# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=517

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 518

---

## [While connecting to activemq using metricbeat, I am getting that error like error making http request: Post transport connection broken: malformed HTTP status code "MaxInactivityDurationInitalDelay"](https://discuss.elastic.co/t/while-connecting-to-activemq-using-metricbeat-i-am-getting-that-error-like-error-making-http-request-post-transport-connection-broken-malformed-http-status-code-maxinactivitydurationinitaldelay/335537)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 0\
**Last updated:** [June 8, 2023, 1:26pm UTC](https://discuss.elastic.co/t/while-connecting-to-activemq-using-metricbeat-i-am-getting-that-error-like-error-making-http-request-post-transport-connection-broken-malformed-http-status-code-maxinactivitydurationinitaldelay/335537 "2023-06-08T13:26:12Z")

</div>

Hi Team, I am getting the below error while connecting to activemq through metricbeat. " ERROR module/wrapper.go:259 Error fetching data for metricset activemq.queue: error making http request: Post "ht…

---

## [Autodiscover not working](https://discuss.elastic.co/t/autodiscover-not-working/335522)

<div class="topic-metadata">

**Author:** [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 11:12am UTC](https://discuss.elastic.co/t/autodiscover-not-working/335522 "2023-06-08T11:12:30Z")

</div>

Greetiings, We enable auto discover with following and it harvest logs from all pods. filebeat.autodiscover: providers: - type: kubernetes hints.enabled: true hints.default\_config: type: con…

---

## [Reverse word search in Elastic](https://discuss.elastic.co/t/reverse-word-search-in-elastic/334173)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 7\
**Last updated:** [May 31, 2023, 10:09am UTC](https://discuss.elastic.co/t/reverse-word-search-in-elastic/334173 "2023-05-31T10:09:32Z")

</div>

Hello, I want to search words in reverse also in Elasticsearch. for Example - "Tpp Info" and "Info Tpp" should give the same result. while in my db the document present is "Tpp Infotech" in the field title. My query is…

---

## [Cannot login to Elastic Cloud, UI keep saying wrong password](https://discuss.elastic.co/t/cannot-login-to-elastic-cloud-ui-keep-saying-wrong-password/335512)

<div class="topic-metadata">

**Author:** [@mecer80](https://discuss.elastic.co/u/mecer80)\
**Replies:** 4\
**Last updated:** [June 8, 2023, 10:55am UTC](https://discuss.elastic.co/t/cannot-login-to-elastic-cloud-ui-keep-saying-wrong-password/335512 "2023-06-08T10:55:00Z")

</div>

Hi, I can't seem to login using the client UI: https://cloud.elastic.co/ It keeps saying my password is wrong even thought I've tried to changed it like 10 times using the "forgot your password". I received the emails…

---

## [Reindexing using Java Client - What happens when one or both of the index do not exist](https://discuss.elastic.co/t/reindexing-using-java-client-what-happens-when-one-or-both-of-the-index-do-not-exist/335505)

<div class="topic-metadata">

**Author:** [@sanskarfc](https://discuss.elastic.co/u/sanskarfc)\
**Replies:** 5\
**Last updated:** [June 8, 2023, 10:06am UTC](https://discuss.elastic.co/t/reindexing-using-java-client-what-happens-when-one-or-both-of-the-index-do-not-exist/335505 "2023-06-08T10:06:24Z")

</div>

What happens when one or both of the index do not exist if we do reindexing using Java Client? When I tested on local, it completes successfully without throwing exception. How does one test if an index already exists o…

---

## [Stopping filebeats affects metricbeat http module](https://discuss.elastic.co/t/stopping-filebeats-affects-metricbeat-http-module/335410)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 4\
**Last updated:** [June 8, 2023, 9:50am UTC](https://discuss.elastic.co/t/stopping-filebeats-affects-metricbeat-http-module/335410 "2023-06-08T09:50:10Z")

</div>

Hello, I use Elasticsearch 7.17.6 on a WIndows server. I started two services : metricbeat and filebeat metricbeat runs modules : system, sql and http metricbeat-http tests http routes every minute filebeat was …

---

## [Problem "filter on maximum of timestamp"](https://discuss.elastic.co/t/problem-filter-on-maximum-of-timestamp/335518)

<div class="topic-metadata">

**Author:** [@elteraxya](https://discuss.elastic.co/u/elteraxya)\
**Replies:** 2\
**Last updated:** [June 8, 2023, 9:37am UTC](https://discuss.elastic.co/t/problem-filter-on-maximum-of-timestamp/335518 "2023-06-08T09:37:45Z")

</div>

Hello everyone, I'd like to tell you about my problem. I have data coming up every day with logstash on my kibana, this data comes up either "ok" or "other" in a "status" field with the @timestamp of the day. I'd like t…

---

## [Kibana User Experience - Not showing on on Observability Overview](https://discuss.elastic.co/t/kibana-user-experience-not-showing-on-on-observability-overview/335462)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 6:23pm UTC](https://discuss.elastic.co/t/kibana-user-experience-not-showing-on-on-observability-overview/335462 "2023-06-07T18:23:28Z")

</div>

Is there a simple reason why the User Experience Metrics does not show on the Observability Overview, but does when clicking on it from the sidebar ?

---

## [Select data based on timestamp](https://discuss.elastic.co/t/select-data-based-on-timestamp/335496)

<div class="topic-metadata">

**Author:** [@laurijssen](https://discuss.elastic.co/u/laurijssen)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 9:22am UTC](https://discuss.elastic.co/t/select-data-based-on-timestamp/335496 "2023-06-08T09:22:34Z")

</div>

Im trying to select data in a timestamp range (plus somie more criteria: @timestamp: \[ "2023-06-07T:07:00:00" TO "2023-06-07T09:00:00" \] but this gives the error: Expected AND, OR, end of input, whitespace but """ fou…

---

## [How to read the log file continuously and make it as key value in elastic UI](https://discuss.elastic.co/t/how-to-read-the-log-file-continuously-and-make-it-as-key-value-in-elastic-ui/335521)

<div class="topic-metadata">

**Author:** [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Replies:** 0\
**Last updated:** [June 8, 2023, 9:10am UTC](https://discuss.elastic.co/t/how-to-read-the-log-file-continuously-and-make-it-as-key-value-in-elastic-ui/335521 "2023-06-08T09:10:34Z")

</div>

Hi, How can i read the log file continuously and make it as readable in elastic UI, Below example is sample log. I tried with grok but it's not helping that much before few fields rolling in between lines (few log line …

---

## [Compatible s3 plugin for my ES](https://discuss.elastic.co/t/compatible-s3-plugin-for-my-es/335510)

<div class="topic-metadata">

**Author:** [@EshaSingh32000](https://discuss.elastic.co/u/EshaSingh32000)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 7:34am UTC](https://discuss.elastic.co/t/compatible-s3-plugin-for-my-es/335510 "2023-06-08T07:34:49Z")

</div>

Hello, My elasticsearch version is elasticsearch -6.4.2-1, what would be suitable s3 plugin for my es, as 6.4.3 version is not compatible with my es, please suggest.

---

## [Elasticsearch 8 Client is giving error The following method did not exist: ‘org.elasticsearch.client.RequestOptions$Builder org.elasticsearch.client.RequestOptions$Builder.removeHeader(java.lang.String)’](https://discuss.elastic.co/t/elasticsearch-8-client-is-giving-error-the-following-method-did-not-exist-org-elasticsearch-client-requestoptions-builder-org-elasticsearch-client-requestoptions-builder-removeheader-java-lang-string/335467)

<div class="topic-metadata">

**Author:** [@Skander\_Mansouri](https://discuss.elastic.co/u/Skander_Mansouri)\
**Replies:** 9\
**Last updated:** [June 8, 2023, 7:32am UTC](https://discuss.elastic.co/t/elasticsearch-8-client-is-giving-error-the-following-method-did-not-exist-org-elasticsearch-client-requestoptions-builder-org-elasticsearch-client-requestoptions-builder-removeheader-java-lang-string/335467 "2023-06-08T07:32:58Z")

</div>

I have copied exactly the same steps as the documentation elastic8 docs @Bean public ElasticsearchClient getElasticSearchClient(){ RestClient restClient = RestClient.builder( new HttpHost("", 9200)).build();…

---

## [Set time range filter to drill-down target from Vega panel](https://discuss.elastic.co/t/set-time-range-filter-to-drill-down-target-from-vega-panel/333805)

<div class="topic-metadata">

**Author:** [@rowish](https://discuss.elastic.co/u/rowish)\
**Replies:** 2\
**Last updated:** [June 8, 2023, 7:17am UTC](https://discuss.elastic.co/t/set-time-range-filter-to-drill-down-target-from-vega-panel/333805 "2023-06-08T07:17:14Z")

</div>

Hello community, I am trying to implement a drill-down functionality to my Vega panel able to send, alongside a manually set query filter, the time range inherited from my origin dashboard. The version that I was able …

---

## [Need Help with ProductCheckOnStartup](https://discuss.elastic.co/t/need-help-with-productcheckonstartup/335478)

<div class="topic-metadata">

**Author:** [@Priyam\_Mozumder](https://discuss.elastic.co/u/Priyam_Mozumder)\
**Replies:** 3\
**Last updated:** [June 8, 2023, 7:15am UTC](https://discuss.elastic.co/t/need-help-with-productcheckonstartup/335478 "2023-06-08T07:15:19Z")

</div>

19:38:24 INF\] Job Initialized \[19:38:25 FTL\] Error: Unsuccessful () low level call on GET: /\_cluster/health?pretty=true&error\_trace=true Audit trail of this API call: - \[1\] ProductCheckOnStartup: Took: 00:00:00.1116282…

---

## [Generate service token button does not work](https://discuss.elastic.co/t/generate-service-token-button-does-not-work/335458)

<div class="topic-metadata">

**Author:** [@Marcos\_Ivan\_Robles\_H](https://discuss.elastic.co/u/Marcos_Ivan_Robles_H)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 6:06pm UTC](https://discuss.elastic.co/t/generate-service-token-button-does-not-work/335458 "2023-06-07T18:06:02Z")

</div>

If you are asking about a problem you are experiencing, please use the following template, as it will help us help you. If you have a different problem, please delete all of this text :slight\_smile: TIP 1: select at lea…

---

## [Authenticaton error installing APM Agent](https://discuss.elastic.co/t/authenticaton-error-installing-apm-agent/335455)

<div class="topic-metadata">

**Author:** [@Marcos\_Ivan\_Robles\_H](https://discuss.elastic.co/u/Marcos_Ivan_Robles_H)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 5:56pm UTC](https://discuss.elastic.co/t/authenticaton-error-installing-apm-agent/335455 "2023-06-07T17:56:12Z")

</div>

If you are asking about a problem you are experiencing, please use the following template, as it will help us help you. If you have a different problem, please delete all of this text :slight\_smile: TIP 1: select at lea…

---

## [Elements Rotation (Arrow) based on Conditions in Canvas (ELK Stack)](https://discuss.elastic.co/t/elements-rotation-arrow-based-on-conditions-in-canvas-elk-stack/335183)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 6\
**Last updated:** [June 8, 2023, 6:33am UTC](https://discuss.elastic.co/t/elements-rotation-arrow-based-on-conditions-in-canvas-elk-stack/335183 "2023-06-08T06:33:33Z")

</div>

How do I rotate an arrow based on certain conditions in Canvas? I just want to integrate the CSS rotate function based on certain conditions. Can anyone suggest what functions we should use to rotate the axis? Below is …

---

## [Elasticsearch cannot restore existing snapshot. Blob not found](https://discuss.elastic.co/t/elasticsearch-cannot-restore-existing-snapshot-blob-not-found/335506)

<div class="topic-metadata">

**Author:** [@Naresh1919](https://discuss.elastic.co/u/Naresh1919)\
**Replies:** 0\
**Last updated:** [June 8, 2023, 6:18am UTC](https://discuss.elastic.co/t/elasticsearch-cannot-restore-existing-snapshot-blob-not-found/335506 "2023-06-08T06:18:15Z")

</div>

Elasticsearch version: 6.3.2 I was trying to restore an old snapshot (taken in January 2018) of a read only S3 repository. The necessary permissions in the IAM role for the instance are setup. Here is the repository de…

---

## [Enhanced table plugin on elastic cloud](https://discuss.elastic.co/t/enhanced-table-plugin-on-elastic-cloud/335214)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [June 8, 2023, 5:45am UTC](https://discuss.elastic.co/t/enhanced-table-plugin-on-elastic-cloud/335214 "2023-06-08T05:45:48Z")

</div>

Hello Elastic Team, I've a request or guidance required .Its important as its causing major isssue now for our usecases. We show statistical data in tables. The data is of following type: 1)Hyperlinks-\>ONCLICK downloa…

---

## [Failed to start Elasticsearch 7.11.2](https://discuss.elastic.co/t/failed-to-start-elasticsearch-7-11-2/334680)

<div class="topic-metadata">

**Author:** [@Nik1](https://discuss.elastic.co/u/Nik1)\
**Replies:** 35\
**Last updated:** [June 8, 2023, 5:43am UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch-7-11-2/334680 "2023-06-08T05:43:28Z")

</div>

Elasticsearch service is not starting on the ubuntu machine. Getting the below error. Anybody having idea? ~# systemctl start elasticsearch Job for elasticsearch.service failed because the control process exited with e…

---

## [Disable \_source field](https://discuss.elastic.co/t/disable-source-field/335434)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 4\
**Last updated:** [June 8, 2023, 5:39am UTC](https://discuss.elastic.co/t/disable-source-field/335434 "2023-06-08T05:39:53Z")

</div>

Hello, I'm currently working on optimizing the size of an index. After reviewing the documentation and analyzing the field sizes, I found that a significant portion of the document size is attributed to the \_source fiel…

---

## [Elastic agent 7.12 32-bit](https://discuss.elastic.co/t/elastic-agent-7-12-32-bit/335495)

<div class="topic-metadata">

**Author:** [@Pukar](https://discuss.elastic.co/u/Pukar)\
**Replies:** 0\
**Last updated:** [June 8, 2023, 5:15am UTC](https://discuss.elastic.co/t/elastic-agent-7-12-32-bit/335495 "2023-06-08T05:15:37Z")

</div>

Hi, i have elasticsearch environment with 7.12 version 64-bit operating system for logging elastic agents to windows 7, one of the w7 machines is 32-bit OS. is it possible to collect logs from elastic agent 32-bit into …

---

## [ILM policy for custom index](https://discuss.elastic.co/t/ilm-policy-for-custom-index/335271)

<div class="topic-metadata">

**Author:** [@lalchand\_rajak](https://discuss.elastic.co/u/lalchand_rajak)\
**Replies:** 6\
**Last updated:** [June 8, 2023, 5:06am UTC](https://discuss.elastic.co/t/ilm-policy-for-custom-index/335271 "2023-06-08T05:06:56Z")

</div>

Hello, I am unable to apply ILM policy to custom index coming from Openshift cluster log forwarding. As It create index with app-write and does not have any aliases. GET app-write/\_ilm/explain output { "indices": { …

---

## [How does Metricbeat get the diskio data of NAS？](https://discuss.elastic.co/t/how-does-metricbeat-get-the-diskio-data-of-nas/335488)

<div class="topic-metadata">

**Author:** [@CatLoveFishma](https://discuss.elastic.co/u/CatLoveFishma)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 3:31am UTC](https://discuss.elastic.co/t/how-does-metricbeat-get-the-diskio-data-of-nas/335488 "2023-06-08T03:31:48Z")

</div>

I have a NAS mounted on my Linux machine. I want to know how to use metricbeat to monitor the disk of nas？

---

## [Unable to enrich document](https://discuss.elastic.co/t/unable-to-enrich-document/335492)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 3:30am UTC](https://discuss.elastic.co/t/unable-to-enrich-document/335492 "2023-06-08T03:30:32Z")

</div>

Hi All, I have created an kibana alert which is ingesting the document to a index. I have set a default pipeline to that index but when i see the documents ingested from kibana alerts it doesn't have the enrich fields. …

---

## [Monitoring Microservice](https://discuss.elastic.co/t/monitoring-microservice/335491)

<div class="topic-metadata">

**Author:** [@Suhendra\_sitorus](https://discuss.elastic.co/u/Suhendra_sitorus)\
**Replies:** 0\
**Last updated:** [June 8, 2023, 2:55am UTC](https://discuss.elastic.co/t/monitoring-microservice/335491 "2023-06-08T02:55:18Z")

</div>

Hallo, I am used ELK version 8.5.0, i am want monitoring Microservice system, the microservice with base pyhton frame work Fast API and the microservice on docker and kubernetes ( OCP ), i have 100 more microservice so …

---

## [Error during restore snapshot "but system indices can only be restored as part of a feature state"](https://discuss.elastic.co/t/error-during-restore-snapshot-but-system-indices-can-only-be-restored-as-part-of-a-feature-state/335489)

<div class="topic-metadata">

**Author:** [@target\_test](https://discuss.elastic.co/u/target_test)\
**Replies:** 0\
**Last updated:** [June 8, 2023, 2:32am UTC](https://discuss.elastic.co/t/error-during-restore-snapshot-but-system-indices-can-only-be-restored-as-part-of-a-feature-state/335489 "2023-06-08T02:32:33Z")

</div>

Hi guys i encountered some error during my restore snapshot. All begin when i check my cluster health there is unassigned shard after i check it. it was .kibana\_alerting\_cases\_8.8.0\_001 and i tried to get information us…

---

## [How to format the grok pattern parsed field value in a new line based on timestamp?](https://discuss.elastic.co/t/how-to-format-the-grok-pattern-parsed-field-value-in-a-new-line-based-on-timestamp/335460)

<div class="topic-metadata">

**Author:** [@abhisheksa](https://discuss.elastic.co/u/abhisheksa)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 6:15pm UTC](https://discuss.elastic.co/t/how-to-format-the-grok-pattern-parsed-field-value-in-a-new-line-based-on-timestamp/335460 "2023-06-07T18:15:42Z")

</div>

I have this log message which is filtered using grok pattern. Entire message gets displayed in a single line in the filtered output. { "message": \[ "Calling com.portal.ws.service.GvpV2Service@2ad03f20 method cr…

---

## [Elasticsearch Circuit breaking exception](https://discuss.elastic.co/t/elasticsearch-circuit-breaking-exception/335305)

<div class="topic-metadata">

**Author:** [@RAM\_NATHAN](https://discuss.elastic.co/u/RAM_NATHAN)\
**Replies:** 2\
**Last updated:** [June 7, 2023, 10:57pm UTC](https://discuss.elastic.co/t/elasticsearch-circuit-breaking-exception/335305 "2023-06-07T22:57:00Z")

</div>

Hi Im using elasticsearch 7.10.2 single node. Im getting this Data too large, data for \[\<http\_request\>\] would be \[3985754120/3.7gb\], which is larger than the limit of \[3910375833/3.6gb\], real usage: \[3985754120/3.7gb\],…

---

## [How to create elastic Agent Policy and Toekns using Curl](https://discuss.elastic.co/t/how-to-create-elastic-agent-policy-and-toekns-using-curl/335482)

<div class="topic-metadata">

**Author:** [@kos](https://discuss.elastic.co/u/kos)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 10:16pm UTC](https://discuss.elastic.co/t/how-to-create-elastic-agent-policy-and-toekns-using-curl/335482 "2023-06-07T22:16:34Z")

</div>

Trying to setup automatic sandbox environment that requires destroy and rebuild quiet often. Every time building the sandbox using the docker compose had to manually login to the GUI and add fleet host, create fleet pol…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=516)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=518)
