# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=566

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 567

---

## [Use data view or direct index](https://discuss.elastic.co/t/use-data-view-or-direct-index/330239)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 7\
**Last updated:** [April 19, 2023, 9:22pm UTC](https://discuss.elastic.co/t/use-data-view-or-direct-index/330239 "2023-04-19T21:22:00Z")

</div>

I have 1000+ index myindex-\<date\>-00000x ( this is all rollover using ILM) in my REST calll should I use myindex-\* or use latest index by it's name like "myindex-\<date\>-00000x" most everytime I retrive data using @…

---

## [Can we extract the 7 days stored common value from the elastic search database and visulazize that information on kibana](https://discuss.elastic.co/t/can-we-extract-the-7-days-stored-common-value-from-the-elastic-search-database-and-visulazize-that-information-on-kibana/329883)

<div class="topic-metadata">

**Author:** [@Tanzeela](https://discuss.elastic.co/u/Tanzeela)\
**Replies:** 6\
**Last updated:** [April 19, 2023, 9:01pm UTC](https://discuss.elastic.co/t/can-we-extract-the-7-days-stored-common-value-from-the-elastic-search-database-and-visulazize-that-information-on-kibana/329883 "2023-04-19T21:01:19Z")

</div>

Hi @Andrew\_Tate , hope you are doing well. Can we write a query that will extract the common value that is stored in Elasticsearch for 7 days and create the visualisation for the extracted information? for example: da…

---

## [Metricbeat Default Dashboards TSVB and Histogram Display Issues after Upgrade from 7.17 to 8.7](https://discuss.elastic.co/t/metricbeat-default-dashboards-tsvb-and-histogram-display-issues-after-upgrade-from-7-17-to-8-7/329492)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 3\
**Last updated:** [April 19, 2023, 8:51pm UTC](https://discuss.elastic.co/t/metricbeat-default-dashboards-tsvb-and-histogram-display-issues-after-upgrade-from-7-17-to-8-7/329492 "2023-04-19T20:51:57Z")

</div>

Hello, I recently upgraded my Elastic Stack from version 7.17 to 8.7, and I am experiencing issues with the default Metricbeat dashboards. The TSVB and Histogram visualizations are not displaying data correctly. I have …

---

## [I am facing issue to open kibana url in iframe](https://discuss.elastic.co/t/i-am-facing-issue-to-open-kibana-url-in-iframe/330215)

<div class="topic-metadata">

**Author:** [@devdev7711](https://discuss.elastic.co/u/devdev7711)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 8:25pm UTC](https://discuss.elastic.co/t/i-am-facing-issue-to-open-kibana-url-in-iframe/330215 "2023-04-19T20:25:14Z")

</div>

I have kibana setup in https and configuare previously. It is working fine for me. but when other user is login in webapplication they are getting errors. iframe src="https://1.2.111.111:8600/app/dashboards#/view/fe3f…

---

## [How to find difference between aggregate average and individual values](https://discuss.elastic.co/t/how-to-find-difference-between-aggregate-average-and-individual-values/330255)

<div class="topic-metadata">

**Author:** [@rahulkothanath](https://discuss.elastic.co/u/rahulkothanath)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 10:56pm UTC](https://discuss.elastic.co/t/how-to-find-difference-between-aggregate-average-and-individual-values/330255 "2023-04-18T22:56:26Z")

</div>

I have a field "y" in the Elasticsearch index and I would like to find sum(y-y.avg) using aggregations for each person in my index. I am able to calculate y.avg for a person using the below query but need help in calcula…

---

## [Can't see Kibana logs](https://discuss.elastic.co/t/cant-see-kibana-logs/330246)

<div class="topic-metadata">

**Author:** [@ishan.abhinit](https://discuss.elastic.co/u/ishan.abhinit)\
**Replies:** 7\
**Last updated:** [April 19, 2023, 7:15pm UTC](https://discuss.elastic.co/t/cant-see-kibana-logs/330246 "2023-04-19T19:15:40Z")

</div>

I had set up Elasticsearch and Kibana on Rocky Linux few months ago for a workshop. Everything worked fine then. I shut down the server after the workshop and restarted it last week. I don't see the logs appearing in Ki…

---

## [Keyword search not behaving as expected](https://discuss.elastic.co/t/keyword-search-not-behaving-as-expected/330328)

<div class="topic-metadata">

**Author:** [@developer3124](https://discuss.elastic.co/u/developer3124)\
**Replies:** 4\
**Last updated:** [April 19, 2023, 7:06pm UTC](https://discuss.elastic.co/t/keyword-search-not-behaving-as-expected/330328 "2023-04-19T19:06:52Z")

</div>

Hello, I'm having an issue with keyword search not behaving how I would expect from the docs. I can see that the following document exists in my index: { "\_index": "my-index", "\_type": "\_doc", "\_id": …

---

## [Logstash, parsing a localised date with HTTPDATE](https://discuss.elastic.co/t/logstash-parsing-a-localised-date-with-httpdate/330297)

<div class="topic-metadata">

**Author:** [@GreenEyed](https://discuss.elastic.co/u/GreenEyed)\
**Replies:** 3\
**Last updated:** [April 19, 2023, 6:15pm UTC](https://discuss.elastic.co/t/logstash-parsing-a-localised-date-with-httpdate/330297 "2023-04-19T18:15:06Z")

</div>

Hi there, We have a library that is sending access logs to logstash with a "similar" to Apache format. We have created the regexp in grok to parse it but I have detected that the library is using the default format, loc…

---

## [How to split data into spaces](https://discuss.elastic.co/t/how-to-split-data-into-spaces/330229)

<div class="topic-metadata">

**Author:** [@Joelgoncalves3000](https://discuss.elastic.co/u/Joelgoncalves3000)\
**Replies:** 9\
**Last updated:** [April 19, 2023, 5:15pm UTC](https://discuss.elastic.co/t/how-to-split-data-into-spaces/330229 "2023-04-19T17:15:50Z")

</div>

Hello, let's imagine that I have a cluster with 5 nodes and each node is a client, I want these 5 to divide the data from these clients into spaces, I would also like to install packebeat and filebeat on each node and se…

---

## [ELK 7.6.2 Licensing](https://discuss.elastic.co/t/elk-7-6-2-licensing/330324)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 5:07pm UTC](https://discuss.elastic.co/t/elk-7-6-2-licensing/330324 "2023-04-19T17:07:36Z")

</div>

Hello, We are using a very old version of ELK cluster 7.6.2 (with Basic license) in our environment. We plan to upgrade to the latest 8.6 version in future. With the 7.6.2 version in place we want to look into the pos…

---

## [Central Elastic Stack setup for a company with 10+ applications using Elasticsearch](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800)

<div class="topic-metadata">

**Author:** [@murat3](https://discuss.elastic.co/u/murat3)\
**Replies:** 7\
**Last updated:** [April 19, 2023, 5:03pm UTC](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800 "2023-04-19T17:03:57Z")

</div>

Hello all, I am trying to understand the setup of a (central) Elastic Stack cluster used by 10+ projects and 20+ applications. Our applications consist of frontend web and Java backend applications. One Cluster Is one…

---

## [Start Elasticsearch with preloaded index](https://discuss.elastic.co/t/start-elasticsearch-with-preloaded-index/330299)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 4:54pm UTC](https://discuss.elastic.co/t/start-elasticsearch-with-preloaded-index/330299 "2023-04-19T16:54:53Z")

</div>

Is there any way we can start the elasticsearch instance with a preloaded index data? Just like we do in postgres: Creating a Docker image with a preloaded database | Coding with Coffee

---

## [How to monitor core usage metrics on Oracle 19c when multiple SIDs on a host](https://discuss.elastic.co/t/how-to-monitor-core-usage-metrics-on-oracle-19c-when-multiple-sids-on-a-host/328957)

<div class="topic-metadata">

**Author:** [@James\_Whittington](https://discuss.elastic.co/u/James_Whittington)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 4:41pm UTC](https://discuss.elastic.co/t/how-to-monitor-core-usage-metrics-on-oracle-19c-when-multiple-sids-on-a-host/328957 "2023-04-19T16:41:14Z")

</div>

I have a delima on how to approach monitoring some key usage based metrics on a Oracle Database server where multiple SIDs reside. We use elastic cloud, version at 8.6, currently just using fleet managed elastic agents. …

---

## [Filebaet and logstash encoding problem](https://discuss.elastic.co/t/filebaet-and-logstash-encoding-problem/330223)

<div class="topic-metadata">

**Author:** [@maks1001281](https://discuss.elastic.co/u/maks1001281)\
**Replies:** 15\
**Last updated:** [April 19, 2023, 3:00pm UTC](https://discuss.elastic.co/t/filebaet-and-logstash-encoding-problem/330223 "2023-04-19T15:00:01Z")

</div>

Hello, I can't understand why Logstash doesn't analyze logs from filebeat correctly, I see strange errors like: JSON parsing error, source data now in message field {:message=\>"Unexpected character ('\*' (code 42)): expe…

---

## [Curl: (7) Failed to connect to 10.x.x.x port 5601: Connection refused](https://discuss.elastic.co/t/curl-7-failed-to-connect-to-10-x-x-x-port-5601-connection-refused/330138)

<div class="topic-metadata">

**Author:** [@ram\_222](https://discuss.elastic.co/u/ram_222)\
**Replies:** 11\
**Last updated:** [April 19, 2023, 2:43pm UTC](https://discuss.elastic.co/t/curl-7-failed-to-connect-to-10-x-x-x-port-5601-connection-refused/330138 "2023-04-19T14:43:35Z")

</div>

Here, I provide the Procedure what I follow to setup a Elastic Search and Kibana on GCP Vm's: Created a 2 Vm's of Es and Kibana with Reserved Internal and External Ip's. Successfully Deployed Es and Kibana Debian packa…

---

## [Shards failures - illegal\_argument\_exception](https://discuss.elastic.co/t/shards-failures-illegal-argument-exception/330311)

<div class="topic-metadata">

**Author:** [@dpecak](https://discuss.elastic.co/u/dpecak)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 2:03pm UTC](https://discuss.elastic.co/t/shards-failures-illegal-argument-exception/330311 "2023-04-19T14:03:17Z")

</div>

I have fresh installation of ELK stack with Filebeat and Metricbeat. When I try to open predefined dashboard (for example "\[Filebeat System\] SSH login attempts ECS"), I see many shard failures: Fielddata is disabled on …

---

## [Retrieval of data on the dashboard is done after hours](https://discuss.elastic.co/t/retrieval-of-data-on-the-dashboard-is-done-after-hours/330237)

<div class="topic-metadata">

**Author:** [@FTOR](https://discuss.elastic.co/u/FTOR)\
**Replies:** 5\
**Last updated:** [April 19, 2023, 12:28pm UTC](https://discuss.elastic.co/t/retrieval-of-data-on-the-dashboard-is-done-after-hours/330237 "2023-04-19T12:28:15Z")

</div>

I have a problem with the data recovery on the dashboard. It gets hours to get the data from Elasticsearch to the Dashboard. I get the right datas on the devTools, but I can not have a real time data on the dashboard. Do…

---

## [Hiding results in Data Table visualisation based on the count](https://discuss.elastic.co/t/hiding-results-in-data-table-visualisation-based-on-the-count/330303)

<div class="topic-metadata">

**Author:** [@Jakub\_J](https://discuss.elastic.co/u/Jakub_J)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 12:17pm UTC](https://discuss.elastic.co/t/hiding-results-in-data-table-visualisation-based-on-the-count/330303 "2023-04-19T12:17:15Z")

</div>

Hello hive mind, After some time I reached a dead end, thus i'd like to ask you assistance from the gurus. here's what I try to achieve. I have an index pattern which includes (amongst others) ProductionID (String). I…

---

## [Help me in Vega Sorting using transform lookup joined field on encoding Y-axis](https://discuss.elastic.co/t/help-me-in-vega-sorting-using-transform-lookup-joined-field-on-encoding-y-axis/330298)

<div class="topic-metadata">

**Author:** [@Nabeel\_Ahmed\_NAK](https://discuss.elastic.co/u/Nabeel_Ahmed_NAK)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 11:35am UTC](https://discuss.elastic.co/t/help-me-in-vega-sorting-using-transform-lookup-joined-field-on-encoding-y-axis/330298 "2023-04-19T11:35:23Z")

</div>

Hi I need help in dynamic sort of "asc" and "desc" based upon 3 fields which I need to select one by one from select option front. Currently I'm sorting on the basis of any particular field hardcoded given field. Proble…

---

## [Rollup Job - New data not Rolled Up](https://discuss.elastic.co/t/rollup-job-new-data-not-rolled-up/330006)

<div class="topic-metadata">

**Author:** [@Vitor\_Nilson](https://discuss.elastic.co/u/Vitor_Nilson)\
**Replies:** 3\
**Last updated:** [April 19, 2023, 11:17am UTC](https://discuss.elastic.co/t/rollup-job-new-data-not-rolled-up/330006 "2023-04-19T11:17:27Z")

</div>

Hello, I'm currently creating a rollup job to reduce storage costs in my company. The rollup job worked well, grouped by the fields that I specified. The problem is that only data older than 7 days is being rolled up t…

---

## [Fleet Server Unable to Communicate to Elasticsearch Due to Bad Certificate](https://discuss.elastic.co/t/fleet-server-unable-to-communicate-to-elasticsearch-due-to-bad-certificate/328038)

<div class="topic-metadata">

**Author:** [@Kowshik\_Islam](https://discuss.elastic.co/u/Kowshik_Islam)\
**Replies:** 4\
**Last updated:** [April 19, 2023, 9:13am UTC](https://discuss.elastic.co/t/fleet-server-unable-to-communicate-to-elasticsearch-due-to-bad-certificate/328038 "2023-04-19T09:13:03Z")

</div>

Hi, I am having trouble with having my fleet server communicate with elasticsearch cluster. My current stack has have 2 EC2 instance for Elasticsearch (es01, es02), 1 EC2 Instance for Kibana and 1 EC2 instance for Fleet …

---

## [Get a substring of a string](https://discuss.elastic.co/t/get-a-substring-of-a-string/330278)

<div class="topic-metadata">

**Author:** [@obelaisk](https://discuss.elastic.co/u/obelaisk)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 8:53am UTC](https://discuss.elastic.co/t/get-a-substring-of-a-string/330278 "2023-04-19T08:53:22Z")

</div>

Hi, im using canvas and i don't know if it's possible to get a substring of a given string in expression editor

---

## [Anomaly Detection transactions financial data](https://discuss.elastic.co/t/anomaly-detection-transactions-financial-data/330207)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 2\
**Last updated:** [April 19, 2023, 7:57am UTC](https://discuss.elastic.co/t/anomaly-detection-transactions-financial-data/330207 "2023-04-19T07:57:05Z")

</div>

I have a data set that holds data like this: I want to create an anomaly detection job that alerts about suspicious large transactions but when I create a anomaly detection job it always looks at for example 1 day an…

---

## [Logstash-8.7 fails to load YAML larger than 3MB](https://discuss.elastic.co/t/logstash-8-7-fails-to-load-yaml-larger-than-3mb/330269)

<div class="topic-metadata">

**Author:** [@Dheeraj\_Gupta](https://discuss.elastic.co/u/Dheeraj_Gupta)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 7:55am UTC](https://discuss.elastic.co/t/logstash-8-7-fails-to-load-yaml-larger-than-3mb/330269 "2023-04-19T07:55:24Z")

</div>

We are using Logstash translate plugin to add user information to IP addresses in logs/events in our organization. The user data is loaded via YAML. The file is large (5.5MB with around 15K entries). Till Logstash-8.6, …

---

## [Count number of times an index was searched](https://discuss.elastic.co/t/count-number-of-times-an-index-was-searched/330260)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 6:30am UTC](https://discuss.elastic.co/t/count-number-of-times-an-index-was-searched/330260 "2023-04-19T06:30:58Z")

</div>

Hi team! Is there a way to find out how many times a particular index was searched/queries? If not a direct API in elastic, is there a workaround to get this metric?

---

## [Kibana Dashboard in slideshow Mode](https://discuss.elastic.co/t/kibana-dashboard-in-slideshow-mode/330263)

<div class="topic-metadata">

**Author:** [@Dipesh](https://discuss.elastic.co/u/Dipesh)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 6:01am UTC](https://discuss.elastic.co/t/kibana-dashboard-in-slideshow-mode/330263 "2023-04-19T06:01:16Z")

</div>

Hi, I have some dashboards with multiple visualisation attached in it, since it has 30+ Visualize charts added in the dashboard, its doesn't look good and also unable to see in a single screen, so i am searching for som…

---

## [Exiting: error initializing publisher: output type http undefined in filebeat.yml](https://discuss.elastic.co/t/exiting-error-initializing-publisher-output-type-http-undefined-in-filebeat-yml/330258)

<div class="topic-metadata">

**Author:** [@karthic](https://discuss.elastic.co/u/karthic)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 5:39am UTC](https://discuss.elastic.co/t/exiting-error-initializing-publisher-output-type-http-undefined-in-filebeat-yml/330258 "2023-04-19T05:39:28Z")

</div>

Hi I need to forward the logs to my own api, In the config, i am using Http.output which says the error "Exiting: error initializing publisher: output type http undefined in filebeat" output.http: url: "https://API…

---

## [AI-powered Elastic search alternative, for small project?](https://discuss.elastic.co/t/ai-powered-elastic-search-alternative-for-small-project/330261)

<div class="topic-metadata">

**Author:** [@c\_u\_be\_binh\_an](https://discuss.elastic.co/u/c_u_be_binh_an)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 4:51am UTC](https://discuss.elastic.co/t/ai-powered-elastic-search-alternative-for-small-project/330261 "2023-04-19T04:51:04Z")

</div>

I am developing a job board using NodeJs and it currently has around 1,000 items. However, I am facing an issue with deploying it on a 1GB RAM VPS as it cannot run Elastic Search on it. Therefore, I am searching for a li…

---

## [Mail enable smtp activity logs](https://discuss.elastic.co/t/mail-enable-smtp-activity-logs/329672)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 2\
**Last updated:** [April 19, 2023, 4:29am UTC](https://discuss.elastic.co/t/mail-enable-smtp-activity-logs/329672 "2023-04-19T04:29:45Z")

</div>

Hello everyone I am trying to pars mail enable activity loga there are millions of logs in un even pattern I write some of the pattern and logs pars in well manner ans structured but now the issue is so many logs parsin…

---

## [How to monitor detail why elasstic data node is overloaded](https://discuss.elastic.co/t/how-to-monitor-detail-why-elasstic-data-node-is-overloaded/330105)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 3\
**Last updated:** [April 19, 2023, 4:25am UTC](https://discuss.elastic.co/t/how-to-monitor-detail-why-elasstic-data-node-is-overloaded/330105 "2023-04-19T04:25:39Z")

</div>

our elastic is v8.6 3 master, 40x datanode (8core/32GB/2TB) , 2x loadbalancer node We ingest 100k-900K events/sec by few hundreds of different ingest pipelines, some of them creates small indices but there is about 5-…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=565)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=567)
