# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=525

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 526

---

## [Root mapping definition has unsupported parameters](https://discuss.elastic.co/t/root-mapping-definition-has-unsupported-parameters/334931)

<div class="topic-metadata">

**Author:** [@pirogan](https://discuss.elastic.co/u/pirogan)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 9:02am UTC](https://discuss.elastic.co/t/root-mapping-definition-has-unsupported-parameters/334931 "2023-06-01T09:02:19Z")

</div>

cant create an easiest mapping from a doc mapping = { "mappings": { "properties": { "age": { "type": "integer" }, "email": { "type": "keyword" }, "name": { "type": "text" } } } } …

---

## [Creating Dashboard for apache access logs using Filebeat](https://discuss.elastic.co/t/creating-dashboard-for-apache-access-logs-using-filebeat/333159)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 73\
**Last updated:** [June 1, 2023, 8:48am UTC](https://discuss.elastic.co/t/creating-dashboard-for-apache-access-logs-using-filebeat/333159 "2023-06-01T08:48:05Z")

</div>

Hey I want to create Dashboard using filebeat for apache access logs. I have complete 11 nodes on staging out of which 7 nodes are of elasticsearch(3 master nodes, 2 coordination nodes, 2 data nodes), and other 3 nodes a…

---

## [Reverse nested problem](https://discuss.elastic.co/t/reverse-nested-problem/334783)

<div class="topic-metadata">

**Author:** [@Kenan\_Seyidov](https://discuss.elastic.co/u/Kenan_Seyidov)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 8:46am UTC](https://discuss.elastic.co/t/reverse-nested-problem/334783 "2023-06-01T08:46:05Z")

</div>

In Elasticsearch we use a nested query, when we use the reverse nesting it does not remember the previous aggregation, it only returns the topmost eligible documents. For example : In the following query, rate\_option, s…

---

## [Filebeat netflow template missing](https://discuss.elastic.co/t/filebeat-netflow-template-missing/334925)

<div class="topic-metadata">

**Author:** [@Sandeepa\_Kariyawasam](https://discuss.elastic.co/u/Sandeepa_Kariyawasam)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 8:40am UTC](https://discuss.elastic.co/t/filebeat-netflow-template-missing/334925 "2023-06-01T08:40:19Z")

</div>

I have configured filebeat netflow.yml to receive netflow data my filebeat.yml input filebeat.inputs: # filestream is an input for collecting log messages from files. - type: filestream # Unique ID among all inputs…

---

## [Throws ssl context error while trying to initialize RestHighLevelClient](https://discuss.elastic.co/t/throws-ssl-context-error-while-trying-to-initialize-resthighlevelclient/334796)

<div class="topic-metadata">

**Author:** [@Developer1318](https://discuss.elastic.co/u/Developer1318)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 8:17am UTC](https://discuss.elastic.co/t/throws-ssl-context-error-while-trying-to-initialize-resthighlevelclient/334796 "2023-06-01T08:17:53Z")

</div>

java.lang.IllegalStateException: could not create the default ssl context at org.elasticsearch.client.RestClientBuilder.createHttpClient(RestClientBuilder.java:222) at org.elasticsearch.client.RestClientBuilder.access$…

---

## [java.net.UnknownHostException/Name or service not known/failed to resolve host](https://discuss.elastic.co/t/java-net-unknownhostexception-name-or-service-not-known-failed-to-resolve-host/334920)

<div class="topic-metadata">

**Author:** [@Sundeep\_Teja\_Polina](https://discuss.elastic.co/u/Sundeep_Teja_Polina)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 7:59am UTC](https://discuss.elastic.co/t/java-net-unknownhostexception-name-or-service-not-known-failed-to-resolve-host/334920 "2023-06-01T07:59:11Z")

</div>

Hi I'm trying to deploy a self-managed containerized multinode Elasticsearch cluster in aws ecs. I was able to deploy and use a single node Elasticsearch cluster inside aws ecs. When I'm trying to host the same in multi…

---

## [Enterprise Search running on a docker container can't connect to Elasticsearch running as a service on windows](https://discuss.elastic.co/t/enterprise-search-running-on-a-docker-container-cant-connect-to-elasticsearch-running-as-a-service-on-windows/334761)

<div class="topic-metadata">

**Author:** [@Mtuni\_Globbal](https://discuss.elastic.co/u/Mtuni_Globbal)\
**Replies:** 6\
**Last updated:** [June 1, 2023, 7:31am UTC](https://discuss.elastic.co/t/enterprise-search-running-on-a-docker-container-cant-connect-to-elasticsearch-running-as-a-service-on-windows/334761 "2023-06-01T07:31:23Z")

</div>

Hi, I'm trying to connect Enterprise Search which I run as a docker container to connect to Elasticsearch and Kibana which are running as Windows service. However, every time I run Enterprise Search it exits, saying that…

---

## [Filebeat process different log paths and write data to seperate index,Without use of logstash and follow ILM/rollover alias defined in template](https://discuss.elastic.co/t/filebeat-process-different-log-paths-and-write-data-to-seperate-index-without-use-of-logstash-and-follow-ilm-rollover-alias-defined-in-template/332593)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 17\
**Last updated:** [June 1, 2023, 7:12am UTC](https://discuss.elastic.co/t/filebeat-process-different-log-paths-and-write-data-to-seperate-index-without-use-of-logstash-and-follow-ilm-rollover-alias-defined-in-template/332593 "2023-06-01T07:12:46Z")

</div>

Hello All, I've a requirement where I will be having diffrent log path defined in server and Filebeat will read this paths and should write the data to there respective elastic index. The ILM policy and required rollo…

---

## [Issue with multiple pipelines of Logstash](https://discuss.elastic.co/t/issue-with-multiple-pipelines-of-logstash/334908)

<div class="topic-metadata">

**Author:** [@Wang\_Yin](https://discuss.elastic.co/u/Wang_Yin)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 6:58am UTC](https://discuss.elastic.co/t/issue-with-multiple-pipelines-of-logstash/334908 "2023-06-01T06:58:04Z")

</div>

I'm using Logstash version 8.8.0. I have two Logstash conf files under /etc/logstash/conf.d folder, one is called "syslog\_cisco.conf", another one is called "test.conf" as below: syslog\_cisco.conf input { udp { …

---

## [Sharing link to dashboard with maximized panel](https://discuss.elastic.co/t/sharing-link-to-dashboard-with-maximized-panel/330221)

<div class="topic-metadata">

**Author:** [@tomhe](https://discuss.elastic.co/u/tomhe)\
**Replies:** 4\
**Last updated:** [June 1, 2023, 6:50am UTC](https://discuss.elastic.co/t/sharing-link-to-dashboard-with-maximized-panel/330221 "2023-06-01T06:50:21Z")

</div>

In Kibana 7.17 and older, our users were able to maximize a single panel (on a multi-panel dashboard), Share -\> Permalinks -\> Snapshot -\> Copy link, and then use the copied link in a browser and see the dashboard with …

---

## [Shards allocation method](https://discuss.elastic.co/t/shards-allocation-method/334900)

<div class="topic-metadata">

**Author:** [@saifulshihab](https://discuss.elastic.co/u/saifulshihab)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 6:43am UTC](https://discuss.elastic.co/t/shards-allocation-method/334900 "2023-06-01T06:43:27Z")

</div>

Hello how shards are allocated in cluster nodes? for the below scenario could anyone explain ? for 3node cluster 3primary shards and 2 replica shards configured. i have to configure my nodes with same storage ? how …

---

## [Query taking longer times than expected, possible ways of optimization at query level](https://discuss.elastic.co/t/query-taking-longer-times-than-expected-possible-ways-of-optimization-at-query-level/334221)

<div class="topic-metadata">

**Author:** [@nadeem.akhter](https://discuss.elastic.co/u/nadeem.akhter)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 4:14am UTC](https://discuss.elastic.co/t/query-taking-longer-times-than-expected-possible-ways-of-optimization-at-query-level/334221 "2023-06-01T04:14:47Z")

</div>

I have an Elasticsearch 8.6.0 instance with some data in it. I have been querying data off it using query string with 130 keywords in the following format: { "query": { "bool": { "should": \[ …

---

## [Error Attempted to send a bulk request but Elasticsearch appears to be unreachable or down by Lgostash](https://discuss.elastic.co/t/error-attempted-to-send-a-bulk-request-but-elasticsearch-appears-to-be-unreachable-or-down-by-lgostash/334894)

<div class="topic-metadata">

**Author:** [@Hoang\_Vu](https://discuss.elastic.co/u/Hoang_Vu)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 4:03am UTC](https://discuss.elastic.co/t/error-attempted-to-send-a-bulk-request-but-elasticsearch-appears-to-be-unreachable-or-down-by-lgostash/334894 "2023-06-01T04:03:04Z")

</div>

I am getting an error like below: System status is Logstash receiving logs and pushing logs to Haproxy then Haproxy Forward back to Elasticsearch the system is running Docker Swarm except Logstash is running building.I …

---

## [Ds-ilm-history index](https://discuss.elastic.co/t/ds-ilm-history-index/334716)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 3:27am UTC](https://discuss.elastic.co/t/ds-ilm-history-index/334716 "2023-06-01T03:27:32Z")

</div>

Hi guys, We have ds-ilm-history index, likely created by ES ilm automatically at some point. We don't use ILM, is it safe to delete this index and disable ILM using API or it can trigger anything which we need to be aw…

---

## [plugins.encryptedSavedObjects\] Failed to decrypt "apiKey" attribute: Unsupported state or unable to authenticate data](https://discuss.elastic.co/t/plugins-encryptedsavedobjects-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/333402)

<div class="topic-metadata">

**Author:** [@vantrung](https://discuss.elastic.co/u/vantrung)\
**Replies:** 3\
**Last updated:** [June 1, 2023, 3:17am UTC](https://discuss.elastic.co/t/plugins-encryptedsavedobjects-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/333402 "2023-06-01T03:17:37Z")

</div>

Hi I installed kibana by ECK on EKS cluster

---

## [Log Forwarding Capabilities](https://discuss.elastic.co/t/log-forwarding-capabilities/334627)

<div class="topic-metadata">

**Author:** [@ddawil](https://discuss.elastic.co/u/ddawil)\
**Replies:** 4\
**Last updated:** [June 1, 2023, 2:20am UTC](https://discuss.elastic.co/t/log-forwarding-capabilities/334627 "2023-06-01T02:20:32Z")

</div>

Network devices logs, system logs and Cloud services logs are sent to Elastic for log storage. Logs are processed are stored JSON format. Does Elastic able to do forwarding of logs simultaneously to a SIEM with its orig…

---

## [Will the "collapse" clause work in Kibana's Alert type "Query DSL"](https://discuss.elastic.co/t/will-the-collapse-clause-work-in-kibanas-alert-type-query-dsl/334726)

<div class="topic-metadata">

**Author:** [@jayesh.patel](https://discuss.elastic.co/u/jayesh.patel)\
**Replies:** 0\
**Last updated:** [May 30, 2023, 9:53pm UTC](https://discuss.elastic.co/t/will-the-collapse-clause-work-in-kibanas-alert-type-query-dsl/334726 "2023-05-30T21:53:23Z")

</div>

Hi, In kibana 8.6, I am trying to create and Alert of type "Query DSL". In the DSL query, I wanted to pick the lastest document, which breached the filesystem used percentage great than 80% for each cloud.instance. Seems…

---

## [Issue with Inaccurate Traffic Statistics in Packetbeat](https://discuss.elastic.co/t/issue-with-inaccurate-traffic-statistics-in-packetbeat/334891)

<div class="topic-metadata">

**Author:** [@Yongb\_Xu](https://discuss.elastic.co/u/Yongb_Xu)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 1:57am UTC](https://discuss.elastic.co/t/issue-with-inaccurate-traffic-statistics-in-packetbeat/334891 "2023-06-01T01:57:53Z")

</div>

Hi everyone, I'm working on a project that requires the use of Elastic + Packetbeat for network traffic statistics. I have set up my environment with Elastic, Packetbeat, and Kibana all installed on a single virtual mac…

---

## [Kibana /api/reporting/generate/csv gets response 503](https://discuss.elastic.co/t/kibana-api-reporting-generate-csv-gets-response-503/334756)

<div class="topic-metadata">

**Author:** [@bivit](https://discuss.elastic.co/u/bivit)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 1:42am UTC](https://discuss.elastic.co/t/kibana-api-reporting-generate-csv-gets-response-503/334756 "2023-06-01T01:42:45Z")

</div>

Hi! We run Kibana 7.11 with docker compose and we tried the "Generate CSV" feature which gives us service unavailable error. The Docker compose file is: version: '3.5' services: kibana01: restart: always ima…

---

## [How to hide controls like Saved Filter Menu and Add Filter Menu, Options Menu when embedding Kibana IFrame URL in the web application](https://discuss.elastic.co/t/how-to-hide-controls-like-saved-filter-menu-and-add-filter-menu-options-menu-when-embedding-kibana-iframe-url-in-the-web-application/332640)

<div class="topic-metadata">

**Author:** [@ramanm](https://discuss.elastic.co/u/ramanm)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 12:22am UTC](https://discuss.elastic.co/t/how-to-hide-controls-like-saved-filter-menu-and-add-filter-menu-options-menu-when-embedding-kibana-iframe-url-in-the-web-application/332640 "2023-06-01T00:22:33Z")

</div>

We are embedding kibana iframe url in our web application. We wanted to hide controls like Saved Filter Menu Add Filter Menu Options Menu Some of the above filters exposes the index names under Data View that are ava…

---

## [Elasticsearch connection](https://discuss.elastic.co/t/elasticsearch-connection/333621)

<div class="topic-metadata">

**Author:** [@rodrigo\_Ceron](https://discuss.elastic.co/u/rodrigo_Ceron)\
**Replies:** 4\
**Last updated:** [June 1, 2023, 12:18am UTC](https://discuss.elastic.co/t/elasticsearch-connection/333621 "2023-06-01T00:18:24Z")

</div>

Hello everyone, I'm developing a custom plugin and I would like to connect to Elasticsearch side client, but the link I'm using (Elasticsearch service | Kibana Guide \[8.7\] | Elastic) is not working and the documentation…

---

## [Event.start value minus Event.start last value code](https://discuss.elastic.co/t/event-start-value-minus-event-start-last-value-code/333374)

<div class="topic-metadata">

**Author:** [@patterno](https://discuss.elastic.co/u/patterno)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 11:44pm UTC](https://discuss.elastic.co/t/event-start-value-minus-event-start-last-value-code/333374 "2023-05-31T23:44:31Z")

</div>

Good day! I am new to elastic and I'm wondering if any other users can help me with my problem. I am having a trouble computing the event.start and event.start (last value) of a certain process on my logs. I am planning…

---

## [@timestamp in .watcher.history-\*](https://discuss.elastic.co/t/timestamp-in-watcher-history/333322)

<div class="topic-metadata">

**Author:** [@rorii](https://discuss.elastic.co/u/rorii)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 11:38pm UTC](https://discuss.elastic.co/t/timestamp-in-watcher-history/333322 "2023-05-31T23:38:13Z")

</div>

I am trying to visualise alerts metrics in Kibana. Since the results.actions are stored in an array, I am trying to query the watcher history and with watcher index action to create my own index where I can aggregate the…

---

## [Kibana Dashboard Interaction on Community version](https://discuss.elastic.co/t/kibana-dashboard-interaction-on-community-version/333127)

<div class="topic-metadata">

**Author:** [@Msacs](https://discuss.elastic.co/u/Msacs)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 11:30pm UTC](https://discuss.elastic.co/t/kibana-dashboard-interaction-on-community-version/333127 "2023-05-31T23:30:56Z")

</div>

Folks, Is there a limitation in the community version on the interaction behavior. Currently I have placed 4 panels in a dashboard all relate data and when I click on a value on a panel it is supposed to apply filter an…

---

## [Storing a value before filterrows and accessing it after](https://discuss.elastic.co/t/storing-a-value-before-filterrows-and-accessing-it-after/333239)

<div class="topic-metadata">

**Author:** [@B\_Hart](https://discuss.elastic.co/u/B_Hart)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 11:28pm UTC](https://discuss.elastic.co/t/storing-a-value-before-filterrows-and-accessing-it-after/333239 "2023-05-31T23:28:31Z")

</div>

I have a situation where I want to filter rows out, but I want to save the number of pre-filtered rows into variable to use later in the variable expression editor (specifically to calculate a percentage value with the p…

---

## [Elastic Agent Integration for Cloudflare account scoped data sets](https://discuss.elastic.co/t/elastic-agent-integration-for-cloudflare-account-scoped-data-sets/334885)

<div class="topic-metadata">

**Author:** [@dflo16](https://discuss.elastic.co/u/dflo16)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 10:55pm UTC](https://discuss.elastic.co/t/elastic-agent-integration-for-cloudflare-account-scoped-data-sets/334885 "2023-05-31T22:55:32Z")

</div>

I am using cloud hosted elastic stack (8.7) and would like to ingest Cloudflare account scoped data sets. These are different data sets than the ones supported by the default Cloudflare integration. The account scoped da…

---

## [Kibana alert rules use today only time window](https://discuss.elastic.co/t/kibana-alert-rules-use-today-only-time-window/333184)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 10:52pm UTC](https://discuss.elastic.co/t/kibana-alert-rules-use-today-only-time-window/333184 "2023-05-31T22:52:01Z")

</div>

Hello, i would like to create a rule that uses only today time window (from 00:00 to 24:00), not the last one day. for example, the rule is triggered every 15 minutes. The first check will be at 00:15 and uses time windo…

---

## [Cluster.initial\_master\_nodes and discovery.seed\_hosts](https://discuss.elastic.co/t/cluster-initial-master-nodes-and-discovery-seed-hosts/334588)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 10:49pm UTC](https://discuss.elastic.co/t/cluster-initial-master-nodes-and-discovery-seed-hosts/334588 "2023-05-31T22:49:21Z")

</div>

Hi, I have elasticsearch cluster (8.7.0) on Kubernetes. In the configmaps of the nodes (master,data,client) I had: ... discovery.seed\_hosts: ${NODE\_LIST} cluster.initial\_master\_nodes: ${MASTER\_NODES} ... In my deploym…

---

## [How to link kibana with elastic search?](https://discuss.elastic.co/t/how-to-link-kibana-with-elastic-search/333183)

<div class="topic-metadata">

**Author:** [@satvika\_maram](https://discuss.elastic.co/u/satvika_maram)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 10:32pm UTC](https://discuss.elastic.co/t/how-to-link-kibana-with-elastic-search/333183 "2023-05-31T22:32:37Z")

</div>

I have a company server and I am using CentOS. With a lot of hardwork, I installed it into my server . Can someone help me out here??

---

## [How can I display current data and time in kibana canvas？](https://discuss.elastic.co/t/how-can-i-display-current-data-and-time-in-kibana-canvas/333011)

<div class="topic-metadata">

**Author:** [@1455929251](https://discuss.elastic.co/u/1455929251)\
**Replies:** 4\
**Last updated:** [May 31, 2023, 10:26pm UTC](https://discuss.elastic.co/t/how-can-i-display-current-data-and-time-in-kibana-canvas/333011 "2023-05-31T22:26:49Z")

</div>

I want to add a shape element and show current data and time on it, like "2023-05-10 10:06:23" which can automatically refresh. But I can not find some function or system variables can query current time.

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=524)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=526)
