# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=589

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 590

---

## [Kibana table column link value route to new dashboard on click](https://discuss.elastic.co/t/kibana-table-column-link-value-route-to-new-dashboard-on-click/327535)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [March 28, 2023, 1:22pm UTC](https://discuss.elastic.co/t/kibana-table-column-link-value-route-to-new-dashboard-on-click/327535 "2023-03-28T13:22:44Z")

</div>

Hello All, 1)I'm trying to achieve this implementation where in I'm having 1 coulmn that I'd like to convert it into hyperlink and on click of that it should redirect to new dashboard with same filed value showing there…

---

## [Kibana is not able to authenticate elastic search in my k8s deployment](https://discuss.elastic.co/t/kibana-is-not-able-to-authenticate-elastic-search-in-my-k8s-deployment/328708)

<div class="topic-metadata">

**Author:** [@tauqeerahmad104](https://discuss.elastic.co/u/tauqeerahmad104)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 11:16am UTC](https://discuss.elastic.co/t/kibana-is-not-able-to-authenticate-elastic-search-in-my-k8s-deployment/328708 "2023-03-28T11:16:25Z")

</div>

I have to deploy Elasticsearch and kibana on my k8s cluster. The pods were running successfully and worked fine. Then I try adding a username and password for kibana and Elasticsearch. Now Elasticsearch is running smooth…

---

## [API or similar to get data from Elastic into Excel](https://discuss.elastic.co/t/api-or-similar-to-get-data-from-elastic-into-excel/328697)

<div class="topic-metadata">

**Author:** [@HenrikTide](https://discuss.elastic.co/u/HenrikTide)\
**Replies:** 4\
**Last updated:** [March 28, 2023, 12:29pm UTC](https://discuss.elastic.co/t/api-or-similar-to-get-data-from-elastic-into-excel/328697 "2023-03-28T12:29:52Z")

</div>

Is there an API or similar tool available to achieve the goal of getting live data from Elastic into Excel and updating it automatically? /Henrik

---

## [Memory Gauge is not showing up the data for last 15 or 30 Minutes in kibana. For some dashboards it does show](https://discuss.elastic.co/t/memory-gauge-is-not-showing-up-the-data-for-last-15-or-30-minutes-in-kibana-for-some-dashboards-it-does-show/328041)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 10\
**Last updated:** [March 28, 2023, 12:05pm UTC](https://discuss.elastic.co/t/memory-gauge-is-not-showing-up-the-data-for-last-15-or-30-minutes-in-kibana-for-some-dashboards-it-does-show/328041 "2023-03-28T12:05:53Z")

</div>

ELK 7.17.3 Kibana - 7.17.3 Please let me know how to solve this issue of Memory gauge where it does not show values for last 15 minutes or 30 minutes. when i click on edit the memory gauge , i can see the values, but w…

---

## [ReadOnly or hidden filters in kibana discover](https://discuss.elastic.co/t/readonly-or-hidden-filters-in-kibana-discover/328699)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 10:55am UTC](https://discuss.elastic.co/t/readonly-or-hidden-filters-in-kibana-discover/328699 "2023-03-28T10:55:37Z")

</div>

Hello, I am using kibana basic license In my use case I want to make some filters hidden for a specific user and only the admin can modify this hidden filter , also that specific user is able to apply other filters So…

---

## [Pie chart least used](https://discuss.elastic.co/t/pie-chart-least-used/328686)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 10:48am UTC](https://discuss.elastic.co/t/pie-chart-least-used/328686 "2023-03-28T10:48:48Z")

</div>

Hello, I am trying to create a pie chart with the least 10 used permissions. I am trying this But it does not give me the correct number of users for each permission. I am getting only 1. How can I create a visual…

---

## [Not analyzed attribute in nest 7.17](https://discuss.elastic.co/t/not-analyzed-attribute-in-nest-7-17/328600)

<div class="topic-metadata">

**Author:** [@reza\_setareh](https://discuss.elastic.co/u/reza_setareh)\
**Replies:** 5\
**Last updated:** [March 28, 2023, 10:42am UTC](https://discuss.elastic.co/t/not-analyzed-attribute-in-nest-7-17/328600 "2023-03-28T10:42:29Z")

</div>

hi everyone i want to use not analyzed attribute in nest 7.17 but i cant find it it was in old versions with this code Index = FieldIndexOption.NotAnalyzed thank you

---

## [JDBC driver library error](https://discuss.elastic.co/t/jdbc-driver-library-error/328705)

<div class="topic-metadata">

**Author:** [@Rakesh\_Mukherjee](https://discuss.elastic.co/u/Rakesh_Mukherjee)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 10:35am UTC](https://discuss.elastic.co/t/jdbc-driver-library-error/328705 "2023-03-28T10:35:50Z")

</div>

I am using Azure MySql server and trying to ingest logs to logstash using jdbc input plug-in. While running logstash, it is giving me error that Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<LogStash::PluginLoadin…

---

## [How to convert incoming JSON data from HTTP response into a string and store it in a new field in Metricbeat?](https://discuss.elastic.co/t/how-to-convert-incoming-json-data-from-http-response-into-a-string-and-store-it-in-a-new-field-in-metricbeat/328700)

<div class="topic-metadata">

**Author:** [@Karan\_Vyas](https://discuss.elastic.co/u/Karan_Vyas)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 10:12am UTC](https://discuss.elastic.co/t/how-to-convert-incoming-json-data-from-http-response-into-a-string-and-store-it-in-a-new-field-in-metricbeat/328700 "2023-03-28T10:12:32Z")

</div>

I am using Metricbeat's HTTP module to make a request to the RabbitMQ API to retrieve queue data. However, the Metricbeat RabbitMQ module does not include some fields like incoming and delivery rate, so I am making the r…

---

## [Get total number of matched nested objects present in a elastcsearch index](https://discuss.elastic.co/t/get-total-number-of-matched-nested-objects-present-in-a-elastcsearch-index/328418)

<div class="topic-metadata">

**Author:** [@sudheesh](https://discuss.elastic.co/u/sudheesh)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 6:13am UTC](https://discuss.elastic.co/t/get-total-number-of-matched-nested-objects-present-in-a-elastcsearch-index/328418 "2023-03-28T06:13:46Z")

</div>

consider the following example where I have an index with a nested field { "mappings": { "properties": { "class": { "type": "text" }, "subject": { "type": "nested", "prope…

---

## [Optimizing for reads with very small and stable index](https://discuss.elastic.co/t/optimizing-for-reads-with-very-small-and-stable-index/328442)

<div class="topic-metadata">

**Author:** [@Meisseli](https://discuss.elastic.co/u/Meisseli)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 9:41am UTC](https://discuss.elastic.co/t/optimizing-for-reads-with-very-small-and-stable-index/328442 "2023-03-28T09:41:57Z")

</div>

Hello! I'm working with a very small index. It is only 65000 documents and is about 50MB in size. Index is also very "stable" since it is only written once a day and does not receive any writes meanwhile. Because of tha…

---

## [ILM delete phase does not seem to do anything to index](https://discuss.elastic.co/t/ilm-delete-phase-does-not-seem-to-do-anything-to-index/328592)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 9:36am UTC](https://discuss.elastic.co/t/ilm-delete-phase-does-not-seem-to-do-anything-to-index/328592 "2023-03-28T09:36:44Z")

</div>

Hi I have a cloud Instance I use for a research project. It has 180gb disk space and it is almost full and causing problems to my stack. I want to free up some space so I looked at the indices that are using up all my s…

---

## [Processes tab loads forever](https://discuss.elastic.co/t/processes-tab-loads-forever/328694)

<div class="topic-metadata">

**Author:** [@Ivan\_Hosea](https://discuss.elastic.co/u/Ivan_Hosea)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 9:32am UTC](https://discuss.elastic.co/t/processes-tab-loads-forever/328694 "2023-03-28T09:32:55Z")

</div>

Hi I installed metricbeat on my linux host, when I checked on inventory, the processes tab seemed to not be able to load, but when I checked on discover, metricbeat is still able to get the system.process logs properly.…

---

## [Sorting on the sub-aggregation fields and applying Pagination on the same](https://discuss.elastic.co/t/sorting-on-the-sub-aggregation-fields-and-applying-pagination-on-the-same/328693)

<div class="topic-metadata">

**Author:** [@Abhijeet\_Gosai](https://discuss.elastic.co/u/Abhijeet_Gosai)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 9:31am UTC](https://discuss.elastic.co/t/sorting-on-the-sub-aggregation-fields-and-applying-pagination-on-the-same/328693 "2023-03-28T09:31:00Z")

</div>

I need to sort the aggregation on the basis of sub-aggregation values and also apply pagination on the same . I found in documentation that we can do pagination with composite aggregation but can not sort on the basis o…

---

## [Explanation for potential security issue?](https://discuss.elastic.co/t/explanation-for-potential-security-issue/328680)

<div class="topic-metadata">

**Author:** [@amc1](https://discuss.elastic.co/u/amc1)\
**Replies:** 2\
**Last updated:** [March 28, 2023, 8:19am UTC](https://discuss.elastic.co/t/explanation-for-potential-security-issue/328680 "2023-03-28T08:19:49Z")

</div>

Hi all, In this video- the video summary says that adding Letsencrypt certs means that other nodes with publicly signed certs can connect, so use a firewall. I am super confused about this - is it a secur…

---

## [Inaccuracy and noises in elastic search rollup data](https://discuss.elastic.co/t/inaccuracy-and-noises-in-elastic-search-rollup-data/328014)

<div class="topic-metadata">

**Author:** [@Mehrab\_Azad](https://discuss.elastic.co/u/Mehrab_Azad)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 7:13am UTC](https://discuss.elastic.co/t/inaccuracy-and-noises-in-elastic-search-rollup-data/328014 "2023-03-28T07:13:38Z")

</div>

I am new to the ELK stack and Elasticsearch. I am currently storing nginx logs in Elasticsearch and using Kibana to visualize the total bytes over time. The purpose of this is to monitor traffic. To reduce storage requir…

---

## [Data view drop list sort order control](https://discuss.elastic.co/t/data-view-drop-list-sort-order-control/328551)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 7:12am UTC](https://discuss.elastic.co/t/data-view-drop-list-sort-order-control/328551 "2023-03-28T07:12:06Z")

</div>

It is possible to control the list order as well as the default of available Data Views in each Space?

---

## [Restore the old behavior for SearchResponse in Elasticsearch 8](https://discuss.elastic.co/t/restore-the-old-behavior-for-searchresponse-in-elasticsearch-8/328678)

<div class="topic-metadata">

**Author:** [@Emanuel\_Zienecker](https://discuss.elastic.co/u/Emanuel_Zienecker)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 7:00am UTC](https://discuss.elastic.co/t/restore-the-old-behavior-for-searchresponse-in-elasticsearch-8/328678 "2023-03-28T07:00:21Z")

</div>

Due to missing compatibility with the GeoBoundingBox query I am forced to use ad-hoc the new Elasticsearch 8 Java client. According to the documentation, when using the search, a document class must now be specified that…

---

## [Elastic Node.processors configuration](https://discuss.elastic.co/t/elastic-node-processors-configuration/328593)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 2\
**Last updated:** [March 28, 2023, 6:07am UTC](https://discuss.elastic.co/t/elastic-node-processors-configuration/328593 "2023-03-28T06:07:58Z")

</div>

Hi, I am running multiple instances (4 data nodes) on the same machine. When running load tests, I see the each node CPU is ~20-30% and Host CPU is ~92%. Elastic recommend to configure Node.processors in such case an…

---

## [Data is lost after elasticsearch restart](https://discuss.elastic.co/t/data-is-lost-after-elasticsearch-restart/328663)

<div class="topic-metadata">

**Author:** [@simplearebest](https://discuss.elastic.co/u/simplearebest)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 5:57am UTC](https://discuss.elastic.co/t/data-is-lost-after-elasticsearch-restart/328663 "2023-03-28T05:57:05Z")

</div>

The cluster(es 2.4.0) contains three nodes (node137,node138,node139) , create an index, 5 shards, and 1 replica. I follow these steps to test: the cluster status is green. shutdown node137. create large amount of data…

---

## [Multiple CSV data table sheets in 1 single report](https://discuss.elastic.co/t/multiple-csv-data-table-sheets-in-1-single-report/328671)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 5:44am UTC](https://discuss.elastic.co/t/multiple-csv-data-table-sheets-in-1-single-report/328671 "2023-03-28T05:44:01Z")

</div>

Hi all, I'm using Kibana 7.9 Currently in my 1 dashboard, I have 4 data tables. I can download CSV reports from these 4 data tables indiviidually. Is there anyway, I can download these 4 data table CSV's in a single …

---

## [Does Rally support benchmark test to multi-instance elasticsearch in single node?](https://discuss.elastic.co/t/does-rally-support-benchmark-test-to-multi-instance-elasticsearch-in-single-node/328514)

<div class="topic-metadata">

**Author:** [@Qinghe12](https://discuss.elastic.co/u/Qinghe12)\
**Replies:** 5\
**Last updated:** [March 28, 2023, 5:37am UTC](https://discuss.elastic.co/t/does-rally-support-benchmark-test-to-multi-instance-elasticsearch-in-single-node/328514 "2023-03-28T05:37:06Z")

</div>

Hi,I want to start on 2 elasticseach instances（ES0 and ES1） in a single node with different port，and use 2 esrally ( esrally0 and esrally1) to benchmark these 2 elasticseach instances. But I find esrally1 cannot start …

---

## [Optimal size of shard: Is 80GB Per shard ok for this use case](https://discuss.elastic.co/t/optimal-size-of-shard-is-80gb-per-shard-ok-for-this-use-case/328668)

<div class="topic-metadata">

**Author:** [@hitesharyal](https://discuss.elastic.co/u/hitesharyal)\
**Replies:** 3\
**Last updated:** [March 28, 2023, 5:30am UTC](https://discuss.elastic.co/t/optimal-size-of-shard-is-80gb-per-shard-ok-for-this-use-case/328668 "2023-03-28T05:30:51Z")

</div>

I am using version 5.5.2 of Elasticsearch( having 3 Nodes= 64 gb each ) with month wise index creation. Daily data insertion is 17 GB i.e 17 \* 30 = 510 GB/month. Right now i am having 6 shards(85gb/shard),1 replica in …

---

## [Get timestamp from your field](https://discuss.elastic.co/t/get-timestamp-from-your-field/328666)

<div class="topic-metadata">

**Author:** [@akeelow](https://discuss.elastic.co/u/akeelow)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 4:56am UTC](https://discuss.elastic.co/t/get-timestamp-from-your-field/328666 "2023-03-28T04:56:39Z")

</div>

The service writes logs in a special way. Part of the time is specified in the file name 23032807.log (yyMMddHHH). Minutes, seconds and microseconds are written inside the log 03:42.370003 (mm:ss.SSS). I created such a …

---

## [Problem in iran dst](https://discuss.elastic.co/t/problem-in-iran-dst/328334)

<div class="topic-metadata">

**Author:** [@behzad\_alipoor](https://discuss.elastic.co/u/behzad_alipoor)\
**Replies:** 5\
**Last updated:** [March 28, 2023, 4:20am UTC](https://discuss.elastic.co/t/problem-in-iran-dst/328334 "2023-03-28T04:20:52Z")

</div>

in iran dst no longer in use from 21/03/2023 now , data timestamp is okay but kibana shows 1 hour in future because of dst . how can i fix this ? I tested diffrenet timezones in advanced setting in kibana but didn't he…

---

## [\[gc\]\[2661\] overhead, spent \[263ms\] collecting in the last \[1s\]](https://discuss.elastic.co/t/gc-2661-overhead-spent-263ms-collecting-in-the-last-1s/328660)

<div class="topic-metadata">

**Author:** [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Replies:** 2\
**Last updated:** [March 28, 2023, 4:02am UTC](https://discuss.elastic.co/t/gc-2661-overhead-spent-263ms-collecting-in-the-last-1s/328660 "2023-03-28T04:02:24Z")

</div>

ES Version: 6.3.0 OS Version: 7.4 Java Version: 1.8.0\_131 cpu cores: 20 memory: total 64g heap 32g There is nearly only the ES service on the server, I wonder should I decrease the heap size less than 32g? Or tot…

---

## [Kibana developer guide](https://discuss.elastic.co/t/kibana-developer-guide/328421)

<div class="topic-metadata">

**Author:** [@dms6978](https://discuss.elastic.co/u/dms6978)\
**Replies:** 5\
**Last updated:** [March 28, 2023, 2:30am UTC](https://discuss.elastic.co/t/kibana-developer-guide/328421 "2023-03-28T02:30:50Z")

</div>

I ran 'yarn kbn bootstrap' while looking at the kibana developer guide, and the error follows. UNHANDLED EXCEPTION: Error: spawn git ENOENT at Process.ChildProcess.\_handle.onexit (node:internal/child\_process:285:19)…

---

## [Inconsistent scoring starting w/ 7.0.0 (worse in 7.4.0)](https://discuss.elastic.co/t/inconsistent-scoring-starting-w-7-0-0-worse-in-7-4-0/328658)

<div class="topic-metadata">

**Author:** [@workmanw](https://discuss.elastic.co/u/workmanw)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 2:21am UTC](https://discuss.elastic.co/t/inconsistent-scoring-starting-w-7-0-0-worse-in-7-4-0/328658 "2023-03-28T02:21:36Z")

</div>

Hello, I'm in the process of upgrading from 6.x to 7.x. Along the way I discovered an unexpected issue with document updates and relevancy scoring. In my application's integration test suite we have a series of very bas…

---

## [How to clear filebeat so it does not into kibana?](https://discuss.elastic.co/t/how-to-clear-filebeat-so-it-does-not-into-kibana/328485)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 1:28am UTC](https://discuss.elastic.co/t/how-to-clear-filebeat-so-it-does-not-into-kibana/328485 "2023-03-28T01:28:34Z")

</div>

Hi, I know I filebeat in my security onion so-status. I am using windows 10. The events get into my kibana, even when i so-elastic-clear and so-nsm-clear. How can I clear filebeat so kibana is completely empty? thanks …

---

## [Is elasticsearch documents stored on file encrypted?](https://discuss.elastic.co/t/is-elasticsearch-documents-stored-on-file-encrypted/328652)

<div class="topic-metadata">

**Author:** [@eleong](https://discuss.elastic.co/u/eleong)\
**Replies:** 2\
**Last updated:** [March 28, 2023, 12:50am UTC](https://discuss.elastic.co/t/is-elasticsearch-documents-stored-on-file-encrypted/328652 "2023-03-28T00:50:39Z")

</div>

Hi, We have a compliance audit coming up soon and one of the requirement is that the information stored in Elastic (as a SIEM) must be encrypted. Now, I understand that Elastic don't do encryption because these documen…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=588)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=590)
