# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=522

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 523

---

## [I am getting CDC data from Transaction tables from MYSQL DB to Elastic search , How Can I see latest status of transactions?](https://discuss.elastic.co/t/i-am-getting-cdc-data-from-transaction-tables-from-mysql-db-to-elastic-search-how-can-i-see-latest-status-of-transactions/334902)

<div class="topic-metadata">

**Author:** [@nitinkapoor](https://discuss.elastic.co/u/nitinkapoor)\
**Replies:** 4\
**Last updated:** [June 5, 2023, 8:01am UTC](https://discuss.elastic.co/t/i-am-getting-cdc-data-from-transaction-tables-from-mysql-db-to-elastic-search-how-can-i-see-latest-status-of-transactions/334902 "2023-06-05T08:01:20Z")

</div>

I am getting CDC data from Transaction tables from MYSQL DB to Elastic search , How Can I see latest status of transactions ? Should I use Transforms ?

---

## [SSL/TLS connection between ELK-Stack with Docker](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040)

<div class="topic-metadata">

**Author:** [@Lokutus25](https://discuss.elastic.co/u/Lokutus25)\
**Replies:** 5\
**Last updated:** [June 5, 2023, 8:01am UTC](https://discuss.elastic.co/t/ssl-tls-connection-between-elk-stack-with-docker/331040 "2023-06-05T08:01:08Z")

</div>

Hi, I have a big problem with my ELK-Stack (version 8.7.0) created with docker. I have created elasticsearch, kibana, logstash and filebeat with docker-compose. elasticsearch and kibana connects per ssl with the token…

---

## [Is context.hits supported on 8.1](https://discuss.elastic.co/t/is-context-hits-supported-on-8-1/334105)

<div class="topic-metadata">

**Author:** [@nitisha](https://discuss.elastic.co/u/nitisha)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 10:39am UTC](https://discuss.elastic.co/t/is-context-hits-supported-on-8-1/334105 "2023-05-23T10:39:20Z")

</div>

Hi Team, Is context.hits supported on kibana version 8.1? I am using "Rules and Connectors" type as "Inventory" to monitor CPU metric threshold. With the default action rule {{alertName}} - {{context.group}} is in a st…

---

## [Grok on logstash not working](https://discuss.elastic.co/t/grok-on-logstash-not-working/334172)

<div class="topic-metadata">

**Author:** [@nitisha](https://discuss.elastic.co/u/nitisha)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 6:17am UTC](https://discuss.elastic.co/t/grok-on-logstash-not-working/334172 "2023-05-24T06:17:13Z")

</div>

Hi, I am monitoring CPU metric threshold of containers in our infra using elasticsearch using Connector as "Server Log" which defaults to kibana.log. I have created the following logstash configuration file to intercep…

---

## [How to use custom field as control filter with values](https://discuss.elastic.co/t/how-to-use-custom-field-as-control-filter-with-values/334077)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 5:00am UTC](https://discuss.elastic.co/t/how-to-use-custom-field-as-control-filter-with-values/334077 "2023-06-05T05:00:20Z")

</div>

Hi, We have created a custom field and we want to use this field as a control filter but not fill the values under the Control filter, please see the attached snap for your reference.

---

## [Elasticsearch killed by oom-killer](https://discuss.elastic.co/t/elasticsearch-killed-by-oom-killer/334982)

<div class="topic-metadata">

**Author:** [@Andy\_Ni](https://discuss.elastic.co/u/Andy_Ni)\
**Replies:** 5\
**Last updated:** [June 5, 2023, 3:27am UTC](https://discuss.elastic.co/t/elasticsearch-killed-by-oom-killer/334982 "2023-06-05T03:27:33Z")

</div>

Elasticsearch version: 6.2.3 System: \[root@my-host-name\]# uname -s -r -v -m -p -i -o Linux 5.4.8-1.el7.elrepo.x86\_64 #1 SMP Sat Jan 4 15:29:03 EST 2020 x86\_64 x86\_64 x86\_64 GNU/Linux ErrorMessage in /var/log/message: …

---

## [Not able to create index patterns as kibana is not getting the indices](https://discuss.elastic.co/t/not-able-to-create-index-patterns-as-kibana-is-not-getting-the-indices/334565)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 15\
**Last updated:** [June 5, 2023, 1:23am UTC](https://discuss.elastic.co/t/not-able-to-create-index-patterns-as-kibana-is-not-getting-the-indices/334565 "2023-06-05T01:23:30Z")

</div>

\-I am getting indices for most of services, but unable to get indices for few services. So I am unable to create index patterns. We are getting logs in servers but unable to see logs in Kibana dashboard. \_Filebeat is up…

---

## [how geo\_distance query works under the hood in Elasticsearch?](https://discuss.elastic.co/t/how-geo-distance-query-works-under-the-hood-in-elasticsearch/335154)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 1\
**Last updated:** [June 4, 2023, 8:38pm UTC](https://discuss.elastic.co/t/how-geo-distance-query-works-under-the-hood-in-elasticsearch/335154 "2023-06-04T20:38:32Z")

</div>

I need to use geo\_distance query on Elasticsearch. Need info about how it works under the hood and what is latency? I am not able to find any doc relevant to this. please help

---

## [Unable to restart the nginx service](https://discuss.elastic.co/t/unable-to-restart-the-nginx-service/335170)

<div class="topic-metadata">

**Author:** [@surajhekare](https://discuss.elastic.co/u/surajhekare)\
**Replies:** 1\
**Last updated:** [June 4, 2023, 7:48pm UTC](https://discuss.elastic.co/t/unable-to-restart-the-nginx-service/335170 "2023-06-04T19:48:02Z")

</div>

ubuntu@ip-172-31-37-106:~$ sudo service nginx restart Job for nginx.service failed because the control process exited with error code. See "systemctl status nginx.service" and "journalctl -xe" for details. systemctl s…

---

## [Error when attempting to create component template using the ECS generator](https://discuss.elastic.co/t/error-when-attempting-to-create-component-template-using-the-ecs-generator/335004)

<div class="topic-metadata">

**Author:** [@bvoros](https://discuss.elastic.co/u/bvoros)\
**Replies:** 1\
**Last updated:** [June 4, 2023, 6:40pm UTC](https://discuss.elastic.co/t/error-when-attempting-to-create-component-template-using-the-ecs-generator/335004 "2023-06-04T18:40:56Z")

</div>

Hello all, I am using the ECS mapping template generator to create the relevant components so we can start using the ECS fields. I cloned GitHub - elastic/ecs: Elastic Common Schema and generated essentially the default…

---

## [Elastisearch doesn't create .security index after loss of data](https://discuss.elastic.co/t/elastisearch-doesnt-create-security-index-after-loss-of-data/335123)

<div class="topic-metadata">

**Author:** [@Savva\_Morozov](https://discuss.elastic.co/u/Savva_Morozov)\
**Replies:** 4\
**Last updated:** [June 4, 2023, 2:30pm UTC](https://discuss.elastic.co/t/elastisearch-doesnt-create-security-index-after-loss-of-data/335123 "2023-06-04T14:30:40Z")

</div>

Hello! We are using Elasticsearch and Kibana on Kubernetes deployed via Helm charts and recently we occasionaly deleted all the data from persistent volumes that our two nodes Elasticsearch cluster uses. Since then we ca…

---

## [Configure es with logstash](https://discuss.elastic.co/t/configure-es-with-logstash/334604)

<div class="topic-metadata">

**Author:** [@sujata\_g](https://discuss.elastic.co/u/sujata_g)\
**Replies:** 6\
**Last updated:** [June 4, 2023, 10:25am UTC](https://discuss.elastic.co/t/configure-es-with-logstash/334604 "2023-06-04T10:25:52Z")

</div>

input { s3 { access\_key\_id =\> "" secret\_access\_key =\> "" bucket =\> "dumpsampleperigon" region =\> "us-west-1" } } output { elasticsearch { hosts =\> \["http://elasticsearch:9200"\] index =\> "logs-%{+YYYY.MM.dd}" …

---

## [Elastic Cluster Architecture Best Practices](https://discuss.elastic.co/t/elastic-cluster-architecture-best-practices/335138)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 5\
**Last updated:** [June 4, 2023, 4:57am UTC](https://discuss.elastic.co/t/elastic-cluster-architecture-best-practices/335138 "2023-06-04T04:57:20Z")

</div>

Hi all, I have an upcoming project to set up a small cluster and thought would use the community help to validate the design scenario that I have in mind. A little background about available resources for that project: …

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/335146)

<div class="topic-metadata">

**Author:** [@surajhekare](https://discuss.elastic.co/u/surajhekare)\
**Replies:** 2\
**Last updated:** [June 4, 2023, 4:36am UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/335146 "2023-06-04T04:36:10Z")

</div>

ubuntu@ip-172-31-37-106:~$ systemctl status elasticsearch.service ● elasticsearch.service - Elasticsearch Loaded: loaded (/lib/systemd/system/elasticsearch.service; disabled; vendor preset: enabled) Active: failed (Re…

---

## [Index Life cycle settings disturbed after setting \_index\_template](https://discuss.elastic.co/t/index-life-cycle-settings-disturbed-after-setting-index-template/335141)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 0\
**Last updated:** [June 3, 2023, 8:09pm UTC](https://discuss.elastic.co/t/index-life-cycle-settings-disturbed-after-setting-index-template/335141 "2023-06-03T20:09:17Z")

</div>

Hello, I had a template named "30days\_cleanup\_template" set for a particular index which was part of the ILM policy named "cleanup-history". Template was set as follows: PUT \_template/30days\_cleanup\_template { "inde…

---

## [Logstash giving error which is not clear](https://discuss.elastic.co/t/logstash-giving-error-which-is-not-clear/335126)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 7\
**Last updated:** [June 3, 2023, 7:06pm UTC](https://discuss.elastic.co/t/logstash-giving-error-which-is-not-clear/335126 "2023-06-03T19:06:59Z")

</div>

I am getting the following error in logstash-plain.log: \[2023-06-03T01:33:34,256\]\[INFO \]\[logstash.runner \] Log4j configuration path used is: /etc/logstash/log4j2.properties \[2023-06-03T01:33:34,272\]\[INFO \]\[logs…

---

## [ELastic-CertUtil erro trying to create Certificate-authorities, .crt, .key](https://discuss.elastic.co/t/elastic-certutil-erro-trying-to-create-certificate-authorities-crt-key/334865)

<div class="topic-metadata">

**Author:** [@yash2](https://discuss.elastic.co/u/yash2)\
**Replies:** 5\
**Last updated:** [June 3, 2023, 6:43pm UTC](https://discuss.elastic.co/t/elastic-certutil-erro-trying-to-create-certificate-authorities-crt-key/334865 "2023-06-03T18:43:19Z")

</div>

Hey guys, i am having issues with generating Ca, crt and key for my nodes specifically using any o the below file and this command : \\Users\\YashCyb\\Downloads\\elasticsearch-8.8.0-windows-x86\_64\\elasticsearch-8.8.0\\bin\>…

---

## [ElasticSearch TLS/SSL Certificate issues 1](https://discuss.elastic.co/t/elasticsearch-tls-ssl-certificate-issues-1/334898)

<div class="topic-metadata">

**Author:** [@yash2](https://discuss.elastic.co/u/yash2)\
**Replies:** 5\
**Last updated:** [June 3, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elasticsearch-tls-ssl-certificate-issues-1/334898 "2023-06-03T18:29:55Z")

</div>

Hey everyone, a very quick question, i have tried to modify my elasticsearch so it may resemble and work with my generated openssl Certificate.crt + private.key. ┌──(root㉿kali)-\[/etc\] └─# openssl req -x509 -nodes -days …

---

## [Synonyms and semantic search](https://discuss.elastic.co/t/synonyms-and-semantic-search/334880)

<div class="topic-metadata">

**Author:** [@Rahul\_Agarwal1](https://discuss.elastic.co/u/Rahul_Agarwal1)\
**Replies:** 2\
**Last updated:** [June 3, 2023, 5:37pm UTC](https://discuss.elastic.co/t/synonyms-and-semantic-search/334880 "2023-06-03T17:37:02Z")

</div>

Need your help with one more thing. What is the best way to support synonyms (we have our own custom list) with semantic search?? Couldn't find anything related to this in the documentation.

---

## [Highlighting and text\_expansion query](https://discuss.elastic.co/t/highlighting-and-text-expansion-query/334679)

<div class="topic-metadata">

**Author:** [@Mark\_Harwood1](https://discuss.elastic.co/u/Mark_Harwood1)\
**Replies:** 2\
**Last updated:** [June 3, 2023, 2:04pm UTC](https://discuss.elastic.co/t/highlighting-and-text-expansion-query/334679 "2023-06-03T14:04:54Z")

</div>

Playing with the new ELSER model and the text\_expansion query in 8.8 which looks to be matching OK. Now I want end users to understand why documents matched but can't get highlighting to work. Does it? I've tried settin…

---

## [Grouping And Ordering Log is Posible?](https://discuss.elastic.co/t/grouping-and-ordering-log-is-posible/335017)

<div class="topic-metadata">

**Author:** [@aidensV](https://discuss.elastic.co/u/aidensV)\
**Replies:** 2\
**Last updated:** [June 3, 2023, 1:11pm UTC](https://discuss.elastic.co/t/grouping-and-ordering-log-is-posible/335017 "2023-06-03T13:11:30Z")

</div>

I have Log with example : (Case 1) CHAN1 : 23:57:05:89 |Message Start CHAN1 : 23:57:05:89 |Lorem CHAN1 : 23:57:05:89 |Ipsum CHAN1 : 23:57:05:89 |Dolor CHAN99i : 23:57:05:89 |Message Start CHAN99i : 23:57:05:89 |Lo…

---

## [ No config files found in path {:path=\>"/etc/logstash/conf.d/\*.conf"}](https://discuss.elastic.co/t/no-config-files-found-in-path-path-etc-logstash-conf-d-conf/335106)

<div class="topic-metadata">

**Author:** [@karma\_services](https://discuss.elastic.co/u/karma_services)\
**Replies:** 1\
**Last updated:** [June 3, 2023, 5:28am UTC](https://discuss.elastic.co/t/no-config-files-found-in-path-path-etc-logstash-conf-d-conf/335106 "2023-06-03T05:28:55Z")

</div>

I have installed ELK stack via debian package on Ubuntu Server. I want to send pfsense logs to logstash. File Settings: 1- /etc/logstash/conf.d/syslog.conf input { tcp { port =\> 514 type =\> "pfsense" } udp { …

---

## [I have two Elastic cloud indices on the same cluster both have one common field Transactionid , Can I join both indices to get combined results](https://discuss.elastic.co/t/i-have-two-elastic-cloud-indices-on-the-same-cluster-both-have-one-common-field-transactionid-can-i-join-both-indices-to-get-combined-results/334915)

<div class="topic-metadata">

**Author:** [@nitinkapoor](https://discuss.elastic.co/u/nitinkapoor)\
**Replies:** 3\
**Last updated:** [June 3, 2023, 2:50am UTC](https://discuss.elastic.co/t/i-have-two-elastic-cloud-indices-on-the-same-cluster-both-have-one-common-field-transactionid-can-i-join-both-indices-to-get-combined-results/334915 "2023-06-03T02:50:38Z")

</div>

I have two Elastic cloud indices on the same cluster both have one common field Transactionid , Can I join both indices to get combined results

---

## [ILM frozen data on amazon Glacier?](https://discuss.elastic.co/t/ilm-frozen-data-on-amazon-glacier/335125)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 1\
**Last updated:** [June 3, 2023, 2:48am UTC](https://discuss.elastic.co/t/ilm-frozen-data-on-amazon-glacier/335125 "2023-06-03T02:48:20Z")

</div>

We have frozen data in S3 bucket. We would like to use glacier instead of s3. Is it possible?

---

## [Visualization in timeline format](https://discuss.elastic.co/t/visualization-in-timeline-format/334448)

<div class="topic-metadata">

**Author:** [@Leandro\_Salamaia](https://discuss.elastic.co/u/Leandro_Salamaia)\
**Replies:** 2\
**Last updated:** [June 3, 2023, 1:35am UTC](https://discuss.elastic.co/t/visualization-in-timeline-format/334448 "2023-06-03T01:35:26Z")

</div>

I need to create a view in kibana that shows the time difference between a Status true message and a Status false message but I haven't found a way yet if anyone can give me some tips log example Device:S0101 Status:1…

---

## [Canva IMAGE moving](https://discuss.elastic.co/t/canva-image-moving/332339)

<div class="topic-metadata">

**Author:** [@ifalanrocha](https://discuss.elastic.co/u/ifalanrocha)\
**Replies:** 4\
**Last updated:** [June 2, 2023, 8:45pm UTC](https://discuss.elastic.co/t/canva-image-moving/332339 "2023-06-02T20:45:35Z")

</div>

Hello everyone, I hope you are well. I need to define margins on my elements inside the canvas, but when I use padding, only the canvasRenderE1 modifies, I would like to move the image. image dataurl={asset "asset-98f5…

---

## [LDAP/AD Configuration - w/o GOLD License](https://discuss.elastic.co/t/ldap-ad-configuration-w-o-gold-license/335116)

<div class="topic-metadata">

**Author:** [@mreed](https://discuss.elastic.co/u/mreed)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 6:40pm UTC](https://discuss.elastic.co/t/ldap-ad-configuration-w-o-gold-license/335116 "2023-06-02T18:40:15Z")

</div>

Hello all, My apologies if this is a long post. I'm looking for some advice around integrating LDAP (Active Directory) logins via Kibana using a basic license (unfortunately we can't afford to pay for the Gold license …

---

## [Unable to initialize Fleet on Kibana in Ubuntu 22.04](https://discuss.elastic.co/t/unable-to-initialize-fleet-on-kibana-in-ubuntu-22-04/334618)

<div class="topic-metadata">

**Author:** [@Calvy93](https://discuss.elastic.co/u/Calvy93)\
**Replies:** 5\
**Last updated:** [June 2, 2023, 4:36pm UTC](https://discuss.elastic.co/t/unable-to-initialize-fleet-on-kibana-in-ubuntu-22-04/334618 "2023-06-02T16:36:40Z")

</div>

I'm currently trying to set up a fleet in Kibana as this seems to be a prerequisite for using a suricata module, but I can't get past the error message "Unable to initialize Fleet - An internal server error occured. Chec…

---

## [Existing index and lifecycle policy](https://discuss.elastic.co/t/existing-index-and-lifecycle-policy/334666)

<div class="topic-metadata">

**Author:** [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Replies:** 2\
**Last updated:** [June 2, 2023, 3:23pm UTC](https://discuss.elastic.co/t/existing-index-and-lifecycle-policy/334666 "2023-06-02T15:23:49Z")

</div>

Hello, I need some help, I've seen many web pages how to configure it but none of them were helpfull. My existing index (daily index) is filebeat-exch-8.7.1-2023.05.30 I have created lifecycle policy 2-days whe…

---

## [Stack Monitoring Alerts Disk Usage, how to get the node name only?](https://discuss.elastic.co/t/stack-monitoring-alerts-disk-usage-how-to-get-the-node-name-only/335012)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 2\
**Last updated:** [June 2, 2023, 3:19pm UTC](https://discuss.elastic.co/t/stack-monitoring-alerts-disk-usage-how-to-get-the-node-name-only/335012 "2023-06-02T15:19:03Z")

</div>

Hello, I'm using the built-in Disk Usage rule in Kibana Alert on my monitoring cluster to alert me when a node reaches more than 94% of disk usage (I've changed my watermarks), this works fine, but now I need to send th…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=521)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=523)
