# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=568

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 569

---

## [Static lookup fields does not appear on Controls in Kibana](https://discuss.elastic.co/t/static-lookup-fields-does-not-appear-on-controls-in-kibana/330218)

<div class="topic-metadata">

**Author:** [@duprijil](https://discuss.elastic.co/u/duprijil)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 12:24pm UTC](https://discuss.elastic.co/t/static-lookup-fields-does-not-appear-on-controls-in-kibana/330218 "2023-04-18T12:24:57Z")

</div>

Hello everyone, In my Kibana dashboard, I'm using \[Controls\] instead of deprecated \[Input controls\] on field with static lookup. The problem is that \[Control\] shows value of field instead of static value. Example: 33…

---

## [Logstash manages to send data to elasticsearch only in debugging mode](https://discuss.elastic.co/t/logstash-manages-to-send-data-to-elasticsearch-only-in-debugging-mode/330196)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 3\
**Last updated:** [April 18, 2023, 11:53am UTC](https://discuss.elastic.co/t/logstash-manages-to-send-data-to-elasticsearch-only-in-debugging-mode/330196 "2023-04-18T11:53:06Z")

</div>

Hello everyone, I am currently trying a basic test setup with apache logs on logstash, but I have a problem, my data is received on kibana/elasticsearch only when I run the following command: /usr/share/logstash/bin/lo…

---

## [Is it possible to visualize different time series based on 2 fields on kibana](https://discuss.elastic.co/t/is-it-possible-to-visualize-different-time-series-based-on-2-fields-on-kibana/330035)

<div class="topic-metadata">

**Author:** [@FTOR](https://discuss.elastic.co/u/FTOR)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 11:41am UTC](https://discuss.elastic.co/t/is-it-possible-to-visualize-different-time-series-based-on-2-fields-on-kibana/330035 "2023-04-18T11:41:37Z")

</div>

Hello, I would like to visualise different time series based on 2 fields (field1 and field2). I have a field named numr\_Ficher that could have the values : 2235/2234/2230.. And another field named operateur that could …

---

## [How to use Spark API to update and insert data in ES](https://discuss.elastic.co/t/how-to-use-spark-api-to-update-and-insert-data-in-es/330216)

<div class="topic-metadata">

**Author:** [@skyruan](https://discuss.elastic.co/u/skyruan)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 11:30am UTC](https://discuss.elastic.co/t/how-to-use-spark-api-to-update-and-insert-data-in-es/330216 "2023-04-18T11:30:29Z")

</div>

There is a issue: there are 4 fields named id,a,b,c if the id is same,i just want to use the latest data to update the value of a，and b,c not handle, if the id is different,adding the record in ES

---

## [How to read Data from ES response](https://discuss.elastic.co/t/how-to-read-data-from-es-response/330213)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 5\
**Last updated:** [April 18, 2023, 11:24am UTC](https://discuss.elastic.co/t/how-to-read-data-from-es-response/330213 "2023-04-18T11:24:21Z")

</div>

Hi, so I see the response of ES is tied to the kind of Query I write. I know Kibana is able to map it into charts so there must be a formal way of extracting information of BUCKETS property. Can I get info about it or is…

---

## [Is it possible to make arithmetic operation on kibana dashboard?](https://discuss.elastic.co/t/is-it-possible-to-make-arithmetic-operation-on-kibana-dashboard/330033)

<div class="topic-metadata">

**Author:** [@FTOR](https://discuss.elastic.co/u/FTOR)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 11:16am UTC](https://discuss.elastic.co/t/is-it-possible-to-make-arithmetic-operation-on-kibana-dashboard/330033 "2023-04-18T11:16:42Z")

</div>

I would like to visualise the average of a processing time of a file according to its size over time. I receive the fields as follows: start\_date end\_date length So I need to calculate length / (end\_date - start\_dat…

---

## [The memory required for elastic search server for uninterrupted usage of kibana dashboard](https://discuss.elastic.co/t/the-memory-required-for-elastic-search-server-for-uninterrupted-usage-of-kibana-dashboard/329961)

<div class="topic-metadata">

**Author:** [@Geethu](https://discuss.elastic.co/u/Geethu)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 10:21am UTC](https://discuss.elastic.co/t/the-memory-required-for-elastic-search-server-for-uninterrupted-usage-of-kibana-dashboard/329961 "2023-04-18T10:21:39Z")

</div>

We are using servers of 16 GB memory but since open JDK in elatsic search is consuming about 50% memory in our server almost 13 GB it is showing as used. So beacuse of this we are getting error while loading kibana URL …

---

## [Cross-Cluster Prices](https://discuss.elastic.co/t/cross-cluster-prices/330210)

<div class="topic-metadata">

**Author:** [@Joelgoncalves3000](https://discuss.elastic.co/u/Joelgoncalves3000)\
**Replies:** 1\
**Last updated:** [April 18, 2023, 10:18am UTC](https://discuss.elastic.co/t/cross-cluster-prices/330210 "2023-04-18T10:18:19Z")

</div>

If I have a cluster with 3 nodes what would be the price of an enterprise license? And if I have a cross-cluster with 2 clusters with 3 nodes each, what would be the price?

---

## [Kibana objects on elasticsearch container](https://discuss.elastic.co/t/kibana-objects-on-elasticsearch-container/329821)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 9:52am UTC](https://discuss.elastic.co/t/kibana-objects-on-elasticsearch-container/329821 "2023-04-18T09:52:40Z")

</div>

hello i want to mount volume of dashboards and visualizalisation in elasticsearch container how can i do it pleaze

---

## [Read data from influxdb from elasticsearch](https://discuss.elastic.co/t/read-data-from-influxdb-from-elasticsearch/329707)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 9:21am UTC](https://discuss.elastic.co/t/read-data-from-influxdb-from-elasticsearch/329707 "2023-04-18T09:21:31Z")

</div>

Hi need to read data from influxdb from elasticsearch and store on an index. I have two choice 1-telegraf 2-logstash need "input plugin for influx" and "output plugin for elastic". Any idea? Thanks

---

## [Tune logstash JDBC input for huge datasets](https://discuss.elastic.co/t/tune-logstash-jdbc-input-for-huge-datasets/330160)

<div class="topic-metadata">

**Author:** [@Marco\_Lagalla](https://discuss.elastic.co/u/Marco_Lagalla)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 9:18am UTC](https://discuss.elastic.co/t/tune-logstash-jdbc-input-for-huge-datasets/330160 "2023-04-18T09:18:39Z")

</div>

Hi all! I am trying to migrate a very huge dataset from a source oracle database to Elasticsearch. The data that I am trying to migrate is contained in a single table, which is partitioned weekly, based on a timestamp …

---

## [iFrame Code goes Wrong](https://discuss.elastic.co/t/iframe-code-goes-wrong/330187)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 5:12am UTC](https://discuss.elastic.co/t/iframe-code-goes-wrong/330187 "2023-04-18T05:12:25Z")

</div>

hi, I'm having trouble embedding anonymously into another website, when I input the kibana.yml like this and when i test it, it's just give a login page. even when i click login, it becomes loop login i also alrea…

---

## [How to copy path to elastic cloud?](https://discuss.elastic.co/t/how-to-copy-path-to-elastic-cloud/330199)

<div class="topic-metadata">

**Author:** [@loong](https://discuss.elastic.co/u/loong)\
**Replies:** 1\
**Last updated:** [April 18, 2023, 8:41am UTC](https://discuss.elastic.co/t/how-to-copy-path-to-elastic-cloud/330199 "2023-04-18T08:41:25Z")

</div>

Hi., I am new here. I would like to create hyphenation\_decompounder token filter on elastic cloud, but I should be able to copy the \*.xml file and the wordlist\_path. how can I copy it into? I got this error ApiError(5…

---

## [Elasticsearch 7.3.2 with java 8 and tcp client access from the java 17 running application](https://discuss.elastic.co/t/elasticsearch-7-3-2-with-java-8-and-tcp-client-access-from-the-java-17-running-application/330185)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 3\
**Last updated:** [April 18, 2023, 8:29am UTC](https://discuss.elastic.co/t/elasticsearch-7-3-2-with-java-8-and-tcp-client-access-from-the-java-17-running-application/330185 "2023-04-18T08:29:40Z")

</div>

Hi We are using elasticsearch 7.3.2 version with java 8 and with the tcp client we are accessing the cluster from the java application running with java 17 is there any issue in this

---

## [How to create a Collapsable Section - Kibana Markdown](https://discuss.elastic.co/t/how-to-create-a-collapsable-section-kibana-markdown/330195)

<div class="topic-metadata">

**Author:** [@federica.forti](https://discuss.elastic.co/u/federica.forti)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 8:19am UTC](https://discuss.elastic.co/t/how-to-create-a-collapsable-section-kibana-markdown/330195 "2023-04-18T08:19:13Z")

</div>

Hi, we would like to insert a collapsable section in Kibana Markdown (text visualization), like in this issue. Can you explain me if this is possible with Kibana 8.6.2 version? Thanks, Federica

---

## [Is it possible to limit http-poller to a single node in a Logstash cluster?](https://discuss.elastic.co/t/is-it-possible-to-limit-http-poller-to-a-single-node-in-a-logstash-cluster/330087)

<div class="topic-metadata">

**Author:** [@jba](https://discuss.elastic.co/u/jba)\
**Replies:** 5\
**Last updated:** [April 18, 2023, 8:06am UTC](https://discuss.elastic.co/t/is-it-possible-to-limit-http-poller-to-a-single-node-in-a-logstash-cluster/330087 "2023-04-18T08:06:35Z")

</div>

I have just discovered the http-poller plugin and it seems like it could replace some custom scripts that we have for getting monitoring data (e.g. index growth) into Elasticsearch. But it is not clear to me if I can res…

---

## [Kibana alert](https://discuss.elastic.co/t/kibana-alert/330145)

<div class="topic-metadata">

**Author:** [@Soren\_vdc](https://discuss.elastic.co/u/Soren_vdc)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 7:55am UTC](https://discuss.elastic.co/t/kibana-alert/330145 "2023-04-18T07:55:16Z")

</div>

Hi, I have a kibana alert that runs every 5 minutes and snooze every day during 10 PM and 8 AM. But I also want to snooze it during the complete weekend. Is there a procedure to do that? br Sören

---

## [Expand existing lens visualization / Create a new lens visualization](https://discuss.elastic.co/t/expand-existing-lens-visualization-create-a-new-lens-visualization/329804)

<div class="topic-metadata">

**Author:** [@LucasE](https://discuss.elastic.co/u/LucasE)\
**Replies:** 6\
**Last updated:** [April 18, 2023, 7:42am UTC](https://discuss.elastic.co/t/expand-existing-lens-visualization-create-a-new-lens-visualization/329804 "2023-04-18T07:42:49Z")

</div>

Hello everyone, I'm using Kibana 8.3.3 My objective is to take the Table from the DashBoard Lens visualization editor and create a new type of visualization called TableM by creating a plugin in Kibana. This table wil…

---

## [Metricbeat error: failed to get docker stats: Cannot connect to the Docker daemon at unix:///run/podman/io.podman](https://discuss.elastic.co/t/metricbeat-error-failed-to-get-docker-stats-cannot-connect-to-the-docker-daemon-at-unix-run-podman-io-podman/329995)

<div class="topic-metadata">

**Author:** [@Usama\_Tariq](https://discuss.elastic.co/u/Usama_Tariq)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 6:34am UTC](https://discuss.elastic.co/t/metricbeat-error-failed-to-get-docker-stats-cannot-connect-to-the-docker-daemon-at-unix-run-podman-io-podman/329995 "2023-04-18T06:34:43Z")

</div>

Hi all. I am facing an issue when trying to get docker metrics via podman. I am getting the following error: "failed to get docker stats: Cannot connect to the Docker daemon at unix:///run/podman/io.podman. Is the docke…

---

## [Use variable in logstash config](https://discuss.elastic.co/t/use-variable-in-logstash-config/330092)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 6:20am UTC](https://discuss.elastic.co/t/use-variable-in-logstash-config/330092 "2023-04-18T06:20:52Z")

</div>

Hi I have logstash input like below, how can i set variable for "cpu" (it is name of table in database) and it has different values like "mem, disk,i/o,...". need to pass name of table as variable instead of define mul…

---

## [GRAYLOG WITH OPENSEACH](https://discuss.elastic.co/t/graylog-with-openseach/330151)

<div class="topic-metadata">

**Author:** [@jomaguca](https://discuss.elastic.co/u/jomaguca)\
**Replies:** 3\
**Last updated:** [April 18, 2023, 6:06am UTC](https://discuss.elastic.co/t/graylog-with-openseach/330151 "2023-04-18T06:06:24Z")

</div>

Hi everyone I am using graylog with opnsearsh and I have a doubt to use filebeat, metricbeat etc because what is the version on all them to use with opensearch? Best regards.

---

## [Kibana 8.7 does not show the time values when clicking the timeslider control](https://discuss.elastic.co/t/kibana-8-7-does-not-show-the-time-values-when-clicking-the-timeslider-control/330098)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 4:10am UTC](https://discuss.elastic.co/t/kibana-8-7-does-not-show-the-time-values-when-clicking-the-timeslider-control/330098 "2023-04-18T04:10:09Z")

</div>

Hi Folks, My timeslider input control does not show the time value as the ticker progresses, i dont see any errors on logs for this . I tried changing the dark BG to default as a test , and the results are the sa…

---

## [How many times (interval/period) do metrics send to elasticsearch? Where i can see these information?](https://discuss.elastic.co/t/how-many-times-interval-period-do-metrics-send-to-elasticsearch-where-i-can-see-these-information/329851)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 1\
**Last updated:** [April 18, 2023, 3:39am UTC](https://discuss.elastic.co/t/how-many-times-interval-period-do-metrics-send-to-elasticsearch-where-i-can-see-these-information/329851 "2023-04-18T03:39:34Z")

</div>

Hello community, how can i see in which interval the metrics from a cluster is sending to elasticsearch? what is this "period" in metricbeat-kubernetes.yml saying ? templates: - config: - m…

---

## [\<ECK\>Kibana 8.7.0 error login](https://discuss.elastic.co/t/eck-kibana-8-7-0-error-login/330181)

<div class="topic-metadata">

**Author:** [@Teresajw](https://discuss.elastic.co/u/Teresajw)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 2:07am UTC](https://discuss.elastic.co/t/eck-kibana-8-7-0-error-login/330181 "2023-04-18T02:07:17Z")

</div>

Kibana can not login :cold\_face: :cold\_face: :cold\_face: When I deployed the es cluster and kibana using Elastic Cloud on Kubernetes, the cluster was deployed successfully and in good health, but kibana could not log in…

---

## [Kibana plugin development: Error when creating plugin in Kibana 8.6](https://discuss.elastic.co/t/kibana-plugin-development-error-when-creating-plugin-in-kibana-8-6/329264)

<div class="topic-metadata">

**Author:** [@dms6978](https://discuss.elastic.co/u/dms6978)\
**Replies:** 6\
**Last updated:** [April 18, 2023, 2:27am UTC](https://discuss.elastic.co/t/kibana-plugin-development-error-when-creating-plugin-in-kibana-8-6/329264 "2023-04-18T02:27:54Z")

</div>

When I create and run plugins, the following error occurs. Refused to execute script from 'http://localhost:5601/mvk/9007199254740991/bundles/plugin/helloKibana/1.0.0/helloKibana.plugin.js' because its MIME type ('appl…

---

## [SSL Certificate problem : Unable to get local issuer certificate](https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125)

<div class="topic-metadata">

**Author:** [@dinbabs](https://discuss.elastic.co/u/dinbabs)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 1:18am UTC](https://discuss.elastic.co/t/ssl-certificate-problem-unable-to-get-local-issuer-certificate/330125 "2023-04-18T01:18:21Z")

</div>

Hi, I have deployed standalone Elasticsearch in one of the VM instance of Google Cloud(GCP). The client(Manychat) which I use to connect to Elasticsearch only supports https, so I did the configurations to run Elastics…

---

## [Logstash filter to extract key/values from curl result](https://discuss.elastic.co/t/logstash-filter-to-extract-key-values-from-curl-result/330083)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [April 18, 2023, 1:00am UTC](https://discuss.elastic.co/t/logstash-filter-to-extract-key-values-from-curl-result/330083 "2023-04-18T01:00:52Z")

</div>

Hi Here is the result of curl command that I need to extract key/values (columns,values) and here is the key/value that i need to send to elastic { "series": { "time": "2023-04-16T07:58:40Z", "cpu": "cpu-…

---

## [Sysmon events not getting to SOC kibana or hunt - connection issues](https://discuss.elastic.co/t/sysmon-events-not-getting-to-soc-kibana-or-hunt-connection-issues/327966)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 23\
**Last updated:** [April 17, 2023, 11:47pm UTC](https://discuss.elastic.co/t/sysmon-events-not-getting-to-soc-kibana-or-hunt-connection-issues/327966 "2023-04-17T23:47:57Z")

</div>

Hi, i am using elasticsearch 8.6.2, Winlogbeat 8.6.2 and sysmon 74 I am trying the ELK system. The data gets into sysmon ok. There are probably many reasons. I was pointing to output.logstash because as I understand …

---

## [Subject query data of restaurants by given location topic that we desire for a year](https://discuss.elastic.co/t/subject-query-data-of-restaurants-by-given-location-topic-that-we-desire-for-a-year/330167)

<div class="topic-metadata">

**Author:** [@Nonchaianon](https://discuss.elastic.co/u/Nonchaianon)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 10:15pm UTC](https://discuss.elastic.co/t/subject-query-data-of-restaurants-by-given-location-topic-that-we-desire-for-a-year/330167 "2023-04-17T22:15:42Z")

</div>

Dear elasticsearch technical I’am developer Food delivery platform We desire to improve performance query data of restaurants by given location Condition -50,000 restaurant -200 km^2 -queries 200,000 times per day …

---

## [Help with data management, I have an index with a size of 119GB, what can I do?](https://discuss.elastic.co/t/help-with-data-management-i-have-an-index-with-a-size-of-119gb-what-can-i-do/329866)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 10:00pm UTC](https://discuss.elastic.co/t/help-with-data-management-i-have-an-index-with-a-size-of-119gb-what-can-i-do/329866 "2023-04-17T22:00:36Z")

</div>

I have an index with a size of 119GB that is causing performance issues when search the data. My first thought was to use an index policy to expire old documents but soon I learned the lifecycle policy only works for t…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=567)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=569)
