# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=514

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 515

---

## [Three Plots from one Data View With Two Different Split Series Applying Individually](https://discuss.elastic.co/t/three-plots-from-one-data-view-with-two-different-split-series-applying-individually/335647)

<div class="topic-metadata">

**Author:** [@nickbarry](https://discuss.elastic.co/u/nickbarry)\
**Replies:** 21\
**Last updated:** [June 12, 2023, 3:59pm UTC](https://discuss.elastic.co/t/three-plots-from-one-data-view-with-two-different-split-series-applying-individually/335647 "2023-06-12T15:59:43Z")

</div>

I have three data plots I wish to display in one visualization. All data is from one wildcard data view and I have defined three y-axes. I would like to have two stacked data plots (line charts, in this case), split by…

---

## [Unable to pull Image from fleet-server docker](https://discuss.elastic.co/t/unable-to-pull-image-from-fleet-server-docker/335634)

<div class="topic-metadata">

**Author:** [@bhavya2810](https://discuss.elastic.co/u/bhavya2810)\
**Replies:** 2\
**Last updated:** [June 12, 2023, 3:56pm UTC](https://discuss.elastic.co/t/unable-to-pull-image-from-fleet-server-docker/335634 "2023-06-12T15:56:03Z")

</div>

I ran this command for setup of fleet server. docker run -it --rm \\ -e ELASTICSEARCH\_HOSTS="https://elasticsearch:9200" \\ -e ELASTICSEARCH\_SERVICE\_TOKEN="someservicetoken" \\ -e ELASTICSEARCH\_CA\_TRUSTED\_FINGERPRINT…

---

## [Install Logstash-jdbc-integration plugin offline](https://discuss.elastic.co/t/install-logstash-jdbc-integration-plugin-offline/335785)

<div class="topic-metadata">

**Author:** [@ztzy1907](https://discuss.elastic.co/u/ztzy1907)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 3:07pm UTC](https://discuss.elastic.co/t/install-logstash-jdbc-integration-plugin-offline/335785 "2023-06-12T15:07:32Z")

</div>

Hi, this is Richard. I'm trying to install logstash-jdbc-integration plugin on Logstash 7.8.0 on a machine that does not have internet access. What I'm trying to do is like below which is similar to install plugin on e…

---

## [This really helped me on Elastic with Logstash 8.x](https://discuss.elastic.co/t/this-really-helped-me-on-elastic-with-logstash-8-x/335781)

<div class="topic-metadata">

**Author:** [@dpresbit](https://discuss.elastic.co/u/dpresbit)\
**Replies:** 0\
**Last updated:** [June 12, 2023, 2:27pm UTC](https://discuss.elastic.co/t/this-really-helped-me-on-elastic-with-logstash-8-x/335781 "2023-06-12T14:27:36Z")

</div>

Continuing the discussion from Where is the object mapping for \[host\] defined?:

---

## [Unable to display large text fields in Kibana Markdown visualization](https://discuss.elastic.co/t/unable-to-display-large-text-fields-in-kibana-markdown-visualization/335757)

<div class="topic-metadata">

**Author:** [@pavlod](https://discuss.elastic.co/u/pavlod)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 2:17pm UTC](https://discuss.elastic.co/t/unable-to-display-large-text-fields-in-kibana-markdown-visualization/335757 "2023-06-12T14:17:24Z")

</div>

Hello, I have one field store in ES that has a big length, around 35.000 - 40.000 characters. They are stored correctly in ES, I can see them in Discover page (mapped as keyword), but when I want to use them in a markd…

---

## [How to keep router updated with history?](https://discuss.elastic.co/t/how-to-keep-router-updated-with-history/335779)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 0\
**Last updated:** [June 12, 2023, 2:14pm UTC](https://discuss.elastic.co/t/how-to-keep-router-updated-with-history/335779 "2023-06-12T14:14:11Z")

</div>

Hi, I am using react-router-dom v6. I am creating a custom plugin in react, and is trying to implement routing (navigation between ui pages). As per this documentation (Routing, Navigation and URL | Kibana Guide \[8.8\] …

---

## [How to use JSON filter correctly to parse my data?](https://discuss.elastic.co/t/how-to-use-json-filter-correctly-to-parse-my-data/335777)

<div class="topic-metadata">

**Author:** [@Chel\_Db](https://discuss.elastic.co/u/Chel_Db)\
**Replies:** 0\
**Last updated:** [June 12, 2023, 2:08pm UTC](https://discuss.elastic.co/t/how-to-use-json-filter-correctly-to-parse-my-data/335777 "2023-06-12T14:08:30Z")

</div>

Below is the JSON format of the current data and I'm using JSON filter to handle the nested JSON construct but it is not working as expected. log field is again a JSON field, which I would like to expand further as Mess…

---

## [Datafeed \[datafeed-packetbeat\_dns\_tunneling\] cannot retrieve data because no index matches datafeed's indices \[packetbeat-\*\]](https://discuss.elastic.co/t/datafeed-datafeed-packetbeat-dns-tunneling-cannot-retrieve-data-because-no-index-matches-datafeeds-indices-packetbeat/334356)

<div class="topic-metadata">

**Author:** [@A113n](https://discuss.elastic.co/u/A113n)\
**Replies:** 15\
**Last updated:** [June 12, 2023, 2:07pm UTC](https://discuss.elastic.co/t/datafeed-datafeed-packetbeat-dns-tunneling-cannot-retrieve-data-because-no-index-matches-datafeeds-indices-packetbeat/334356 "2023-06-12T14:07:10Z")

</div>

Hi folks I have been searching high and low regarding this error and I am very new to the ELK stack. ELK 8.7.1, using Elastic Agents on clients. When I try to enable the ML job packetbeat\_dns\_tunneling it fails with t…

---

## [Use new kibana plugin in another instance](https://discuss.elastic.co/t/use-new-kibana-plugin-in-another-instance/335754)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 1:50pm UTC](https://discuss.elastic.co/t/use-new-kibana-plugin-in-another-instance/335754 "2023-06-12T13:50:07Z")

</div>

Hello, I want to create a new kibana plugin. I am referring to this link External plugin development | Kibana Guide \[8.8\] | Elastic but my question is how to package the plugin I created and use it in another kibana i…

---

## [{"statusCode":503,"error":"Service Unavailable","message":"License is not available."}](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/335741)

<div class="topic-metadata">

**Author:** [@R1d3rBG](https://discuss.elastic.co/u/R1d3rBG)\
**Replies:** 6\
**Last updated:** [June 12, 2023, 1:41pm UTC](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/335741 "2023-06-12T13:41:52Z")

</div>

Hello, I have installed Elastic, but after 2-3 days stops working with the following error. {"statusCode":503,"error":"Service Unavailable","message":"License is not available."} Could you help me with investigation w…

---

## [\[es/search\] failed: \[search\_phase\_execution\_exception\] all shards failed](https://discuss.elastic.co/t/es-search-failed-search-phase-execution-exception-all-shards-failed/335428)

<div class="topic-metadata">

**Author:** [@FTOR](https://discuss.elastic.co/u/FTOR)\
**Replies:** 6\
**Last updated:** [June 12, 2023, 1:31pm UTC](https://discuss.elastic.co/t/es-search-failed-search-phase-execution-exception-all-shards-failed/335428 "2023-06-12T13:31:52Z")

</div>

Hello, I would like to get documents from an index that contains a huge number of data ~ (1 million). I am using ElasticSearchClient to connect and get information from Elasticsearch. I tested the solution with a small…

---

## [Difficulty creating role](https://discuss.elastic.co/t/difficulty-creating-role/335764)

<div class="topic-metadata">

**Author:** [@Jck\_H\_ui](https://discuss.elastic.co/u/Jck_H_ui)\
**Replies:** 6\
**Last updated:** [June 12, 2023, 1:04pm UTC](https://discuss.elastic.co/t/difficulty-creating-role/335764 "2023-06-12T13:04:18Z")

</div>

I'm trying to create a role using the command as described in the doc's ( I'm using elastic 8.7) curl -X POST "localhost:9200/\_security/role/myprofile?pretty" -H 'Content-Type: application/json' -d' { "indices": \[ …

---

## [Error message: the node is expected to continue to exceed the high disk watermark when these relocations are complete](https://discuss.elastic.co/t/error-message-the-node-is-expected-to-continue-to-exceed-the-high-disk-watermark-when-these-relocations-are-complete/335660)

<div class="topic-metadata">

**Author:** [@Mhvrke](https://discuss.elastic.co/u/Mhvrke)\
**Replies:** 2\
**Last updated:** [June 12, 2023, 1:00pm UTC](https://discuss.elastic.co/t/error-message-the-node-is-expected-to-continue-to-exceed-the-high-disk-watermark-when-these-relocations-are-complete/335660 "2023-06-12T13:00:02Z")

</div>

Hi! There’s this scenario where my cluster elasticsearch in rke logs is showing the following message: the node is expected to continue to exceed the high disk watermark when these relocations are complete. It keeps lo…

---

## [Anyone please help me for How to make flyaway for elastic search with node js?](https://discuss.elastic.co/t/anyone-please-help-me-for-how-to-make-flyaway-for-elastic-search-with-node-js/335707)

<div class="topic-metadata">

**Author:** [@faiyaz\_18](https://discuss.elastic.co/u/faiyaz_18)\
**Replies:** 4\
**Last updated:** [June 12, 2023, 12:33pm UTC](https://discuss.elastic.co/t/anyone-please-help-me-for-how-to-make-flyaway-for-elastic-search-with-node-js/335707 "2023-06-12T12:33:33Z")

</div>

Elastic search

---

## [Fail to checkin to fleet-server](https://discuss.elastic.co/t/fail-to-checkin-to-fleet-server/334210)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 16\
**Last updated:** [June 12, 2023, 12:33pm UTC](https://discuss.elastic.co/t/fail-to-checkin-to-fleet-server/334210 "2023-06-12T12:33:16Z")

</div>

Hi All, I have successfully enrolled my remote server/machine into my Fleet server and I can see my metrics and logs coming thru. The issue is that at the beginning of the enrollment the status of the agent in kiban…

---

## [Cannot post document to TimeSeries DataStream after upgrade from 8.6.2 to 8.7.1](https://discuss.elastic.co/t/cannot-post-document-to-timeseries-datastream-after-upgrade-from-8-6-2-to-8-7-1/335313)

<div class="topic-metadata">

**Author:** [@VietDuc](https://discuss.elastic.co/u/VietDuc)\
**Replies:** 14\
**Last updated:** [June 12, 2023, 11:39am UTC](https://discuss.elastic.co/t/cannot-post-document-to-timeseries-datastream-after-upgrade-from-8-6-2-to-8-7-1/335313 "2023-06-12T11:39:57Z")

</div>

Hi everyone, We had some Timeseries DataStream in version 8.6.2 and we have just upgraded our cluster to version 8.7.1. However, after the upgrade, new documents cannot be posted to those TSDS and we got the following e…

---

## [Which storage type should I use for Elasticsearch?](https://discuss.elastic.co/t/which-storage-type-should-i-use-for-elasticsearch/335511)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 11:33am UTC](https://discuss.elastic.co/t/which-storage-type-should-i-use-for-elasticsearch/335511 "2023-06-12T11:33:59Z")

</div>

I'm installing elasticsearch and needs 2 TB storage for shipping from filesystem log files using beats and logstash. What is the proper storage type as per our required design (frequent writes, many nodes and less read) …

---

## [Which table to use/how to filter columns in aggreagtion based data table](https://discuss.elastic.co/t/which-table-to-use-how-to-filter-columns-in-aggreagtion-based-data-table/334209)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 11:18am UTC](https://discuss.elastic.co/t/which-table-to-use-how-to-filter-columns-in-aggreagtion-based-data-table/334209 "2023-06-12T11:18:57Z")

</div>

Hello, i'm using Kibana 8.7.0 and i have data in this form: {id: 1, valueToFilterBy: 0, valueToSum: 10, stringValue: "someString1"}, {id: 1, valueToFilterBy: 0, valueToSum: 20, stringValue: "someString2"}, {id: 1, va…

---

## [Kibana Table Visualisation CPU](https://discuss.elastic.co/t/kibana-table-visualisation-cpu/334968)

<div class="topic-metadata">

**Author:** [@rl0ne](https://discuss.elastic.co/u/rl0ne)\
**Replies:** 4\
**Last updated:** [June 12, 2023, 10:20am UTC](https://discuss.elastic.co/t/kibana-table-visualisation-cpu/334968 "2023-06-12T10:20:43Z")

</div>

Hello Everyone , Kibana 7.16 Need help to understand if it possible to create a table in Kibana to display servers where CPU above 80% for 5 minutes ( not a single event in 5 minutes but during 5 minutes ). So I can se…

---

## [Kibana failing to start due to unable to verify the first certificate](https://discuss.elastic.co/t/kibana-failing-to-start-due-to-unable-to-verify-the-first-certificate/335608)

<div class="topic-metadata">

**Author:** [@Sudhir\_Batchu](https://discuss.elastic.co/u/Sudhir_Batchu)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 9:58am UTC](https://discuss.elastic.co/t/kibana-failing-to-start-due-to-unable-to-verify-the-first-certificate/335608 "2023-06-12T09:58:16Z")

</div>

Hi need help in fixing this ES version 8.8 Kibana version 8.8 Here is Kibana logs Jun 09 08:28:10 ip-100-90-3-56.us-west-2.compute.internal kibana\[20111\]: \[2023-06-09T08:28:10.667+00:00\]\[INFO \]\[plugins.screenshotting…

---

## [Error when developing plugin in Kibana 8.9 (master branch) and 8.6](https://discuss.elastic.co/t/error-when-developing-plugin-in-kibana-8-9-master-branch-and-8-6/335742)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 9:19am UTC](https://discuss.elastic.co/t/error-when-developing-plugin-in-kibana-8-9-master-branch-and-8-6/335742 "2023-06-12T09:19:16Z")

</div>

Hi, I was working on a custom plugin in 8.5.3. It was working fine. Even new plugin generation, etc... all were smooth in 8.5.3. I had tried the same on 8.6... and now in 8.9. In both these versions, I just generated a…

---

## [Filebeat: How to edit apache module ingest pipeline](https://discuss.elastic.co/t/filebeat-how-to-edit-apache-module-ingest-pipeline/335749)

<div class="topic-metadata">

**Author:** [@Akshaychdev](https://discuss.elastic.co/u/Akshaychdev)\
**Replies:** 0\
**Last updated:** [June 12, 2023, 9:17am UTC](https://discuss.elastic.co/t/filebeat-how-to-edit-apache-module-ingest-pipeline/335749 "2023-06-12T09:17:09Z")

</div>

Using Elasticsearch and Kibana 7.17 with Filebeat and Filebeat-apache module to index apache access and error logs to elasticsearch. I need to add some more filtering to Apache Error log message, for that prepared the n…

---

## [Is is possible to disable clock skew adjustment for APM dashboard (kibana)](https://discuss.elastic.co/t/is-is-possible-to-disable-clock-skew-adjustment-for-apm-dashboard-kibana/335737)

<div class="topic-metadata">

**Author:** [@Xumin\_Zhou](https://discuss.elastic.co/u/Xumin_Zhou)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 6:49am UTC](https://discuss.elastic.co/t/is-is-possible-to-disable-clock-skew-adjustment-for-apm-dashboard-kibana/335737 "2023-06-12T06:49:53Z")

</div>

As the title says. First-hand information (real readout) is important for monitoring and tracing. There're a lot of problems not solved with this adjustment, for example, it does not preserve the relative positions of …

---

## [ConnectionRefusedError: \[Errno 111\] Connection refused error while running rally for an existing elastic cluster](https://discuss.elastic.co/t/connectionrefusederror-errno-111-connection-refused-error-while-running-rally-for-an-existing-elastic-cluster/335333)

<div class="topic-metadata">

**Author:** [@Swathi\_Kakumanu](https://discuss.elastic.co/u/Swathi_Kakumanu)\
**Replies:** 3\
**Last updated:** [June 12, 2023, 6:37am UTC](https://discuss.elastic.co/t/connectionrefusederror-errno-111-connection-refused-error-while-running-rally-for-an-existing-elastic-cluster/335333 "2023-06-12T06:37:12Z")

</div>

Hi, I am new to rally and trying to run the benchmark for the existing cluster. I have 3 K8's nodes (1 master,2 worker) 192.168.105.116 192.168.105.117 192.168.105.118 I have created an Elasticsearch cluster on top…

---

## [Add unique value for each fields](https://discuss.elastic.co/t/add-unique-value-for-each-fields/335695)

<div class="topic-metadata">

**Author:** [@sevbans](https://discuss.elastic.co/u/sevbans)\
**Replies:** 6\
**Last updated:** [June 11, 2023, 9:26pm UTC](https://discuss.elastic.co/t/add-unique-value-for-each-fields/335695 "2023-06-11T21:26:30Z")

</div>

I have a index something like this: All countries' names, along with their populations, exist in my index. Since Kibana does not allow us to use the countries' normal names, I have to add unique country codes such as…

---

## [How can I add add an extra field to all documents indexed by beats](https://discuss.elastic.co/t/how-can-i-add-add-an-extra-field-to-all-documents-indexed-by-beats/335622)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 6\
**Last updated:** [June 11, 2023, 4:24pm UTC](https://discuss.elastic.co/t/how-can-i-add-add-an-extra-field-to-all-documents-indexed-by-beats/335622 "2023-06-11T16:24:54Z")

</div>

Hi all. Lets imagine that I have a single elasticsearch cluster to store document from two different companies Company1 has server1 server2 and server3 Company2 has server1 server2 and server3 For me the easier…

---

## [Metrics do nothing in my file](https://discuss.elastic.co/t/metrics-do-nothing-in-my-file/335700)

<div class="topic-metadata">

**Author:** [@javierelastic](https://discuss.elastic.co/u/javierelastic)\
**Replies:** 2\
**Last updated:** [June 11, 2023, 10:35am UTC](https://discuss.elastic.co/t/metrics-do-nothing-in-my-file/335700 "2023-06-11T10:35:19Z")

</div>

I am trying to count the number of logs that appear in my file. Now I am using a file with logs as an example, but later I will use a syslog, and I want it to count the logs that arrive in 2 minutes. if \[msgFinal\] =~…

---

## [URL Drilldown - How to pass specific column value](https://discuss.elastic.co/t/url-drilldown-how-to-pass-specific-column-value/335719)

<div class="topic-metadata">

**Author:** [@azulgrana](https://discuss.elastic.co/u/azulgrana)\
**Replies:** 0\
**Last updated:** [June 11, 2023, 10:32am UTC](https://discuss.elastic.co/t/url-drilldown-how-to-pass-specific-column-value/335719 "2023-06-11T10:32:22Z")

</div>

Hi there, I have a table with 3 fields. Id, IOC, Severity. And I have a set of drilldowns to perform an IOC search against virustotal, Whois and map the Id to an internal app. I'm using {{event.value}} across all the dr…

---

## [Too many open files](https://discuss.elastic.co/t/too-many-open-files/335677)

<div class="topic-metadata">

**Author:** [@lchqlchq](https://discuss.elastic.co/u/lchqlchq)\
**Replies:** 4\
**Last updated:** [June 11, 2023, 7:36am UTC](https://discuss.elastic.co/t/too-many-open-files/335677 "2023-06-11T07:36:32Z")

</div>

i have a three node es7.4 cluster without data. choose one node,ifdown the network，and es filehandler increasing quickly until the ulimit filehandler fills up。the new added filehandler point the same socket id as:ll /pro…

---

## [How to add \_size mapping to index template in elasticsearch?](https://discuss.elastic.co/t/how-to-add-size-mapping-to-index-template-in-elasticsearch/335432)

<div class="topic-metadata">

**Author:** [@Amirhossein\_eidy](https://discuss.elastic.co/u/Amirhossein_eidy)\
**Replies:** 6\
**Last updated:** [June 11, 2023, 6:54am UTC](https://discuss.elastic.co/t/how-to-add-size-mapping-to-index-template-in-elasticsearch/335432 "2023-06-11T06:54:38Z")

</div>

Hi friends I have installed size mapping plugin and I added it to Kibana meta fields too I could successfully enable "\_size" in Elasticsearch via bellow command and see the result in kibana PUT logstash-2023-06-06 { …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=513)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=515)
