# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=590

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 591

---

## [Error in the installation Elasticsearch process](https://discuss.elastic.co/t/error-in-the-installation-elasticsearch-process/328607)

<div class="topic-metadata">

**Author:** [@Hubert\_Homaei](https://discuss.elastic.co/u/Hubert_Homaei)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 10:28pm UTC](https://discuss.elastic.co/t/error-in-the-installation-elasticsearch-process/328607 "2023-03-27T22:28:48Z")

</div>

Hi, I wanted to install Elastic search on a local system; I checked all requirements, installed JDK, and set the variable path for java.exe. But when I execute elasticsearch.bat in CMD, I got this warning: warning: igno…

---

## [Metricbeat:action \[indices:admin/auto\_create\] is unauthorized for user \[metricbeat\] with effective roles \[ES\_metricbeat\] on indices \[metricbeat-8.6.2\], this action is granted by the index privileges](https://discuss.elastic.co/t/metricbeat-action-indices-admin-auto-create-is-unauthorized-for-user-metricbeat-with-effective-roles-es-metricbeat-on-indices-metricbeat-8-6-2-this-action-is-granted-by-the-index-privileges/328648)

<div class="topic-metadata">

**Author:** [@Tussingh](https://discuss.elastic.co/u/Tussingh)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 7:54pm UTC](https://discuss.elastic.co/t/metricbeat-action-indices-admin-auto-create-is-unauthorized-for-user-metricbeat-with-effective-roles-es-metricbeat-on-indices-metricbeat-8-6-2-this-action-is-granted-by-the-index-privileges/328648 "2023-03-27T19:54:33Z")

</div>

I am facing error in ingesting data from metricbeat to elastic. Please help {"log.level":"warn","@timestamp":"2023-03-28T01:22:21.499+0530","log.logger":"elasticsearch","log.origin":{"file.name":"elasticsearch/client.go…

---

## [Several configuration files for one pipeline](https://discuss.elastic.co/t/several-configuration-files-for-one-pipeline/328640)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 6:34pm UTC](https://discuss.elastic.co/t/several-configuration-files-for-one-pipeline/328640 "2023-03-27T18:34:23Z")

</div>

I'm trying to reduce high cpu consumption in our logstash, so i decide to join several pipelines in one and run these configuration files as only one pipeline I'm testing with only two files without filter, only input a…

---

## [Elastic Search First Query is always slow and shards not getting distributed properly](https://discuss.elastic.co/t/elastic-search-first-query-is-always-slow-and-shards-not-getting-distributed-properly/328639)

<div class="topic-metadata">

**Author:** [@Gaurav\_Sachdeva](https://discuss.elastic.co/u/Gaurav_Sachdeva)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elastic-search-first-query-is-always-slow-and-shards-not-getting-distributed-properly/328639 "2023-03-27T18:29:39Z")

</div>

I am creating per day index in Elastic Search ( version: 7.5.1 ). I have 3 nodes in total and 2 shards with one replica each, total disk: 5.6 TB and JVM Heap: 95.8 GB per day index size is 40 GB with 110m documents. I …

---

## [Split data in painless](https://discuss.elastic.co/t/split-data-in-painless/327576)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 6:28pm UTC](https://discuss.elastic.co/t/split-data-in-painless/327576 "2023-03-27T18:28:52Z")

</div>

Hi team This is part of a watcher that i'm doing, but split part is nor working, this is my example String indices = "index1\\nindex2\\n"; String\[\] arr = indices.split('\\n'); return arr; But i g…

---

## [Case\_insensitive not working on wildcard field type with cyrilic data](https://discuss.elastic.co/t/case-insensitive-not-working-on-wildcard-field-type-with-cyrilic-data/326839)

<div class="topic-metadata">

**Author:** [@irfan94](https://discuss.elastic.co/u/irfan94)\
**Replies:** 3\
**Last updated:** [March 27, 2023, 6:27pm UTC](https://discuss.elastic.co/t/case-insensitive-not-working-on-wildcard-field-type-with-cyrilic-data/326839 "2023-03-27T18:27:12Z")

</div>

Hello, When you have an index with field that its type is wildcard and its filled with Cyrillic data and then when you perform wildcard query with case\_insensitive: true, no documents are found. Note: we are currently …

---

## [Comparison between index size and doc source size](https://discuss.elastic.co/t/comparison-between-index-size-and-doc-source-size/328596)

<div class="topic-metadata">

**Author:** [@AlessandroKP](https://discuss.elastic.co/u/AlessandroKP)\
**Replies:** 4\
**Last updated:** [March 27, 2023, 6:18pm UTC](https://discuss.elastic.co/t/comparison-between-index-size-and-doc-source-size/328596 "2023-03-27T18:18:20Z")

</div>

Hello, I have some questions regarding the mapper size plugin and how the size of the source of documents relate to the size of the index. So, I installed the mapper size plugin on a single-node Elasticsearch cluster, …

---

## [Dense vector search using script\_score](https://discuss.elastic.co/t/dense-vector-search-using-script-score/328375)

<div class="topic-metadata">

**Author:** [@Marco\_Scoppetta](https://discuss.elastic.co/u/Marco_Scoppetta)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 5:13pm UTC](https://discuss.elastic.co/t/dense-vector-search-using-script-score/328375 "2023-03-27T17:13:19Z")

</div>

Hi all, I'm trying to run an exact kNN search. I've created the following index with the mappings: await client.indices.create({ index: "semantic-stuff", mappings: { properties: { data: { …

---

## [Filebeat / Haproxy : Grok in pipeline need to have both request and response headers captured to parse them](https://discuss.elastic.co/t/filebeat-haproxy-grok-in-pipeline-need-to-have-both-request-and-response-headers-captured-to-parse-them/328637)

<div class="topic-metadata">

**Author:** [@lpoujol](https://discuss.elastic.co/u/lpoujol)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 4:10pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-grok-in-pipeline-need-to-have-both-request-and-response-headers-captured-to-parse-them/328637 "2023-03-27T16:10:35Z")

</div>

Hi I've been testing Filebeat (8.6.2) to collect logs generated by HAProxy 2.2. The logs are directly sent to Elasticsearch, and treated by the haproxy pipeline setup by Filebeat. In my Haproxy setup, I only capture re…

---

## [Discover - eager loading](https://discuss.elastic.co/t/discover-eager-loading/328458)

<div class="topic-metadata">

**Author:** [@Kamil\_Zielinski](https://discuss.elastic.co/u/Kamil_Zielinski)\
**Replies:** 3\
**Last updated:** [March 27, 2023, 3:56pm UTC](https://discuss.elastic.co/t/discover-eager-loading/328458 "2023-03-27T15:56:46Z")

</div>

Hey, Is there a way to enable the eager loading of the logs in the Kibana/Discovery tab? I'm using Kibana 8.6v. Currently, When I type some query into the Discover search box I get around 400 rows with various JSONs. …

---

## [Teams Connector Kibana with proxy](https://discuss.elastic.co/t/teams-connector-kibana-with-proxy/328482)

<div class="topic-metadata">

**Author:** [@federica.forti](https://discuss.elastic.co/u/federica.forti)\
**Replies:** 3\
**Last updated:** [March 27, 2023, 3:31pm UTC](https://discuss.elastic.co/t/teams-connector-kibana-with-proxy/328482 "2023-03-27T15:31:49Z")

</div>

Hi, we would like to implement Teams connector in Kibana, we create the webhook url but the problem is that this url only works if we use a proxy (we tested as curl in the server). How can we add the proxy setting in t…

---

## [Managed Elasticsearch service in AZURE, GCP and AWC](https://discuss.elastic.co/t/managed-elasticsearch-service-in-azure-gcp-and-awc/328590)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 3\
**Last updated:** [March 27, 2023, 3:24pm UTC](https://discuss.elastic.co/t/managed-elasticsearch-service-in-azure-gcp-and-awc/328590 "2023-03-27T15:24:04Z")

</div>

Would like to know which license - Platinum or Enterprise is considered for the managed elasticsearch service on Azure, AWS and GCP?

---

## [Custom Plugins in Elasticsearch](https://discuss.elastic.co/t/custom-plugins-in-elasticsearch/328432)

<div class="topic-metadata">

**Author:** [@JAYAVARDHAN\_VEJENDLA](https://discuss.elastic.co/u/JAYAVARDHAN_VEJENDLA)\
**Replies:** 7\
**Last updated:** [March 27, 2023, 3:05pm UTC](https://discuss.elastic.co/t/custom-plugins-in-elasticsearch/328432 "2023-03-27T15:05:32Z")

</div>

Hello everyone! We are using Elasticsearch in the Legal and Investigation area. We need to perform Proximity and Wildcard Search in a single query-string query, and we found out that elasticsearch is not providing that f…

---

## [ELK version 8.6.2 - custom data-stream and index name](https://discuss.elastic.co/t/elk-version-8-6-2-custom-data-stream-and-index-name/328382)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 2:53pm UTC](https://discuss.elastic.co/t/elk-version-8-6-2-custom-data-stream-and-index-name/328382 "2023-03-27T14:53:13Z")

</div>

Hi. Since i updated to this new version, i can´t configure a custom name to my index and data-stream. By default, filebeat creates a Data Stream named "filebeat-8.6.2" and a index ".ds-filebeat-8.6.2-2023.03.23-000001"…

---

## [Slowlog will not show specific document searches](https://discuss.elastic.co/t/slowlog-will-not-show-specific-document-searches/328628)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 2:41pm UTC](https://discuss.elastic.co/t/slowlog-will-not-show-specific-document-searches/328628 "2023-03-27T14:41:45Z")

</div>

Hey there, I was trying to get the slowlog for every search operations sent to ES. I saw that I can trace only standard search query, while I cannot see any GET operation of a specific and unique document. is this correc…

---

## [Filebeat - doesn't log kafka processor activity](https://discuss.elastic.co/t/filebeat-doesnt-log-kafka-processor-activity/328623)

<div class="topic-metadata">

**Author:** [@jose\_carlos](https://discuss.elastic.co/u/jose_carlos)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 2:20pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-log-kafka-processor-activity/328623 "2023-03-27T14:20:41Z")

</div>

Hi, Currently monitoring a log file with Filebeat and sending content to Kafka. All is working as expected however, unless we raise the debug level do "debug" we have no idea if Filebeat worked properly. We have a diss…

---

## [Using collapse DSL queries in Kibana?](https://discuss.elastic.co/t/using-collapse-dsl-queries-in-kibana/328500)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 2:20pm UTC](https://discuss.elastic.co/t/using-collapse-dsl-queries-in-kibana/328500 "2023-03-27T14:20:35Z")

</div>

I have a DSL query that I wrote in Dev Console and I'm trying to use it in Kibana to filter down results to show in a pie chart. However, when I add the following script as a filter in Kibana, it removes the collapse por…

---

## [How to add action buttons to a Kibana DashBoard table?](https://discuss.elastic.co/t/how-to-add-action-buttons-to-a-kibana-dashboard-table/328437)

<div class="topic-metadata">

**Author:** [@LucasE](https://discuss.elastic.co/u/LucasE)\
**Replies:** 4\
**Last updated:** [March 27, 2023, 2:19pm UTC](https://discuss.elastic.co/t/how-to-add-action-buttons-to-a-kibana-dashboard-table/328437 "2023-03-27T14:19:57Z")

</div>

Hello everyone, I currently have a Kibana ( 8.3.3 ) DashBoard that uses data from Elastic Search ( Data View ). In this DashBoard I have a table that shows flows, the number of messages sent through each flow etc. I w…

---

## [Assign a role to multiple users](https://discuss.elastic.co/t/assign-a-role-to-multiple-users/328462)

<div class="topic-metadata">

**Author:** [@artax\_sb](https://discuss.elastic.co/u/artax_sb)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 1:59pm UTC](https://discuss.elastic.co/t/assign-a-role-to-multiple-users/328462 "2023-03-27T13:59:29Z")

</div>

I want to assign a new role to my users, but i have 150 users.... there is a way to assign the role to all users at the same time thanks in advance

---

## [Create fleet agent status table for a particular space](https://discuss.elastic.co/t/create-fleet-agent-status-table-for-a-particular-space/328620)

<div class="topic-metadata">

**Author:** [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 1:37pm UTC](https://discuss.elastic.co/t/create-fleet-agent-status-table-for-a-particular-space/328620 "2023-03-27T13:37:51Z")

</div>

Hi Experts, I want to create a custom dashboard for a space in my Kibana to show all agents registered to a particular fleet agent policy. In order to achieve this I used Index pattern .fleet-agents\* with appropriate…

---

## [Logstash could not index event, how to view what server send the event](https://discuss.elastic.co/t/logstash-could-not-index-event-how-to-view-what-server-send-the-event/328619)

<div class="topic-metadata">

**Author:** [@ginokok1996](https://discuss.elastic.co/u/ginokok1996)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 1:28pm UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-how-to-view-what-server-send-the-event/328619 "2023-03-27T13:28:27Z")

</div>

Hi, We are currently receiving quite some errors relating to the same issue: \[2023-03-27T15:13:43,994\]\[WARN \]\[logstash.outputs.elasticsearch\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:…

---

## [Elastic Search Docker Install not starting in AWS Ubuntu](https://discuss.elastic.co/t/elastic-search-docker-install-not-starting-in-aws-ubuntu/328617)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 1:17pm UTC](https://discuss.elastic.co/t/elastic-search-docker-install-not-starting-in-aws-ubuntu/328617 "2023-03-27T13:17:21Z")

</div>

Hi, tried installing Elastic Search through official Docs Docker way. Getting the below error

---

## [Dynamic textbox from kibana dataview](https://discuss.elastic.co/t/dynamic-textbox-from-kibana-dataview/328608)

<div class="topic-metadata">

**Author:** [@joerg55](https://discuss.elastic.co/u/joerg55)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 1:02pm UTC](https://discuss.elastic.co/t/dynamic-textbox-from-kibana-dataview/328608 "2023-03-27T13:02:44Z")

</div>

Hi community, with directly in json embedded data a dynamic text will work like this: { "$schema": "https://vega.github.io/schema/vega/v5.json", "data": { "name": "dataName", "values": \[ {"c1": "1", "…

---

## [Best way to count documents in index](https://discuss.elastic.co/t/best-way-to-count-documents-in-index/328610)

<div class="topic-metadata">

**Author:** [@SalvoDM91](https://discuss.elastic.co/u/SalvoDM91)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 12:37pm UTC](https://discuss.elastic.co/t/best-way-to-count-documents-in-index/328610 "2023-03-27T12:37:33Z")

</div>

Hi Guys, I'm creating a pipeline to calculate a price. I need to multiply the number of documents of my index (with a filter like room = red) with a constant 1.27€. Could you please help me about the best way in order…

---

## [Not able to scroll and sort in drop down control visual in the Kibana 8.6 version](https://discuss.elastic.co/t/not-able-to-scroll-and-sort-in-drop-down-control-visual-in-the-kibana-8-6-version/328476)

<div class="topic-metadata">

**Author:** [@Kibana\_User](https://discuss.elastic.co/u/Kibana_User)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 12:02pm UTC](https://discuss.elastic.co/t/not-able-to-scroll-and-sort-in-drop-down-control-visual-in-the-kibana-8-6-version/328476 "2023-03-27T12:02:15Z")

</div>

Regarding the drop down control option in the Kibana 8.6 version. We are not able to scroll down the list of items in the drop down and it is showing only 10 items by default. We couldn’t find any sort option here to s…

---

## [Is cloudfront codec for logstash working?](https://discuss.elastic.co/t/is-cloudfront-codec-for-logstash-working/328614)

<div class="topic-metadata">

**Author:** [@soumyajk](https://discuss.elastic.co/u/soumyajk)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 11:55am UTC](https://discuss.elastic.co/t/is-cloudfront-codec-for-logstash-working/328614 "2023-03-27T11:55:48Z")

</div>

Hello, Is Cloudfront codec working? logstash\[575080\]: \[2023-03-27T11:50:05,811\]\[ERROR\]\[logstash.inputs.s3 \]\[main\]\[cloudfront\] Failed to read file, processing skipped {:exception=\>Java::JavaLang::IllegalArgumentExc…

---

## [What is the difference between 7.17.8 and 7.17.9](https://discuss.elastic.co/t/what-is-the-difference-between-7-17-8-and-7-17-9/326698)

<div class="topic-metadata">

**Author:** [@Jayasree\_N](https://discuss.elastic.co/u/Jayasree_N)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 10:43am UTC](https://discuss.elastic.co/t/what-is-the-difference-between-7-17-8-and-7-17-9/326698 "2023-03-27T10:43:33Z")

</div>

Hi Team, My current elasticsearch version is 7.17.8, it seems there is a new patch version released 7.17.9. Trying to figure the differences between 7.17.8 and 7.17.9 versions, are there any security vulnerabilities that…

---

## [How to configure these secure headers on the ELK stack hosted on nginx server](https://discuss.elastic.co/t/how-to-configure-these-secure-headers-on-the-elk-stack-hosted-on-nginx-server/328613)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 11:52am UTC](https://discuss.elastic.co/t/how-to-configure-these-secure-headers-on-the-elk-stack-hosted-on-nginx-server/328613 "2023-03-27T11:52:27Z")

</div>

Any thoughts on how to configure the following HTTP secure headers:

---

## [Reindexing loses documents](https://discuss.elastic.co/t/reindexing-loses-documents/327673)

<div class="topic-metadata">

**Author:** [@JanGoAutonomous](https://discuss.elastic.co/u/JanGoAutonomous)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 11:17am UTC](https://discuss.elastic.co/t/reindexing-loses-documents/327673 "2023-03-27T11:17:30Z")

</div>

With the C# NEST client (version 7.17.5), I am updating an index by copying it to a temporary index, re-creating it, and copying the data back again. During this process, some documents get lost. For instance, starting …

---

## [Asking About Dashboard In Kibana](https://discuss.elastic.co/t/asking-about-dashboard-in-kibana/328122)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 5\
**Last updated:** [March 27, 2023, 10:56am UTC](https://discuss.elastic.co/t/asking-about-dashboard-in-kibana/328122 "2023-03-27T10:56:50Z")

</div>

Hi I want to know how packetloss works on the kibana dashboard? if I use the system module, will packet loss display data? i always get 0 packetloss and i once tried to shut down one of my vm to try to get the packetlos…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=589)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=591)
