# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=607

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 608

---

## [Kibana Vega: simple text-label](https://discuss.elastic.co/t/kibana-vega-simple-text-label/327489)

<div class="topic-metadata">

**Author:** [@joerg55](https://discuss.elastic.co/u/joerg55)\
**Replies:** 0\
**Last updated:** [March 11, 2023, 7:05pm UTC](https://discuss.elastic.co/t/kibana-vega-simple-text-label/327489 "2023-03-11T19:05:11Z")

</div>

Hi community, I need a simple text in vertical orientation. I found this: https://vega.github.io/vega/docs/marks/text/ but I'm not very familiar with vega and this example is not to understand by me. Can somebody give…

---

## [Error filebeat - Trying to retrieve too many docvalue\_fields](https://discuss.elastic.co/t/error-filebeat-trying-to-retrieve-too-many-docvalue-fields/327394)

<div class="topic-metadata">

**Author:** [@Maria\_Gabriela\_Perez](https://discuss.elastic.co/u/Maria_Gabriela_Perez)\
**Replies:** 1\
**Last updated:** [March 11, 2023, 4:30pm UTC](https://discuss.elastic.co/t/error-filebeat-trying-to-retrieve-too-many-docvalue-fields/327394 "2023-03-11T16:30:01Z")

</div>

\[illegal\_argument\_exception\] Trying to retrieve too many docvalue\_fields. Must be less than or equal to: \[200\] but was \[208\]. This limit can be set by changing the \[index.max\_docvalue\_fields\_search\] index level setting.

---

## [How to detect and avoid UDP input loss](https://discuss.elastic.co/t/how-to-detect-and-avoid-udp-input-loss/327483)

<div class="topic-metadata">

**Author:** [@YvesZhi](https://discuss.elastic.co/u/YvesZhi)\
**Replies:** 1\
**Last updated:** [March 11, 2023, 3:22pm UTC](https://discuss.elastic.co/t/how-to-detect-and-avoid-udp-input-loss/327483 "2023-03-11T15:22:26Z")

</div>

I'm using Envoy, which is kind of similar to Nginx, as the gateway of my micro-services backend. Since it's micro-service, there are five Envoys. All of envoys are deployed by Docker and their logs are sent to my Logsta…

---

## [How Translog Work on elastic](https://discuss.elastic.co/t/how-translog-work-on-elastic/325880)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 6\
**Last updated:** [March 11, 2023, 10:35am UTC](https://discuss.elastic.co/t/how-translog-work-on-elastic/325880 "2023-03-11T10:35:29Z")

</div>

Hi everyone, I have a question about translog. So here is the situation: I have one index with 1 primary and 1 replica shard and continuously ingesting data. If i read documentation, it says that primary and replica sh…

---

## [How to cut off the part of syslog](https://discuss.elastic.co/t/how-to-cut-off-the-part-of-syslog/327242)

<div class="topic-metadata">

**Author:** [@YvesZhi](https://discuss.elastic.co/u/YvesZhi)\
**Replies:** 2\
**Last updated:** [March 11, 2023, 6:25am UTC](https://discuss.elastic.co/t/how-to-cut-off-the-part-of-syslog/327242 "2023-03-11T06:25:51Z")

</div>

I've some micro services, which are deployed with Docker. They send their logs to my Logstash with the log driver syslog. Here is the config of my Logstash: input { syslog { port =\> 9771 type =\> "syslog" } }…

---

## [Insert multiple fields in nested array](https://discuss.elastic.co/t/insert-multiple-fields-in-nested-array/327415)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 2\
**Last updated:** [March 11, 2023, 1:21am UTC](https://discuss.elastic.co/t/insert-multiple-fields-in-nested-array/327415 "2023-03-11T01:21:59Z")

</div>

Hi Guys I have the following input as example: generator { count =\> 1 lines =\> \[ '{ "RATING\_GROUP": "7,843,13", "CONSUMO": "328994,29715,13948" }' \] codec =\> json } Which filter can I use in Logstash to obtain a outp…

---

## [How to make a time series of discrete events](https://discuss.elastic.co/t/how-to-make-a-time-series-of-discrete-events/327367)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 4\
**Last updated:** [March 10, 2023, 9:15pm UTC](https://discuss.elastic.co/t/how-to-make-a-time-series-of-discrete-events/327367 "2023-03-10T21:15:44Z")

</div>

It seems I can only make time series (including with TSBV) of numerical values. What I have are gateways that send a finite set of event types. What I would like to do is plot in a time series which type event was sent.…

---

## [Slow indexing speed, possibly related to filebeat misconfiguration](https://discuss.elastic.co/t/slow-indexing-speed-possibly-related-to-filebeat-misconfiguration/327283)

<div class="topic-metadata">

**Author:** [@alexandrpaliy](https://discuss.elastic.co/u/alexandrpaliy)\
**Replies:** 4\
**Last updated:** [March 10, 2023, 9:05pm UTC](https://discuss.elastic.co/t/slow-indexing-speed-possibly-related-to-filebeat-misconfiguration/327283 "2023-03-10T21:05:38Z")

</div>

I have actually no idea which tag/subforum to use, because I have an issue with a general filebeat -\> logstash -\> elasticsearch pipelinem and I am not entirely sure, is this issue related to ES indexing performance, or i…

---

## [Going from data nodes to hot and warm nodes](https://discuss.elastic.co/t/going-from-data-nodes-to-hot-and-warm-nodes/327311)

<div class="topic-metadata">

**Author:** [@reswob](https://discuss.elastic.co/u/reswob)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 8:36pm UTC](https://discuss.elastic.co/t/going-from-data-nodes-to-hot-and-warm-nodes/327311 "2023-03-10T20:36:01Z")

</div>

Lab Environment: 3 Master and 2 Data nodes. Just sent some data to cluster without building custom templates or ILM policies or mappings. I added 2 more Data nodes and made the first two Hot and the new 2 Warm nodes p…

---

## [How can I force the order of labels?](https://discuss.elastic.co/t/how-can-i-force-the-order-of-labels/327424)

<div class="topic-metadata">

**Author:** [@Wpq](https://discuss.elastic.co/u/Wpq)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 7:29pm UTC](https://discuss.elastic.co/t/how-can-i-force-the-order-of-labels/327424 "2023-03-10T19:29:22Z")

</div>

I have data with a label priority that I show on a heatmap: The order at the bottom is not the one I would like to have (which is CRITICAL, HIGH, ...) How can I instruct Kibana to use a specific order for the labels…

---

## [Logstash second conf file is not taking](https://discuss.elastic.co/t/logstash-second-conf-file-is-not-taking/327354)

<div class="topic-metadata">

**Author:** [@ekambaram\_varathan](https://discuss.elastic.co/u/ekambaram_varathan)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 6:47pm UTC](https://discuss.elastic.co/t/logstash-second-conf-file-is-not-taking/327354 "2023-03-10T18:47:42Z")

</div>

I am using docker-compose version: v2.9.0. and version: '3.7' in docker-compose yml file and using the below command in logstash section., when i see the logstash logs only its taking the first conf file, second conf fil…

---

## [Using essql query results a second query against another index](https://discuss.elastic.co/t/using-essql-query-results-a-second-query-against-another-index/327396)

<div class="topic-metadata">

**Author:** [@dreynolds](https://discuss.elastic.co/u/dreynolds)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 6:42pm UTC](https://discuss.elastic.co/t/using-essql-query-results-a-second-query-against-another-index/327396 "2023-03-10T18:42:26Z")

</div>

In Canvas I'm attempting to query an index, return the results of a specific column, and then query another index with the results of the original query. An example would be two indices: Index 1: login\_activity; two fi…

---

## [Disable enrolment-token requirement on initial startup of Elasticsearch and Kibana](https://discuss.elastic.co/t/disable-enrolment-token-requirement-on-initial-startup-of-elasticsearch-and-kibana/327399)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 6\
**Last updated:** [March 10, 2023, 6:08pm UTC](https://discuss.elastic.co/t/disable-enrolment-token-requirement-on-initial-startup-of-elasticsearch-and-kibana/327399 "2023-03-10T18:08:02Z")

</div>

Hello. I'm running Elasticsearch and Kibana via docker containers, whose images I'm building from the Dockerfiles from this repository: GitHub - elastic/dockerfiles: Dockerfiles for the official Elastic Stack images. On …

---

## [Time series line chart querying two different indexes](https://discuss.elastic.co/t/time-series-line-chart-querying-two-different-indexes/327233)

<div class="topic-metadata">

**Author:** [@Tom\_White](https://discuss.elastic.co/u/Tom_White)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 4:58pm UTC](https://discuss.elastic.co/t/time-series-line-chart-querying-two-different-indexes/327233 "2023-03-10T16:58:48Z")

</div>

Hello, I would like to create a very simple time series line chart in Kibana. One line would be a filtered aggregation (count) from Index A, and the other line would be a filtered aggregation (count) from Index B. Is thi…

---

## [Search functionality in Elastic Stack fails with a proxy error](https://discuss.elastic.co/t/search-functionality-in-elastic-stack-fails-with-a-proxy-error/327372)

<div class="topic-metadata">

**Author:** [@Bhanuji\_paluri](https://discuss.elastic.co/u/Bhanuji_paluri)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 4:24pm UTC](https://discuss.elastic.co/t/search-functionality-in-elastic-stack-fails-with-a-proxy-error/327372 "2023-03-10T16:24:07Z")

</div>

when the search is filtered with indices of large size and with more no of days ex: more than 7 days. Steps to reproduce: Login to Kibana service: https://docklin-efk-ks.sel .rnd.internal.com/ select index pattern d…

---

## [Connect sql server database to elasticsearch](https://discuss.elastic.co/t/connect-sql-server-database-to-elasticsearch/327465)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 4:23pm UTC](https://discuss.elastic.co/t/connect-sql-server-database-to-elasticsearch/327465 "2023-03-10T16:23:56Z")

</div>

I want to connect sql server database to elasticsearch without copying the sql data to elasticsearch, with a simple call of the sql data or simple connection , without loading the data from sql server to elasticsearch I…

---

## [Dashboard filtering](https://discuss.elastic.co/t/dashboard-filtering/327437)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 4:17pm UTC](https://discuss.elastic.co/t/dashboard-filtering/327437 "2023-03-10T16:17:40Z")

</div>

Hello, I want to add a filter that eliminates the records with type Disconnect and have user admin. So only for user admin to eliminate the Disconnect events. I've tried this, but it is not ok { "query": { "boo…

---

## [The stack cannot be started according to the instructions](https://discuss.elastic.co/t/the-stack-cannot-be-started-according-to-the-instructions/327431)

<div class="topic-metadata">

**Author:** [@alexanderzhirov](https://discuss.elastic.co/u/alexanderzhirov)\
**Replies:** 13\
**Last updated:** [March 10, 2023, 4:00pm UTC](https://discuss.elastic.co/t/the-stack-cannot-be-started-according-to-the-instructions/327431 "2023-03-10T16:00:14Z")

</div>

I'm trying to run the stack in docker according to this instruction. My .env: # Password for the 'elastic' user (at least 6 characters) ELASTIC\_PASSWORD=elastic # Password for the 'kibana\_system' user (at least 6 char…

---

## [Can i send message from logstash to pagerduty by http output plugin](https://discuss.elastic.co/t/can-i-send-message-from-logstash-to-pagerduty-by-http-output-plugin/326129)

<div class="topic-metadata">

**Author:** [@YasuhiroOkumura](https://discuss.elastic.co/u/YasuhiroOkumura)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 3:22pm UTC](https://discuss.elastic.co/t/can-i-send-message-from-logstash-to-pagerduty-by-http-output-plugin/326129 "2023-03-10T15:22:25Z")

</div>

Are there any having sample code using http output plugin of logstash to send message to pagerduty. Can I see the code.

---

## [Is it possible to move a one time snapshot to Glacier?](https://discuss.elastic.co/t/is-it-possible-to-move-a-one-time-snapshot-to-glacier/327455)

<div class="topic-metadata">

**Author:** [@John\_Newman1](https://discuss.elastic.co/u/John_Newman1)\
**Replies:** 4\
**Last updated:** [March 10, 2023, 2:41pm UTC](https://discuss.elastic.co/t/is-it-possible-to-move-a-one-time-snapshot-to-glacier/327455 "2023-03-10T14:41:09Z")

</div>

Hi, In the docs, it states that after snapshotting an index to S3 you shouldn't transition it to Glacier. I have a use case where I would like to snapshot an index as a one off event and store it as cheaply as possible,…

---

## [Nested aggregation Error](https://discuss.elastic.co/t/nested-aggregation-error/327451)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 1:50pm UTC](https://discuss.elastic.co/t/nested-aggregation-error/327451 "2023-03-10T13:50:01Z")

</div>

So, I have my mappings as this and my query request object as referred to \[this link\](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-nested-aggregation.html) Query JSON { …

---

## [Error Loading data into ElasticSearch using Azure Data Factory - Zappysys connector](https://discuss.elastic.co/t/error-loading-data-into-elasticsearch-using-azure-data-factory-zappysys-connector/327442)

<div class="topic-metadata">

**Author:** [@gau\_prpce](https://discuss.elastic.co/u/gau_prpce)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 10:58am UTC](https://discuss.elastic.co/t/error-loading-data-into-elasticsearch-using-azure-data-factory-zappysys-connector/327442 "2023-03-10T10:58:33Z")

</div>

I was trying to load data from azure postgresql to elasticsearch through ADF copy activity using Zappysys connector. Facing this issue. Failure happened on 'Sink' side. ErrorCode=UserErrorOdbcOperationFailed,'Type=Micr…

---

## [SLM cron expression](https://discuss.elastic.co/t/slm-cron-expression/327357)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 12:55pm UTC](https://discuss.elastic.co/t/slm-cron-expression/327357 "2023-03-10T12:55:36Z")

</div>

Hi Team, I am using a slm policy and wanted to add the cron expression such that it run on every 26th day. e.g for 1st month jan it run on 26/01/2023 and then run on +26 days that is 21/02/2023 and so on. Can someone pl…

---

## [How to create managed indexes with current date in names?](https://discuss.elastic.co/t/how-to-create-managed-indexes-with-current-date-in-names/327312)

<div class="topic-metadata">

**Author:** [@maar](https://discuss.elastic.co/u/maar)\
**Replies:** 4\
**Last updated:** [March 10, 2023, 12:46pm UTC](https://discuss.elastic.co/t/how-to-create-managed-indexes-with-current-date-in-names/327312 "2023-03-10T12:46:10Z")

</div>

How to setup ILM policies with dates in the names of the indexes? Here's the setup that works (without dates): PUT \_index\_template/index-test { "index\_patterns": \["index-test-\*"\], "template": { …

---

## [Boxplot, Title Y-axis](https://discuss.elastic.co/t/boxplot-title-y-axis/327441)

<div class="topic-metadata">

**Author:** [@joerg55](https://discuss.elastic.co/u/joerg55)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 10:57am UTC](https://discuss.elastic.co/t/boxplot-title-y-axis/327441 "2023-03-10T10:57:50Z")

</div>

Hi community, the Y-title of my boxplot should be 'Percent'. But the Chart shows the Title like this: The source of the chart is this: { "$schema": "https://vega.github.io/schema/vega-lite/v5.json", "title": "Re…

---

## [How can I delete unnassigned shards?](https://discuss.elastic.co/t/how-can-i-delete-unnassigned-shards/327433)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 10:56am UTC](https://discuss.elastic.co/t/how-can-i-delete-unnassigned-shards/327433 "2023-03-10T10:56:03Z")

</div>

In my cluster there are unassigned shards which are not primary shards. I don't know why I have these secondary shards in my cluster. I didn't create them intentionally and I use the default configuration (elasticsearch…

---

## [How to remove the empty result set caused by bucket\_selector?](https://discuss.elastic.co/t/how-to-remove-the-empty-result-set-caused-by-bucket-selector/327430)

<div class="topic-metadata">

**Author:** [@Jinnrry](https://discuss.elastic.co/u/Jinnrry)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 10:48am UTC](https://discuss.elastic.co/t/how-to-remove-the-empty-result-set-caused-by-bucket-selector/327430 "2023-03-10T10:48:13Z")

</div>

This operation will show you my problem. 1、Create Index PUT car { "mappings": { "properties": { "color": { "type": "keyword" }, "company": { "type": "keyword" }, "pri…

---

## [Not able to send data from filebeat to elastic cloud however with same settings it works on EFK stack on linux](https://discuss.elastic.co/t/not-able-to-send-data-from-filebeat-to-elastic-cloud-however-with-same-settings-it-works-on-efk-stack-on-linux/327390)

<div class="topic-metadata">

**Author:** [@sameer\_rathod](https://discuss.elastic.co/u/sameer_rathod)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 10:40am UTC](https://discuss.elastic.co/t/not-able-to-send-data-from-filebeat-to-elastic-cloud-however-with-same-settings-it-works-on-efk-stack-on-linux/327390 "2023-03-10T10:40:52Z")

</div>

I am using elastic cloud and when I used filebeat to send IIS logs from windows machine, elasticsearch only received the error logs and not even a single access logs from default directory. In last two days I tried setti…

---

## [Packetbeat isn't capture mysql network traffic](https://discuss.elastic.co/t/packetbeat-isnt-capture-mysql-network-traffic/327378)

<div class="topic-metadata">

**Author:** [@Ivan\_Picca](https://discuss.elastic.co/u/Ivan_Picca)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 10:12am UTC](https://discuss.elastic.co/t/packetbeat-isnt-capture-mysql-network-traffic/327378 "2023-03-10T10:12:57Z")

</div>

hey guys. I'm stuck. I got this problem. I've configured packetbeat to capture network traffic. I've 1 server contains elk stack and another host where i' ve installed packetbeat and mysql. The main idea is forward pack…

---

## [How to Add Another Host To Kibana On Different Device or Server](https://discuss.elastic.co/t/how-to-add-another-host-to-kibana-on-different-device-or-server/327250)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 4\
**Last updated:** [March 10, 2023, 9:39am UTC](https://discuss.elastic.co/t/how-to-add-another-host-to-kibana-on-different-device-or-server/327250 "2023-03-10T09:39:40Z")

</div>

I want add more host to my kibana on windows server 2019, but i have no idea how to do it. Anyone can help me with that simple question?

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=606)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=608)
