# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=625

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 626

---

## [Infinite extent for field "y1": \[Infinity, -Infinity\]](https://discuss.elastic.co/t/infinite-extent-for-field-y1-infinity-infinity/326137)

<div class="topic-metadata">

**Author:** [@Thearith](https://discuss.elastic.co/u/Thearith)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 7:55am UTC](https://discuss.elastic.co/t/infinite-extent-for-field-y1-infinity-infinity/326137 "2023-02-22T07:55:42Z")

</div>

Here is the code that I'm using for create sankey diagram: { $schema: https://vega.github.io/schema/vega/v3.0.json data: \[ { // query ES based on the currently selected time range and filter string name: rawData u…

---

## [Kafka increasing consumer lag](https://discuss.elastic.co/t/kafka-increasing-consumer-lag/326125)

<div class="topic-metadata">

**Author:** [@Sophia](https://discuss.elastic.co/u/Sophia)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 5:53am UTC](https://discuss.elastic.co/t/kafka-increasing-consumer-lag/326125 "2023-02-22T05:53:12Z")

</div>

Hello! I have ELK stack installed with Kafka on Docker containers. There is lag between incoming logs and consuming logs that is increasing, and offset reading speed is not enough. Kafka have only one topic. I tried dif…

---

## [Https communication not secured for elasticsearch](https://discuss.elastic.co/t/https-communication-not-secured-for-elasticsearch/326026)

<div class="topic-metadata">

**Author:** [@akhilkv43](https://discuss.elastic.co/u/akhilkv43)\
**Replies:** 3\
**Last updated:** [February 22, 2023, 5:59am UTC](https://discuss.elastic.co/t/https-communication-not-secured-for-elasticsearch/326026 "2023-02-22T05:59:21Z")

</div>

I am using single node version is 8.5.3 Getting" Your connection to this site is not secured". I used cert and key in yml file Attaching the yml file can anybody advise on installation ======================== Elas…

---

## [Need help for installing Elastic-search, filebeat, logstash, metricbeat and kibana via helm using 8.5.1](https://discuss.elastic.co/t/need-help-for-installing-elastic-search-filebeat-logstash-metricbeat-and-kibana-via-helm-using-8-5-1/325994)

<div class="topic-metadata">

**Author:** [@Ram\_M](https://discuss.elastic.co/u/Ram_M)\
**Replies:** 11\
**Last updated:** [February 22, 2023, 4:43am UTC](https://discuss.elastic.co/t/need-help-for-installing-elastic-search-filebeat-logstash-metricbeat-and-kibana-via-helm-using-8-5-1/325994 "2023-02-22T04:43:25Z")

</div>

Hi all... I've using the helm chart for Elastic -search, Filebeat, Logstash and Kibana. Version is 8.5.1 environment in kubernetes AKS. Issue is Logstash not recognize the elastic-search. I need proper installation gui…

---

## [Using synonym\_graph means non-synonyms are not found](https://discuss.elastic.co/t/using-synonym-graph-means-non-synonyms-are-not-found/326022)

<div class="topic-metadata">

**Author:** [@Jonathan\_Mugan](https://discuss.elastic.co/u/Jonathan_Mugan)\
**Replies:** 8\
**Last updated:** [February 22, 2023, 4:20am UTC](https://discuss.elastic.co/t/using-synonym-graph-means-non-synonyms-are-not-found/326022 "2023-02-22T04:20:43Z")

</div>

Hi, I have this analyzer settings = { "analysis": { "analyzer": { "gale\_analyzer": { "tokenizer": "standard", "filter": \[ "lowercase", …

---

## [Manually-configured security in cluster](https://discuss.elastic.co/t/manually-configured-security-in-cluster/325708)

<div class="topic-metadata">

**Author:** [@frank\_2](https://discuss.elastic.co/u/frank_2)\
**Replies:** 3\
**Last updated:** [February 22, 2023, 1:23am UTC](https://discuss.elastic.co/t/manually-configured-security-in-cluster/325708 "2023-02-22T01:23:42Z")

</div>

Hello, I'm following the guide on how to manually set up security within a cluster. Am I right in thinking that the instructions tell the reader to copy the same transport certificate and key to every node in the clust…

---

## [Trying to bring up filebeat + logstash + Elasticsea + Kibana](https://discuss.elastic.co/t/trying-to-bring-up-filebeat-logstash-elasticsea-kibana/326095)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 3\
**Last updated:** [February 22, 2023, 1:05am UTC](https://discuss.elastic.co/t/trying-to-bring-up-filebeat-logstash-elasticsea-kibana/326095 "2023-02-22T01:05:58Z")

</div>

Hi! Followed Elasticsearch docs while installing elasticsearch + kibana + logstash + filebeat default set up. For the moment filebeat configured to send events using logstash-tutorial.log.gz (extracted to logstash-tu…

---

## [Missing "Edit hosts" button under "Fleet server hosts" in Kibana](https://discuss.elastic.co/t/missing-edit-hosts-button-under-fleet-server-hosts-in-kibana/326109)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 2\
**Last updated:** [February 22, 2023, 12:57am UTC](https://discuss.elastic.co/t/missing-edit-hosts-button-under-fleet-server-hosts-in-kibana/326109 "2023-02-22T00:57:00Z")

</div>

Hello. I am trying to set up APM for my Elastic Stack by following this tutorial (Quick start | APM User Guide \[8.6\] | Elastic). I am currently on "Step 1: Set up Fleet". The second step of that section says, "Under Fle…

---

## [No logstash output on windows](https://discuss.elastic.co/t/no-logstash-output-on-windows/326077)

<div class="topic-metadata">

**Author:** [@jeanette](https://discuss.elastic.co/u/jeanette)\
**Replies:** 6\
**Last updated:** [February 21, 2023, 11:50pm UTC](https://discuss.elastic.co/t/no-logstash-output-on-windows/326077 "2023-02-21T23:50:09Z")

</div>

Hello, I have been troubleshooting my logstash for some time now. I was following the "Parsing Logs with Logstash" tutorial for Windows and have not been able to see any output with the basic pipeline. Below is my first-…

---

## [Ruby script for auditd EXECVE logs](https://discuss.elastic.co/t/ruby-script-for-auditd-execve-logs/326098)

<div class="topic-metadata">

**Author:** [@JCW](https://discuss.elastic.co/u/JCW)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 10:53pm UTC](https://discuss.elastic.co/t/ruby-script-for-auditd-execve-logs/326098 "2023-02-21T22:53:09Z")

</div>

I want to make a ruby script that makes an extra field for "command" that it parses out of the message that auditd creates, however it does not work and I am unable to figure out why. example log: type=EXECVE msg=audit…

---

## [\[ERROR\] Cannot race. Worker \[22\] has exited prematurely](https://discuss.elastic.co/t/error-cannot-race-worker-22-has-exited-prematurely/325690)

<div class="topic-metadata">

**Author:** [@Utkarsh17](https://discuss.elastic.co/u/Utkarsh17)\
**Replies:** 1\
**Last updated:** [February 21, 2023, 9:40pm UTC](https://discuss.elastic.co/t/error-cannot-race-worker-22-has-exited-prematurely/325690 "2023-02-21T21:40:35Z")

</div>

Hi, I am getting the error -------\>\[ERROR\] Cannot race. Worker \[22\] has exited prematurely. Following is setup and configuration Elastic Search ver 8.5.2 ESRally ver 2.7.0 5 node Kubernetes cluster with 1 controller …

---

## [Elaticsearch cluster back up is failing - "reason":"RepositoryMissingException"](https://discuss.elastic.co/t/elaticsearch-cluster-back-up-is-failing-reason-repositorymissingexception/326074)

<div class="topic-metadata">

**Author:** [@chateesh](https://discuss.elastic.co/u/chateesh)\
**Replies:** 10\
**Last updated:** [February 21, 2023, 9:39pm UTC](https://discuss.elastic.co/t/elaticsearch-cluster-back-up-is-failing-reason-repositorymissingexception/326074 "2023-02-21T21:39:14Z")

</div>

We've backup repository type as S3, and cluster is running as dockerized AWS EC2, recently snapshot process is failing with reason "reason":"RepositoryMissingException". This error is coming from one of the data node. C…

---

## [Why does indexation load create query load?](https://discuss.elastic.co/t/why-does-indexation-load-create-query-load/326055)

<div class="topic-metadata">

**Author:** [@alsyia](https://discuss.elastic.co/u/alsyia)\
**Replies:** 1\
**Last updated:** [February 21, 2023, 9:36pm UTC](https://discuss.elastic.co/t/why-does-indexation-load-create-query-load/326055 "2023-02-21T21:36:32Z")

</div>

Hi everyone, I've noticed when my ES (5.6) cluster is indexing lots of documents the number of queries being answered also increases. I index using the op\_type "create" with predefined ids, so I guess this is just the c…

---

## [Got err with ES API request "no handler found for uri"](https://discuss.elastic.co/t/got-err-with-es-api-request-no-handler-found-for-uri/325820)

<div class="topic-metadata">

**Author:** [@dsafsdzdfaer](https://discuss.elastic.co/u/dsafsdzdfaer)\
**Replies:** 1\
**Last updated:** [February 21, 2023, 9:31pm UTC](https://discuss.elastic.co/t/got-err-with-es-api-request-no-handler-found-for-uri/325820 "2023-02-21T21:31:29Z")

</div>

I got err with the below request : url = ENV\['KIBANA\_ELASTICSEARCH\_SERVICE'\] + '/mib\_prod\*/\_search?filter\_path=hits.hits.\_source.message,hits.hits.\_source.timestamp' header = {'Content-Type' =\> 'application/json'} …

---

## [Elasticsearch monitoring by metricbeat creating index with pattern .ds-.monitoring-es-8-mb-yyyy.mm.dd-\*](https://discuss.elastic.co/t/elasticsearch-monitoring-by-metricbeat-creating-index-with-pattern-ds-monitoring-es-8-mb-yyyy-mm-dd/326084)

<div class="topic-metadata">

**Author:** [@ramdas](https://discuss.elastic.co/u/ramdas)\
**Replies:** 0\
**Last updated:** [February 21, 2023, 2:55pm UTC](https://discuss.elastic.co/t/elasticsearch-monitoring-by-metricbeat-creating-index-with-pattern-ds-monitoring-es-8-mb-yyyy-mm-dd/326084 "2023-02-21T14:55:58Z")

</div>

Hi, I have recently started testing to use metricbeat for elasticsearch's monitoring. i have elasticsearch deployed as statefulset and metricbeat as daemonset on azure kubernetes services cluster. i have configured met…

---

## [Multiline settings for handling edge cases of stdout logs of mixed ndjson and java](https://discuss.elastic.co/t/multiline-settings-for-handling-edge-cases-of-stdout-logs-of-mixed-ndjson-and-java/324189)

<div class="topic-metadata">

**Author:** [@tolland](https://discuss.elastic.co/u/tolland)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 8:40pm UTC](https://discuss.elastic.co/t/multiline-settings-for-handling-edge-cases-of-stdout-logs-of-mixed-ndjson-and-java/324189 "2023-02-21T20:40:47Z")

</div>

Hi, I am currently working with a system that has spring apps running as wars in tomcat, and am currently sending the logs to an ingest pipeline using filebeat. Unfortunately due to legacy reasons, logs are being output…

---

## [How to prevent other nodes from joining my cluster?](https://discuss.elastic.co/t/how-to-prevent-other-nodes-from-joining-my-cluster/326096)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 3\
**Last updated:** [February 21, 2023, 7:25pm UTC](https://discuss.elastic.co/t/how-to-prevent-other-nodes-from-joining-my-cluster/326096 "2023-02-21T19:25:02Z")

</div>

How can I prevent other elasticsearch nodes from joining my cluster. Let's say I initiate a single node elastic cluster like this: (Notice I am using letsencrypt ssl certificates) cluster.initial\_master\_nodes: \["node1…

---

## [Kibana error: There are no living connections](https://discuss.elastic.co/t/kibana-error-there-are-no-living-connections/326097)

<div class="topic-metadata">

**Author:** [@bcantrell](https://discuss.elastic.co/u/bcantrell)\
**Replies:** 0\
**Last updated:** [February 21, 2023, 6:55pm UTC](https://discuss.elastic.co/t/kibana-error-there-are-no-living-connections/326097 "2023-02-21T18:55:55Z")

</div>

Hello all, All servers are running ELK versions 8.1.3 (I know, upgrade is in the works), on Windows 2016. This error started getting spammed on 2023-02-17 after hours in the kibana log file and I cannot figure out how …

---

## [How to add "missing" parameter in multi\_terms aggregations using Java Api Client](https://discuss.elastic.co/t/how-to-add-missing-parameter-in-multi-terms-aggregations-using-java-api-client/326046)

<div class="topic-metadata">

**Author:** [@AlexSafonov](https://discuss.elastic.co/u/AlexSafonov)\
**Replies:** 0\
**Last updated:** [February 21, 2023, 9:52am UTC](https://discuss.elastic.co/t/how-to-add-missing-parameter-in-multi-terms-aggregations-using-java-api-client/326046 "2023-02-21T09:52:52Z")

</div>

Hi! I would like to find a way to add "missing" parameter in multi\_terms aggregations using java api client. "multi\_terms": { "terms": \[ { "field": "workDate" }, { "field": "teamName…

---

## [Compare 2 fields and drop the matching](https://discuss.elastic.co/t/compare-2-fields-and-drop-the-matching/326032)

<div class="topic-metadata">

**Author:** [@Dr.Dark92](https://discuss.elastic.co/u/Dr.Dark92)\
**Replies:** 1\
**Last updated:** [February 21, 2023, 5:27pm UTC](https://discuss.elastic.co/t/compare-2-fields-and-drop-the-matching/326032 "2023-02-21T17:27:45Z")

</div>

Hi, I am trying to make a Dashbaord for Bind9 engine, in brief i have 3 indexes, first index for Blacklist logs second index for whitelist logs third index for resolver logs. the goal is : to drop any blacklisted d…

---

## [An alias for the node.name settings](https://discuss.elastic.co/t/an-alias-for-the-node-name-settings/326082)

<div class="topic-metadata">

**Author:** [@Roberto\_B](https://discuss.elastic.co/u/Roberto_B)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 4:52pm UTC](https://discuss.elastic.co/t/an-alias-for-the-node-name-settings/326082 "2023-02-21T16:52:40Z")

</div>

Hi all, it could be a strange question, but i need to have an alias for the same host in the cluster, for example: if i have a host with node.name: host1 I would like to have an alias for the same host like: "host1.fak…

---

## [Financial Year in Controls Visualization Options](https://discuss.elastic.co/t/financial-year-in-controls-visualization-options/324873)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [February 21, 2023, 4:01pm UTC](https://discuss.elastic.co/t/financial-year-in-controls-visualization-options/324873 "2023-02-21T16:01:40Z")

</div>

Hi all, I'm trying to display control visualization to show reports of a dashboard for 3 financial years ( Apr2021-Mar2022 & so on). But I cannot show this financial year in my controls option? from my date field, I c…

---

## [Nest Fuzzy Search per Account Field](https://discuss.elastic.co/t/nest-fuzzy-search-per-account-field/326093)

<div class="topic-metadata">

**Author:** [@Andreas1](https://discuss.elastic.co/u/Andreas1)\
**Replies:** 0\
**Last updated:** [February 21, 2023, 3:40pm UTC](https://discuss.elastic.co/t/nest-fuzzy-search-per-account-field/326093 "2023-02-21T15:40:29Z")

</div>

I am struggling with Elasticsearch using NEST for C#. Let's assume an index of UserAccounts which looks like \[{ AccountId: 1, Name: "Test Account", Email: "test@test.com", Phone: "01234/5678", Street: "test Street 1", Z…

---

## [Snmptrap to logstash](https://discuss.elastic.co/t/snmptrap-to-logstash/326092)

<div class="topic-metadata">

**Author:** [@diegz](https://discuss.elastic.co/u/diegz)\
**Replies:** 0\
**Last updated:** [February 21, 2023, 3:35pm UTC](https://discuss.elastic.co/t/snmptrap-to-logstash/326092 "2023-02-21T15:35:45Z")

</div>

Hello, I would like to send traps retrieved via the snmptrap service on RHEL 8 to logstash to store them on Elasticsearch. As the snmptrap input module does not support v3, I installed snmptrapd on the logstash server …

---

## [Elastic Defend integration on Windows Servers influences results from system.process dataset](https://discuss.elastic.co/t/elastic-defend-integration-on-windows-servers-influences-results-from-system-process-dataset/326087)

<div class="topic-metadata">

**Author:** [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Replies:** 0\
**Last updated:** [February 21, 2023, 3:22pm UTC](https://discuss.elastic.co/t/elastic-defend-integration-on-windows-servers-influences-results-from-system-process-dataset/326087 "2023-02-21T15:22:31Z")

</div>

I have added the Elastic Defend integration to Policies for Windows and Linux Servers today. After activation, the system.process dataset on the Windows servers doesn't report elastic-agent.exe as a running process any …

---

## [How to change valueColor to linear-gradient color of progress wheel in kibana canvas?](https://discuss.elastic.co/t/how-to-change-valuecolor-to-linear-gradient-color-of-progress-wheel-in-kibana-canvas/326086)

<div class="topic-metadata">

**Author:** [@RJ\_Chen](https://discuss.elastic.co/u/RJ_Chen)\
**Replies:** 0\
**Last updated:** [February 21, 2023, 3:07pm UTC](https://discuss.elastic.co/t/how-to-change-valuecolor-to-linear-gradient-color-of-progress-wheel-in-kibana-canvas/326086 "2023-02-21T15:07:47Z")

</div>

Hi, I want to change progress wheel's valueColor to linear-gradient color , I try to use expression editor and css to change it . but it's not work.... \>\<

---

## [Logstash Grok Path "\\" character](https://discuss.elastic.co/t/logstash-grok-path-character/326083)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 1\
**Last updated:** [February 21, 2023, 3:03pm UTC](https://discuss.elastic.co/t/logstash-grok-path-character/326083 "2023-02-21T15:03:42Z")

</div>

Hello, I have a problem that seems simple to solve, but I'm having trouble solving it. I have to grok a path, here is a path similar to mine: D:\\MyFiles\\allmylogs.log I have a problem with the "\\". How can I inclu…

---

## [Filter the list of shown in Kibana Dashboard Control](https://discuss.elastic.co/t/filter-the-list-of-shown-in-kibana-dashboard-control/324681)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 2:04pm UTC](https://discuss.elastic.co/t/filter-the-list-of-shown-in-kibana-dashboard-control/324681 "2023-02-21T14:04:18Z")

</div>

I am creating a dashboard in Kibana, and I'm using a Control for the first time, rather than an Input Control, as I have in the past. The issue: I'm using a lens that only draws data from a subset of hosts by applying a…

---

## [I have this code, and it is getting information from a database, and I would like this code to be able to see it in a graph. Can one help me?](https://discuss.elastic.co/t/i-have-this-code-and-it-is-getting-information-from-a-database-and-i-would-like-this-code-to-be-able-to-see-it-in-a-graph-can-one-help-me/325503)

<div class="topic-metadata">

**Author:** [@edson](https://discuss.elastic.co/u/edson)\
**Replies:** 7\
**Last updated:** [February 21, 2023, 2:07pm UTC](https://discuss.elastic.co/t/i-have-this-code-and-it-is-getting-information-from-a-database-and-i-would-like-this-code-to-be-able-to-see-it-in-a-graph-can-one-help-me/325503 "2023-02-21T14:07:57Z")

</div>

{ "name": "server5", "middleware": \[ { "name": "mq", "version": "9.2", "status": "green" }, { "name": "was", "version": "9", "status": "green" } \] }

---

## [Elasticsearch snapshot working](https://discuss.elastic.co/t/elasticsearch-snapshot-working/326067)

<div class="topic-metadata">

**Author:** [@Vikrant\_Aggarwal](https://discuss.elastic.co/u/Vikrant_Aggarwal)\
**Replies:** 3\
**Last updated:** [February 21, 2023, 2:01pm UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-working/326067 "2023-02-21T14:01:38Z")

</div>

Hello Experts, I have theoretical question about working of ES snapshots. I know snapshots are incremental. We have one cluster in which we are keeping the data forever, we take the snapshot on daily basis, we want to …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=624)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=626)
