# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=623

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 624

---

## [Why Kibana not showing date when minimum interval is selected in minutes](https://discuss.elastic.co/t/why-kibana-not-showing-date-when-minimum-interval-is-selected-in-minutes/326319)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 12:52pm UTC](https://discuss.elastic.co/t/why-kibana-not-showing-date-when-minimum-interval-is-selected-in-minutes/326319 "2023-02-23T12:52:45Z")

</div>

When I am selecting minimum interval as "Minutes", Kibana is not having dates in timestamp column. Whereas when i am selecting "Hour", it is working as per expectation. Screenshot -when minutes selected Screenshot -…

---

## [Can we give more than 32GB Memory to dedicated Machine learning Node?](https://discuss.elastic.co/t/can-we-give-more-than-32gb-memory-to-dedicated-machine-learning-node/325159)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 6\
**Last updated:** [February 23, 2023, 12:05pm UTC](https://discuss.elastic.co/t/can-we-give-more-than-32gb-memory-to-dedicated-machine-learning-node/325159 "2023-02-23T12:05:39Z")

</div>

As per the documentation it is recommended by Elasticsearch Team that every Elasticsearch node should have the memory slightly less than 32GB. Now My question is that does this apply to a dedicated Machine learning Node …

---

## [ECE Deployment issue on Centos 8](https://discuss.elastic.co/t/ece-deployment-issue-on-centos-8/326304)

<div class="topic-metadata">

**Author:** [@opensourcengineer](https://discuss.elastic.co/u/opensourcengineer)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 10:37am UTC](https://discuss.elastic.co/t/ece-deployment-issue-on-centos-8/326304 "2023-02-23T10:37:17Z")

</div>

I am trying to install the ECE using the ansible deployment git repo for the medium-size installation on centos 8 (https://github.com/elastic/ansible-elastic-cloud-enterprisehttps://github.com/elastic/ansible-elastic-clo…

---

## [Controls feature is not working properly](https://discuss.elastic.co/t/controls-feature-is-not-working-properly/326201)

<div class="topic-metadata">

**Author:** [@Apoorva\_Shandilya](https://discuss.elastic.co/u/Apoorva_Shandilya)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 4:17pm UTC](https://discuss.elastic.co/t/controls-feature-is-not-working-properly/326201 "2023-02-22T16:17:40Z")

</div>

Hi Control feature in kibana is not working for me Can you please help Below i have attached the screenshot where i am trying to filter the result . as you can see in first screenshot the list in the drop down …

---

## [Problems with cloudwatch input plugin - namespace AWS/EC2 NameError](https://discuss.elastic.co/t/problems-with-cloudwatch-input-plugin-namespace-aws-ec2-nameerror/326297)

<div class="topic-metadata">

**Author:** [@wodnd6646](https://discuss.elastic.co/u/wodnd6646)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 10:27am UTC](https://discuss.elastic.co/t/problems-with-cloudwatch-input-plugin-namespace-aws-ec2-nameerror/326297 "2023-02-23T10:27:27Z")

</div>

Hello All, problem summary: logstash can't recognize 'AWS/EC2' I am setting up a logstash configuration file to get cloudwatch(EC2, RDS) data. I have written input plugin code as below, and RDS is working as I expecte…

---

## [Transform a log fields integer value received with snmp](https://discuss.elastic.co/t/transform-a-log-fields-integer-value-received-with-snmp/326292)

<div class="topic-metadata">

**Author:** [@Christer\_Palmen](https://discuss.elastic.co/u/Christer_Palmen)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 9:52am UTC](https://discuss.elastic.co/t/transform-a-log-fields-integer-value-received-with-snmp/326292 "2023-02-23T09:52:56Z")

</div>

Blockquote Hello. I am setting up a logstash pipeline to monitor the environment of my customers server cabinets with the snmp plugin. Everything looks good except for the value of the temperature, which is shown in…

---

## [GEOGRAPHY Elastic.Clients.Elasticsearch v8.x C# .NET](https://discuss.elastic.co/t/geography-elastic-clients-elasticsearch-v8-x-c-net/326282)

<div class="topic-metadata">

**Author:** [@IceF1reX](https://discuss.elastic.co/u/IceF1reX)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 9:49am UTC](https://discuss.elastic.co/t/geography-elastic-clients-elasticsearch-v8-x-c-net/326282 "2023-02-23T09:49:14Z")

</div>

How to use geo in Elastic.Clients.Elasticsearch v8.x C# .NET??

---

## [Replacing an Elasticsearch node](https://discuss.elastic.co/t/replacing-an-elasticsearch-node/326203)

<div class="topic-metadata">

**Author:** [@smutel](https://discuss.elastic.co/u/smutel)\
**Replies:** 4\
**Last updated:** [February 23, 2023, 9:22am UTC](https://discuss.elastic.co/t/replacing-an-elasticsearch-node/326203 "2023-02-23T09:22:29Z")

</div>

Hello, I have a cluster with 5 nodes (3 master nodes and 2 data nodes) hosted on vms. I am using Elasticsearch version 7.17.8. I need to replace these VMs (to destroy them and to create new ones). I replaced the seco…

---

## [\[ES 8.6.1\]Elastic agent not deleting SQS message after processing](https://discuss.elastic.co/t/es-8-6-1-elastic-agent-not-deleting-sqs-message-after-processing/325372)

<div class="topic-metadata">

**Author:** [@rubal033](https://discuss.elastic.co/u/rubal033)\
**Replies:** 9\
**Last updated:** [February 23, 2023, 8:57am UTC](https://discuss.elastic.co/t/es-8-6-1-elastic-agent-not-deleting-sqs-message-after-processing/325372 "2023-02-23T08:57:40Z")

</div>

Hi I am using Elastic agent integration to monitor ELB logs (via s3-sqs setup). I am able to see ELB logs in Elasticsearch cluster but my SQS inflight messages are keep on increasing. Looks like agent is not able to del…

---

## [Kubernetes: Filebeat parses JSON in message field no matter if I want or not](https://discuss.elastic.co/t/kubernetes-filebeat-parses-json-in-message-field-no-matter-if-i-want-or-not/326089)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 8:45am UTC](https://discuss.elastic.co/t/kubernetes-filebeat-parses-json-in-message-field-no-matter-if-i-want-or-not/326089 "2023-02-23T08:45:15Z")

</div>

I want to use Filebeat (current version) to collect logs from our Kubernetes Cluster by using this manual: Run Filebeat on Kubernetes | Filebeat Reference \[8.6\] | Elastic I want to control if the message of a cointainer…

---

## [Show export button in lens](https://discuss.elastic.co/t/show-export-button-in-lens/326224)

<div class="topic-metadata">

**Author:** [@karlanakamura](https://discuss.elastic.co/u/karlanakamura)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 8:35am UTC](https://discuss.elastic.co/t/show-export-button-in-lens/326224 "2023-02-23T08:35:01Z")

</div>

Hello, I'm using version 8.6.0 in elastic cloud. I would like to know if it is possible to show the export button in lens table as well as in the data table in aggregation based (as shown in the figure below).

---

## [Alerting related queries](https://discuss.elastic.co/t/alerting-related-queries/326167)

<div class="topic-metadata">

**Author:** [@pranati](https://discuss.elastic.co/u/pranati)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 7:56am UTC](https://discuss.elastic.co/t/alerting-related-queries/326167 "2023-02-23T07:56:48Z")

</div>

Hi All, I am new to kibana, I need some help in creating alert if some counts doesn't match between two files. so in elk , i can see alerting option but when i click on it , it goes to create monitor. there is some is…

---

## [About fix log4j2 vulnerabilities, use the parameter -Dlog4j2.formatMsgNoLookups=true](https://discuss.elastic.co/t/about-fix-log4j2-vulnerabilities-use-the-parameter-dlog4j2-formatmsgnolookups-true/326271)

<div class="topic-metadata">

**Author:** [@qiuxb](https://discuss.elastic.co/u/qiuxb)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 7:17am UTC](https://discuss.elastic.co/t/about-fix-log4j2-vulnerabilities-use-the-parameter-dlog4j2-formatmsgnolookups-true/326271 "2023-02-23T07:17:28Z")

</div>

Currently, there are multiple ES versions in our online environment. To fix the logj2 vulnerability, we plan to add the parameter -Dlog4j2.formatMsgNoLookups=true to jvm.option. Do the following versions support this met…

---

## [Failed to obtain node locks, tried \[/usr/share/elasticsearch/data\]; maybe these locations are not writable or multiple nodes were started on the same data path?](https://discuss.elastic.co/t/failed-to-obtain-node-locks-tried-usr-share-elasticsearch-data-maybe-these-locations-are-not-writable-or-multiple-nodes-were-started-on-the-same-data-path/326264)

<div class="topic-metadata">

**Author:** [@limedong1](https://discuss.elastic.co/u/limedong1)\
**Replies:** 7\
**Last updated:** [February 23, 2023, 7:15am UTC](https://discuss.elastic.co/t/failed-to-obtain-node-locks-tried-usr-share-elasticsearch-data-maybe-these-locations-are-not-writable-or-multiple-nodes-were-started-on-the-same-data-path/326264 "2023-02-23T07:15:49Z")

</div>

I use k8s built a ela cluster, I in the yaml document data directory: / usr/share/elasticsearch/data local hostpath path is: / data/elasticsearch/data This is directory permission information: drwxr-xr-x. 3 1000 100…

---

## [Elasticsearch snapshot retention behavior](https://discuss.elastic.co/t/elasticsearch-snapshot-retention-behavior/326262)

<div class="topic-metadata">

**Author:** [@Vivek\_Shinde](https://discuss.elastic.co/u/Vivek_Shinde)\
**Replies:** 3\
**Last updated:** [February 23, 2023, 7:08am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-retention-behavior/326262 "2023-02-23T07:08:14Z")

</div>

Lets say we create daily indices with ILM policy that delete data after 1 year. And lets say we have SLM that have retention period of 30 days. So, eventually what will be the content of snapshot after 1 year. Is it one…

---

## [Unable to connect filebeat to elastic search host](https://discuss.elastic.co/t/unable-to-connect-filebeat-to-elastic-search-host/326260)

<div class="topic-metadata">

**Author:** [@Shrivatsa\_Rao](https://discuss.elastic.co/u/Shrivatsa_Rao)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 6:10am UTC](https://discuss.elastic.co/t/unable-to-connect-filebeat-to-elastic-search-host/326260 "2023-02-23T06:10:10Z")

</div>

Hi I am running filebeat docker image with following command docker run docker.elastic.co/beats/filebeat:8.6.2 setup -E setup.kibana.host=http://localhost:5601 -E output.elasticsearch.hosts=\["https://localhost:9200"\] b…

---

## [NativeSearchQuery exact match sort problems](https://discuss.elastic.co/t/nativesearchquery-exact-match-sort-problems/326256)

<div class="topic-metadata">

**Author:** [@iles983](https://discuss.elastic.co/u/iles983)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 4:46am UTC](https://discuss.elastic.co/t/nativesearchquery-exact-match-sort-problems/326256 "2023-02-23T04:46:57Z")

</div>

Hello everyone. I'm doing search using Java and elasticsearch 6.2.2 I'm having some troubles with sorting The way i need it to be: all exact match sorted by price, with fuzziness 1 sorted by price and then with fuzzine…

---

## [Kibana visualization](https://discuss.elastic.co/t/kibana-visualization/326253)

<div class="topic-metadata">

**Author:** [@joelle\_umutoni](https://discuss.elastic.co/u/joelle_umutoni)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 4:36am UTC](https://discuss.elastic.co/t/kibana-visualization/326253 "2023-02-23T04:36:39Z")

</div>

What to do when you click on visualization for filtering purpose but the other visualization does not update to show the data related to the one clicked

---

## [io.netty.handler.ssl.SslHandshakeTimeoutException: handshake timed out after 10000ms](https://discuss.elastic.co/t/io-netty-handler-ssl-sslhandshaketimeoutexception-handshake-timed-out-after-10000ms/326117)

<div class="topic-metadata">

**Author:** [@Raghulvishal](https://discuss.elastic.co/u/Raghulvishal)\
**Replies:** 6\
**Last updated:** [February 23, 2023, 3:25am UTC](https://discuss.elastic.co/t/io-netty-handler-ssl-sslhandshaketimeoutexception-handshake-timed-out-after-10000ms/326117 "2023-02-23T03:25:11Z")

</div>

Hi Team, We are getting this below exception daily. so, can you please give solution for this exception. we are using Elasticsearch 7.3.2, java version 1.8.0\_131 and tomcat version 9. 2023-02-19 18:55:20.683 \[elastic…

---

## [Elasticsearch getting killed by the oom killer because an out of memory](https://discuss.elastic.co/t/elasticsearch-getting-killed-by-the-oom-killer-because-an-out-of-memory/326218)

<div class="topic-metadata">

**Author:** [@noreddinelam](https://discuss.elastic.co/u/noreddinelam)\
**Replies:** 4\
**Last updated:** [February 23, 2023, 3:03am UTC](https://discuss.elastic.co/t/elasticsearch-getting-killed-by-the-oom-killer-because-an-out-of-memory/326218 "2023-02-23T03:03:13Z")

</div>

Good morning, We are facing the problem "Out Of Memory" with elasticsearch. Our configuration : We are running on ec2 instance (tg4.micro) with 1gb ram and 1cpu. I know that perhaps it is not sufficient but i want to …

---

## [Having issue to setup filebeat](https://discuss.elastic.co/t/having-issue-to-setup-filebeat/326235)

<div class="topic-metadata">

**Author:** [@ermilan2309](https://discuss.elastic.co/u/ermilan2309)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 11:18pm UTC](https://discuss.elastic.co/t/having-issue-to-setup-filebeat/326235 "2023-02-22T23:18:59Z")

</div>

Hello I am having issue while setup the filebeat module for threat hunting. This is the error I am getting.. root@wazuh:/etc/kibana# sudo filebeat setup Overwriting ILM policy is disabled. Set setup.ilm.overwrite: tru…

---

## [How to get current/existing pipelines from ELK](https://discuss.elastic.co/t/how-to-get-current-existing-pipelines-from-elk/326217)

<div class="topic-metadata">

**Author:** [@tymercer](https://discuss.elastic.co/u/tymercer)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 10:51pm UTC](https://discuss.elastic.co/t/how-to-get-current-existing-pipelines-from-elk/326217 "2023-02-22T22:51:50Z")

</div>

I just became the owner of a very old ELK cluster and need to get all of the configs pulled from it to migrate to a cloud hosted instance. The system shows there are several pipelines in Kibana Management, Logstash, Pip…

---

## [Kibana unable to authenticate user \[elastic\]](https://discuss.elastic.co/t/kibana-unable-to-authenticate-user-elastic/325678)

<div class="topic-metadata">

**Author:** [@chromus](https://discuss.elastic.co/u/chromus)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 10:46pm UTC](https://discuss.elastic.co/t/kibana-unable-to-authenticate-user-elastic/325678 "2023-02-22T22:46:03Z")

</div>

Hello Team. I am running ELK using a docker multi-node deployment. My docker-compose.yml file is almost identical to the example one from the page (Install Elasticsearch with Docker | Elasticsearch Guide \[8.6\] | Elastic)…

---

## [Filebeat to elastic/cloud not using defined index in yml config](https://discuss.elastic.co/t/filebeat-to-elastic-cloud-not-using-defined-index-in-yml-config/326216)

<div class="topic-metadata">

**Author:** [@tymercer](https://discuss.elastic.co/u/tymercer)\
**Replies:** 9\
**Last updated:** [February 22, 2023, 10:35pm UTC](https://discuss.elastic.co/t/filebeat-to-elastic-cloud-not-using-defined-index-in-yml-config/326216 "2023-02-22T22:35:07Z")

</div>

First, I am new to all of this and have next to no knowledge of how all of our systems were setup originally as I took this over when the person in charge of it left the company. ELK 6.8.12, Filebeats 6.4 (yes, old, it …

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/326196)

<div class="topic-metadata">

**Author:** [@Umbler\_Casel](https://discuss.elastic.co/u/Umbler_Casel)\
**Replies:** 2\
**Last updated:** [February 22, 2023, 10:14pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/326196 "2023-02-22T22:14:04Z")

</div>

Kibana Version: 8.6 Elastic Search Version: 8.6 Certificate Used: Rapid SSL SHA1 ( might be the problem, but im not sure ) OS: Ubuntu 22.04 Error: Kibana presents a message on UI with the following: "Kibana serve…

---

## [Config Map condition based on the log event on child element](https://discuss.elastic.co/t/config-map-condition-based-on-the-log-event-on-child-element/326213)

<div class="topic-metadata">

**Author:** [@rravitech](https://discuss.elastic.co/u/rravitech)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 10:09pm UTC](https://discuss.elastic.co/t/config-map-condition-based-on-the-log-event-on-child-element/326213 "2023-02-22T22:09:24Z")

</div>

Here is what i am trying to achieve. Below is my log event { "version" : "1.0.0", "message" : "noisemaker draftsmanship's soundproofing grads werewolf's", "@version" : "1", "logplane"…

---

## [Can you query AD with Elastic to see Last Logon time?](https://discuss.elastic.co/t/can-you-query-ad-with-elastic-to-see-last-logon-time/326230)

<div class="topic-metadata">

**Author:** [@Mahigs](https://discuss.elastic.co/u/Mahigs)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 9:58pm UTC](https://discuss.elastic.co/t/can-you-query-ad-with-elastic-to-see-last-logon-time/326230 "2023-02-22T21:58:30Z")

</div>

Relatively new to Elastic and all that it can do. Our team is trying to query Active Directory with Elastic so that we can view user's last logon time. We're trying to satisfy DoD requirements relating to accounts needin…

---

## [String Replace in Painless](https://discuss.elastic.co/t/string-replace-in-painless/326231)

<div class="topic-metadata">

**Author:** [@John\_Warner](https://discuss.elastic.co/u/John_Warner)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 9:53pm UTC](https://discuss.elastic.co/t/string-replace-in-painless/326231 "2023-02-22T21:53:46Z")

</div>

I tried the following replace, and it did not work. Seems to be returning the empty string. Is this the correct way to do a string replace? Note that what I found on this thread does not seem to work for me. Replace stri…

---

## ["Error: fleet-server failed: context canceled" error when trying to "Install Fleet Server to a centralized host"](https://discuss.elastic.co/t/error-fleet-server-failed-context-canceled-error-when-trying-to-install-fleet-server-to-a-centralized-host/326112)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 9:30pm UTC](https://discuss.elastic.co/t/error-fleet-server-failed-context-canceled-error-when-trying-to-install-fleet-server-to-a-centralized-host/326112 "2023-02-22T21:30:09Z")

</div>

I am trying to "Add a Fleet Server" but am getting an error when I try to install the Elastic Agent. After running the following command as instructed: curl -L -O https://artifacts.elastic.co/downloads/beats/elastic…

---

## [ES custom ILM policy with cumulative index or disk size](https://discuss.elastic.co/t/es-custom-ilm-policy-with-cumulative-index-or-disk-size/326135)

<div class="topic-metadata">

**Author:** [@blueren](https://discuss.elastic.co/u/blueren)\
**Replies:** 3\
**Last updated:** [February 22, 2023, 9:25pm UTC](https://discuss.elastic.co/t/es-custom-ilm-policy-with-cumulative-index-or-disk-size/326135 "2023-02-22T21:25:47Z")

</div>

We're trying to implement an ILM policy for moving indices between hot -\> warm -\> cold in out on-premise server. What we have is this: SSD for storing hot indices HDD for storing warm indices \> 7d NAS for storing cold…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=622)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=624)
