadata">

**Author:** [@Geek2.0](https://discuss.elastic.co/u/Geek2.0)\
**Replies:** 1\
**Last updated:** [June 25, 2023, 8:24pm UTC](https://discuss.elastic.co/t/changing-es-scheme-to-http/336839 "2023-06-25T20:24:20Z")

</div>

Hi Community, I am working on Arches project which uses Elasticsearch as its search engine. In Arches Documentation, it is mentioned to add the following line to the settings.py in my project's directory: ELASTICSEARC…

---

## [Is it possible to create a dynamic table name in statement of jdbc input plugin in Logstash?](https://discuss.elastic.co/t/is-it-possible-to-create-a-dynamic-table-name-in-statement-of-jdbc-input-plugin-in-logstash/336846)

<div class="topic-metadata">

**Author:** [@rabih](https://discuss.elastic.co/u/rabih)\
**Replies:** 1\
**Last updated:** [June 25, 2023, 7:51pm UTC](https://discuss.elastic.co/t/is-it-possible-to-create-a-dynamic-table-name-in-statement-of-jdbc-input-plugin-in-logstash/336846 "2023-06-25T19:51:18Z")

</div>

input { jdbc { jdbc\_connection\_string =\> "jdbc:sqlserver://ip\_address:1433;databaseName=database\_name;encrypt=true;trustServerCertificate=true;" jdbc\_user =\> "userxxxx" jdbc\_password =\> "passxxxx" jdbc\_…

---

## [Filebeat exclude\_files is not working as expected for windows](https://discuss.elastic.co/t/filebeat-exclude-files-is-not-working-as-expected-for-windows/336829)

<div class="topic-metadata">

**Author:** [@junly](https://discuss.elastic.co/u/junly)\
**Replies:** 1\
**Last updated:** [June 25, 2023, 5:19pm UTC](https://discuss.elastic.co/t/filebeat-exclude-files-is-not-working-as-expected-for-windows/336829 "2023-06-25T17:19:28Z")

</div>

Elastic Filebeat 8.7.0 file path "d:\\log\\LuceneSOA\\排序搜索结果\\2023-06-21.txt", Exclude txt files dated under the file but not working the regexp was verified with regex101.com filebeat.yml input filebeat.inputs: -…

---

## [Filestream input sends duplicates events on restart and during operation](https://discuss.elastic.co/t/filestream-input-sends-duplicates-events-on-restart-and-during-operation/334951)

<div class="topic-metadata">

**Author:** [@michaelbu](https://discuss.elastic.co/u/michaelbu)\
**Replies:** 33\
**Last updated:** [June 25, 2023, 4:22pm UTC](https://discuss.elastic.co/t/filestream-input-sends-duplicates-events-on-restart-and-during-operation/334951 "2023-06-25T16:22:10Z")

</div>

We use more than 1.800 filebeats with the filestream-input in version: $ filebeat version filebeat version 8.7.0 (amd64), libbeat 8.7.0 \[a8dbc6c06381f4fe33a5dc23906d63c04c9e2444 built 2023-03-23 00:37:07 +0000 UTC\] Ro…

---

## [Auditbeat. failed to set audit PID - audiebeat complaining about itself](https://discuss.elastic.co/t/auditbeat-failed-to-set-audit-pid-audiebeat-complaining-about-itself/336841)

<div class="topic-metadata">

**Author:** [@JohnAnderson](https://discuss.elastic.co/u/JohnAnderson)\
**Replies:** 0\
**Last updated:** [June 25, 2023, 4:19pm UTC](https://discuss.elastic.co/t/auditbeat-failed-to-set-audit-pid-audiebeat-complaining-about-itself/336841 "2023-06-25T16:19:43Z")

</div>

Hi everyone! I have got no ideas where to find problem in next situation. When I start/restart container with auditd option socket\_type: unicast, I can see in logs "message":"Failure receiving audit events","service.nam…

---

## [Aproximate Nearest Neighbours python with leastic 8.8](https://discuss.elastic.co/t/aproximate-nearest-neighbours-python-with-leastic-8-8/336692)

<div class="topic-metadata">

**Author:** [@Ran\_Dubin](https://discuss.elastic.co/u/Ran_Dubin)\
**Replies:** 2\
**Last updated:** [June 25, 2023, 1:58pm UTC](https://discuss.elastic.co/t/aproximate-nearest-neighbours-python-with-leastic-8-8/336692 "2023-06-25T13:58:29Z")

</div>

Hello All I am using elastic version 8.8.1. The API for ANN has changed and I managed to index but not to query content. Index: from datetime import datetime b\_index = 'shot\_index' dim = 1280 response = es.indice…

---

## [Can we use sub aggregation after top metric aggregation](https://discuss.elastic.co/t/can-we-use-sub-aggregation-after-top-metric-aggregation/330957)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 7\
**Last updated:** [May 3, 2023, 8:53am UTC](https://discuss.elastic.co/t/can-we-use-sub-aggregation-after-top-metric-aggregation/330957 "2023-05-03T08:53:41Z")

</div>

I want to get sum of latest value of a field . With several conditions which is applied over other fields. I am working on time series data and want to get information from last poled value. Example Data:- A B C …

---

## [Show discover result in dashboard](https://discuss.elastic.co/t/show-discover-result-in-dashboard/336826)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [June 25, 2023, 7:05am UTC](https://discuss.elastic.co/t/show-discover-result-in-dashboard/336826 "2023-06-25T07:05:23Z")

</div>

Hi Need to put discovery search on dashboard. how can i do this? the main issue is I've create table on dashboard that show top apm span by duration. as far as i know i can't add column that show this field "span.db.st…

---

## [How to connect eck elasticsearch with eck logstash](https://discuss.elastic.co/t/how-to-connect-eck-elasticsearch-with-eck-logstash/336804)

<div class="topic-metadata">

**Author:** [@Piyumitha\_Nirman](https://discuss.elastic.co/u/Piyumitha_Nirman)\
**Replies:** 3\
**Last updated:** [June 25, 2023, 6:40am UTC](https://discuss.elastic.co/t/how-to-connect-eck-elasticsearch-with-eck-logstash/336804 "2023-06-25T06:40:33Z")

</div>

eck logtash 8 version needs ca.crt of eck Elasticsearch. But i dont know how to access this ca.crt file using logstash. my log stash file has cacert location. but I don't know how to access ca.crt file. hosts =\> …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=498)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=500)
