# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=624

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 625

---

## [Kibana upgrade from 7.16.1 to 7.17.8 using docker compose](https://discuss.elastic.co/t/kibana-upgrade-from-7-16-1-to-7-17-8-using-docker-compose/325609)

<div class="topic-metadata">

**Author:** [@Irshu786](https://discuss.elastic.co/u/Irshu786)\
**Replies:** 7\
**Last updated:** [February 22, 2023, 9:25pm UTC](https://discuss.elastic.co/t/kibana-upgrade-from-7-16-1-to-7-17-8-using-docker-compose/325609 "2023-02-22T21:25:20Z")

</div>

What is the procedure to perform kibana upgrade with zero downtime.

---

## [Deploying elastic agent container in kubernetes: error retrieving resource lock](https://discuss.elastic.co/t/deploying-elastic-agent-container-in-kubernetes-error-retrieving-resource-lock/326227)

<div class="topic-metadata">

**Author:** [@jmyns](https://discuss.elastic.co/u/jmyns)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 9:22pm UTC](https://discuss.elastic.co/t/deploying-elastic-agent-container-in-kubernetes-error-retrieving-resource-lock/326227 "2023-02-22T21:22:24Z")

</div>

When I deploy an elastic agent image I see this repeated error in the container logs. error retrieving resource lock default/elastic-agent-cluster-leader: leases.coordination.k8s.io "elastic-agent-cluster-leader" is for…

---

## [Load different formats of data under the same index name](https://discuss.elastic.co/t/load-different-formats-of-data-under-the-same-index-name/326131)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 9:16pm UTC](https://discuss.elastic.co/t/load-different-formats-of-data-under-the-same-index-name/326131 "2023-02-22T21:16:08Z")

</div>

Hello All, Is it possible to load different formats of data (from different sources) under the same index name in Elasticsearch? If yes, how can we do and what are the pros and cons. Please advise

---

## [Cannot use ElasticSearch IP Address as Node URI (does not trust server certificate)](https://discuss.elastic.co/t/cannot-use-elasticsearch-ip-address-as-node-uri-does-not-trust-server-certificate/326155)

<div class="topic-metadata">

**Author:** [@lemesios10](https://discuss.elastic.co/u/lemesios10)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 10:16am UTC](https://discuss.elastic.co/t/cannot-use-elasticsearch-ip-address-as-node-uri-does-not-trust-server-certificate/326155 "2023-02-22T10:16:18Z")

</div>

Hello all. This is my first post here, so please bear with me! Current setup: -Elasticsearch & Kibana hosted on an ubuntu server with docker (therefore the Elastics API URI is something like xxx.xxx.xxx.xxx:9200 for El…

---

## [Slow transform performance](https://discuss.elastic.co/t/slow-transform-performance/326195)

<div class="topic-metadata">

**Author:** [@ijsco](https://discuss.elastic.co/u/ijsco)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 3:38pm UTC](https://discuss.elastic.co/t/slow-transform-performance/326195 "2023-02-22T15:38:27Z")

</div>

I'm currently running multiple transforms on the same source index. The source index is an ILM with a lifecycle policy, which shrinks the data after 30 days. These are my transform stats for one of my transforms: { "…

---

## [Kibana shows old/expired Cluster's certificates even though I have updated them](https://discuss.elastic.co/t/kibana-shows-old-expired-clusters-certificates-even-though-i-have-updated-them/326120)

<div class="topic-metadata">

**Author:** [@raespinoza](https://discuss.elastic.co/u/raespinoza)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 9:09pm UTC](https://discuss.elastic.co/t/kibana-shows-old-expired-clusters-certificates-even-though-i-have-updated-them/326120 "2023-02-22T21:09:01Z")

</div>

Hi all, I have updated our cluster's certificates that are about to expire. I followed the steps suggested by the official docs and completed the task with success.....at least that's what I thought. I generated all ne…

---

## [Create time series index from non-time series index](https://discuss.elastic.co/t/create-time-series-index-from-non-time-series-index/326221)

<div class="topic-metadata">

**Author:** [@butchkelley](https://discuss.elastic.co/u/butchkelley)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 8:25pm UTC](https://discuss.elastic.co/t/create-time-series-index-from-non-time-series-index/326221 "2023-02-22T20:25:08Z")

</div>

Hello, I have a non-time series index that is updated on occasion however the data is typically very static. I would like to create a time series index from this data so I can track when it changes. I thought I could …

---

## [How to improve Kibana Dashboard loading Performance](https://discuss.elastic.co/t/how-to-improve-kibana-dashboard-loading-performance/325545)

<div class="topic-metadata">

**Author:** [@ysattvik](https://discuss.elastic.co/u/ysattvik)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 5:59pm UTC](https://discuss.elastic.co/t/how-to-improve-kibana-dashboard-loading-performance/325545 "2023-02-22T17:59:15Z")

</div>

Hi Team, I am using Kibana 8.5.0 And I am using single cluster, single node and index size is also not so big, it is some kb but still while loading the Dashboard, it is taking more than 10 seconds of time. \*\*Is there …

---

## [Unable to restart Kibana after configuring CSV max size](https://discuss.elastic.co/t/unable-to-restart-kibana-after-configuring-csv-max-size/325494)

<div class="topic-metadata">

**Author:** [@maskrider1111](https://discuss.elastic.co/u/maskrider1111)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 5:49pm UTC](https://discuss.elastic.co/t/unable-to-restart-kibana-after-configuring-csv-max-size/325494 "2023-02-22T17:49:52Z")

</div>

Hey guys, My Kibana failed to restart after i changed the CSV setting "maxSizeBytes" in kibana.yml. Its working well if i reverted back the settings. Please advise

---

## [Logstash logs filling up disk. How to configure log4j?](https://discuss.elastic.co/t/logstash-logs-filling-up-disk-how-to-configure-log4j/326207)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 5:29pm UTC](https://discuss.elastic.co/t/logstash-logs-filling-up-disk-how-to-configure-log4j/326207 "2023-02-22T17:29:13Z")

</div>

Hi all, We are currently facing an issue where Logstash fills up disk space on some of the nodes on our K8s cluster by outputting entire events to stdout. I am aware that I can change the loglevel of Logstash as a whole…

---

## [Trouble with my ILM](https://discuss.elastic.co/t/trouble-with-my-ilm/326051)

<div class="topic-metadata">

**Author:** [@ccaillet](https://discuss.elastic.co/u/ccaillet)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 3:50pm UTC](https://discuss.elastic.co/t/trouble-with-my-ilm/326051 "2023-02-22T15:50:04Z")

</div>

Hi all, I've the following paramters on my ILM : "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": { "rollover": { "max\_primary\_shard\_size": "12gb…

---

## [Very big time gap when use wildcard field on one word search](https://discuss.elastic.co/t/very-big-time-gap-when-use-wildcard-field-on-one-word-search/325947)

<div class="topic-metadata">

**Author:** [@913043599](https://discuss.elastic.co/u/913043599)\
**Replies:** 3\
**Last updated:** [February 22, 2023, 3:48pm UTC](https://discuss.elastic.co/t/very-big-time-gap-when-use-wildcard-field-on-one-word-search/325947 "2023-02-22T15:48:19Z")

</div>

Hi, When I used the new field type - wildcard field - for some queries, I found that different query inputs had a significant time difference, even though the input length was always one character: You can see ther…

---

## [Error Events with "\>"](https://discuss.elastic.co/t/error-events-with/326192)

<div class="topic-metadata">

**Author:** [@akrog79](https://discuss.elastic.co/u/akrog79)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 3:43pm UTC](https://discuss.elastic.co/t/error-events-with/326192 "2023-02-22T15:43:21Z")

</div>

Hello people! I have a trouble with the ingestion of a anomaly events in fortigate. The raw event is: \<185\>logver=702032456 timestamp=1676305141 devname="FG200-E" devid="FG200ETK189243" vd="root" date=2023-02-13 time=…

---

## [Custom integration](https://discuss.elastic.co/t/custom-integration/324819)

<div class="topic-metadata">

**Author:** [@adrien\_moreau](https://discuss.elastic.co/u/adrien_moreau)\
**Replies:** 2\
**Last updated:** [February 22, 2023, 3:30pm UTC](https://discuss.elastic.co/t/custom-integration/324819 "2023-02-22T15:30:04Z")

</div>

Hi, I would like to build my own custom elastic integration for a self managed elk. I read documentation here: https://www.elastic.co/guide/en/integrations-developer I would like to know if the only way to use that in…

---

## [Dashboard creation with a query](https://discuss.elastic.co/t/dashboard-creation-with-a-query/326064)

<div class="topic-metadata">

**Author:** [@Haneesha](https://discuss.elastic.co/u/Haneesha)\
**Replies:** 7\
**Last updated:** [February 22, 2023, 3:07pm UTC](https://discuss.elastic.co/t/dashboard-creation-with-a-query/326064 "2023-02-22T15:07:27Z")

</div>

Hi Team, Could you please let me know how to create a dashboard using a query. I have a query, i am supposed to create a dashboard. Query: select type\_cd,status\_cd, count(row\_id) from siebel.s\_loy\_txn where TXN\_DT \>=…

---

## [Question about KEMP LoadManager](https://discuss.elastic.co/t/question-about-kemp-loadmanager/326188)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 3:02pm UTC](https://discuss.elastic.co/t/question-about-kemp-loadmanager/326188 "2023-02-22T15:02:27Z")

</div>

In my home lab i am testing the collection of syslog from a Kemp LoadManager. Has anyone every worked with this product to ingest or have the syslogs captured? I was able to find the folowing page and have gone throug…

---

## [Joins across heterogenous documents in an index](https://discuss.elastic.co/t/joins-across-heterogenous-documents-in-an-index/325536)

<div class="topic-metadata">

**Author:** [@kembhootha](https://discuss.elastic.co/u/kembhootha)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 2:58pm UTC](https://discuss.elastic.co/t/joins-across-heterogenous-documents-in-an-index/325536 "2023-02-22T14:58:35Z")

</div>

Newbie to ES. I have heterogenous documents being thrown into the same index in ES . Some example documents ( 8 typical documents that would be in the index ) {"actor\_id":1, "actor\_name":"Adam Sandler"} {"actor\_id":2,…

---

## [Unable to send logs using Filebeat to Logstash](https://discuss.elastic.co/t/unable-to-send-logs-using-filebeat-to-logstash/326114)

<div class="topic-metadata">

**Author:** [@Chris\_W1](https://discuss.elastic.co/u/Chris_W1)\
**Replies:** 11\
**Last updated:** [February 22, 2023, 2:57pm UTC](https://discuss.elastic.co/t/unable-to-send-logs-using-filebeat-to-logstash/326114 "2023-02-22T14:57:53Z")

</div>

Hi Team, I am trying to send logs in .json file on one of my server to Logstash using Filebeat. Below are the configs I did on the Filebeat & Logstash but I am not able to send it successfully. Your suggestions and help…

---

## [Implement elastic agent to collect postgresql log](https://discuss.elastic.co/t/implement-elastic-agent-to-collect-postgresql-log/326189)

<div class="topic-metadata">

**Author:** [@bagafoot](https://discuss.elastic.co/u/bagafoot)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 2:47pm UTC](https://discuss.elastic.co/t/implement-elastic-agent-to-collect-postgresql-log/326189 "2023-02-22T14:47:50Z")

</div>

Hello all, I recently install elastic agent in postgresql server, I follow steps that in integration scope "add postgresql" in kibana user interface, download the yaml file and copy to postgresql server agent home dir …

---

## [How to maintain the JSON sequence in the response from Elasctic, currently ordering is getting changed](https://discuss.elastic.co/t/how-to-maintain-the-json-sequence-in-the-response-from-elasctic-currently-ordering-is-getting-changed/326168)

<div class="topic-metadata">

**Author:** [@Shraddha29](https://discuss.elastic.co/u/Shraddha29)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 2:08pm UTC](https://discuss.elastic.co/t/how-to-maintain-the-json-sequence-in-the-response-from-elasctic-currently-ordering-is-getting-changed/326168 "2023-02-22T14:08:33Z")

</div>

How to maintain the JSON sequence in the response from Elastic, currently ordering is getting changed to what was inserted.

---

## [Kibana email alert](https://discuss.elastic.co/t/kibana-email-alert/326147)

<div class="topic-metadata">

**Author:** [@Sharmila\_Natarajan](https://discuss.elastic.co/u/Sharmila_Natarajan)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 1:56pm UTC](https://discuss.elastic.co/t/kibana-email-alert/326147 "2023-02-22T13:56:25Z")

</div>

Hi, We are using ELK setup on Kubernetes with a basic license version (8.5.3 - ECK TEMPLATE INSTALLATION), our requirement is to send email alerts based on some logs from the index (eg. if number of test environments ar…

---

## [Transporterror 429 for search & bulk operations](https://discuss.elastic.co/t/transporterror-429-for-search-bulk-operations/326180)

<div class="topic-metadata">

**Author:** [@abhaygc](https://discuss.elastic.co/u/abhaygc)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 1:55pm UTC](https://discuss.elastic.co/t/transporterror-429-for-search-bulk-operations/326180 "2023-02-22T13:55:02Z")

</div>

I am getting elasticsearch.exceptions.TransportError: TransportError(429, '429 Too Many Requests for my "\_search" & "\_bulk" operations. My cluster health is green. I have monitored threadpool write & search queues. Nu…

---

## [Rabbitmq output plugin with 'x-delayed-message' exchange](https://discuss.elastic.co/t/rabbitmq-output-plugin-with-x-delayed-message-exchange/326182)

<div class="topic-metadata">

**Author:** [@yilmazbuhar](https://discuss.elastic.co/u/yilmazbuhar)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 1:04pm UTC](https://discuss.elastic.co/t/rabbitmq-output-plugin-with-x-delayed-message-exchange/326182 "2023-02-22T13:04:07Z")

</div>

Hi all, Can i send a message to "x-delayed-message" exchange with logstash. When i try this, getting error like this output { rabbitmq { # This setting must be a \["fanout", "direct", "topic", "x-consistent-…

---

## [How to search Multiple dense vector fields, including nested filelds](https://discuss.elastic.co/t/how-to-search-multiple-dense-vector-fields-including-nested-filelds/326119)

<div class="topic-metadata">

**Author:** [@shijithp007](https://discuss.elastic.co/u/shijithp007)\
**Replies:** 3\
**Last updated:** [February 22, 2023, 12:58pm UTC](https://discuss.elastic.co/t/how-to-search-multiple-dense-vector-fields-including-nested-filelds/326119 "2023-02-22T12:58:04Z")

</div>

I am working on semantic search, where i try to save processed results of scraped website data. Website has title, summary, sub\_section\_headings and sub\_section\_data. i am storing title & summary as dense vectors and sub…

---

## [Logstash setup on Azure kubernetes services](https://discuss.elastic.co/t/logstash-setup-on-azure-kubernetes-services/326159)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 10:38am UTC](https://discuss.elastic.co/t/logstash-setup-on-azure-kubernetes-services/326159 "2023-02-22T10:38:13Z")

</div>

i am running Elasticsearch and kibana as container on azure kubernetes services iam able to run as expected both Elasticsearch and kibana and load some sample logs from a file Now iam trying to load kubernetes sample lo…

---

## [Cant convert timestamp field from text to date](https://discuss.elastic.co/t/cant-convert-timestamp-field-from-text-to-date/326158)

<div class="topic-metadata">

**Author:** [@Dor\_Steinberg](https://discuss.elastic.co/u/Dor_Steinberg)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 10:36am UTC](https://discuss.elastic.co/t/cant-convert-timestamp-field-from-text-to-date/326158 "2023-02-22T10:36:30Z")

</div>

hello everyone, i got problem converting log.timestamp field from text to date someone can help me understand what am i doing wrong? i also will appreciate if do you have an idea of getting the day of the week from th…

---

## [Index pattern not creating](https://discuss.elastic.co/t/index-pattern-not-creating/326126)

<div class="topic-metadata">

**Author:** [@akhilkv43](https://discuss.elastic.co/u/akhilkv43)\
**Replies:** 2\
**Last updated:** [February 22, 2023, 9:54am UTC](https://discuss.elastic.co/t/index-pattern-not-creating/326126 "2023-02-22T09:54:30Z")

</div>

In Elasticsearch yml i have provided the code to create index pattern named production When opening kibana its not reflecting. here is the code i ahve injected in elasticsearch action.auto\_create\_index: .monitoring\*,.…

---

## [Kibana 8.6.1 keeps Loading Elastic forever when using a JWT token](https://discuss.elastic.co/t/kibana-8-6-1-keeps-loading-elastic-forever-when-using-a-jwt-token/325282)

<div class="topic-metadata">

**Author:** [@frits](https://discuss.elastic.co/u/frits)\
**Replies:** 11\
**Last updated:** [February 22, 2023, 9:18am UTC](https://discuss.elastic.co/t/kibana-8-6-1-keeps-loading-elastic-forever-when-using-a-jwt-token/325282 "2023-02-22T09:18:50Z")

</div>

I've been trying to get a JWT token login to work for a few days now. I've made a couple of great steps, I think I've managed to authenticate against the JWT provider (Broadcom IDM). I think I've created a correct role a…

---

## [Weired behaviour of fuzziness in elasticsearch](https://discuss.elastic.co/t/weired-behaviour-of-fuzziness-in-elasticsearch/326058)

<div class="topic-metadata">

**Author:** [@alliswell](https://discuss.elastic.co/u/alliswell)\
**Replies:** 2\
**Last updated:** [February 22, 2023, 9:10am UTC](https://discuss.elastic.co/t/weired-behaviour-of-fuzziness-in-elasticsearch/326058 "2023-02-22T09:10:14Z")

</div>

I have following document in my\_index: { "title": "weiß", "id": 1 } Consider the following query: GET my\_index/\_search?explain=true { "\_source": \["title"\], "query": { "bool": { "must": \[ { …

---

## [\[ERROR\]\[plugins.alerting\] Executing Alert default:monitoring\_alert\_XXX](https://discuss.elastic.co/t/error-plugins-alerting-executing-alert-default-monitoring-alert-xxx/326140)

<div class="topic-metadata">

**Author:** [@thesn](https://discuss.elastic.co/u/thesn)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 8:52am UTC](https://discuss.elastic.co/t/error-plugins-alerting-executing-alert-default-monitoring-alert-xxx/326140 "2023-02-22T08:52:34Z")

</div>

Hi, I have ES and Kibana 7.16.2 running on Docker. When I see the docker logs for Kibana, there are a number of errors related to plugins.alerting: \[2023-02-21T17:07:20.438+07:00\]\[ERROR\]\[plugins.alerting\] Executing Al…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=623)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=625)
