# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=576

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 577

---

## [What the different between ClusterStateTaskListener and AckedClusterStateTaskListener](https://discuss.elastic.co/t/what-the-different-between-clusterstatetasklistener-and-ackedclusterstatetasklistener/329719)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 10:05am UTC](https://discuss.elastic.co/t/what-the-different-between-clusterstatetasklistener-and-ackedclusterstatetasklistener/329719 "2023-04-11T10:05:25Z")

</div>

what the different between ClusterStateTaskListener.clusterStateProcessed and AckedClusterStateTaskListener.onAllNodesAcked , they all call after elasticsearch publish finish.

---

## [Use .cer file ( security certifciates ) with default elastic search installation](https://discuss.elastic.co/t/use-cer-file-security-certifciates-with-default-elastic-search-installation/329032)

<div class="topic-metadata">

**Author:** [@Nilesh\_Jethwani](https://discuss.elastic.co/u/Nilesh_Jethwani)\
**Replies:** 4\
**Last updated:** [April 11, 2023, 10:13am UTC](https://discuss.elastic.co/t/use-cer-file-security-certifciates-with-default-elastic-search-installation/329032 "2023-04-11T10:13:39Z")

</div>

I have been provided 3 certificate files from one of the providers intermediate.cer root.cer main.cer I want to use the above in my default elasticsearch deployment. Currently http.p12 is being used ( default)

---

## [Elasticsearch Cluster Sizing](https://discuss.elastic.co/t/elasticsearch-cluster-sizing/329703)

<div class="topic-metadata">

**Author:** [@Darshan\_J](https://discuss.elastic.co/u/Darshan_J)\
**Replies:** 4\
**Last updated:** [April 11, 2023, 9:57am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-sizing/329703 "2023-04-11T09:57:00Z")

</div>

The webinar above showcases bunch of formulas for Elasticsearch cluster sizing. There are discussions where responses show unfamiliarity with the formulas or techniques given in the webinar. The discussion also follows…

---

## [Filebeat read different log paths and write to different elastic index with their own ilm policy,How?](https://discuss.elastic.co/t/filebeat-read-different-log-paths-and-write-to-different-elastic-index-with-their-own-ilm-policy-how/327638)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 25\
**Last updated:** [April 11, 2023, 9:47am UTC](https://discuss.elastic.co/t/filebeat-read-different-log-paths-and-write-to-different-elastic-index-with-their-own-ilm-policy-how/327638 "2023-04-11T09:47:23Z")

</div>

Hello All, I'm having a bit of a hard time understanding the best config for our setup. We are running filebeat to ship several logs from different file location to elastic that need their own index template and policy. …

---

## [Logstash input pipelines are slow after restart](https://discuss.elastic.co/t/logstash-input-pipelines-are-slow-after-restart/329715)

<div class="topic-metadata">

**Author:** [@Amit\_Gupta2](https://discuss.elastic.co/u/Amit_Gupta2)\
**Replies:** 1\
**Last updated:** [April 11, 2023, 8:03am UTC](https://discuss.elastic.co/t/logstash-input-pipelines-are-slow-after-restart/329715 "2023-04-11T08:03:56Z")

</div>

Hi Team, I am facing slowness issue in data sync after every restart of logstash. My observation is that input pipeline are taking time to start in parallel. I am using Logstash 6.8 which is deployed on an EC2 instance…

---

## [Logs getting Merged/clubbed with each other in some cases](https://discuss.elastic.co/t/logs-getting-merged-clubbed-with-each-other-in-some-cases/329588)

<div class="topic-metadata">

**Author:** [@shadu88](https://discuss.elastic.co/u/shadu88)\
**Replies:** 10\
**Last updated:** [April 11, 2023, 7:52am UTC](https://discuss.elastic.co/t/logs-getting-merged-clubbed-with-each-other-in-some-cases/329588 "2023-04-11T07:52:05Z")

</div>

Hello Dear ELKs, I'm using logstash7.10 for forward the logs to Qradar and Azure sentinel. Have noticed some irregularities with some log source type. Log flow : heterogenous logs -\> file --\> logstash( file input) --\> …

---

## [How a elastic machine learning(anomaly detection) job depends on historical data?](https://discuss.elastic.co/t/how-a-elastic-machine-learning-anomaly-detection-job-depends-on-historical-data/327806)

<div class="topic-metadata">

**Author:** [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Replies:** 5\
**Last updated:** [April 11, 2023, 6:53am UTC](https://discuss.elastic.co/t/how-a-elastic-machine-learning-anomaly-detection-job-depends-on-historical-data/327806 "2023-04-11T06:53:25Z")

</div>

Hi, Is it possible to redirect one machine learning (anomaly detection) job to a new data stream having the same sets of fields of the old historical index when it is live? Background: We have 10 ML jobs (anomaly det…

---

## [How to add deletion phase in policy (POST does not seem to work)](https://discuss.elastic.co/t/how-to-add-deletion-phase-in-policy-post-does-not-seem-to-work/329409)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 6:53am UTC](https://discuss.elastic.co/t/how-to-add-deletion-phase-in-policy-post-does-not-seem-to-work/329409 "2023-04-11T06:53:07Z")

</div>

I am trying to add a deletion phase in an existing policy. The policy works fine, creating new indices every day. However, I cannot add a deletion phase. Since this is not possible from the UI, I tried with a POST : Bu…

---

## [getFieldMapping request using java API for elasticsearch](https://discuss.elastic.co/t/getfieldmapping-request-using-java-api-for-elasticsearch/329705)

<div class="topic-metadata">

**Author:** [@shwetanb](https://discuss.elastic.co/u/shwetanb)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 5:10am UTC](https://discuss.elastic.co/t/getfieldmapping-request-using-java-api-for-elasticsearch/329705 "2023-04-11T05:10:34Z")

</div>

I am trying to replicate below query DSL using java: GET /test/\_mapping/field/\*?include\_defaults=true I am using below code to get mappings: GetFieldMappingResponse resp = client.indices().getFieldMapping(new GetField…

---

## [Table in dashboards is not showing multiline logs](https://discuss.elastic.co/t/table-in-dashboards-is-not-showing-multiline-logs/328355)

<div class="topic-metadata">

**Author:** [@tulio.farias](https://discuss.elastic.co/u/tulio.farias)\
**Replies:** 11\
**Last updated:** [April 10, 2023, 10:06pm UTC](https://discuss.elastic.co/t/table-in-dashboards-is-not-showing-multiline-logs/328355 "2023-04-10T22:06:18Z")

</div>

In Dashboad, I have created a table to show only ERROR logs' messages, but it is not showing logs with multiple lines: If I go to Discover, I see there is a multiline log (using the same filters): Could someone h…

---

## [How to filter Filebeat output by input id?](https://discuss.elastic.co/t/how-to-filter-filebeat-output-by-input-id/329603)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 4\
**Last updated:** [April 10, 2023, 9:44pm UTC](https://discuss.elastic.co/t/how-to-filter-filebeat-output-by-input-id/329603 "2023-04-10T21:44:02Z")

</div>

I configured filebeat.yml as follows: filebeat.inputs: - type: filestream id: my-input1 paths: - /opt/mything1/logs/\*.log - type: filestream id: my-input2 paths: - /opt/mything2/logs/\*.log - type: file…

---

## [Kibana Dashboard shows no result even if there is non-zero number of hits](https://discuss.elastic.co/t/kibana-dashboard-shows-no-result-even-if-there-is-non-zero-number-of-hits/326668)

<div class="topic-metadata">

**Author:** [@Piotrek](https://discuss.elastic.co/u/Piotrek)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 9:33pm UTC](https://discuss.elastic.co/t/kibana-dashboard-shows-no-result-even-if-there-is-non-zero-number-of-hits/326668 "2023-04-10T21:33:45Z")

</div>

Dear Community, I'm designing my Dashboard with controls, where user can filter all the results on agregated data. However when using particular filters on some values I receive 'No results found' however when inspectin…

---

## [Dashboard as pdf which is scheduled in Advanced watcher alert showing incomplete visuals](https://discuss.elastic.co/t/dashboard-as-pdf-which-is-scheduled-in-advanced-watcher-alert-showing-incomplete-visuals/327083)

<div class="topic-metadata">

**Author:** [@Avinash\_J](https://discuss.elastic.co/u/Avinash_J)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 9:27pm UTC](https://discuss.elastic.co/t/dashboard-as-pdf-which-is-scheduled-in-advanced-watcher-alert-showing-incomplete-visuals/327083 "2023-04-10T21:27:35Z")

</div>

Hi Team, I have created an Advanced watcher alert in which a dashboard will be shared as pdf to the mentioned email id's. As my dashboard contains too many visuals and the index pattern used for dashboard holds large v…

---

## [Control/filter how to show only possible values](https://discuss.elastic.co/t/control-filter-how-to-show-only-possible-values/328377)

<div class="topic-metadata">

**Author:** [@pratverd](https://discuss.elastic.co/u/pratverd)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 9:23pm UTC](https://discuss.elastic.co/t/control-filter-how-to-show-only-possible-values/328377 "2023-04-10T21:23:50Z")

</div>

Hi everyone :slight\_smile: I'm trying to filter with controls and I would like to have only possible values when I choose a filter and I have to filter with another one. Above an example: | filter 1 | filter 2 | | ap…

---

## [FIPS 140-2 Config, On-Prem](https://discuss.elastic.co/t/fips-140-2-config-on-prem/329686)

<div class="topic-metadata">

**Author:** [@pschadha1](https://discuss.elastic.co/u/pschadha1)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 9:05pm UTC](https://discuss.elastic.co/t/fips-140-2-config-on-prem/329686 "2023-04-10T21:05:04Z")

</div>

Hello, We have a requirement to run ES in FIPS mode. I understand that xpack.security.fips\_mode.enabled is what allows ES to run in a JVM that is configured for FIPS. I also understand that it requires a Platinum lice…

---

## [How to display a "string" metric](https://discuss.elastic.co/t/how-to-display-a-string-metric/327815)

<div class="topic-metadata">

**Author:** [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 8:34pm UTC](https://discuss.elastic.co/t/how-to-display-a-string-metric/327815 "2023-04-10T20:34:57Z")

</div>

Hi! I want to display a single string in my dashboard - a hash that represents the commit hash of the repo from which the visualized data was generated. Ideally I'd like to use the "Metric" visualization, since it's on…

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/329632)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 24\
**Last updated:** [April 10, 2023, 8:02pm UTC](https://discuss.elastic.co/t/elasticsearch/329632 "2023-04-10T20:02:57Z")

</div>

HI I I want to run the container of elasticsearch : i use this command docker run --name es01 --net elastic -p 9200:9200 -it docker.elastic.co/elasticsearch/elasticsearch:8.2.3 and this : docker cp es01:/usr/share/e…

---

## [Storage Configuration Question](https://discuss.elastic.co/t/storage-configuration-question/329675)

<div class="topic-metadata">

**Author:** [@Safty](https://discuss.elastic.co/u/Safty)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 8:00pm UTC](https://discuss.elastic.co/t/storage-configuration-question/329675 "2023-04-10T20:00:21Z")

</div>

Hello, In the storage documentation link There is a reference in the path.data section that states the following: "Elasticsearch requires the filesystem to act as if it were backed by a local disk, but this means that…

---

## [Can't get filebeat to read filestream](https://discuss.elastic.co/t/cant-get-filebeat-to-read-filestream/329598)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 2\
**Last updated:** [April 10, 2023, 7:22pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-read-filestream/329598 "2023-04-10T19:22:13Z")

</div>

I'm trying to switch my filebeat "logs" streams to filestreams. I set up a really simple prospector file: --- filebeat.inputs: - type: filestream id: admintools paths: - '/home/geo/nba/6.3.5.1280/logs/admin-tool…

---

## [Pod container logs stop randomly](https://discuss.elastic.co/t/pod-container-logs-stop-randomly/325632)

<div class="topic-metadata">

**Author:** [@woodywoodsta](https://discuss.elastic.co/u/woodywoodsta)\
**Replies:** 5\
**Last updated:** [April 10, 2023, 5:20pm UTC](https://discuss.elastic.co/t/pod-container-logs-stop-randomly/325632 "2023-04-10T17:20:23Z")

</div>

Since upgrading to 8.6.1 (from 8.5.x), I'm finding that logs that are supposed to be collected via the Kubernetes Integration for an elastic agent in Fleet mode are stopping completely and randomly (as far as I can see). …

---

## [SSL alert number 47](https://discuss.elastic.co/t/ssl-alert-number-47/329599)

<div class="topic-metadata">

**Author:** [@nielarshi](https://discuss.elastic.co/u/nielarshi)\
**Replies:** 4\
**Last updated:** [April 10, 2023, 3:55pm UTC](https://discuss.elastic.co/t/ssl-alert-number-47/329599 "2023-04-10T15:55:30Z")

</div>

I am trying to setup Elasticsearch and Kibana 8.7.0 but facing issue with Kibana setup. It is failing with \[ERROR\]\[elasticsearch-service\] Unable to retrieve version information from Elasticsearch nodes. write EPROTO 14…

---

## [Help - Display correct document from multiple aggregation](https://discuss.elastic.co/t/help-display-correct-document-from-multiple-aggregation/329669)

<div class="topic-metadata">

**Author:** [@Santiago\_Lovera](https://discuss.elastic.co/u/Santiago_Lovera)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 3:18pm UTC](https://discuss.elastic.co/t/help-display-correct-document-from-multiple-aggregation/329669 "2023-04-10T15:18:35Z")

</div>

I need help please. I want to display a label in vega with information returned by one aggregation operation. I'm only looking for just 2 documents the minimum and the maximum for the log.json.sequence field. When I …

---

## [Elastic Agent v8.7.0, Filebeat UDP listener error](https://discuss.elastic.co/t/elastic-agent-v8-7-0-filebeat-udp-listener-error/329579)

<div class="topic-metadata">

**Author:** [@rowra](https://discuss.elastic.co/u/rowra)\
**Replies:** 5\
**Last updated:** [April 10, 2023, 2:55pm UTC](https://discuss.elastic.co/t/elastic-agent-v8-7-0-filebeat-udp-listener-error/329579 "2023-04-10T14:55:47Z")

</div>

Hi After upgrading from 8.6.2 to 8.7.0 this error happens all the time causing the agent/filebeat to crash and restart: nagent | {"log.level":"error","@timestamp":"2023-04-07T12:57:29.090+0200","message":"panic: runti…

---

## [Error 400 - Rejected by Elasticsearch](https://discuss.elastic.co/t/error-400-rejected-by-elasticsearch/329661)

<div class="topic-metadata">

**Author:** [@bobus](https://discuss.elastic.co/u/bobus)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 1:50pm UTC](https://discuss.elastic.co/t/error-400-rejected-by-elasticsearch/329661 "2023-04-10T13:50:46Z")

</div>

I'm trying to install the newest EFK stack on a Kubernetes cluster. ES and Kibana Helm charts are from Bitnami, while Fluentd is from Kokuwa (Bitnami's Fluentd simply doesn't work for me, if fails to link to ES). The ver…

---

## [Simple\_query\_string is not matching correctly](https://discuss.elastic.co/t/simple-query-string-is-not-matching-correctly/329656)

<div class="topic-metadata">

**Author:** [@jilson](https://discuss.elastic.co/u/jilson)\
**Replies:** 2\
**Last updated:** [April 10, 2023, 1:39pm UTC](https://discuss.elastic.co/t/simple-query-string-is-not-matching-correctly/329656 "2023-04-10T13:39:03Z")

</div>

I am trying the below query using simple\_query\_string to match customer\_id GET order-info/\_search { "query": { "simple\_query\_string": { "query": "1c0298d6-a911-5044-a904-6e848fb05eef", "fields": \["cust…

---

## [Treemap aggregation is not right](https://discuss.elastic.co/t/treemap-aggregation-is-not-right/329539)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 4\
**Last updated:** [April 10, 2023, 12:27pm UTC](https://discuss.elastic.co/t/treemap-aggregation-is-not-right/329539 "2023-04-10T12:27:58Z")

</div>

Hi, When showing a 2 level tree map if the bottom level is averaged why does the top level sum the averages? {"Country": "India", "sample":1 , "State":"Karnataka" } {"Country": "India", "sample": 2, "State":"Delhi" }…

---

## [How to created multi field parsh message from snort](https://discuss.elastic.co/t/how-to-created-multi-field-parsh-message-from-snort/329637)

<div class="topic-metadata">

**Author:** [@wisnu\_adiputra](https://discuss.elastic.co/u/wisnu_adiputra)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 12:15pm UTC](https://discuss.elastic.co/t/how-to-created-multi-field-parsh-message-from-snort/329637 "2023-04-10T12:15:06Z")

</div>

Continuing the discussion from Grok pattern for snort alerts: 1/03-21:37:12.106096 \[\] \[1:249:8\] DDOS mstream client to handler \[\] \[Classification: Attempted Denial of Service\] \[Priority: 2\] {TCP} 172.16.0.5:61301 -\> 19…

---

## [How can I make logstash automatically send my information to elasticsearch?](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447)

<div class="topic-metadata">

**Author:** [@Raul\_dum](https://discuss.elastic.co/u/Raul_dum)\
**Replies:** 5\
**Last updated:** [April 10, 2023, 7:38am UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447 "2023-04-10T07:38:20Z")

</div>

Hi I was wondering if there is a method on how I could make logstash automatically send information to my elasticsearch.I have my config file : input { stdin {} } filter { grok { match =\> { "message" =\> "time=…

---

## [KQL formula in vega lite](https://discuss.elastic.co/t/kql-formula-in-vega-lite/328420)

<div class="topic-metadata">

**Author:** [@Nanditha](https://discuss.elastic.co/u/Nanditha)\
**Replies:** 2\
**Last updated:** [April 10, 2023, 8:08am UTC](https://discuss.elastic.co/t/kql-formula-in-vega-lite/328420 "2023-04-10T08:08:01Z")

</div>

Hi Team, I'm trying to plot a line graph using vega-lite. How to give KQL formulas in vega-lite. I used field called "claculate" but may be my syntax is wrong. Please help on creating line graph. { "$schema": "https:…

---

## [Self Managed ElasticSearch Cluster on AWS](https://discuss.elastic.co/t/self-managed-elasticsearch-cluster-on-aws/329645)

<div class="topic-metadata">

**Author:** [@shreyansh](https://discuss.elastic.co/u/shreyansh)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 7:48am UTC](https://discuss.elastic.co/t/self-managed-elasticsearch-cluster-on-aws/329645 "2023-04-10T07:48:35Z")

</div>

I am trying to setup a production ready self managed Elasticsearch cluster on AWS. The main reason for going self managed is that we want: Latest ES version (8.6+) Deploy in a specific VPC Install custom plugins We ar…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=575)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=577)
