# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=543

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 544

---

## [Fleet server is offline](https://discuss.elastic.co/t/fleet-server-is-offline/333419)

<div class="topic-metadata">

**Author:** [@samiujan](https://discuss.elastic.co/u/samiujan)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 8:04am UTC](https://discuss.elastic.co/t/fleet-server-is-offline/333419 "2023-05-15T08:04:19Z")

</div>

Hi I am trying to set up APM using Fleet on an on-prem EC2 instance After much back and forth, I got the agent installed and it's running on an unsecured endpoint I want to move it to a secure endpoint and have added …

---

## [Getting Could not find the data view error on kibana dashboard](https://discuss.elastic.co/t/getting-could-not-find-the-data-view-error-on-kibana-dashboard/332792)

<div class="topic-metadata">

**Author:** [@Sachchan](https://discuss.elastic.co/u/Sachchan)\
**Replies:** 26\
**Last updated:** [May 15, 2023, 7:59am UTC](https://discuss.elastic.co/t/getting-could-not-find-the-data-view-error-on-kibana-dashboard/332792 "2023-05-15T07:59:25Z")

</div>

Hi All, I am using kibana dashboards to visualize the data. but i am getting "Could not find the data view" error very frequently and when i refresh again, this error doesn't come. Please help in resolving this error. T…

---

## [While helm upgrade getting error elasticsearch 7.17.5](https://discuss.elastic.co/t/while-helm-upgrade-getting-error-elasticsearch-7-17-5/333417)

<div class="topic-metadata">

**Author:** [@shivaji\_laxmi](https://discuss.elastic.co/u/shivaji_laxmi)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 7:57am UTC](https://discuss.elastic.co/t/while-helm-upgrade-getting-error-elasticsearch-7-17-5/333417 "2023-05-15T07:57:56Z")

</div>

I upgraded the kubernetes cluster from 1.24 to 1.25. When I try to add additional node in elasticsearch cluster. I am getting following error. $ helm upgrade esdata . -f esdata\_prod.yml -n dea-elk --debug --dry-run up…

---

## [Logstash/Kibana : time field incorrect](https://discuss.elastic.co/t/logstash-kibana-time-field-incorrect/333303)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 7:51am UTC](https://discuss.elastic.co/t/logstash-kibana-time-field-incorrect/333303 "2023-05-15T07:51:30Z")

</div>

I've been stuck for 4 days on this problem. The logs that appear in Kibana have their field time changed (+2 hours) + the logs that appear in kibana are logs from two hours ago. It's currently 14h10, here is my last lo…

---

## [Configure host for fleet server/APM agent policy](https://discuss.elastic.co/t/configure-host-for-fleet-server-apm-agent-policy/332507)

<div class="topic-metadata">

**Author:** [@samiujan](https://discuss.elastic.co/u/samiujan)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 7:29am UTC](https://discuss.elastic.co/t/configure-host-for-fleet-server-apm-agent-policy/332507 "2023-05-15T07:29:43Z")

</div>

Hi I have installed Elastic/Kibana 8.7 and am running a Fleet server and APM - this is all running successfully on localhost Now I want to allow access to a NodeJS application on an EC2 and a web app running off S3/clo…

---

## [Logstash configuration when failing to handle message](https://discuss.elastic.co/t/logstash-configuration-when-failing-to-handle-message/333406)

<div class="topic-metadata">

**Author:** [@TheZadok42](https://discuss.elastic.co/u/TheZadok42)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 7:02am UTC](https://discuss.elastic.co/t/logstash-configuration-when-failing-to-handle-message/333406 "2023-05-15T07:02:10Z")

</div>

Hi! Recently I started to integrate logstash into our infrastructure, and while reading the documentation I didn’t quite understand how to handle bad messages. My current flow is as follows: Application -\> rabbitmq -\> …

---

## [Autodetect\_column\_names is not working as expected in csv filter plugin](https://discuss.elastic.co/t/autodetect-column-names-is-not-working-as-expected-in-csv-filter-plugin/333269)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 6:39am UTC](https://discuss.elastic.co/t/autodetect-column-names-is-not-working-as-expected-in-csv-filter-plugin/333269 "2023-05-15T06:39:13Z")

</div>

Hi, I have this logstash .conf file: input { file { path =\> "/eee/\*.csv" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" } } filter { csv { autodetect\_column\_names =\> true } } And multi…

---

## [Data enrichment using logstash with translate plugin](https://discuss.elastic.co/t/data-enrichment-using-logstash-with-translate-plugin/333403)

<div class="topic-metadata">

**Author:** [@gpandey7](https://discuss.elastic.co/u/gpandey7)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 6:37am UTC](https://discuss.elastic.co/t/data-enrichment-using-logstash-with-translate-plugin/333403 "2023-05-15T06:37:29Z")

</div>

I am trying to enrich the data before it gets indexed, I have tried the below methods but both are currently not working Using the elasticsearch plugin in filter input { kafka { bootstrap\_servers =\> "x…

---

## [Is there a way to plot trend on Opensource Dashobard 2.6](https://discuss.elastic.co/t/is-there-a-way-to-plot-trend-on-opensource-dashobard-2-6/333301)

<div class="topic-metadata">

**Author:** [@Priyanka\_Rajpal](https://discuss.elastic.co/u/Priyanka_Rajpal)\
**Replies:** 3\
**Last updated:** [May 15, 2023, 6:00am UTC](https://discuss.elastic.co/t/is-there-a-way-to-plot-trend-on-opensource-dashobard-2-6/333301 "2023-05-15T06:00:01Z")

</div>

I am using OpensearchDashboards which is a fork of kibana 7.10.2 opensource, is there a way to get a trend on that?

---

## [Winlogbeat 8.4.3 "Start-Service winlogbeat" error](https://discuss.elastic.co/t/winlogbeat-8-4-3-start-service-winlogbeat-error/331532)

<div class="topic-metadata">

**Author:** [@Banuka\_In\_A\_Shoe](https://discuss.elastic.co/u/Banuka_In_A_Shoe)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 4:13am UTC](https://discuss.elastic.co/t/winlogbeat-8-4-3-start-service-winlogbeat-error/331532 "2023-05-15T04:13:31Z")

</div>

Hello, I'm installing winlogbeat on a windows server 2019 machine. I'm fairly certain the config files are ok as the following commands output a positive response. (Also my file/audit/metrics run fine on Linux) .\\winl…

---

## [Migrating from Hot to Hot-Cold Elastic Cluster using Snapshot and Restore](https://discuss.elastic.co/t/migrating-from-hot-to-hot-cold-elastic-cluster-using-snapshot-and-restore/332886)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 11:40pm UTC](https://discuss.elastic.co/t/migrating-from-hot-to-hot-cold-elastic-cluster-using-snapshot-and-restore/332886 "2023-05-14T23:40:47Z")

</div>

Hi Elastic Community, We're considering migrating from a Elastic cluster (with only Hot nodes) to a hot-cold cluster to optimize performance and reduce hardware costs. Our question is, how will the cluster behave when w…

---

## [Does filebeat support ordered pubsub?](https://discuss.elastic.co/t/does-filebeat-support-ordered-pubsub/332835)

<div class="topic-metadata">

**Author:** [@iFamZ](https://discuss.elastic.co/u/iFamZ)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 11:38pm UTC](https://discuss.elastic.co/t/does-filebeat-support-ordered-pubsub/332835 "2023-05-14T23:38:47Z")

</div>

I am working on a project that sends events (two types - open and closed) to an ordered pubsub (verified that the subscription is ordered with an ordering key). I am then consuming this data from the pubsub into my elast…

---

## [What are alternatives for query string to implement slope between phrases?](https://discuss.elastic.co/t/what-are-alternatives-for-query-string-to-implement-slope-between-phrases/333158)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 11:36pm UTC](https://discuss.elastic.co/t/what-are-alternatives-for-query-string-to-implement-slope-between-phrases/333158 "2023-05-14T23:36:29Z")

</div>

What are alternatives for query string to implement slope between phrases?

---

## [About configuring the ELK Stack in centos7 server](https://discuss.elastic.co/t/about-configuring-the-elk-stack-in-centos7-server/333208)

<div class="topic-metadata">

**Author:** [@Anil\_Sai\_Pinnelli](https://discuss.elastic.co/u/Anil_Sai_Pinnelli)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 11:34pm UTC](https://discuss.elastic.co/t/about-configuring-the-elk-stack-in-centos7-server/333208 "2023-05-14T23:34:32Z")

</div>

We are trying to Install ELK Stack in Centos7 server in order to pull the MySql data from the same centos7 server. Could You pls give us in detail instructions how to configure the Elasticsearch, Kibana and Logstash and …

---

## [Virtuel Deshboard](https://discuss.elastic.co/t/virtuel-deshboard/333308)

<div class="topic-metadata">

**Author:** [@Ali\_Trache](https://discuss.elastic.co/u/Ali_Trache)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 1:20pm UTC](https://discuss.elastic.co/t/virtuel-deshboard/333308 "2023-05-12T13:20:03Z")

</div>

hello community, I installed and configured elastic then I configured logstach and I shouted an index afterwards I configured a VMware virtual machine to send and analyzed ESXI logs with Kibana how can I shout a virtual …

---

## [SnakeYAML vulnerability with latest Logstash version](https://discuss.elastic.co/t/snakeyaml-vulnerability-with-latest-logstash-version/333332)

<div class="topic-metadata">

**Author:** [@Nikhil\_Khurana](https://discuss.elastic.co/u/Nikhil_Khurana)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 11:29pm UTC](https://discuss.elastic.co/t/snakeyaml-vulnerability-with-latest-logstash-version/333332 "2023-05-14T23:29:26Z")

</div>

Hi, In the latest version of Logstash, SnakeYAML dependency was bumped to 1.33 but it seems that is vulnerable as well. The vulnerability CVE-2022-1471 is a critical one with score of 9.8. Are there plans to bump it to…

---

## [How to increase output efficiency in logstash to elastic search?](https://discuss.elastic.co/t/how-to-increase-output-efficiency-in-logstash-to-elastic-search/333291)

<div class="topic-metadata">

**Author:** [@Arjav](https://discuss.elastic.co/u/Arjav)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 6:51pm UTC](https://discuss.elastic.co/t/how-to-increase-output-efficiency-in-logstash-to-elastic-search/333291 "2023-05-14T18:51:07Z")

</div>

I have a logstash configuration that has input for postgres database table that has 14 lakh records and an output to elasticsearch database that in setup on ec2 machine c5 x large, when i see documents formation for that…

---

## [Getting An unknown error occurred sending a bulk request to Elasticsearch](https://discuss.elastic.co/t/getting-an-unknown-error-occurred-sending-a-bulk-request-to-elasticsearch/333378)

<div class="topic-metadata">

**Author:** [@Manjiri](https://discuss.elastic.co/u/Manjiri)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 5:33pm UTC](https://discuss.elastic.co/t/getting-an-unknown-error-occurred-sending-a-bulk-request-to-elasticsearch/333378 "2023-05-14T17:33:42Z")

</div>

After Starting the logstash the logs are fetching for 5 mins after that in logstash facing below error : An unknown error occurred sending a bulk request to Elasticsearch (will retry indefinitely) {:message=\> "incompati…

---

## [Prioritized a master node in ES cluster](https://discuss.elastic.co/t/prioritized-a-master-node-in-es-cluster/333350)

<div class="topic-metadata">

**Author:** [@ahmed.emad](https://discuss.elastic.co/u/ahmed.emad)\
**Replies:** 13\
**Last updated:** [May 14, 2023, 2:25pm UTC](https://discuss.elastic.co/t/prioritized-a-master-node-in-es-cluster/333350 "2023-05-14T14:25:22Z")

</div>

Hello, My ES Cluster contains 3 Master nodes (node-1, node-2, node-3), and nodes have a priority (99,98,97) in order so when node-1 goes down it elects node-2 as the new master node this is good till now, but when node-…

---

## [Best practice for data model of geo data - less objects with nested vs. more objects with duplication](https://discuss.elastic.co/t/best-practice-for-data-model-of-geo-data-less-objects-with-nested-vs-more-objects-with-duplication/333376)

<div class="topic-metadata">

**Author:** [@gmmorris](https://discuss.elastic.co/u/gmmorris)\
**Replies:** 0\
**Last updated:** [May 14, 2023, 11:48am UTC](https://discuss.elastic.co/t/best-practice-for-data-model-of-geo-data-less-objects-with-nested-vs-more-objects-with-duplication/333376 "2023-05-14T11:48:47Z")

</div>

Hello, my dear Elasticians, I miss you dearly. :wave: On my new adventure, I encountered a data modelling dilemma and thought I'd ask the experts what they think. We're ingesting large data sets of geospatial data and …

---

## [Configuring the same source container twice](https://discuss.elastic.co/t/configuring-the-same-source-container-twice/333258)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 6\
**Last updated:** [May 13, 2023, 3:58pm UTC](https://discuss.elastic.co/t/configuring-the-same-source-container-twice/333258 "2023-05-13T15:58:15Z")

</div>

Hi, I need to filter events coming from the same source in filebeat level and tag them (filtred not filtred for ex) before sending them to logstash. And I wonder if there is some options to duplicate events (like clone…

---

## [Logstash: Logevent when shutting down but not when starting up](https://discuss.elastic.co/t/logstash-logevent-when-shutting-down-but-not-when-starting-up/333146)

<div class="topic-metadata">

**Author:** [@bitnapper](https://discuss.elastic.co/u/bitnapper)\
**Replies:** 5\
**Last updated:** [May 14, 2023, 10:54am UTC](https://discuss.elastic.co/t/logstash-logevent-when-shutting-down-but-not-when-starting-up/333146 "2023-05-14T10:54:50Z")

</div>

Hi, simple question. Logstash produces a log-event when shutting down but not when starting up. Can I make it do that without activating the whol debug log? Regards

---

## [How to construct geo\_point field from separate fields of latitude and longitude from Kafka?](https://discuss.elastic.co/t/how-to-construct-geo-point-field-from-separate-fields-of-latitude-and-longitude-from-kafka/333370)

<div class="topic-metadata">

**Author:** [@Jagath\_Prasanga](https://discuss.elastic.co/u/Jagath_Prasanga)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 10:29am UTC](https://discuss.elastic.co/t/how-to-construct-geo-point-field-from-separate-fields-of-latitude-and-longitude-from-kafka/333370 "2023-05-14T10:29:17Z")

</div>

How to construct geo\_point field in logstash from Kafka input? This is my logstash config file. But Kibana not recognizing as a geo\_point field. input { kafka { bootstrap\_servers =\> "localhost:9095" top…

---

## [Difference duration calculation between start and end time to show in table](https://discuss.elastic.co/t/difference-duration-calculation-between-start-and-end-time-to-show-in-table/330137)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 4:34am UTC](https://discuss.elastic.co/t/difference-duration-calculation-between-start-and-end-time-to-show-in-table/330137 "2023-05-14T04:34:03Z")

</div>

Hello All, I'd like to know how can I calculate the duration difference between start execution-end execution(Date format) and only get the duration to show in third column. How can this be done?,backend only provides …

---

## [Could not able to install ELK in windows11](https://discuss.elastic.co/t/could-not-able-to-install-elk-in-windows11/333369)

<div class="topic-metadata">

**Author:** [@priyanka\_g](https://discuss.elastic.co/u/priyanka_g)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 3:47am UTC](https://discuss.elastic.co/t/could-not-able-to-install-elk-in-windows11/333369 "2023-05-14T03:47:52Z")

</div>

Hi Team, As i need to do pattern analysis for log files. i had downloaded Elasticsearch, Kibana and Logstack. But when i gave "elasticsearch.bat" in the command prompt, it is not getting installed properly, instead i…

---

## [Kibana in a Docker container](https://discuss.elastic.co/t/kibana-in-a-docker-container/333295)

<div class="topic-metadata">

**Author:** [@GrigoryPtashko](https://discuss.elastic.co/u/GrigoryPtashko)\
**Replies:** 1\
**Last updated:** [May 13, 2023, 5:04pm UTC](https://discuss.elastic.co/t/kibana-in-a-docker-container/333295 "2023-05-13T17:04:51Z")

</div>

Hello. I'm setting up the ELK stack in Docker containers. Elasticsearch, Kibana, Filebeats, Logstash all in their own containers. One thing I cannot understand is whether I have to make a persistent volume for Kibana? F…

---

## [Integration Ingest pipeline not executed when logstash ouptut is activated for Agent Policy (Fleet)](https://discuss.elastic.co/t/integration-ingest-pipeline-not-executed-when-logstash-ouptut-is-activated-for-agent-policy-fleet/332936)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 3\
**Last updated:** [May 13, 2023, 1:12pm UTC](https://discuss.elastic.co/t/integration-ingest-pipeline-not-executed-when-logstash-ouptut-is-activated-for-agent-policy-fleet/332936 "2023-05-13T13:12:27Z")

</div>

8.7 here For some obscure reason, when I add a pipeline to an integration via Custom configurations (lower red rectangle in first screen below), it is not triggered when the policy integration output is set to logstash…

---

## [Logstash Limits](https://discuss.elastic.co/t/logstash-limits/331353)

<div class="topic-metadata">

**Author:** [@shushuu](https://discuss.elastic.co/u/shushuu)\
**Replies:** 4\
**Last updated:** [May 13, 2023, 12:32pm UTC](https://discuss.elastic.co/t/logstash-limits/331353 "2023-05-13T12:32:13Z")

</div>

Hi, We would like to use Logstash to receive log messages from multiple services (nxlog) and send them further to Elastic. i.e. using this architecture - but with nxlog instead of Beats: What are the limits of a si…

---

## [Custom Sample data - same sata reoccuring every week](https://discuss.elastic.co/t/custom-sample-data-same-sata-reoccuring-every-week/333348)

<div class="topic-metadata">

**Author:** [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Replies:** 0\
**Last updated:** [May 13, 2023, 12:27pm UTC](https://discuss.elastic.co/t/custom-sample-data-same-sata-reoccuring-every-week/333348 "2023-05-13T12:27:51Z")

</div>

How to achieve a configuration in an Elasticsearch/Kibana, which will handle my custom sample data to be shown as reoccurring for, lets say, every week? Just like the essential "Kibana Sample Data" - these are clearly li…

---

## [Unique Doc related to one \`field\`](https://discuss.elastic.co/t/unique-doc-related-to-one-field/333344)

<div class="topic-metadata">

**Author:** [@\_zogaj](https://discuss.elastic.co/u/_zogaj)\
**Replies:** 0\
**Last updated:** [May 13, 2023, 6:02am UTC](https://discuss.elastic.co/t/unique-doc-related-to-one-field/333344 "2023-05-13T06:02:38Z")

</div>

Hey, I am using pagination and i want to filter duplicated doc related to one field. For the moment i am trying it with Collapse functionality to filter duplicated and with Cardinality aggregation to get the total unique…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=542)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=544)
