# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=573

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 574

---

## [KIBANA 7.1X alerts anomaly](https://discuss.elastic.co/t/kibana-7-1x-alerts-anomaly/329924)

<div class="topic-metadata">

**Author:** [@mkibani](https://discuss.elastic.co/u/mkibani)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 12:35pm UTC](https://discuss.elastic.co/t/kibana-7-1x-alerts-anomaly/329924 "2023-04-13T12:35:08Z")

</div>

Hey Community, i have a recurring problem where my Kibana security alerts stop being fired. I have noticed this problem in two clusters, one running Kibana version 7.14.1 and the other running 7.17.2, the queries succe…

---

## [Error in Logstash - failed to parse date field with format strict\_date\_optional\_time||epoch\_millis date-time-parse-exception](https://discuss.elastic.co/t/error-in-logstash-failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis-date-time-parse-exception/329797)

<div class="topic-metadata">

**Author:** [@sarath.sarepaka](https://discuss.elastic.co/u/sarath.sarepaka)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 12:30pm UTC](https://discuss.elastic.co/t/error-in-logstash-failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis-date-time-parse-exception/329797 "2023-04-13T12:30:34Z")

</div>

Hi, We are getting the below error in the logstash. We are using a field called "destination" for both time and string. We observed below issue when the destination field value is a string . ELasticsearch and Logstash …

---

## [How to use pipelines](https://discuss.elastic.co/t/how-to-use-pipelines/329919)

<div class="topic-metadata">

**Author:** [@Hajar\_Lachhab](https://discuss.elastic.co/u/Hajar_Lachhab)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 11:00am UTC](https://discuss.elastic.co/t/how-to-use-pipelines/329919 "2023-04-13T11:00:29Z")

</div>

Hello evryone, I have created a pipeline that parse web logs but I don't know how to apply it on my data view. My data view is filebeat-8.6.2 and my pipeline is this:

---

## [Kibana 8.6 I dont see in fiscovery my data](https://discuss.elastic.co/t/kibana-8-6-i-dont-see-in-fiscovery-my-data/328280)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 10:56am UTC](https://discuss.elastic.co/t/kibana-8-6-i-dont-see-in-fiscovery-my-data/328280 "2023-04-13T10:56:43Z")

</div>

I copied the pipeline from our old stack (7.17) and pasted it to our new ELK stack (8.6). I copied the mapping of one of my indices in the old stack and created a new index in my new kibana with that mapping. In my new…

---

## [Loss of logs when using filebeat 8.4.3 with autodiscover feature is enabled](https://discuss.elastic.co/t/loss-of-logs-when-using-filebeat-8-4-3-with-autodiscover-feature-is-enabled/329918)

<div class="topic-metadata">

**Author:** [@teja\_tata](https://discuss.elastic.co/u/teja_tata)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 10:17am UTC](https://discuss.elastic.co/t/loss-of-logs-when-using-filebeat-8-4-3-with-autodiscover-feature-is-enabled/329918 "2023-04-13T10:17:17Z")

</div>

When configured filebeat with autodiscover feature enabled I could observe some loss of logs with version 8.4.3 filebeat. Is it an expected behaviour or any ongoing ticket on this issue..? Could someone help here..

---

## [Different counts of unique values in Kibana and CSV-export of the raw data](https://discuss.elastic.co/t/different-counts-of-unique-values-in-kibana-and-csv-export-of-the-raw-data/327654)

<div class="topic-metadata">

**Author:** [@Mario\_Lie](https://discuss.elastic.co/u/Mario_Lie)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 10:05am UTC](https://discuss.elastic.co/t/different-counts-of-unique-values-in-kibana-and-csv-export-of-the-raw-data/327654 "2023-04-13T10:05:50Z")

</div>

Hello Community! I am using Kibana v 7.17.9 I count unique values for various log variables (Visualize-\>Metric-\>unique count). But the number of unique values differs slightly, depending on whether I use Kibana or expo…

---

## [How to enable/hide not necessary k8s pod metrics with metricbeat?](https://discuss.elastic.co/t/how-to-enable-hide-not-necessary-k8s-pod-metrics-with-metricbeat/329437)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 11\
**Last updated:** [April 13, 2023, 9:26am UTC](https://discuss.elastic.co/t/how-to-enable-hide-not-necessary-k8s-pod-metrics-with-metricbeat/329437 "2023-04-13T09:26:36Z")

</div>

Hi team, i successfully getting from my multiple cluster the metrics in Kibana. But now i see that i don't want ALL metrics from a cluster the pods.. Example: one Cluster has 15 Pods but i need total 8 Pod of them. I…

---

## [Should we use filebeat include\_lines to pre-filter messages before sent it to logstash?](https://discuss.elastic.co/t/should-we-use-filebeat-include-lines-to-pre-filter-messages-before-sent-it-to-logstash/329914)

<div class="topic-metadata">

**Author:** [@atline](https://discuss.elastic.co/u/atline)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 9:28am UTC](https://discuss.elastic.co/t/should-we-use-filebeat-include-lines-to-pre-filter-messages-before-sent-it-to-logstash/329914 "2023-04-13T09:28:53Z")

</div>

Usually in logstash we could use next to filter messages: filter { grok { match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:logtime}.\*\] %{NOTSPACE:device}: place acquired by %{NOTSPACE:user}" …

---

## [Logstash is not reading data in Docker](https://discuss.elastic.co/t/logstash-is-not-reading-data-in-docker/329666)

<div class="topic-metadata">

**Author:** [@vvsenthil](https://discuss.elastic.co/u/vvsenthil)\
**Replies:** 7\
**Last updated:** [April 13, 2023, 8:08am UTC](https://discuss.elastic.co/t/logstash-is-not-reading-data-in-docker/329666 "2023-04-13T08:08:14Z")

</div>

Hi, Someone would you be able to help me on setting up the logstah in docker. I am able to setup and push the message to Elasticsearch without docker. But if i move the logstah to docker i am not able to push the message…

---

## [Elasticsearch data migration to elastic cloud](https://discuss.elastic.co/t/elasticsearch-data-migration-to-elastic-cloud/329897)

<div class="topic-metadata">

**Author:** [@amaan05](https://discuss.elastic.co/u/amaan05)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 7:43am UTC](https://discuss.elastic.co/t/elasticsearch-data-migration-to-elastic-cloud/329897 "2023-04-13T07:43:46Z")

</div>

Hi, I want to migrate data from elasticsearch to elastic cloud. kindly suggest how can I do the same. Thanks,

---

## [What are fees for cross cluster replication and cross region replication and search](https://discuss.elastic.co/t/what-are-fees-for-cross-cluster-replication-and-cross-region-replication-and-search/329886)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 7:21am UTC](https://discuss.elastic.co/t/what-are-fees-for-cross-cluster-replication-and-cross-region-replication-and-search/329886 "2023-04-13T07:21:34Z")

</div>

As per this link for platinum it is 125 dollars per month. How much it is for onprem will it increase if we use 100GB RAM 2 tb storage for each node.

---

## [Elasticsearch index heavy reads](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739)

<div class="topic-metadata">

**Author:** [@hopa56](https://discuss.elastic.co/u/hopa56)\
**Replies:** 12\
**Last updated:** [April 13, 2023, 6:55am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739 "2023-04-13T06:55:56Z")

</div>

i have 3 indices in the cluster that are read-heavy and the load on the nodes on which the shards of these indices are located is very high (the indexes are small, the largest index weighs 5 gigabytes) we are thinking …

---

## [Elasticsearch local computer, use it on a dreamiest website](https://discuss.elastic.co/t/elasticsearch-local-computer-use-it-on-a-dreamiest-website/329879)

<div class="topic-metadata">

**Author:** [@Francisco\_Martell](https://discuss.elastic.co/u/Francisco_Martell)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 6:24am UTC](https://discuss.elastic.co/t/elasticsearch-local-computer-use-it-on-a-dreamiest-website/329879 "2023-04-13T06:24:30Z")

</div>

if I have Elasticsearch on my local computer running, can I make a search bar and query data to display on a website I host with dream host? Sorry for anybody questions, all these topics are new to me and I haven't foun…

---

## [Indices in red state. "cannot allocate because all found copies of the shard are either stale or corrupt"](https://discuss.elastic.co/t/indices-in-red-state-cannot-allocate-because-all-found-copies-of-the-shard-are-either-stale-or-corrupt/328871)

<div class="topic-metadata">

**Author:** [@Bhuvesh\_Seth](https://discuss.elastic.co/u/Bhuvesh_Seth)\
**Replies:** 10\
**Last updated:** [April 13, 2023, 6:20am UTC](https://discuss.elastic.co/t/indices-in-red-state-cannot-allocate-because-all-found-copies-of-the-shard-are-either-stale-or-corrupt/328871 "2023-04-13T06:20:08Z")

</div>

Hi, we are facing one issue where some of indices health not getting updated to yellow or green due to this error "cannot allocate because all found copies of the shard are either stale or corrupt". Can someone please gu…

---

## [MAX\_LOCKED\_MEMORY=unlimited setting in Elasticsearch 8.x](https://discuss.elastic.co/t/max-locked-memory-unlimited-setting-in-elasticsearch-8-x/329884)

<div class="topic-metadata">

**Author:** [@Tomas\_Bartek](https://discuss.elastic.co/u/Tomas_Bartek)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 5:34am UTC](https://discuss.elastic.co/t/max-locked-memory-unlimited-setting-in-elasticsearch-8-x/329884 "2023-04-13T05:34:29Z")

</div>

Is MAX\_LOCKED\_MEMORY=unlimited settings in /etc/default/elasticsearch (on Ubuntu) still necessary in Elasticsearch 8.x? It looks like settings in /etc/default/elasticsearch system configuration file is quite simplified …

---

## [Mongodb logstash data input](https://discuss.elastic.co/t/mongodb-logstash-data-input/329830)

<div class="topic-metadata">

**Author:** [@jskang](https://discuss.elastic.co/u/jskang)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 5:34am UTC](https://discuss.elastic.co/t/mongodb-logstash-data-input/329830 "2023-04-13T05:34:09Z")

</div>

hello. After struggling for days, I finally connected mongodb and logstash. But another problem arose. I want to send only newly entered logs to the index using sql\_last\_value, but it doesn't work. Is this impossible…

---

## [Unable to send bunyan logs in kibana using elastic apm node module (node js code)](https://discuss.elastic.co/t/unable-to-send-bunyan-logs-in-kibana-using-elastic-apm-node-module-node-js-code/329652)

<div class="topic-metadata">

**Author:** [@sandboxpd123](https://discuss.elastic.co/u/sandboxpd123)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 4:52am UTC](https://discuss.elastic.co/t/unable-to-send-bunyan-logs-in-kibana-using-elastic-apm-node-module-node-js-code/329652 "2023-04-13T04:52:32Z")

</div>

Hi Team, I have created a node js code where I created a bunyan logger class consist of a constructor that returns the logger in below format - public logger: any constructor (serviceName: string) { this.logger = bun…

---

## [Heartbeat to monitor same service installed in mutiple server and check status in which server up or down?,](https://discuss.elastic.co/t/heartbeat-to-monitor-same-service-installed-in-mutiple-server-and-check-status-in-which-server-up-or-down/329434)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 2:33am UTC](https://discuss.elastic.co/t/heartbeat-to-monitor-same-service-installed-in-mutiple-server-and-check-status-in-which-server-up-or-down/329434 "2023-04-13T02:33:22Z")

</div>

Hello All, I'm facing one issue I've configured below http.yml and with config what is happening is that: I have same service installed in multiple servers, ex: abc service on server A,B,C,similarly others also. Now s…

---

## [Removing one of the s3 snapshot repository causing connection pool shutdown](https://discuss.elastic.co/t/removing-one-of-the-s3-snapshot-repository-causing-connection-pool-shutdown/329857)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 2:31am UTC](https://discuss.elastic.co/t/removing-one-of-the-s3-snapshot-repository-causing-connection-pool-shutdown/329857 "2023-04-13T02:31:02Z")

</div>

Hello - When we configure single S3 bucket for backup, snapshot functionality is working as expected. But when we create a additional repository and remove it afterwards, elasticsearch snapshot functionality is failing t…

---

## [Filebeat v.8 can't fetch the EOF with input type filestream](https://discuss.elastic.co/t/filebeat-v-8-cant-fetch-the-eof-with-input-type-filestream/329877)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 1:46am UTC](https://discuss.elastic.co/t/filebeat-v-8-cant-fetch-the-eof-with-input-type-filestream/329877 "2023-04-13T01:46:21Z")

</div>

Hi. In Filebeat v.7.3.2, it used to send the EOF in its logs. However, in Filebeat v.8.6.2, it does not send EOF and cant fetch the end of the file reached. What I changed is the input type log to filestream only. fil…

---

## [Where is “End Of File reached” message in Filebeat logs in v.8?](https://discuss.elastic.co/t/where-is-end-of-file-reached-message-in-filebeat-logs-in-v-8/329161)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 1:31am UTC](https://discuss.elastic.co/t/where-is-end-of-file-reached-message-in-filebeat-logs-in-v-8/329161 "2023-04-13T01:31:13Z")

</div>

My app finishes the connection to Filebeat when the message "End Of File reached" comes out from Filebeat(v.7) logs. However in Filebeat v.8, I can't find the eof message. Does v.8 Filebeat send the message like v.7 use…

---

## [Browser error: Your browser does not meet the security requirements for Kibana](https://discuss.elastic.co/t/browser-error-your-browser-does-not-meet-the-security-requirements-for-kibana/329499)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 10:39pm UTC](https://discuss.elastic.co/t/browser-error-your-browser-does-not-meet-the-security-requirements-for-kibana/329499 "2023-04-12T22:39:27Z")

</div>

Hi all, When my dashboards get loaded in browser, the below error pops up everytime & it gets frustrating to show this pop up to others. Dashboards get loaded , but this error pops up too. I'm using ES version 8.6.2 …

---

## [Date parse error](https://discuss.elastic.co/t/date-parse-error/329871)

<div class="topic-metadata">

**Author:** [@Kostyantyn\_Dobriohlo](https://discuss.elastic.co/u/Kostyantyn_Dobriohlo)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 9:23pm UTC](https://discuss.elastic.co/t/date-parse-error/329871 "2023-04-12T21:23:30Z")

</div>

Hello, I have recently got this problem with parsing date of this format '2022-08-02T9:00:00 AMZ'. failed to parse field \[Date\] of type \[date\] in document with id 'uVxVd4cB4mQncJVwtSB8'. Preview of field's value: '2022-…

---

## [Disabling Hostname Verification on Elasticsearch 7.16 Outbound Connections](https://discuss.elastic.co/t/disabling-hostname-verification-on-elasticsearch-7-16-outbound-connections/329816)

<div class="topic-metadata">

**Author:** [@icey7z](https://discuss.elastic.co/u/icey7z)\
**Replies:** 4\
**Last updated:** [April 12, 2023, 8:01pm UTC](https://discuss.elastic.co/t/disabling-hostname-verification-on-elasticsearch-7-16-outbound-connections/329816 "2023-04-12T20:01:16Z")

</div>

I'm trying to do a remote reindexing from a 5.3 cluster to a 7.16 cluster, and need a way to disable hostname verification when communicating between them. The 5.3 cluster's certificate doesn't match the hostname, and I…

---

## [Graphing boolean values after setting static convert to 0 and 1](https://discuss.elastic.co/t/graphing-boolean-values-after-setting-static-convert-to-0-and-1/327108)

<div class="topic-metadata">

**Author:** [@shelby](https://discuss.elastic.co/u/shelby)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 6:59pm UTC](https://discuss.elastic.co/t/graphing-boolean-values-after-setting-static-convert-to-0-and-1/327108 "2023-04-12T18:59:23Z")

</div>

I have a boolean field in my index. I apply the static conversion to 0,1 I just want to create a simple graph with Timestamp on ths x-axis and 0 or 1 (or empty) on the y axis. However, when I go to lens to try to crea…

---

## [React Vega Issue in Kibana 8.6.2 Version](https://discuss.elastic.co/t/react-vega-issue-in-kibana-8-6-2-version/329665)

<div class="topic-metadata">

**Author:** [@mohammedniyaz](https://discuss.elastic.co/u/mohammedniyaz)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 6:41pm UTC](https://discuss.elastic.co/t/react-vega-issue-in-kibana-8-6-2-version/329665 "2023-04-12T18:41:03Z")

</div>

Hi Team, We are facing the below error while embedding the react vega in kibana 8.6.2 version. Please let you know any solution for this requirement or any fix for the below mentioned issue. React Vega - Component │ …

---

## [Error during plugin bundling , while running gradlew gem command](https://discuss.elastic.co/t/error-during-plugin-bundling-while-running-gradlew-gem-command/329864)

<div class="topic-metadata">

**Author:** [@Theophila\_Vaiz\_R](https://discuss.elastic.co/u/Theophila_Vaiz_R)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 6:08pm UTC](https://discuss.elastic.co/t/error-during-plugin-bundling-while-running-gradlew-gem-command/329864 "2023-04-12T18:08:47Z")

</div>

I created a logstash output plugin and tried building using ./gradlew gem command but locally its fine I changed it as a automated jenkins pipeline there I'm facing this error TypeError: Could not initialize copy of dig…

---

## [Remote cluster license with ECK operator](https://discuss.elastic.co/t/remote-cluster-license-with-eck-operator/329861)

<div class="topic-metadata">

**Author:** [@gidonshn](https://discuss.elastic.co/u/gidonshn)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 5:42pm UTC](https://discuss.elastic.co/t/remote-cluster-license-with-eck-operator/329861 "2023-04-12T17:42:50Z")

</div>

Hi all. I have an ECK operator and that manages two ES clusters in the same k8s namespace. I'm trying to configure one of them as a remote cluster in the other. looking at this doc: https://www.elastic.co/guide/en/cl…

---

## [I want to get all the spaces in my kibana using python API](https://discuss.elastic.co/t/i-want-to-get-all-the-spaces-in-my-kibana-using-python-api/327859)

<div class="topic-metadata">

**Author:** [@Bhrugu\_Sharma](https://discuss.elastic.co/u/Bhrugu_Sharma)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 5:14pm UTC](https://discuss.elastic.co/t/i-want-to-get-all-the-spaces-in-my-kibana-using-python-api/327859 "2023-04-12T17:14:49Z")

</div>

I am trying to write a python script to get all the spaces in my Kibana spaces I tried all the different combos but there seems to be no proper way for it. Here are the few examples that i tired resp = client.api.space…

---

## [Data mapping is not correct in Kibana data table](https://discuss.elastic.co/t/data-mapping-is-not-correct-in-kibana-data-table/329244)

<div class="topic-metadata">

**Author:** [@Tanzeela](https://discuss.elastic.co/u/Tanzeela)\
**Replies:** 10\
**Last updated:** [April 12, 2023, 4:46pm UTC](https://discuss.elastic.co/t/data-mapping-is-not-correct-in-kibana-data-table/329244 "2023-04-12T16:46:10Z")

</div>

Hi Elastic community, I am newbie . I have written code that provide this information, In Discover you can see the data received correct as code Incorrect Data mapping as shown in kibana data table: Data is…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=572)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=574)
