# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=541

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 542

---

## [Can Snapshots save index in a limited time](https://discuss.elastic.co/t/can-snapshots-save-index-in-a-limited-time/333553)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 4\
**Last updated:** [May 16, 2023, 12:04pm UTC](https://discuss.elastic.co/t/can-snapshots-save-index-in-a-limited-time/333553 "2023-05-16T12:04:17Z")

</div>

Hello everyone, I would like to know if it is possible to set up a snapshot policy that retrieves for example indexes only from the last 7 days. For example, I save my logs from my active directory with this format: in…

---

## [\[macOS 10.15.7\] Cannot execute filebeat, auditbeat, or metricbeat](https://discuss.elastic.co/t/macos-10-15-7-cannot-execute-filebeat-auditbeat-or-metricbeat/333471)

<div class="topic-metadata">

**Author:** [@Coolgum15](https://discuss.elastic.co/u/Coolgum15)\
**Replies:** 2\
**Last updated:** [May 16, 2023, 11:32am UTC](https://discuss.elastic.co/t/macos-10-15-7-cannot-execute-filebeat-auditbeat-or-metricbeat/333471 "2023-05-16T11:32:05Z")

</div>

Cannot run any of these beats. Same error for all of them (below). Using default configuration, except outputting to logstash server. The logstash server is functional, and my Linux beats are outputting to it just fine. …

---

## [Elastic search usermanagement with out using tls](https://discuss.elastic.co/t/elastic-search-usermanagement-with-out-using-tls/333550)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 9:36am UTC](https://discuss.elastic.co/t/elastic-search-usermanagement-with-out-using-tls/333550 "2023-05-16T09:36:25Z")

</div>

Hi Team, Currently i'm deploying elasticsearch 7.14 version , added usermangement with tls certs , its deploying but while accesing elasticsearch its not asking credentials , But i have added secrets for namespace. \< …

---

## [Aggregations: How to get number of combinations](https://discuss.elastic.co/t/aggregations-how-to-get-number-of-combinations/333560)

<div class="topic-metadata">

**Author:** [@es\_make](https://discuss.elastic.co/u/es_make)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 11:24am UTC](https://discuss.elastic.co/t/aggregations-how-to-get-number-of-combinations/333560 "2023-05-16T11:24:11Z")

</div>

Hello, Let's say we have a simple ES index having two fields: "name" (string) and "expired" (boolean) in one nested object "products" (array). Each product name can be mentioned only once in each document. Here's the e…

---

## [Java errors when running Logstash with database configuration](https://discuss.elastic.co/t/java-errors-when-running-logstash-with-database-configuration/333557)

<div class="topic-metadata">

**Author:** [@runnerpaul](https://discuss.elastic.co/u/runnerpaul)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 10:47am UTC](https://discuss.elastic.co/t/java-errors-when-running-logstash-with-database-configuration/333557 "2023-05-16T10:47:12Z")

</div>

I added the below jdbc config to my conf.d/logstash-simple.conf file. jdbc { add\_field =\> { "\[index\_name\]" =\> "pglogdb" } add\_field =\> { "\[@metadata\]\[beat\]" =\> "jdbc" } add\_field =\> { "\[@metadata\]\[version\]" …

---

## [Storage polygon is judged to be self-intersecting](https://discuss.elastic.co/t/storage-polygon-is-judged-to-be-self-intersecting/333555)

<div class="topic-metadata">

**Author:** [@baiwenbo1997](https://discuss.elastic.co/u/baiwenbo1997)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 10:45am UTC](https://discuss.elastic.co/t/storage-polygon-is-judged-to-be-self-intersecting/333555 "2023-05-16T10:45:27Z")

</div>

I want to know the tolerance or precision of self-intersecting graphics when storing. error: Polygon self-intersection at lat=22.773210573949637 lon=113.95022321162234 Here is my figure： \[0\] 113.950224078 22.77320374…

---

## [Logstash Mapping - Duplicate values in nested properties](https://discuss.elastic.co/t/logstash-mapping-duplicate-values-in-nested-properties/333554)

<div class="topic-metadata">

**Author:** [@kgazula](https://discuss.elastic.co/u/kgazula)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 10:05am UTC](https://discuss.elastic.co/t/logstash-mapping-duplicate-values-in-nested-properties/333554 "2023-05-16T10:05:58Z")

</div>

Hello, can someone please help with mapping when there are more than 1 nested type properties in the mapping? We are using the 8.0 version and using Logstash we are synching the data from our Database to the ES index. P…

---

## [Elasticsearch not showing correct count of documents in index](https://discuss.elastic.co/t/elasticsearch-not-showing-correct-count-of-documents-in-index/330986)

<div class="topic-metadata">

**Author:** [@Taby](https://discuss.elastic.co/u/Taby)\
**Replies:** 9\
**Last updated:** [May 16, 2023, 10:08am UTC](https://discuss.elastic.co/t/elasticsearch-not-showing-correct-count-of-documents-in-index/330986 "2023-05-16T10:08:28Z")

</div>

Hi. Our Java 8 based application is sending an input data of total 17061816 documents to elasticsearch 7.17.4 to index these documents. However, after all indexing is completed, the curl \_count is showing a total of 168…

---

## [About using a two node cluster for data loss prevention](https://discuss.elastic.co/t/about-using-a-two-node-cluster-for-data-loss-prevention/333509)

<div class="topic-metadata">

**Author:** [@usaadi](https://discuss.elastic.co/u/usaadi)\
**Replies:** 4\
**Last updated:** [May 16, 2023, 10:01am UTC](https://discuss.elastic.co/t/about-using-a-two-node-cluster-for-data-loss-prevention/333509 "2023-05-16T10:01:06Z")

</div>

Hello... I have a question about whether a two nodes cluster can be a sufficient setup in avoiding data loss in the event of the complete failure of one node. In other words, for a two nodes cluster, can it be set up s…

---

## [Filebeat CPU and RAM utilization are all over the place](https://discuss.elastic.co/t/filebeat-cpu-and-ram-utilization-are-all-over-the-place/333430)

<div class="topic-metadata">

**Author:** [@Elay17](https://discuss.elastic.co/u/Elay17)\
**Replies:** 2\
**Last updated:** [May 16, 2023, 10:00am UTC](https://discuss.elastic.co/t/filebeat-cpu-and-ram-utilization-are-all-over-the-place/333430 "2023-05-16T10:00:14Z")

</div>

I am currently running ECK 8.6.1 on a bare metal cluster, but I'm experiencing some issues with Filebeats. Depending on the configuration, it either leaks RAM or utilizes an excessive amount of CPU. Here is the configura…

---

## [Pause a node of the cluster](https://discuss.elastic.co/t/pause-a-node-of-the-cluster/330964)

<div class="topic-metadata">

**Author:** [@Blacktek](https://discuss.elastic.co/u/Blacktek)\
**Replies:** 6\
**Last updated:** [May 16, 2023, 9:34am UTC](https://discuss.elastic.co/t/pause-a-node-of-the-cluster/330964 "2023-05-16T09:34:15Z")

</div>

Hello, we've a three nodes cluster, and every once in a while we need to restart services or nodes to perform updates. We'd like to perform such activity in a graceful manner, waiting that current in-flight requests co…

---

## [I can't authenticate using 'elastic' , 'kibana\_system' in ELK version 8.5](https://discuss.elastic.co/t/i-cant-authenticate-using-elastic-kibana-system-in-elk-version-8-5/333455)

<div class="topic-metadata">

**Author:** [@linux\_admin](https://discuss.elastic.co/u/linux_admin)\
**Replies:** 3\
**Last updated:** [May 16, 2023, 9:02am UTC](https://discuss.elastic.co/t/i-cant-authenticate-using-elastic-kibana-system-in-elk-version-8-5/333455 "2023-05-16T09:02:30Z")

</div>

I am using ELK cluster consists of three nodes. I can't access Kibana using its URL https://kibana\_IP:5601. When I checked the logs of /var/log/elasticsearch/elasticsearch.log I found these errors: Authentication of \[e…

---

## [Issues starting elastic search](https://discuss.elastic.co/t/issues-starting-elastic-search/333496)

<div class="topic-metadata">

**Author:** [@tanchev](https://discuss.elastic.co/u/tanchev)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 8:59am UTC](https://discuss.elastic.co/t/issues-starting-elastic-search/333496 "2023-05-16T08:59:29Z")

</div>

I'm currently attempting to install and run Elasticsearch on CloudLinux, but I'm encountering some difficulties. The main issue is the absence of a .log file in the directory: /var/log/elasticsearch Despite the log pat…

---

## [Installed elasticsearch and Kibana on my GCP Red Hat Linux 9 but its not working](https://discuss.elastic.co/t/installed-elasticsearch-and-kibana-on-my-gcp-red-hat-linux-9-but-its-not-working/333240)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 3\
**Last updated:** [May 16, 2023, 7:15am UTC](https://discuss.elastic.co/t/installed-elasticsearch-and-kibana-on-my-gcp-red-hat-linux-9-but-its-not-working/333240 "2023-05-16T07:15:06Z")

</div>

I installed elastic and kibana v.7.17.9 using rpm and was able to start the service with no issues. I don't see any errors in logs but when I try to access http://localhost:5601, it doesn't work and I get can't connect t…

---

## [Logstash errors](https://discuss.elastic.co/t/logstash-errors/333531)

<div class="topic-metadata">

**Author:** [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 6:48am UTC](https://discuss.elastic.co/t/logstash-errors/333531 "2023-05-16T06:48:32Z")

</div>

In some moment after i try to restart logstash i start to get errors like this, so everithing stoped to work. \[2023-05-16T16:43:06,516\]\[ERROR\]\[logstash.javapipeline \]\[main\] Pipeline worker error, the pipeline will be…

---

## [How do I implement an alert for packet loss?](https://discuss.elastic.co/t/how-do-i-implement-an-alert-for-packet-loss/333425)

<div class="topic-metadata">

**Author:** [@Waruguru\_Joyce](https://discuss.elastic.co/u/Waruguru_Joyce)\
**Replies:** 2\
**Last updated:** [May 16, 2023, 5:27am UTC](https://discuss.elastic.co/t/how-do-i-implement-an-alert-for-packet-loss/333425 "2023-05-16T05:27:31Z")

</div>

I need to implement an alert for packet loss. I have a dashboard in place and the remaining bit is coming up with a rule for checking on packets loss in and out..... Any leads on how to go about it.

---

## [Error Failed to start crawler: starting input failed: error while initializing input: you must choose between TCP or UDP](https://discuss.elastic.co/t/error-failed-to-start-crawler-starting-input-failed-error-while-initializing-input-you-must-choose-between-tcp-or-udp/333014)

<div class="topic-metadata">

**Author:** [@Mauricio\_Martinez](https://discuss.elastic.co/u/Mauricio_Martinez)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 5:08am UTC](https://discuss.elastic.co/t/error-failed-to-start-crawler-starting-input-failed-error-while-initializing-input-you-must-choose-between-tcp-or-udp/333014 "2023-05-16T05:08:44Z")

</div>

related with the same solution of this post: Filebeat tcp and Udp error I have a questions, if i want to use as input a syslog from another server in that i can't installing something due impacts in the performance, but…

---

## [Error restoring state from URL rison decoder error: missing ':'](https://discuss.elastic.co/t/error-restoring-state-from-url-rison-decoder-error-missing/330053)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 10\
**Last updated:** [May 16, 2023, 5:06am UTC](https://discuss.elastic.co/t/error-restoring-state-from-url-rison-decoder-error-missing/330053 "2023-05-16T05:06:38Z")

</div>

Hi, since updated from 6.8.8 to 7.12.0, always get this message "Error restoring state from URL". I have used a scripted field as URL to link one dashboard to another. See below for the URL (sample.com). I've verified w…

---

## [Why my elk always report an error "{"statusCode":503,"error":"Service Unavailable","message":"License is not available."}"](https://discuss.elastic.co/t/why-my-elk-always-report-an-error-statuscode-503-error-service-unavailable-message-license-is-not-available/332780)

<div class="topic-metadata">

**Author:** [@maf\_77](https://discuss.elastic.co/u/maf_77)\
**Replies:** 6\
**Last updated:** [May 16, 2023, 4:59am UTC](https://discuss.elastic.co/t/why-my-elk-always-report-an-error-statuscode-503-error-service-unavailable-message-license-is-not-available/332780 "2023-05-16T04:59:39Z")

</div>

I made a ELK system,but there offen have a error,the kibana html report:{"statusCode":503,"error":"Service Unavailable","message":"License is not available."} I don't know how to find the reason,so i had restart the ser…

---

## [Custom label size issue in transaction metadata](https://discuss.elastic.co/t/custom-label-size-issue-in-transaction-metadata/333520)

<div class="topic-metadata">

**Author:** [@APandey](https://discuss.elastic.co/u/APandey)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 4:37am UTC](https://discuss.elastic.co/t/custom-label-size-issue-in-transaction-metadata/333520 "2023-05-16T04:37:25Z")

</div>

Hi team, We have modified the apm java agent code to add some metadata in transactions that is having dynamic length. One issue we are facing is that sometimes when the size of that metadata value is large let say more …

---

## [I am getting this error in fluentd pods , i have a efk setup in eks cluster , can someone help me with this please - error\_class=Fluent::Plugin::ElasticsearchErrorHandler::ElasticsearchError error="400 - Rejected by Elasticsearch" location=nil tag="ku](https://discuss.elastic.co/t/i-am-getting-this-error-in-fluentd-pods-i-have-a-efk-setup-in-eks-cluster-can-someone-help-me-with-this-please-error-class-fluent-elasticsearcherror-error-400-rejected-by-elasticsearch-location-nil-tag-ku/333040)

<div class="topic-metadata">

**Author:** [@jatinarora0](https://discuss.elastic.co/u/jatinarora0)\
**Replies:** 2\
**Last updated:** [May 16, 2023, 4:48am UTC](https://discuss.elastic.co/t/i-am-getting-this-error-in-fluentd-pods-i-have-a-efk-setup-in-eks-cluster-can-someone-help-me-with-this-please-error-class-fluent-elasticsearcherror-error-400-rejected-by-elasticsearch-location-nil-tag-ku/333040 "2023-05-16T04:48:24Z")

</div>

error\_class=Fluent::Plugin::ElasticsearchErrorHandler::ElasticsearchError error="400 - Rejected by Elasticsearch" location=nil tag="kubernetes.var.log.containers.fluentd

---

## [Help me to solve this Grok error](https://discuss.elastic.co/t/help-me-to-solve-this-grok-error/333385)

<div class="topic-metadata">

**Author:** [@aaronlbk](https://discuss.elastic.co/u/aaronlbk)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 3:22am UTC](https://discuss.elastic.co/t/help-me-to-solve-this-grok-error/333385 "2023-05-16T03:22:22Z")

</div>

Hello, I created a pipeline in kibana # Click the Variables button, above, to create your own variable PUT \_ingest/pipeline/exemple-pipeline-apache { "description": "Mon premier pipeline pour appliquer un grok patter…

---

## [Triggering E-mail Alert (Conditional)](https://discuss.elastic.co/t/triggering-e-mail-alert-conditional/333415)

<div class="topic-metadata">

**Author:** [@Bong\_Fabian](https://discuss.elastic.co/u/Bong_Fabian)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 7:57am UTC](https://discuss.elastic.co/t/triggering-e-mail-alert-conditional/333415 "2023-05-15T07:57:22Z")

</div>

Hi All, How canI come out with an e-mail alert that is based on condition? Using Rules and Connectors For e.g Alert trigger by single IP\* group by specific API\*\* within 24 hours if the activities is more than 10 Indi…

---

## [Filebeat - last update time of log file](https://discuss.elastic.co/t/filebeat-last-update-time-of-log-file/333511)

<div class="topic-metadata">

**Author:** [@dunowhat](https://discuss.elastic.co/u/dunowhat)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 1:11am UTC](https://discuss.elastic.co/t/filebeat-last-update-time-of-log-file/333511 "2023-05-16T01:11:05Z")

</div>

hi there, i am newbie to beats world. can i use filebeat to monitor a logfile updation and send an alert/event if the file is not updated like last 15 mins? if yes, please guide me on parameters

---

## [Using certificate chain in Elasticsearch](https://discuss.elastic.co/t/using-certificate-chain-in-elasticsearch/333422)

<div class="topic-metadata">

**Author:** [@akansha.agarwal1](https://discuss.elastic.co/u/akansha.agarwal1)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 8:08am UTC](https://discuss.elastic.co/t/using-certificate-chain-in-elasticsearch/333422 "2023-05-15T08:08:06Z")

</div>

Hi, I want to configure security in elasticsearch using company signed CA certificate. The CA certificate provided is a cert chain. Now, when i I am trying to create certificates for elastic nodes, it is throwing err…

---

## [Kibana service keeps failing after upgrade from 7.17 to 8.7](https://discuss.elastic.co/t/kibana-service-keeps-failing-after-upgrade-from-7-17-to-8-7/333099)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 2\
**Last updated:** [May 16, 2023, 12:17am UTC](https://discuss.elastic.co/t/kibana-service-keeps-failing-after-upgrade-from-7-17-to-8-7/333099 "2023-05-16T00:17:04Z")

</div>

Hi, I'm trying to upgrade my cluster from 7.17.7 to 8.7 and I'm testing the upgrade on a single node cluster. I treated all the errors found by the upgrade assistant and upgraded elasticsearch just fine and tried witho…

---

## [WinlogBeat stuck @ "Stopping" / Windows-Service](https://discuss.elastic.co/t/winlogbeat-stuck-stopping-windows-service/332879)

<div class="topic-metadata">

**Author:** [@florianmulatz](https://discuss.elastic.co/u/florianmulatz)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 11:38pm UTC](https://discuss.elastic.co/t/winlogbeat-stuck-stopping-windows-service/332879 "2023-05-15T23:38:44Z")

</div>

Good Morning guys - please don't blame me if this topic is already covered somewhere - at least I was not able to find it. I've the problem that my winlogbeat Service (as well as the manually spawned process) never stop…

---

## [Logstash and/or Kibana config wrong](https://discuss.elastic.co/t/logstash-and-or-kibana-config-wrong/333317)

<div class="topic-metadata">

**Author:** [@mariolanno](https://discuss.elastic.co/u/mariolanno)\
**Replies:** 3\
**Last updated:** [May 15, 2023, 9:50pm UTC](https://discuss.elastic.co/t/logstash-and-or-kibana-config-wrong/333317 "2023-05-15T21:50:26Z")

</div>

Hi, I cannot understand why I create two indexes on logstash to grab syslogs from two devices and then send to EL. input { udp { host =\> "192.168.0.73" port =\> "5515" } } filter {} output { ela…

---

## [Kibana bootstrap fails 8.7.1](https://discuss.elastic.co/t/kibana-bootstrap-fails-8-7-1/333480)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 8:55pm UTC](https://discuss.elastic.co/t/kibana-bootstrap-fails-8-7-1/333480 "2023-05-15T20:55:59Z")

</div>

Trying to build kibana 8.7.1 and I am getting this error I was not getting when I build 8.6.2 yarn kbn bootstrap yarn run v1.22.19 $ node scripts/kbn bootstrap \[bazel\] INFO: Invocation ID: ff0c547e-d7a4-489e-a5ac-693642…

---

## [Add built-in normalizer to existing indices](https://discuss.elastic.co/t/add-built-in-normalizer-to-existing-indices/333360)

<div class="topic-metadata">

**Author:** [@NishuGoel](https://discuss.elastic.co/u/NishuGoel)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 8:52pm UTC](https://discuss.elastic.co/t/add-built-in-normalizer-to-existing-indices/333360 "2023-05-15T20:52:09Z")

</div>

Hi there, I was going through the documentation where it says for some mapping parameters, we CAN update the existing index using PUT index/\_mapping. "normalizer" being one of those parameters - Update mapping API | El…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=540)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=542)
