# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=501

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 502

---

## [How can i write with red color?](https://discuss.elastic.co/t/how-can-i-write-with-red-color/336764)

<div class="topic-metadata">

**Author:** [@Hocine\_MEZOUGHI](https://discuss.elastic.co/u/Hocine_MEZOUGHI)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 11:48am UTC](https://discuss.elastic.co/t/how-can-i-write-with-red-color/336764 "2023-06-23T11:48:36Z")

</div>

I have a WATCHER that calculates the percentage difference and I'd like to write this difference in red in the body of the email. Using like this : {{ecart}} My example doesn't work, what wrong ???? "actions": { "sen…

---

## [Winlogbeat ingest pipelines missing geoIP](https://discuss.elastic.co/t/winlogbeat-ingest-pipelines-missing-geoip/334575)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 5\
**Last updated:** [June 23, 2023, 11:51am UTC](https://discuss.elastic.co/t/winlogbeat-ingest-pipelines-missing-geoip/334575 "2023-06-23T11:51:07Z")

</div>

Winlogbeat ingest pipelines Security and Sysmon missing geoIP. It is on purpose? All filebeat ingest pipelines have geoIP enrichment and it seems strange that winlogbeat missing geoIP.

---

## [Winlogbeat stops sending logs](https://discuss.elastic.co/t/winlogbeat-stops-sending-logs/336756)

<div class="topic-metadata">

**Author:** [@Fursel](https://discuss.elastic.co/u/Fursel)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 11:31am UTC](https://discuss.elastic.co/t/winlogbeat-stops-sending-logs/336756 "2023-06-23T11:31:57Z")

</div>

Hello, We are collecting events from DCs and somehow lately winlogbeat stopps sending them on multiple devices. I did set logging for debug logging.level: debug logging.to\_file: true logging.files: path: 'C:\\Progra…

---

## [Modifing eui basic table expanded rows](https://discuss.elastic.co/t/modifing-eui-basic-table-expanded-rows/336753)

<div class="topic-metadata">

**Author:** [@iljaskajrris](https://discuss.elastic.co/u/iljaskajrris)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 8:56am UTC](https://discuss.elastic.co/t/modifing-eui-basic-table-expanded-rows/336753 "2023-06-23T08:56:41Z")

</div>

Hi all! I took euiBasicTable expanded rows, but ran into issue. Cant make any button clickable inside of expanded event. Can anybody help with that or give some directions? I just need the Table to be able to open contex…

---

## [Logstash s3 input reads file multiple times](https://discuss.elastic.co/t/logstash-s3-input-reads-file-multiple-times/336751)

<div class="topic-metadata">

**Author:** [@jpchev](https://discuss.elastic.co/u/jpchev)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 8:52am UTC](https://discuss.elastic.co/t/logstash-s3-input-reads-file-multiple-times/336751 "2023-06-23T08:52:56Z")

</div>

hello, I have configured the following s3 input in logstash, and it keeps reading the same file from the given S3 bucket. I noticed that the given sincedb file ${DATA\_DIR}/.sincedb\_activities.txt is being used and it co…

---

## [Elasticsearch 8 won't start on Centos 7](https://discuss.elastic.co/t/elasticsearch-8-wont-start-on-centos-7/336722)

<div class="topic-metadata">

**Author:** [@Geek2.0](https://discuss.elastic.co/u/Geek2.0)\
**Replies:** 4\
**Last updated:** [June 23, 2023, 8:06am UTC](https://discuss.elastic.co/t/elasticsearch-8-wont-start-on-centos-7/336722 "2023-06-23T08:06:26Z")

</div>

I have installed Elasticsearch 7.8 on centos 7 server and it was running normally. After uninstalling it and installing elasticsearch 8.8, I get the following error when trying to start it with the command sudo systemc…

---

## [Sort results by query string](https://discuss.elastic.co/t/sort-results-by-query-string/336743)

<div class="topic-metadata">

**Author:** [@samba](https://discuss.elastic.co/u/samba)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 7:40am UTC](https://discuss.elastic.co/t/sort-results-by-query-string/336743 "2023-06-23T07:40:11Z")

</div>

Hello, It is possible to set sort order by querystring? What I mean is when a user searches pink chairs the results beggining with pink and containing chairs must appear first and followed by that contain the query str…

---

## [Please update documentation of Routing and Navigation with correct links](https://discuss.elastic.co/t/please-update-documentation-of-routing-and-navigation-with-correct-links/335780)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 4\
**Last updated:** [June 23, 2023, 7:04am UTC](https://discuss.elastic.co/t/please-update-documentation-of-routing-and-navigation-with-correct-links/335780 "2023-06-23T07:04:36Z")

</div>

Hi, The links in documentation of Routing and Navigation (Routing, Navigation and URL | Kibana Guide \[8.8\] | Elastic) are obsolete. They are inaccessible. Please update the same with correct ones. Moreover, I think the…

---

## [Aggregate count and max per document query](https://discuss.elastic.co/t/aggregate-count-and-max-per-document-query/334583)

<div class="topic-metadata">

**Author:** [@dimalini](https://discuss.elastic.co/u/dimalini)\
**Replies:** 4\
**Last updated:** [June 23, 2023, 7:03am UTC](https://discuss.elastic.co/t/aggregate-count-and-max-per-document-query/334583 "2023-06-23T07:03:18Z")

</div>

Hi, I have a mapping similar to PUT my-index-000001 { "mappings": { "properties": { "message": { "type": "keyword" } } } } now this field holds an array of messages. What I would like to…

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/336738)

<div class="topic-metadata">

**Author:** [@Sudhangshu](https://discuss.elastic.co/u/Sudhangshu)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 6:30am UTC](https://discuss.elastic.co/t/elasticsearch/336738 "2023-06-23T06:30:56Z")

</div>

(myenv) C:\\Misc\\Django\_elasticsearch\>python manage.py search\_index --rebuild C:\\Misc\\Django\_elasticsearch\\myenv\\Lib\\site-packages\\elasticsearch\\connection\\base.py:200: ElasticsearchWarning: this request accesses system …

---

## [Metric Beat - windows services](https://discuss.elastic.co/t/metric-beat-windows-services/336734)

<div class="topic-metadata">

**Author:** [@sreeraj\_palat](https://discuss.elastic.co/u/sreeraj_palat)\
**Replies:** 0\
**Last updated:** [June 23, 2023, 5:19am UTC](https://discuss.elastic.co/t/metric-beat-windows-services/336734 "2023-06-23T05:19:47Z")

</div>

iam installed metricbeat in 5 servers. i want to monitor the windows services in the kibana dashboard. i can get the installed services in windows. how can i get the cpu memory usage of each services

---

## [Component template and \_tier\_preference index setting](https://discuss.elastic.co/t/component-template-and-tier-preference-index-setting/336500)

<div class="topic-metadata">

**Author:** [@bstdenis](https://discuss.elastic.co/u/bstdenis)\
**Replies:** 1\
**Last updated:** [June 23, 2023, 3:49am UTC](https://discuss.elastic.co/t/component-template-and-tier-preference-index-setting/336500 "2023-06-23T03:49:14Z")

</div>

I am trying to use component\_templates per the warning I received after using old index template. It seems to work, other than the \_tier\_preference setting. Specifically, setting "\_tier\_preference" to "data\_content" or …

---

## [Kibana Dashboard - net::ERR\_ABORTED 400](https://discuss.elastic.co/t/kibana-dashboard-net-err-aborted-400/335806)

<div class="topic-metadata">

**Author:** [@duartera](https://discuss.elastic.co/u/duartera)\
**Replies:** 12\
**Last updated:** [June 22, 2023, 10:59pm UTC](https://discuss.elastic.co/t/kibana-dashboard-net-err-aborted-400/335806 "2023-06-22T22:59:30Z")

</div>

Hey, We are facing a very random issue, the most of the time the Kibana Dashboard loads properly but when not, we got this error messages: Here the Kibana logs (a piece of it, these are the only relevant records on …

---

## [Command line syntax to use the logstash.yml instead of the pipeline (.conf)](https://discuss.elastic.co/t/command-line-syntax-to-use-the-logstash-yml-instead-of-the-pipeline-conf/336630)

<div class="topic-metadata">

**Author:** [@elBilo](https://discuss.elastic.co/u/elBilo)\
**Replies:** 5\
**Last updated:** [June 22, 2023, 9:25pm UTC](https://discuss.elastic.co/t/command-line-syntax-to-use-the-logstash-yml-instead-of-the-pipeline-conf/336630 "2023-06-22T21:25:36Z")

</div>

I see plenty of examples with the command line option -f for using a specific pipeline file can I use the same syntax to use a specific logstash.yml file? the current helm file settings I have are command: - logstash …

---

## [Kibana Discover field statistics not showing](https://discuss.elastic.co/t/kibana-discover-field-statistics-not-showing/335466)

<div class="topic-metadata">

**Author:** [@joshuachough](https://discuss.elastic.co/u/joshuachough)\
**Replies:** 5\
**Last updated:** [June 22, 2023, 9:03pm UTC](https://discuss.elastic.co/t/kibana-discover-field-statistics-not-showing/335466 "2023-06-22T21:03:09Z")

</div>

I have some data I am trying to get statistics on (e.g. what percentage of documents have a description?). However, the field statistics are not showing, even when I hit refresh... When I click on one of the fields, …

---

## [Prevent ingest pipeline processor from nesting field names](https://discuss.elastic.co/t/prevent-ingest-pipeline-processor-from-nesting-field-names/336723)

<div class="topic-metadata">

**Author:** [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 8:18pm UTC](https://discuss.elastic.co/t/prevent-ingest-pipeline-processor-from-nesting-field-names/336723 "2023-06-22T20:18:25Z")

</div>

Consider the following ingest pipeline w/simulation... PUT \_ingest/pipeline/test { "processors": \[ { "set": { "field": "donot.nest", "value": "somevalue", "if": "ctx\['somedata'\] == 2"…

---

## [Unable to access Elastic with error message: "This Elastic installation has strict security requirements enabled that your current browser does not meet."](https://discuss.elastic.co/t/unable-to-access-elastic-with-error-message-this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/336606)

<div class="topic-metadata">

**Author:** [@AlexCloudSec](https://discuss.elastic.co/u/AlexCloudSec)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 7:16pm UTC](https://discuss.elastic.co/t/unable-to-access-elastic-with-error-message-this-elastic-installation-has-strict-security-requirements-enabled-that-your-current-browser-does-not-meet/336606 "2023-06-22T19:16:59Z")

</div>

Basically Title. My Browser is upgraded. Receiving this error across Chrome, Edge, and Firefox. How do I resolve this issue?

---

## [Inconsistency with queries on unknown fields](https://discuss.elastic.co/t/inconsistency-with-queries-on-unknown-fields/335841)

<div class="topic-metadata">

**Author:** [@yfful](https://discuss.elastic.co/u/yfful)\
**Replies:** 4\
**Last updated:** [June 22, 2023, 6:56pm UTC](https://discuss.elastic.co/t/inconsistency-with-queries-on-unknown-fields/335841 "2023-06-22T18:56:35Z")

</div>

Hello, If you make a search request with a geo\_bounding\_box query, it will fail with a QueryShardException with message failed to find geo field \[my-field\] in the case where the index doesn't have a mapping for my-field.…

---

## [Elastic Search Transport Client(6.8.23) not able to connect to ES 7.17.10](https://discuss.elastic.co/t/elastic-search-transport-client-6-8-23-not-able-to-connect-to-es-7-17-10/336637)

<div class="topic-metadata">

**Author:** [@Abhilashsr2008](https://discuss.elastic.co/u/Abhilashsr2008)\
**Replies:** 5\
**Last updated:** [June 22, 2023, 6:06pm UTC](https://discuss.elastic.co/t/elastic-search-transport-client-6-8-23-not-able-to-connect-to-es-7-17-10/336637 "2023-06-22T18:06:18Z")

</div>

Hi Team My application is using the Elastic Search Transport Client(6.8.23) and am trying to connect to an Elasticsearch server which is 7.17.10 version. And am getting the below exception. Caused by: NoNodeAvailableEx…

---

## [Elastic \`\_cluster/health\` showing unassigned shards](https://discuss.elastic.co/t/elastic-cluster-health-showing-unassigned-shards/336691)

<div class="topic-metadata">

**Author:** [@PresGas](https://discuss.elastic.co/u/PresGas)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 5:54pm UTC](https://discuss.elastic.co/t/elastic-cluster-health-showing-unassigned-shards/336691 "2023-06-22T17:54:33Z")

</div>

Hello! I inherited a 3 node Elastic 7.17 cluster and yesterday, the health status was red. \_cluster/health?pretty=true { "cluster\_name" : "graylog-production", "status" : "red", "timed\_out" : false, "number\_of\_…

---

## [Reading containers logs using FileBeat and logstash](https://discuss.elastic.co/t/reading-containers-logs-using-filebeat-and-logstash/336717)

<div class="topic-metadata">

**Author:** [@M\_D](https://discuss.elastic.co/u/M_D)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 5:18pm UTC](https://discuss.elastic.co/t/reading-containers-logs-using-filebeat-and-logstash/336717 "2023-06-22T17:18:58Z")

</div>

I am trying to read docker containers logs using Filebeat and logstash. right now, i got multiple outputs like following: { "@version" =\> "1", "event" =\> { "original" =\> "233.61.46.84 - - \[22/Jun…

---

## [Create a job from a model imported with Eland](https://discuss.elastic.co/t/create-a-job-from-a-model-imported-with-eland/336713)

<div class="topic-metadata">

**Author:** [@Lulu\_Martinez](https://discuss.elastic.co/u/Lulu_Martinez)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 4:35pm UTC](https://discuss.elastic.co/t/create-a-job-from-a-model-imported-with-eland/336713 "2023-06-22T16:35:53Z")

</div>

Hello, I would like to know if it is possible to create a machine learning job from an external model that I imported into Elastic platform using Eland. If so, how I can run that job each hour thus ingesting the data f…

---

## [Usage of Logstash - Nullifying the logs when not required to be published](https://discuss.elastic.co/t/usage-of-logstash-nullifying-the-logs-when-not-required-to-be-published/334027)

<div class="topic-metadata">

**Author:** [@pavan\_tiriveedhi](https://discuss.elastic.co/u/pavan_tiriveedhi)\
**Replies:** 5\
**Last updated:** [June 22, 2023, 3:40pm UTC](https://discuss.elastic.co/t/usage-of-logstash-nullifying-the-logs-when-not-required-to-be-published/334027 "2023-06-22T15:40:14Z")

</div>

Hi, We are using Logstash to push logs from our kubernetes environments to Azure for storing and computing, we have installed the services via help chart - helm-charts/logstash at main · elastic/helm-charts · GitHub. Mo…

---

## [Some data points in "Line" visualization cannot draw lines after split series](https://discuss.elastic.co/t/some-data-points-in-line-visualization-cannot-draw-lines-after-split-series/336512)

<div class="topic-metadata">

**Author:** [@grace\_Li](https://discuss.elastic.co/u/grace_Li)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 3:35pm UTC](https://discuss.elastic.co/t/some-data-points-in-line-visualization-cannot-draw-lines-after-split-series/336512 "2023-06-22T15:35:40Z")

</div>

Hello friends, I'm trying to display some data as a "Line" graph. The line looks good when not split series. But I need to split it into 2 lines to compare the trends. After split with a filter, some data points are n…

---

## [Visulaize dashboard kibana](https://discuss.elastic.co/t/visulaize-dashboard-kibana/335490)

<div class="topic-metadata">

**Author:** [@Suhendra\_sitorus](https://discuss.elastic.co/u/Suhendra_sitorus)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 3:32pm UTC](https://discuss.elastic.co/t/visulaize-dashboard-kibana/335490 "2023-06-22T15:32:24Z")

</div>

Hallo, I will be created dashboard on kibana for monitoring, we used ELK version 8.6.0, and beat family for collect the data. Sample dashboard like on attchement, so what on kibana can created dashboard like a attchmen…

---

## [How to aggregation in Kibana dashboard](https://discuss.elastic.co/t/how-to-aggregation-in-kibana-dashboard/334637)

<div class="topic-metadata">

**Author:** [@kanamasa](https://discuss.elastic.co/u/kanamasa)\
**Replies:** 1\
**Last updated:** [June 22, 2023, 3:29pm UTC](https://discuss.elastic.co/t/how-to-aggregation-in-kibana-dashboard/334637 "2023-06-22T15:29:38Z")

</div>

Hi, Collect network traffic data in Elasticsearch. Please tell me how to aggregate in the Kibana dashboard. I tried to make it with table visualization, but I didn't know how to aggregate with multiple items. \[Data c…

---

## [Derivatives with "missing docs"](https://discuss.elastic.co/t/derivatives-with-missing-docs/336705)

<div class="topic-metadata">

**Author:** [@Pieter\_Agenbag](https://discuss.elastic.co/u/Pieter_Agenbag)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 2:25pm UTC](https://discuss.elastic.co/t/derivatives-with-missing-docs/336705 "2023-06-22T14:25:46Z")

</div>

Hi, I have a problem where I need to calculate the derivative on a sequence of documents that are Not at a specific interval. As a simplified example , imagine a series "login" event inserted into an index with a times…

---

## [Dynamic individual chart](https://discuss.elastic.co/t/dynamic-individual-chart/336244)

<div class="topic-metadata">

**Author:** [@SYGH](https://discuss.elastic.co/u/SYGH)\
**Replies:** 3\
**Last updated:** [June 22, 2023, 1:56pm UTC](https://discuss.elastic.co/t/dynamic-individual-chart/336244 "2023-06-22T13:56:18Z")

</div>

Hi, I need to create 10 individual charts for a list of top 10 count of X field. For example, chart 1 is the chart for the value with id = 1 in the top 10 list, chart 2 is the chart for the value id = 2 in the top 10 li…

---

## [Filebeat 7.17.0 - Unable to parse time field "Jun 21 09:16:38" with \[Stamp\]](https://discuss.elastic.co/t/filebeat-7-17-0-unable-to-parse-time-field-jun-21-0938-with-stamp/336703)

<div class="topic-metadata">

**Author:** [@vavaux](https://discuss.elastic.co/u/vavaux)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 1:41pm UTC](https://discuss.elastic.co/t/filebeat-7-17-0-unable-to-parse-time-field-jun-21-0938-with-stamp/336703 "2023-06-22T13:41:01Z")

</div>

Hello, Quite newbie on ELK & Filebeat (using v7.17.0), I'm trying to parse and retrieve the log line date as timestamp from following logs: Jun 19 22:08:00: WARNING: RCP timeout when waiting for ping response. Disconne…

---

## [Elasticsearch not loading logs](https://discuss.elastic.co/t/elasticsearch-not-loading-logs/336700)

<div class="topic-metadata">

**Author:** [@vanwoes](https://discuss.elastic.co/u/vanwoes)\
**Replies:** 0\
**Last updated:** [June 22, 2023, 1:26pm UTC](https://discuss.elastic.co/t/elasticsearch-not-loading-logs/336700 "2023-06-22T13:26:41Z")

</div>

Hi, We have an elasticsearch cluster in docker swarm that consists of: 3 x controllers 1 x hot node 1 x warm node 1 x cold node The cluster is showing as healthy and the nodes all have quite low memory/CPU usage ho…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=500)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=502)
