# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=571

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 572

---

## [Kibana server.publicBaseUrl](https://discuss.elastic.co/t/kibana-server-publicbaseurl/328444)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:05am UTC](https://discuss.elastic.co/t/kibana-server-publicbaseurl/328444 "2023-04-15T04:05:17Z")

</div>

Hi Team , Deployed kibana 8.5.3 through ECK Facing issue like Kibana server.publicBaseUrl Please find kibana manifest file apiVersion: kibana.k8s.elastic.co/v1 kind: Kibana metadata: name: kibana spec: version: 8.…

---

## [Kibana Node High Load](https://discuss.elastic.co/t/kibana-node-high-load/329882)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:02am UTC](https://discuss.elastic.co/t/kibana-node-high-load/329882 "2023-04-15T04:02:20Z")

</div>

Hi all, I"m using Kibana 8.6.2 version cluster with 5 nodes. To handle the query load, I'm using 5 nodes. But ultimately, I have to host Kibana in only 1 node. So even when querying is high and there is a crash for ES…

---

## [TSVB plot to project the rate of a counter against the auto time scale](https://discuss.elastic.co/t/tsvb-plot-to-project-the-rate-of-a-counter-against-the-auto-time-scale/329890)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 3:59am UTC](https://discuss.elastic.co/t/tsvb-plot-to-project-the-rate-of-a-counter-against-the-auto-time-scale/329890 "2023-04-15T03:59:17Z")

</div>

Hi I wanted to create a TSVB for plotting a counter value against the time period. Timestamp is set to 'auto' so that Kibana can plot any number of data points. Now, i want to define a math aggregation to plot a rate …

---

## [Convert Date of birth into Age in KQL](https://discuss.elastic.co/t/convert-date-of-birth-into-age-in-kql/329894)

<div class="topic-metadata">

**Author:** [@Sam\_Armstrong](https://discuss.elastic.co/u/Sam_Armstrong)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 3:54am UTC](https://discuss.elastic.co/t/convert-date-of-birth-into-age-in-kql/329894 "2023-04-15T03:54:55Z")

</div>

Hi there I currently have data stored as 2022-01-25 and am wanting to get out my records in brackets of say 10 yrs. Example: Bar/Pie Chart showing 0-7 yrs - X Clients 8-15 yrs - X Clients 16-25 - X Clients 26-35 - …

---

## [Kibana - Node JS gets terminated without leaving trace](https://discuss.elastic.co/t/kibana-node-js-gets-terminated-without-leaving-trace/329922)

<div class="topic-metadata">

**Author:** [@kiril\_penkov](https://discuss.elastic.co/u/kiril_penkov)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 3:39am UTC](https://discuss.elastic.co/t/kibana-node-js-gets-terminated-without-leaving-trace/329922 "2023-04-15T03:39:30Z")

</div>

Hi, We have an On-Premise clustered deployment on version 7.16.3 of Elasticsearch and Kibana. Our issue is that sometimes, on random the Node.js gets terminated without leaving any trace in Windows or Kibana logs and we…

---

## [Do I have to restart Elasticsearch cluster if I replace CA certificate?](https://discuss.elastic.co/t/do-i-have-to-restart-elasticsearch-cluster-if-i-replace-ca-certificate/329927)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 3:29am UTC](https://discuss.elastic.co/t/do-i-have-to-restart-elasticsearch-cluster-if-i-replace-ca-certificate/329927 "2023-04-15T03:29:35Z")

</div>

Hi, I have elasticsearch 8.6 My certificate is going to expire so I followed the process where restart of cluster is required however I have tested just simple file replacement of CA cert and it seems to work even w…

---

## [TSVB Axis names](https://discuss.elastic.co/t/tsvb-axis-names/329979)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 1:35am UTC](https://discuss.elastic.co/t/tsvb-axis-names/329979 "2023-04-15T01:35:07Z")

</div>

Hi Could anyone please suggest any method to add custom axis names in TSVB chart? I wanted to give suitable names for both Y-axis and X-Axis. I do not see any options in Elasticsearch 8.6.2. Regards Venkatesh

---

## [Drop\_fields](https://discuss.elastic.co/t/drop-fields/330045)

<div class="topic-metadata">

**Author:** [@y34rz3r0](https://discuss.elastic.co/u/y34rz3r0)\
**Replies:** 2\
**Last updated:** [April 15, 2023, 12:00am UTC](https://discuss.elastic.co/t/drop-fields/330045 "2023-04-15T00:00:40Z")

</div>

Hello! I've just started learning ELK and I'm having some confusion with filebeat's drop\_fields processor. My configuration: filebeat.inputs: - type: log paths: - /mnt/var/log/ovpnagent.log fields\_unde…

---

## [Elasticsearch keyword not generated](https://discuss.elastic.co/t/elasticsearch-keyword-not-generated/330043)

<div class="topic-metadata">

**Author:** [@pjangam](https://discuss.elastic.co/u/pjangam)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 9:20pm UTC](https://discuss.elastic.co/t/elasticsearch-keyword-not-generated/330043 "2023-04-14T21:20:01Z")

</div>

I have Elasticsearch entry with text field value as 14-Apr-2023 20:44:46.693 INFO \[pool-2-thread-24\] com.xyz.log \[app\_id:uuid\] calling execute-task with url=https://example.com/api/applications/uuid/tasks/TASK\_NAME/exec…

---

## [How to implement a search by multiple fields and support whitespace, symbols, case insensitive](https://discuss.elastic.co/t/how-to-implement-a-search-by-multiple-fields-and-support-whitespace-symbols-case-insensitive/330030)

<div class="topic-metadata">

**Author:** [@Juan\_Manuel](https://discuss.elastic.co/u/Juan_Manuel)\
**Replies:** 4\
**Last updated:** [April 14, 2023, 8:00pm UTC](https://discuss.elastic.co/t/how-to-implement-a-search-by-multiple-fields-and-support-whitespace-symbols-case-insensitive/330030 "2023-04-14T20:00:12Z")

</div>

I have an index with many fields and I want to be able to search by some of them at the same time, and this search should support partial match (in any position), case insensitive, support some symbols. Example of my in…

---

## [Find Unique values of field while using match query on other field](https://discuss.elastic.co/t/find-unique-values-of-field-while-using-match-query-on-other-field/330037)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 7:02pm UTC](https://discuss.elastic.co/t/find-unique-values-of-field-while-using-match-query-on-other-field/330037 "2023-04-14T19:02:34Z")

</div>

Hello, I would like find all unique set values of field3 that roll up under a specific value of field1 and a specific value of field2. I've tried collapsing on field3 but it gives me the error that no mapping was found…

---

## [Edge n-gram search for terms with optional spaces](https://discuss.elastic.co/t/edge-n-gram-search-for-terms-with-optional-spaces/330018)

<div class="topic-metadata">

**Author:** [@kedomingo](https://discuss.elastic.co/u/kedomingo)\
**Replies:** 3\
**Last updated:** [April 14, 2023, 4:08pm UTC](https://discuss.elastic.co/t/edge-n-gram-search-for-terms-with-optional-spaces/330018 "2023-04-14T16:08:31Z")

</div>

Short version: I have "Pentium 3" and "Pentium4", in the index. I want to be able to search "Pentium 4" and get the record for "Pentium4". I want to be able to search "Pentium3" and get the record for "Pentium 3" I want…

---

## [Alternative to lookup datatype?](https://discuss.elastic.co/t/alternative-to-lookup-datatype/329836)

<div class="topic-metadata">

**Author:** [@captainzura195](https://discuss.elastic.co/u/captainzura195)\
**Replies:** 3\
**Last updated:** [April 14, 2023, 3:53pm UTC](https://discuss.elastic.co/t/alternative-to-lookup-datatype/329836 "2023-04-14T15:53:51Z")

</div>

I wanted to populate a description field using its corresponding key, code, and another index having a key, lookup\_code, column, and a corresponding description column but without the lookup datatype I am finding it hard…

---

## [Rollup - date histogram issues](https://discuss.elastic.co/t/rollup-date-histogram-issues/328509)

<div class="topic-metadata">

**Author:** [@JeroenK](https://discuss.elastic.co/u/JeroenK)\
**Replies:** 5\
**Last updated:** [April 14, 2023, 3:47pm UTC](https://discuss.elastic.co/t/rollup-date-histogram-issues/328509 "2023-04-14T15:47:42Z")

</div>

I have a rollup job with the following settings: "groups": { "date\_histogram": { "field": "timestamp", "time\_zone": "Europe/Stockholm", "calendar\_interval"…

---

## [Configure Plugin through Cluster Settings API - Listen for updates](https://discuss.elastic.co/t/configure-plugin-through-cluster-settings-api-listen-for-updates/329946)

<div class="topic-metadata">

**Author:** [@smillies](https://discuss.elastic.co/u/smillies)\
**Replies:** 5\
**Last updated:** [April 14, 2023, 3:32pm UTC](https://discuss.elastic.co/t/configure-plugin-through-cluster-settings-api-listen-for-updates/329946 "2023-04-14T15:32:05Z")

</div>

Hello there, I am writing a plugin and would like to configure it through the cluster settings API. I have overwritten getSettings, and so far so good. I can also update my dynamic settings through the cluster settings…

---

## [Restrict the Number of Unique term to be indexed for a Document](https://discuss.elastic.co/t/restrict-the-number-of-unique-term-to-be-indexed-for-a-document/329060)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 6\
**Last updated:** [April 14, 2023, 3:15pm UTC](https://discuss.elastic.co/t/restrict-the-number-of-unique-term-to-be-indexed-for-a-document/329060 "2023-04-14T15:15:10Z")

</div>

Hi , I have a requirement wherein I need to restrict the number of unique terms to Index for any Document to 1000. Any unique terms beyond 1000 for a particular document should be ignored and not Index during Indexing. I…

---

## [External URLs not enabled for Vega on Elastic Cloud - Review](https://discuss.elastic.co/t/external-urls-not-enabled-for-vega-on-elastic-cloud-review/329435)

<div class="topic-metadata">

**Author:** [@victorhmorales](https://discuss.elastic.co/u/victorhmorales)\
**Replies:** 4\
**Last updated:** [April 14, 2023, 3:07pm UTC](https://discuss.elastic.co/t/external-urls-not-enabled-for-vega-on-elastic-cloud-review/329435 "2023-04-14T15:07:20Z")

</div>

Hello there, As clarified in previous posts (2018-2020), redirection to external URLs is not enabled for Vega charts on Elastic Cloud for security reasons (vega.enableExternalUrls). I would like to check if there is an…

---

## [Generate node certificate](https://discuss.elastic.co/t/generate-node-certificate/329951)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 4\
**Last updated:** [April 14, 2023, 2:51pm UTC](https://discuss.elastic.co/t/generate-node-certificate/329951 "2023-04-14T14:51:02Z")

</div>

What am I doing wrong? missing some option, parameter? I have my cluster setup with certificate and working fine with following config on all nodes. it was created using /usr/share/elasticsearch/bin/elasticsearch-cert…

---

## [Filebeat Suricata Module "module suricata is configured but has no enabled filesets"](https://discuss.elastic.co/t/filebeat-suricata-module-module-suricata-is-configured-but-has-no-enabled-filesets/329954)

<div class="topic-metadata">

**Author:** [@Aaron\_C\_de\_Bruyn](https://discuss.elastic.co/u/Aaron_C_de_Bruyn)\
**Replies:** 4\
**Last updated:** [April 14, 2023, 2:44pm UTC](https://discuss.elastic.co/t/filebeat-suricata-module-module-suricata-is-configured-but-has-no-enabled-filesets/329954 "2023-04-14T14:44:50Z")

</div>

I'm running filebeat 8.6.2. I initially had it grabbing /var/log/remote.log and it worked fine. Then I enabled the suricata module and set the configuration to this (excluding the output.elasticsearch section): filebe…

---

## [Error when importing Postgres 12 and 15 queries](https://discuss.elastic.co/t/error-when-importing-postgres-12-and-15-queries/330021)

<div class="topic-metadata">

**Author:** [@\_Leonardo\_Moerschber](https://discuss.elastic.co/u/_Leonardo_Moerschber)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 2:04pm UTC](https://discuss.elastic.co/t/error-when-importing-postgres-12-and-15-queries/330021 "2023-04-14T14:04:24Z")

</div>

My environment is for testing: Elasticsearch 8.7 + fleetserver I'm trying to collect queries from Postgres version 12 and version 15 through elastic-agent. I'm not able to collect them through the csv log. Here are th…

---

## [Cannot Retrieve Search Results](https://discuss.elastic.co/t/cannot-retrieve-search-results/328711)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 3\
**Last updated:** [April 14, 2023, 1:56pm UTC](https://discuss.elastic.co/t/cannot-retrieve-search-results/328711 "2023-04-14T13:56:52Z")

</div>

Hello, I have been getting an error message in discover on and off when I run a number of different queries: Cannot Retrieve Search Results Then w/in the text box there is a base64 encoded string. When I decode the …

---

## [Filebeat (Zeek and Suricata) output to Logstash suddenly broke](https://discuss.elastic.co/t/filebeat-zeek-and-suricata-output-to-logstash-suddenly-broke/329909)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 1\
**Last updated:** [April 14, 2023, 1:40pm UTC](https://discuss.elastic.co/t/filebeat-zeek-and-suricata-output-to-logstash-suddenly-broke/329909 "2023-04-14T13:40:17Z")

</div>

Hello, I am sending filebeat data from a network sensor that is running Zeek and Suricata to a logstash server. This server has been sending logs successfully w/o issue for over 6 months. This morning something happened…

---

## [How do you pass custom environment variable on Amazon Elastic Beanstalk (AWS EBS)?](https://discuss.elastic.co/t/how-do-you-pass-custom-environment-variable-on-amazon-elastic-beanstalk-aws-ebs/329972)

<div class="topic-metadata">

**Author:** [@karthik\_kumar](https://discuss.elastic.co/u/karthik_kumar)\
**Replies:** 1\
**Last updated:** [April 14, 2023, 1:38pm UTC](https://discuss.elastic.co/t/how-do-you-pass-custom-environment-variable-on-amazon-elastic-beanstalk-aws-ebs/329972 "2023-04-14T13:38:40Z")

</div>

The Amazon Elastic Beanstalk blurb says: Elastic Beanstalk lets you "open the hood" and retain full control ... even pass environment variables through the Elastic Beanstalk console. How to pass other environment var…

---

## [Is possible to use Filebeat o365 plugin on "offline" data](https://discuss.elastic.co/t/is-possible-to-use-filebeat-o365-plugin-on-offline-data/329998)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 1\
**Last updated:** [April 14, 2023, 1:25pm UTC](https://discuss.elastic.co/t/is-possible-to-use-filebeat-o365-plugin-on-offline-data/329998 "2023-04-14T13:25:14Z")

</div>

Hello community! I have recently discovered o365 module for Filebeat (Office 365 module | Filebeat Reference \[8.7\] | Elastic). My question is: is it possible to use it for offline data? I'm interested to have it since…

---

## [Winlogbeat not pushing logs to elastic](https://discuss.elastic.co/t/winlogbeat-not-pushing-logs-to-elastic/330014)

<div class="topic-metadata">

**Author:** [@Ben\_C8400](https://discuss.elastic.co/u/Ben_C8400)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 1:20pm UTC](https://discuss.elastic.co/t/winlogbeat-not-pushing-logs-to-elastic/330014 "2023-04-14T13:20:16Z")

</div>

Hi all, I've been trying to setup winlogbeat, but have had no success so far. After running the script i get following result, not giving any errors. On Kibana it actually shows the index template, and the dashboards …

---

## [Azure snapshot issue - getting: blob\_storage\_exception","reason":"Status code 400, "﻿\\nBlobTypeNotSupportedBlock blobs are not supported](https://discuss.elastic.co/t/azure-snapshot-issue-getting-blob-storage-exception-reason-status-code-400-nblobtypenotsupportedblock-blobs-are-not-supported/328690)

<div class="topic-metadata">

**Author:** [@Mariusko82](https://discuss.elastic.co/u/Mariusko82)\
**Replies:** 1\
**Last updated:** [April 14, 2023, 12:43pm UTC](https://discuss.elastic.co/t/azure-snapshot-issue-getting-blob-storage-exception-reason-status-code-400-nblobtypenotsupportedblock-blobs-are-not-supported/328690 "2023-04-14T12:43:01Z")

</div>

Elasticsearch Version Version: 8.2.3, Build: default/docker/9905bfb62a3f0b044948376b4f607f70a8a151b4/2022-06-08T22:21:36.455508792Z, JVM: 18.0.1.1 Installed Plugins No response Java Version bundled OS Version Linux el…

---

## [Elasticsearch is not allowing me to upload news category dataset](https://discuss.elastic.co/t/elasticsearch-is-not-allowing-me-to-upload-news-category-dataset/330001)

<div class="topic-metadata">

**Author:** [@Arvind\_Singharpuria](https://discuss.elastic.co/u/Arvind_Singharpuria)\
**Replies:** 2\
**Last updated:** [April 14, 2023, 12:18pm UTC](https://discuss.elastic.co/t/elasticsearch-is-not-allowing-me-to-upload-news-category-dataset/330001 "2023-04-14T12:18:45Z")

</div>

While uploading the dataset, it is showing me this error

---

## [Negative boosting via elastic cloud admin panel](https://discuss.elastic.co/t/negative-boosting-via-elastic-cloud-admin-panel/329999)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 10:39am UTC](https://discuss.elastic.co/t/negative-boosting-via-elastic-cloud-admin-panel/329999 "2023-04-14T10:39:21Z")

</div>

Hi guys! Is it possible to set negative boosting for a specific field via elastic cloud admin panel ( App search). I found an option to set only positive boosting. I know how to do it with API, but is there any way to do…

---

## [Search with cluster wildcard returns data from non-matching indices](https://discuss.elastic.co/t/search-with-cluster-wildcard-returns-data-from-non-matching-indices/329990)

<div class="topic-metadata">

**Author:** [@VincentR](https://discuss.elastic.co/u/VincentR)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 9:41am UTC](https://discuss.elastic.co/t/search-with-cluster-wildcard-returns-data-from-non-matching-indices/329990 "2023-04-14T09:41:24Z")

</div>

Hello, I am currently migrating from Elastic Search 7.17.8 to 8.6.2 and I am observing a very strange change of behaviour in the search API. Using the search REST api, when the index pattern (target) contains both a …

---

## [Pipelined bucket aggregation](https://discuss.elastic.co/t/pipelined-bucket-aggregation/329989)

<div class="topic-metadata">

**Author:** [@HansPeterSloot](https://discuss.elastic.co/u/HansPeterSloot)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 9:38am UTC](https://discuss.elastic.co/t/pipelined-bucket-aggregation/329989 "2023-04-14T09:38:56Z")

</div>

Hello I am ingesting logs from different servers into elastic and want to be alerted when a server suddenly stops sending data. For this I have come up with this aggregation: GET .xxxt\*/\_search?size=0 { "query": { …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=570)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=572)
