# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=600

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 601

---

## [Kibana degraded, available on Kubernetes](https://discuss.elastic.co/t/kibana-degraded-available-on-kubernetes/327059)

<div class="topic-metadata">

**Author:** [@PustyB](https://discuss.elastic.co/u/PustyB)\
**Replies:** 3\
**Last updated:** [March 19, 2023, 11:26pm UTC](https://discuss.elastic.co/t/kibana-degraded-available-on-kubernetes/327059 "2023-03-19T23:26:58Z")

</div>

Hey I've had a problem with Kibana for a while now. I installed Elastic Stack on kubernetes using the operator. At first everything was fine, however, since some time in the kibana logs it started throwing such errors: …

---

## [Receiving harvestor errors and invalid CRI log format on filebeat](https://discuss.elastic.co/t/receiving-harvestor-errors-and-invalid-cri-log-format-on-filebeat/327347)

<div class="topic-metadata">

**Author:** [@Narendra](https://discuss.elastic.co/u/Narendra)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 10:41am UTC](https://discuss.elastic.co/t/receiving-harvestor-errors-and-invalid-cri-log-format-on-filebeat/327347 "2023-03-09T10:41:06Z")

</div>

Hi, I have an ELK setup with deamonset filebeat(7.14) as input from 31 kubernetes nodes moved to logstash and then to ES. From couple of days we and are facing log drop and getting below logs in Filebeat. \<\<\<\<\<\<\<\<\<\< …

---

## [How to use Java api UpdateRequest for conditional write with optimistic locking control in place](https://discuss.elastic.co/t/how-to-use-java-api-updaterequest-for-conditional-write-with-optimistic-locking-control-in-place/327386)

<div class="topic-metadata">

**Author:** [@ted2349](https://discuss.elastic.co/u/ted2349)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 6:28pm UTC](https://discuss.elastic.co/t/how-to-use-java-api-updaterequest-for-conditional-write-with-optimistic-locking-control-in-place/327386 "2023-03-09T18:28:38Z")

</div>

Hi, My scenario is upsert the whole document with optimistic locking control (seqno/ primary term) I also want to do some conditional update meaning I want to update only when current doc's updatedAt is earlier than w…

---

## [How to get the Elastic search data running on my docker in my host](https://discuss.elastic.co/t/how-to-get-the-elastic-search-data-running-on-my-docker-in-my-host/327402)

<div class="topic-metadata">

**Author:** [@Anubhavg](https://discuss.elastic.co/u/Anubhavg)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 11:15pm UTC](https://discuss.elastic.co/t/how-to-get-the-elastic-search-data-running-on-my-docker-in-my-host/327402 "2023-03-19T23:15:09Z")

</div>

I am running the docker image of Elasticsearch and not able to bind the volume (/usr/share/elasticsearch/data) to my host volume (/home). I am using the following command: sudo docker run --name els6 --net elasticsearc…

---

## [Auditbeat vs elastic endpoint for collecting endpoint data](https://discuss.elastic.co/t/auditbeat-vs-elastic-endpoint-for-collecting-endpoint-data/327410)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 4:34am UTC](https://discuss.elastic.co/t/auditbeat-vs-elastic-endpoint-for-collecting-endpoint-data/327410 "2023-03-10T04:34:40Z")

</div>

Hi all, My elastic cluster is currently using both auditbeat and elastic endpoint to collect data from the endpoint server but due to limited space in the data node i have to cut off 1 type. I want to ask if which one …

---

## [Getting the latest transform trigger time in a continuous transform](https://discuss.elastic.co/t/getting-the-latest-transform-trigger-time-in-a-continuous-transform/327420)

<div class="topic-metadata">

**Author:** [@cwwongaz](https://discuss.elastic.co/u/cwwongaz)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 7:49am UTC](https://discuss.elastic.co/t/getting-the-latest-transform-trigger-time-in-a-continuous-transform/327420 "2023-03-10T07:49:03Z")

</div>

Hi, I am running a continuous transform at a 15-minute frequency to transform the data from index\_A to index\_B. In the transform, I have set a 120s sync delay time to avoid missing the latest data. However, in the aggre…

---

## [Elasticsearch function\_score not working inside nested aggregations](https://discuss.elastic.co/t/elasticsearch-function-score-not-working-inside-nested-aggregations/327479)

<div class="topic-metadata">

**Author:** [@frarafra](https://discuss.elastic.co/u/frarafra)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 11:28pm UTC](https://discuss.elastic.co/t/elasticsearch-function-score-not-working-inside-nested-aggregations/327479 "2023-03-10T23:28:36Z")

</div>

I have an Elasticsearch query with nested aggregations. It was working as expected but when I added a function\_score query it seems to not take it into account. This is my query: GET reviews/\_search { "size": 0, "a…

---

## [Field data type conflict](https://discuss.elastic.co/t/field-data-type-conflict/327507)

<div class="topic-metadata">

**Author:** [@Sara\_YB](https://discuss.elastic.co/u/Sara_YB)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 11:05pm UTC](https://discuss.elastic.co/t/field-data-type-conflict/327507 "2023-03-19T23:05:22Z")

</div>

I have nested field type (text, long). After upgrading to v 8.6, a conflict happened in this field. Below is the message I got: "The type of the (field name) field changes across indices and might not be available for s…

---

## [Globalsearch: Resolving Logic From Person Type to Country Type](https://discuss.elastic.co/t/globalsearch-resolving-logic-from-person-type-to-country-type/327736)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 11:00pm UTC](https://discuss.elastic.co/t/globalsearch-resolving-logic-from-person-type-to-country-type/327736 "2023-03-19T23:00:46Z")

</div>

We have a "globalsearch" index that stores "person", "address", "country" information in one single index: { "id":"PER\_0001", "type":"person", "addressId":"ADDR\_001" }, { "id":"ADDR\_001", "type":"address", "countryId":"…

---

## [Filebeat consumes all memory](https://discuss.elastic.co/t/filebeat-consumes-all-memory/327592)

<div class="topic-metadata">

**Author:** [@Radoslav\_Stefanov](https://discuss.elastic.co/u/Radoslav_Stefanov)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 10:39pm UTC](https://discuss.elastic.co/t/filebeat-consumes-all-memory/327592 "2023-03-19T22:39:45Z")

</div>

Hi! I have the following setup to ingest logs from s3. filebeat pulls data from s3 and sends it to logstash. logstash ingests into elastic. The problem is after a while (usually a day or two) filebeat consumes all se…

---

## [Sankey vega using netflow collection with Elastiflow/Elasticsearch/Kibana](https://discuss.elastic.co/t/sankey-vega-using-netflow-collection-with-elastiflow-elasticsearch-kibana/327603)

<div class="topic-metadata">

**Author:** [@jvunc](https://discuss.elastic.co/u/jvunc)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 1:24am UTC](https://discuss.elastic.co/t/sankey-vega-using-netflow-collection-with-elastiflow-elasticsearch-kibana/327603 "2023-03-14T01:24:29Z")

</div>

reeting I have netflow data collection through Elastiflow/elasticsearch/kibana which display correctly sankey screenshot, on Visualize menu. this is the request for selected timestamp: { "size": 0, "aggs": { …

---

## [Logstash plugins unit tests](https://discuss.elastic.co/t/logstash-plugins-unit-tests/327686)

<div class="topic-metadata">

**Author:** [@mabourgeot](https://discuss.elastic.co/u/mabourgeot)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 3:43pm UTC](https://discuss.elastic.co/t/logstash-plugins-unit-tests/327686 "2023-03-14T15:43:26Z")

</div>

Hi there ! I'm very new to JRuby unit tests and I'm struggling a bit to run existing unit tests in GitHub - logstash-plugins/logstash-integration-aws. I've opened a PR to add a feature and would like to add some tests …

---

## [How to resolve metricbeat docker container internal errors?](https://discuss.elastic.co/t/how-to-resolve-metricbeat-docker-container-internal-errors/327689)

<div class="topic-metadata">

**Author:** [@angel1](https://discuss.elastic.co/u/angel1)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 4:04pm UTC](https://discuss.elastic.co/t/how-to-resolve-metricbeat-docker-container-internal-errors/327689 "2023-03-14T16:04:41Z")

</div>

Hello, I am new to this forum but I am glad it exists. I recently started using the ELK stack and I am still new to it. I am currently trying to setup a docker-compose file with my microservices plus elasticsearch, kib…

---

## [Formatting problems when I import a metricbeat index from one elastic instance to another](https://discuss.elastic.co/t/formatting-problems-when-i-import-a-metricbeat-index-from-one-elastic-instance-to-another/327808)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 10:21pm UTC](https://discuss.elastic.co/t/formatting-problems-when-i-import-a-metricbeat-index-from-one-elastic-instance-to-another/327808 "2023-03-19T22:21:30Z")

</div>

I am exporting a metricbeat index from elastic using logstash. I am using the following pipeline: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearc…

---

## [How do I output metadata when exporting data from elasticsearch with logstash?](https://discuss.elastic.co/t/how-do-i-output-metadata-when-exporting-data-from-elasticsearch-with-logstash/327684)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 3:15pm UTC](https://discuss.elastic.co/t/how-do-i-output-metadata-when-exporting-data-from-elasticsearch-with-logstash/327684 "2023-03-14T15:15:44Z")

</div>

I am using the following pipeline in logstash: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearch { hosts =\> "http://localhost:9200" …

---

## [Require Changing Password on First Login](https://discuss.elastic.co/t/require-changing-password-on-first-login/327735)

<div class="topic-metadata">

**Author:** [@htunahan](https://discuss.elastic.co/u/htunahan)\
**Replies:** 2\
**Last updated:** [March 19, 2023, 10:19pm UTC](https://discuss.elastic.co/t/require-changing-password-on-first-login/327735 "2023-03-19T22:19:39Z")

</div>

Hi, I am using Kibana 8.6.1 and I am creating some users. I am giving temporary passwords to them but actually I need that Kibana should ask to change passwords on their first login. Can I do that? If I can, should I do…

---

## [How to list CLOSED indices on 6.4.X?](https://discuss.elastic.co/t/how-to-list-closed-indices-on-6-4-x/327861)

<div class="topic-metadata">

**Author:** [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Replies:** 2\
**Last updated:** [March 19, 2023, 10:17pm UTC](https://discuss.elastic.co/t/how-to-list-closed-indices-on-6-4-x/327861 "2023-03-19T22:17:16Z")

</div>

Hi I'm trying to get a list of closed indices on ES 6.4.2.... This /\_cluster/state/blocks?pretty this returns { "cluster\_name" : "XXXXXX", "compressed\_size\_in\_bytes" : 961428, "cluster\_uuid" : "XXXXXX", "blocks"…

---

## [Elastic and Kibana](https://discuss.elastic.co/t/elastic-and-kibana/327548)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 5\
**Last updated:** [March 19, 2023, 8:45pm UTC](https://discuss.elastic.co/t/elastic-and-kibana/327548 "2023-03-19T20:45:59Z")

</div>

Hi Team, I have installed the elasticsearch(8.5.3) and kibana throgh eck , its working I can able to login If we login first time i'm getting issue like \< elastic did not load properly check the server output for infor…

---

## [Kibana becomes unavailable](https://discuss.elastic.co/t/kibana-becomes-unavailable/327868)

<div class="topic-metadata">

**Author:** [@selvaraj-sembulingam](https://discuss.elastic.co/u/selvaraj-sembulingam)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 8:44pm UTC](https://discuss.elastic.co/t/kibana-becomes-unavailable/327868 "2023-03-19T20:44:29Z")

</div>

Hi Team, My Kibana Web UI becomes unavailable quite often. From the logs I could see it as, \[INFO\] \[status\] Kibana is now degraded (was unavailable) \[INFO\] \[status\] Kibana is now available (was degraded) Elasticsearc…

---

## [Elastic Agent Kubernetes Integration Logs Moniotring](https://discuss.elastic.co/t/elastic-agent-kubernetes-integration-logs-moniotring/327881)

<div class="topic-metadata">

**Author:** [@Savva\_Morozov](https://discuss.elastic.co/u/Savva_Morozov)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 8:40pm UTC](https://discuss.elastic.co/t/elastic-agent-kubernetes-integration-logs-moniotring/327881 "2023-03-16T20:40:19Z")

</div>

Hello! I am using Elastic Agent on Kubernetes and I am using Kubernetes integration to capture the logs, but I would like to capture logs only from our applications and filter out the logs of Kubernetes components. I sa…

---

## [Error Add New Node Elasticsearch](https://discuss.elastic.co/t/error-add-new-node-elasticsearch/327814)

<div class="topic-metadata">

**Author:** [@ilham\_bahrul](https://discuss.elastic.co/u/ilham_bahrul)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 8:40pm UTC](https://discuss.elastic.co/t/error-add-new-node-elasticsearch/327814 "2023-03-19T20:40:39Z")

</div>

I want to add new nodes in my cluster from 3 nodes to 4 nodes. The condition of port 9300 and 9200 is already open on each node. However, I encountered a problem when adding a new node. the following is the error that oc…

---

## [How big should the disk of each node usually be configured reasonably?](https://discuss.elastic.co/t/how-big-should-the-disk-of-each-node-usually-be-configured-reasonably/327897)

<div class="topic-metadata">

**Author:** [@jaryzhong](https://discuss.elastic.co/u/jaryzhong)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 8:40pm UTC](https://discuss.elastic.co/t/how-big-should-the-disk-of-each-node-usually-be-configured-reasonably/327897 "2023-03-19T20:40:06Z")

</div>

We have 10TB of data and this 10TB of data already contains all replicas, we have 5 data nodes, each node will store 2TB of data, how big should the disk of each node usually be configured reasonably?

---

## [How to address json objects in a json array in jdbc-output-plugin logstash conf?](https://discuss.elastic.co/t/how-to-address-json-objects-in-a-json-array-in-jdbc-output-plugin-logstash-conf/327980)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 0\
**Last updated:** [March 18, 2023, 6:56am UTC](https://discuss.elastic.co/t/how-to-address-json-objects-in-a-json-array-in-jdbc-output-plugin-logstash-conf/327980 "2023-03-18T06:56:16Z")

</div>

for example you have this json array : { "accounting" : \[ { "firstName" : "John", "lastName" : "Doe", "age" : 23 }, …

---

## [Solr to Elasticsearch Migration](https://discuss.elastic.co/t/solr-to-elasticsearch-migration/327981)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 3\
**Last updated:** [March 19, 2023, 5:51pm UTC](https://discuss.elastic.co/t/solr-to-elasticsearch-migration/327981 "2023-03-19T17:51:49Z")

</div>

Is there any migration guidelines for migration from Apache Solr to Elasticsearch?

---

## [Add a field to @metadata dictionary](https://discuss.elastic.co/t/add-a-field-to-metadata-dictionary/328025)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 0\
**Last updated:** [March 19, 2023, 3:34pm UTC](https://discuss.elastic.co/t/add-a-field-to-metadata-dictionary/328025 "2023-03-19T15:34:08Z")

</div>

Wondering if would be possible to add an extra field to the @metadata 'dictionary' from an input section of filebeat? Eg. someting like: filebeat.input: - type: filestream id: \<some id goes here\> enabled: true @…

---

## [Question about the logstash plugin version](https://discuss.elastic.co/t/question-about-the-logstash-plugin-version/328022)

<div class="topic-metadata">

**Author:** [@wensionblao](https://discuss.elastic.co/u/wensionblao)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 2:28pm UTC](https://discuss.elastic.co/t/question-about-the-logstash-plugin-version/328022 "2023-03-19T14:28:31Z")

</div>

When I use logstash-integration-kafka at version 10.4.0, I find that the corresponding kafka-clients version is 2.4 but logstash-input-kafka and logstash-output-kafka of version 10.4.0 have kafka-clients of version 2…

---

## [Winlogbeat and metricbeat taking high storage space](https://discuss.elastic.co/t/winlogbeat-and-metricbeat-taking-high-storage-space/327996)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 2\
**Last updated:** [March 19, 2023, 1:42pm UTC](https://discuss.elastic.co/t/winlogbeat-and-metricbeat-taking-high-storage-space/327996 "2023-03-19T13:42:32Z")

</div>

Hi All, I am using ELK version 8.0.0, with winlogbeat and metricbeat version 8.0.0 we are monitoring around 200 environments for event logs and metrics from winlog and metricbeat respectively. BUt not sure why the winlo…

---

## [Help in Export Elasticsearch data](https://discuss.elastic.co/t/help-in-export-elasticsearch-data/326823)

<div class="topic-metadata">

**Author:** [@sameer\_khamkar](https://discuss.elastic.co/u/sameer_khamkar)\
**Replies:** 3\
**Last updated:** [March 19, 2023, 1:29pm UTC](https://discuss.elastic.co/t/help-in-export-elasticsearch-data/326823 "2023-03-19T13:29:12Z")

</div>

Hello Team, I am new to Elasticsearch I have an situation where I want to reindex data from elasticsearch to opensearch I dont have any cluster so its a single node I wan some clarity on my below queries How to exp…

---

## [Logging from script within Ruby Filter](https://discuss.elastic.co/t/logging-from-script-within-ruby-filter/328012)

<div class="topic-metadata">

**Author:** [@16318a22907f3cbfa04b](https://discuss.elastic.co/u/16318a22907f3cbfa04b)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 9:48am UTC](https://discuss.elastic.co/t/logging-from-script-within-ruby-filter/328012 "2023-03-19T09:48:42Z")

</div>

Hello, I can write to the logfile of Logstash from code within ruby filter. https://discuss.elastic.co/t/logging-from-within-ruby-filter/127983/2 Is it possible to do the same from script (not code)? And when yes how? …

---

## [SSL certificate - x509: certificate signed by unknown authority (Solved)](https://discuss.elastic.co/t/ssl-certificate-x509-certificate-signed-by-unknown-authority-solved/328011)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pelletier](https://discuss.elastic.co/u/Nicolas_Pelletier)\
**Replies:** 0\
**Last updated:** [March 19, 2023, 8:15am UTC](https://discuss.elastic.co/t/ssl-certificate-x509-certificate-signed-by-unknown-authority-solved/328011 "2023-03-19T08:15:24Z")

</div>

I've deployed a standalone elastic-agent on my host machine where ELK is running. I've add the MISP integration policy to this standalone agent with https://localhost as MISP url variable. It's self signed certificate. …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=599)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=601)
