# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=567

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 568

---

## [How to monitor detail why elasstic data node is overloaded](https://discuss.elastic.co/t/how-to-monitor-detail-why-elasstic-data-node-is-overloaded/330105)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 3\
**Last updated:** [April 19, 2023, 4:25am UTC](https://discuss.elastic.co/t/how-to-monitor-detail-why-elasstic-data-node-is-overloaded/330105 "2023-04-19T04:25:39Z")

</div>

our elastic is v8.6 3 master, 40x datanode (8core/32GB/2TB) , 2x loadbalancer node We ingest 100k-900K events/sec by few hundreds of different ingest pipelines, some of them creates small indices but there is about 5-…

---

## [Getting 403 denied to elastic.co (for anything: apt refresh, wget, etc)](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co-for-anything-apt-refresh-wget-etc/329903)

<div class="topic-metadata">

**Author:** [@olegkrysinov](https://discuss.elastic.co/u/olegkrysinov)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 2:20am UTC](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co-for-anything-apt-refresh-wget-etc/329903 "2023-04-19T02:20:28Z")

</div>

Hello! I\`ve a problem (( Error:1 https://artifacts.elastic.co:443/packages/8.x/apt stable InRelease 403 Forbidden \[IP: 34.120.127.130 443\] E: Failed to fetch http://artifacts.elastic.co/packages/8.x/apt/dists/stable/I…

---

## [Move all Indexes to new host](https://discuss.elastic.co/t/move-all-indexes-to-new-host/329825)

<div class="topic-metadata">

**Author:** [@acosta353](https://discuss.elastic.co/u/acosta353)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 2:14am UTC](https://discuss.elastic.co/t/move-all-indexes-to-new-host/329825 "2023-04-19T02:14:39Z")

</div>

Hello, I have a host for Warm and another to Cold Phase without replicas configured. Now, I need to proceed to a maintenance on this Warm host, so i wanted to move all those Warm Indexes temporarily to Cold host (Added …

---

## [Error generating a custom certificate and private key for Fleet Server](https://discuss.elastic.co/t/error-generating-a-custom-certificate-and-private-key-for-fleet-server/330256)

<div class="topic-metadata">

**Author:** [@Lelc79](https://discuss.elastic.co/u/Lelc79)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 12:57am UTC](https://discuss.elastic.co/t/error-generating-a-custom-certificate-and-private-key-for-fleet-server/330256 "2023-04-19T00:57:13Z")

</div>

Hi Elastic community I am generating my certificates to my Fleet Server Step1 ./bin/elasticsearch-certutil ca --pem i moved my CA.cert & ca.key to /path/to/ca Step2: ./bin/elasticsearch-certutil cert --name Flee…

---

## [Cluster health wrong yellow spikes (because new index ?)](https://discuss.elastic.co/t/cluster-health-wrong-yellow-spikes-because-new-index/330124)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 7\
**Last updated:** [April 18, 2023, 10:53pm UTC](https://discuss.elastic.co/t/cluster-health-wrong-yellow-spikes-because-new-index/330124 "2023-04-18T22:53:25Z")

</div>

We are running elasticsearch on kubernetes, via the ECK operator. Every day we receive at least 4 alerts about elasticsearch cluster health go to yellow. Also, we use argocd to deploy it, the health check script here a…

---

## [Possible Bug in Timeline: Fields containing "\\\\" string](https://discuss.elastic.co/t/possible-bug-in-timeline-fields-containing-string/330248)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 8:10pm UTC](https://discuss.elastic.co/t/possible-bug-in-timeline-fields-containing-string/330248 "2023-04-18T20:10:42Z")

</div>

Hey, I just experienced a possible bug with timeline: I have found events in a timeline view. All events in my timeline have the field "winlog.event\_data.ShareName "="\\\*\\Archiv". So when I filter for this field, nothi…

---

## [Error: fleet-server failed: context canceled](https://discuss.elastic.co/t/error-fleet-server-failed-context-canceled/330050)

<div class="topic-metadata">

**Author:** [@Lelc79](https://discuss.elastic.co/u/Lelc79)\
**Replies:** 3\
**Last updated:** [April 18, 2023, 6:21pm UTC](https://discuss.elastic.co/t/error-fleet-server-failed-context-canceled/330050 "2023-04-18T18:21:28Z")

</div>

hello elastic community I have a problem trying to configure the fleet server, I have done the following: Inside Kibana - fleet/settings Fleet server hosts I have put my local server 192.0.1.20 with port 8220 Output…

---

## [Mapping Error with Run Time Field](https://discuss.elastic.co/t/mapping-error-with-run-time-field/330231)

<div class="topic-metadata">

**Author:** [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 5:25pm UTC](https://discuss.elastic.co/t/mapping-error-with-run-time-field/330231 "2023-04-18T17:25:18Z")

</div>

Hello, I'm having issues with runtime fields with Elastic. I have this run time field working fine in Kibana, however, I need this field to be present in the database. I simplified the script, mostly to redact it's sen…

---

## [Embedding kibana via fastly edge proxy](https://discuss.elastic.co/t/embedding-kibana-via-fastly-edge-proxy/330242)

<div class="topic-metadata">

**Author:** [@Shubham\_Pancholi](https://discuss.elastic.co/u/Shubham_Pancholi)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 5:23pm UTC](https://discuss.elastic.co/t/embedding-kibana-via-fastly-edge-proxy/330242 "2023-04-18T17:23:33Z")

</div>

We are using Elasticsearch and kibana, we are using kibana to create dashboard which we will are embedding into our system. We don't want to use login in kibana from fontend so we are using our fastly compute edge to re…

---

## [Control visualisation issues](https://discuss.elastic.co/t/control-visualisation-issues/330170)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [April 18, 2023, 5:15pm UTC](https://discuss.elastic.co/t/control-visualisation-issues/330170 "2023-04-18T17:15:03Z")

</div>

I have 8.5.3 and control is messed up there as well. it has white background and light color font, hard to see anything. it is fixed in next version, but I am not ready to upgrade . It seems control viz is not good eno…

---

## [Time difference between dashboard and devTools (ElasticSearch)](https://discuss.elastic.co/t/time-difference-between-dashboard-and-devtools-elasticsearch/330236)

<div class="topic-metadata">

**Author:** [@FTOR](https://discuss.elastic.co/u/FTOR)\
**Replies:** 3\
**Last updated:** [April 18, 2023, 5:02pm UTC](https://discuss.elastic.co/t/time-difference-between-dashboard-and-devtools-elasticsearch/330236 "2023-04-18T17:02:54Z")

</div>

Hello, I have a time difference of 2 hours between Elasticsearch and kibana's dashboard. For example, the dashboard shows this date as follow, but the real value is 2023-04-18 13:53:00.890 I changed the Time Zone …

---

## [How to customize the exported fields?](https://discuss.elastic.co/t/how-to-customize-the-exported-fields/330240)

<div class="topic-metadata">

**Author:** [@matheuscirillo](https://discuss.elastic.co/u/matheuscirillo)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 4:59pm UTC](https://discuss.elastic.co/t/how-to-customize-the-exported-fields/330240 "2023-04-18T16:59:01Z")

</div>

I have a very basic filebeats.yml configuration file: filebeat: inputs: - type: filestream id: my-log-stream paths: - /path/to/application/logs/\*.log json: keys\_under\_root: true add\_err…

---

## [Logstash JDBC Static Filter Can't Connect to SQLite DB](https://discuss.elastic.co/t/logstash-jdbc-static-filter-cant-connect-to-sqlite-db/330171)

<div class="topic-metadata">

**Author:** [@Dustin527](https://discuss.elastic.co/u/Dustin527)\
**Replies:** 6\
**Last updated:** [April 18, 2023, 4:52pm UTC](https://discuss.elastic.co/t/logstash-jdbc-static-filter-cant-connect-to-sqlite-db/330171 "2023-04-18T16:52:00Z")

</div>

Hi I am having trouble getting the JDBC static filter to work with an SQLite DB. I am using the xerial sqlite jdbc lib on Debian and the latest logstash package. I even have a small java program that can connect to and …

---

## [Ask For help](https://discuss.elastic.co/t/ask-for-help/330234)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 3:50pm UTC](https://discuss.elastic.co/t/ask-for-help/330234 "2023-04-18T15:50:11Z")

</div>

Good morning I'm doing an internship in Business intelligence working to collect data from odoo.sh to ELK Stack I'm working in odoo.sh. I want to ask you about the integration of the module in odoo.sh is possible or no…

---

## ["reset" ILM failed step](https://discuss.elastic.co/t/reset-ilm-failed-step/327754)

<div class="topic-metadata">

**Author:** [@pestevao](https://discuss.elastic.co/u/pestevao)\
**Replies:** 7\
**Last updated:** [April 18, 2023, 3:40pm UTC](https://discuss.elastic.co/t/reset-ilm-failed-step/327754 "2023-04-18T15:40:44Z")

</div>

Hello, I've some restricted indices stuck on ILM actions because of permissions. security\_exception: action \[indices:admin/delete\] is unauthorized for user \[xxx\] with roles \[superuser\] on restricted indices \[.ds-.fleet…

---

## [Filter result by collapsed date](https://discuss.elastic.co/t/filter-result-by-collapsed-date/330235)

<div class="topic-metadata">

**Author:** [@Mickael\_BARBIER](https://discuss.elastic.co/u/Mickael_BARBIER)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 3:35pm UTC](https://discuss.elastic.co/t/filter-result-by-collapsed-date/330235 "2023-04-18T15:35:32Z")

</div>

Hello, i have a topic/news system (a topic can have many news in different language) i want to get the oldest news of each topic. And i want the result sorted by the oldest news displayedAt column. ex: topic1 -News…

---

## [Last value in painless script](https://discuss.elastic.co/t/last-value-in-painless-script/329298)

<div class="topic-metadata">

**Author:** [@martinsbleu](https://discuss.elastic.co/u/martinsbleu)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 3:32pm UTC](https://discuss.elastic.co/t/last-value-in-painless-script/329298 "2023-04-18T15:32:56Z")

</div>

Hello Team, Like in the title, I am trying to get the last\_value of a field for the Return On Investment calculation. Normally, I can do this in Lens Formula (rf. below) on a monthly index. But I don't know how for a da…

---

## [Add field from filebeat eventhub input parameter](https://discuss.elastic.co/t/add-field-from-filebeat-eventhub-input-parameter/330139)

<div class="topic-metadata">

**Author:** [@Paf](https://discuss.elastic.co/u/Paf)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 3:18pm UTC](https://discuss.elastic.co/t/add-field-from-filebeat-eventhub-input-parameter/330139 "2023-04-18T15:18:40Z")

</div>

Hello, I want to add field from filebeat eventhub input parameter. I use this input configuration: - type: azure-eventhub id: azure-eventhub-insights-activity-1 eventhub: "activity-logs" consumer\_group: "$Defaul…

---

## [How to build query using elastic8 java client](https://discuss.elastic.co/t/how-to-build-query-using-elastic8-java-client/330194)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 3:14pm UTC](https://discuss.elastic.co/t/how-to-build-query-using-elastic8-java-client/330194 "2023-04-18T15:14:25Z")

</div>

I need one example where using elastic 8 dsl creates query which includes boolquery with should shouldnot must .query(q -\> q.bool( b -\> b.must(ListObj).should(listShould).mustNot(listMustNot)…

---

## [Sort document based on a field value](https://discuss.elastic.co/t/sort-document-based-on-a-field-value/330084)

<div class="topic-metadata">

**Author:** [@mohammedsajidkhaleel](https://discuss.elastic.co/u/mohammedsajidkhaleel)\
**Replies:** 8\
**Last updated:** [April 18, 2023, 2:41pm UTC](https://discuss.elastic.co/t/sort-document-based-on-a-field-value/330084 "2023-04-18T14:41:19Z")

</div>

Hi, Am having a real estate ads and I would like sort the document based on the users current city. All ads based on the current user city should be on top and other cities ads should be after this. What is the option t…

---

## [Alerts in a cluster](https://discuss.elastic.co/t/alerts-in-a-cluster/330203)

<div class="topic-metadata">

**Author:** [@Joelgoncalves3000](https://discuss.elastic.co/u/Joelgoncalves3000)\
**Replies:** 19\
**Last updated:** [April 18, 2023, 2:36pm UTC](https://discuss.elastic.co/t/alerts-in-a-cluster/330203 "2023-04-18T14:36:08Z")

</div>

Is it possible to create a cluster and each node configure rules and when an alert is heard in a node, this alert is replicated to a master node? But I didn't want alerts from other nodes or master's alerts to be replica…

---

## [Possible to disable session timeout for users in Elastic Cloud?](https://discuss.elastic.co/t/possible-to-disable-session-timeout-for-users-in-elastic-cloud/330149)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 2:27pm UTC](https://discuss.elastic.co/t/possible-to-disable-session-timeout-for-users-in-elastic-cloud/330149 "2023-04-18T14:27:24Z")

</div>

We have a dashboard that we display on a TV in the office 24/7 and it seems to get logged out after ~2 weeks. The dashboard graphs are setup to automatically refresh every 10 minutes. We'd prefer if it never logged out b…

---

## [Alerting with mail](https://discuss.elastic.co/t/alerting-with-mail/330152)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 2:04pm UTC](https://discuss.elastic.co/t/alerting-with-mail/330152 "2023-04-18T14:04:52Z")

</div>

Hello, In Kibana 7.17, I have configured an alert associated with a connector mail. The alarm seems to be triggered correctly : but I don't receive mail. Where can I find usefull information about this, like logs …

---

## [My elastic agent's won't send logs without the ssl.verification\_mode: none](https://discuss.elastic.co/t/my-elastic-agents-wont-send-logs-without-the-ssl-verification-mode-none/330228)

<div class="topic-metadata">

**Author:** [@Elier\_Saavedra](https://discuss.elastic.co/u/Elier_Saavedra)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 2:00pm UTC](https://discuss.elastic.co/t/my-elastic-agents-wont-send-logs-without-the-ssl-verification-mode-none/330228 "2023-04-18T14:00:17Z")

</div>

Hi, i’ve been having some trouble with the elastic agent, I have 3 agents enrolled (1 Windows 2 Centos 7) all of them are healthy but they won’t send logs if I don’t have the ssl.verification\_mode: none In fleet setting…

---

## [Significant terms aggregation returns incorrect bg\_count value when querying index with nested objects in version 8.3.3](https://discuss.elastic.co/t/significant-terms-aggregation-returns-incorrect-bg-count-value-when-querying-index-with-nested-objects-in-version-8-3-3/329466)

<div class="topic-metadata">

**Author:** [@shimpeko](https://discuss.elastic.co/u/shimpeko)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 1:51pm UTC](https://discuss.elastic.co/t/significant-terms-aggregation-returns-incorrect-bg-count-value-when-querying-index-with-nested-objects-in-version-8-3-3/329466 "2023-04-18T13:51:28Z")

</div>

Significant terms aggregation returns incorrect bg\_count value when querying index with nested objects. The value is the same as the document counts returned by \_cat/indices API (which returns Lucene-level doc count). I'…

---

## [How to set alert on total size of indices matching a pattern?](https://discuss.elastic.co/t/how-to-set-alert-on-total-size-of-indices-matching-a-pattern/330159)

<div class="topic-metadata">

**Author:** [@ppine7](https://discuss.elastic.co/u/ppine7)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 1:50pm UTC](https://discuss.elastic.co/t/how-to-set-alert-on-total-size-of-indices-matching-a-pattern/330159 "2023-04-18T13:50:14Z")

</div>

Hi! I've posted this question on SO: elastic stack - Elasticsearch how to set alert on total size of indices matching a pattern? - Stack Overflow but am re-posting it here in hopes to get a more focused audience …

---

## [Kibana: map heat map score to set of numbers?](https://discuss.elastic.co/t/kibana-map-heat-map-score-to-set-of-numbers/327621)

<div class="topic-metadata">

**Author:** [@smchamberlin](https://discuss.elastic.co/u/smchamberlin)\
**Replies:** 1\
**Last updated:** [April 18, 2023, 1:31pm UTC](https://discuss.elastic.co/t/kibana-map-heat-map-score-to-set-of-numbers/327621 "2023-04-18T13:31:06Z")

</div>

Is there a way, using the formula for the heat map score, to map a count of the items into a limited domain of numbers? like: if there are \< X number of these items, assign a 0 if there are between 1 and 5 of these it…

---

## [Elasticsearch Down](https://discuss.elastic.co/t/elasticsearch-down/330175)

<div class="topic-metadata">

**Author:** [@Lelc79](https://discuss.elastic.co/u/Lelc79)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 12:48pm UTC](https://discuss.elastic.co/t/elasticsearch-down/330175 "2023-04-18T12:48:19Z")

</div>

hi community My elasticsearch Server is Down, ¿what could be happening? Elasticsearch 8.7 1) systemctl status elasticsearch elasticsearch.service - Elasticsearch Loaded: loaded (/lib/systemd/system/elasticsearch.ser…

---

## [Problem with Alerts](https://discuss.elastic.co/t/problem-with-alerts/330220)

<div class="topic-metadata">

**Author:** [@Hajar\_Lachhab](https://discuss.elastic.co/u/Hajar_Lachhab)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 12:44pm UTC](https://discuss.elastic.co/t/problem-with-alerts/330220 "2023-04-18T12:44:30Z")

</div>

Hi everyone, I have a problem with Alerts as you can see here, the rule works properly and it shows the alerts But here when I'm coming back to Security or Observability to see the alerts after the enabling the rule…

---

## [Elasticsearch 8: new OOM kills in comparison with ES7](https://discuss.elastic.co/t/elasticsearch-8-new-oom-kills-in-comparison-with-es7/330016)

<div class="topic-metadata">

**Author:** [@Tomas\_Bartek](https://discuss.elastic.co/u/Tomas_Bartek)\
**Replies:** 9\
**Last updated:** [April 18, 2023, 12:31pm UTC](https://discuss.elastic.co/t/elasticsearch-8-new-oom-kills-in-comparison-with-es7/330016 "2023-04-18T12:31:28Z")

</div>

We test Elasticsearch 8.7.0 cluster setup (to migrate from ES 7.17.9) and we face the problem that the voting-only node in the testing cluster is sometimes killed by OOM. We use almost identical setup like in our curr…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=566)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=568)
