# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=626

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 627

---

## [How to display the value in x-axis of a stacked bar only once instead of multiple times?](https://discuss.elastic.co/t/how-to-display-the-value-in-x-axis-of-a-stacked-bar-only-once-instead-of-multiple-times/324434)

<div class="topic-metadata">

**Author:** [@Srikanth\_V](https://discuss.elastic.co/u/Srikanth_V)\
**Replies:** 1\
**Last updated:** [February 21, 2023, 1:54pm UTC](https://discuss.elastic.co/t/how-to-display-the-value-in-x-axis-of-a-stacked-bar-only-once-instead-of-multiple-times/324434 "2023-02-21T13:54:30Z")

</div>

Hello, I am currently using a histogram date interval as year and it seems to be appearing multiple times in the x-axis. Is there a way, we can restrict this value to be shown only once? Thanks in advance.

---

## [Fleet Server - Filebeat Using HTTP instead of HTTPS](https://discuss.elastic.co/t/fleet-server-filebeat-using-http-instead-of-https/325657)

<div class="topic-metadata">

**Author:** [@pritchey](https://discuss.elastic.co/u/pritchey)\
**Replies:** 8\
**Last updated:** [February 21, 2023, 1:38pm UTC](https://discuss.elastic.co/t/fleet-server-filebeat-using-http-instead-of-https/325657 "2023-02-21T13:38:59Z")

</div>

I have a self-hosted elastic stack running 8.6.1. I'm trying to get fleet running but I'm hitting a wall on one part. The fleet server and any agents show as "healthy" but no data every shows up. Digging into things I…

---

## [Logstash webhook when parsing is done](https://discuss.elastic.co/t/logstash-webhook-when-parsing-is-done/326050)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 1\
**Last updated:** [February 21, 2023, 12:59pm UTC](https://discuss.elastic.co/t/logstash-webhook-when-parsing-is-done/326050 "2023-02-21T12:59:33Z")

</div>

Hello community! I'm currently working on integration elastic stack with my custom application. I'm trying to find out if possible for logstash to create webook call when processing is done? The workload is: File upload…

---

## [Lower precision\_threshold in cardinality takes more time than higher](https://discuss.elastic.co/t/lower-precision-threshold-in-cardinality-takes-more-time-than-higher/326063)

<div class="topic-metadata">

**Author:** [@Maya\_Simhi](https://discuss.elastic.co/u/Maya_Simhi)\
**Replies:** 0\
**Last updated:** [February 21, 2023, 11:56am UTC](https://discuss.elastic.co/t/lower-precision-threshold-in-cardinality-takes-more-time-than-higher/326063 "2023-02-21T11:56:20Z")

</div>

Hi, I'm using cardinality aggregation as a sub aggregation inside a term aggregation. I read a lot of explanations from Elasticsearch that says the higher the precision\_threshold the more time the query takes. but I se…

---

## [How to run a ruby function that updates and event and clears the empty fields recursively](https://discuss.elastic.co/t/how-to-run-a-ruby-function-that-updates-and-event-and-clears-the-empty-fields-recursively/326057)

<div class="topic-metadata">

**Author:** [@vilman](https://discuss.elastic.co/u/vilman)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 11:12am UTC](https://discuss.elastic.co/t/how-to-run-a-ruby-function-that-updates-and-event-and-clears-the-empty-fields-recursively/326057 "2023-02-21T11:12:30Z")

</div>

I got an event which sometimes contain empty fields. I would like to delete those fields which are null and those which are empty.

---

## [Unwanted line break of numerical value in tooltip](https://discuss.elastic.co/t/unwanted-line-break-of-numerical-value-in-tooltip/325706)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 4\
**Last updated:** [February 21, 2023, 10:57am UTC](https://discuss.elastic.co/t/unwanted-line-break-of-numerical-value-in-tooltip/325706 "2023-02-21T10:57:50Z")

</div>

Hello, when adding a break down to visualizations, the tooltip width can be to small, so a line break is made. Which is ok, by itself, but it results in also adding a line break in the numerical value in the end: The…

---

## [High Level Rest Client Java initialisation slowing down the application](https://discuss.elastic.co/t/high-level-rest-client-java-initialisation-slowing-down-the-application/326044)

<div class="topic-metadata">

**Author:** [@anis.tajouri](https://discuss.elastic.co/u/anis.tajouri)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 10:34am UTC](https://discuss.elastic.co/t/high-level-rest-client-java-initialisation-slowing-down-the-application/326044 "2023-02-21T10:34:45Z")

</div>

Using following java code initialising the High Level Rest Client in a web service, without performing any elasticsearch request, I have additional 250ms when calling the web service. commenting this code, I have less a…

---

## [How to remove duplication when aggregating data for visualization?](https://discuss.elastic.co/t/how-to-remove-duplication-when-aggregating-data-for-visualization/324407)

<div class="topic-metadata">

**Author:** [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 10:10am UTC](https://discuss.elastic.co/t/how-to-remove-duplication-when-aggregating-data-for-visualization/324407 "2023-02-01T10:10:12Z")

</div>

Hi! Based on answers from other posts, I learned that I need to upload "normalized data" to Kibana, which may come at the cost of sending duplicated data: { file: foo, project: foo, count: 123, id: 1 } { file: foo, pr…

---

## [Embed dashboard and/or kibana anonymous on ElasticCloud](https://discuss.elastic.co/t/embed-dashboard-and-or-kibana-anonymous-on-elasticcloud/324996)

<div class="topic-metadata">

**Author:** [@hagud](https://discuss.elastic.co/u/hagud)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 10:17am UTC](https://discuss.elastic.co/t/embed-dashboard-and-or-kibana-anonymous-on-elasticcloud/324996 "2023-02-08T10:17:02Z")

</div>

Good morning We are testing Elastic Cloud and we do not know if it possible or how could be offer public\_url iframe to selected dashboard or graphs. I have seen tha tlocal installation is able to share anonymous iframe…

---

## [CSV export - Please use Kibana feature privileges instead](https://discuss.elastic.co/t/csv-export-please-use-kibana-feature-privileges-instead/325722)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 10:44am UTC](https://discuss.elastic.co/t/csv-export-please-use-kibana-feature-privileges-instead/325722 "2023-02-16T10:44:12Z")

</div>

Hey there, I saw that reporting\_user role is deprecated so I have to enable the correct privileges using Spaces. I follow this official page Kibana doc, but I am still getting the error "Sorry, you don't have access to…

---

## [Find a pattern within field's value using regular expression Kibana UI](https://discuss.elastic.co/t/find-a-pattern-within-fields-value-using-regular-expression-kibana-ui/324885)

<div class="topic-metadata">

**Author:** [@aklimo](https://discuss.elastic.co/u/aklimo)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 10:28am UTC](https://discuss.elastic.co/t/find-a-pattern-within-fields-value-using-regular-expression-kibana-ui/324885 "2023-02-07T10:28:19Z")

</div>

Hello, I am trying to find a pattern within the field using regular expression and it's not working the way I think it should. The field is message.ApiData.ResponseBody and it contains a JSON response. It is a collecti…

---

## [Is it possible to capture all the documents returned by a particular Kibana dashboard?](https://discuss.elastic.co/t/is-it-possible-to-capture-all-the-documents-returned-by-a-particular-kibana-dashboard/325732)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 12:08pm UTC](https://discuss.elastic.co/t/is-it-possible-to-capture-all-the-documents-returned-by-a-particular-kibana-dashboard/325732 "2023-02-16T12:08:09Z")

</div>

I took a Saved Session for a Kibana dashboard, and did inspect on it, which returned this: { "timeRange": { "from": "2023-02-16T09:49:46.292Z", "to": "2023-02-16T10:08:50.981Z" }, "query": { "language"…

---

## [How many Aliases can an Index have?](https://discuss.elastic.co/t/how-many-aliases-can-an-index-have/325953)

<div class="topic-metadata">

**Author:** [@tbart01](https://discuss.elastic.co/u/tbart01)\
**Replies:** 7\
**Last updated:** [February 21, 2023, 10:04am UTC](https://discuss.elastic.co/t/how-many-aliases-can-an-index-have/325953 "2023-02-21T10:04:24Z")

</div>

We have an index with some 250,000 aliases, and rapidly growing. Are there any known limits that we should be aware of? We were not able to find any concrete information searching the web/documentation. Lately, we've no…

---

## [Audio in Canvas](https://discuss.elastic.co/t/audio-in-canvas/326043)

<div class="topic-metadata">

**Author:** [@AdityaKhajuria](https://discuss.elastic.co/u/AdityaKhajuria)\
**Replies:** 1\
**Last updated:** [February 21, 2023, 9:58am UTC](https://discuss.elastic.co/t/audio-in-canvas/326043 "2023-02-21T09:58:11Z")

</div>

Hi ELK team, Is there a way i can use and play audio file in Kibana Canvas or Dashboard? If not, is it possible to implement the same by some external plugins or any other way around. Thank you

---

## [How can I access elasticsearch cluster created by docker compose by using actual ip address?](https://discuss.elastic.co/t/how-can-i-access-elasticsearch-cluster-created-by-docker-compose-by-using-actual-ip-address/326037)

<div class="topic-metadata">

**Author:** [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)\
**Replies:** 1\
**Last updated:** [February 21, 2023, 9:36am UTC](https://discuss.elastic.co/t/how-can-i-access-elasticsearch-cluster-created-by-docker-compose-by-using-actual-ip-address/326037 "2023-02-21T09:36:26Z")

</div>

Hi Community. I am following the instructions in this tutorial -- Start a multi-node cluster with Docker: I could access Elasticsearch by using this command "curl --cacert ca.crt -u elastic:rogerfan https://localhost:…

---

## [Problem with running kibana](https://discuss.elastic.co/t/problem-with-running-kibana/326034)

<div class="topic-metadata">

**Author:** [@reza\_setareh](https://discuss.elastic.co/u/reza_setareh)\
**Replies:** 4\
**Last updated:** [February 21, 2023, 8:54am UTC](https://discuss.elastic.co/t/problem-with-running-kibana/326034 "2023-02-21T08:54:56Z")

</div>

hi everybody.i got error when i run kibana.bat this is error below Unable to retrieve version information from Elasticsearch nodes. security\_exception: \[security\_exception\] Reason: missing authentication credentials for…

---

## [Rising trends of data values to latest data in Heatmap visualisation](https://discuss.elastic.co/t/rising-trends-of-data-values-to-latest-data-in-heatmap-visualisation/326031)

<div class="topic-metadata">

**Author:** [@Sahil\_Sharma1](https://discuss.elastic.co/u/Sahil_Sharma1)\
**Replies:** 0\
**Last updated:** [February 21, 2023, 7:42am UTC](https://discuss.elastic.co/t/rising-trends-of-data-values-to-latest-data-in-heatmap-visualisation/326031 "2023-02-21T07:42:39Z")

</div>

Hi, We want to show rising trends of data values in selected date range. The logic is that we want to show attributes with consistent growing values sorted in descending order. Kindly suggest how can we achieve the sam…

---

## [Refresh schedule](https://discuss.elastic.co/t/refresh-schedule/325999)

<div class="topic-metadata">

**Author:** [@Apoorva\_Shandilya](https://discuss.elastic.co/u/Apoorva_Shandilya)\
**Replies:** 4\
**Last updated:** [February 21, 2023, 8:44am UTC](https://discuss.elastic.co/t/refresh-schedule/325999 "2023-02-21T08:44:24Z")

</div>

Hi all I am beginner here . Can we add information related to refresh schedule in dashboard . I want to see if a dashboard is updated today, I would like to have this date and time as an info in the dashboard it shou…

---

## [Sum of a field after terms aggregation](https://discuss.elastic.co/t/sum-of-a-field-after-terms-aggregation/325985)

<div class="topic-metadata">

**Author:** [@Miguel\_Azorin](https://discuss.elastic.co/u/Miguel_Azorin)\
**Replies:** 4\
**Last updated:** [February 21, 2023, 8:26am UTC](https://discuss.elastic.co/t/sum-of-a-field-after-terms-aggregation/325985 "2023-02-21T08:26:32Z")

</div>

Hi! Given docs as the ones in the example below: { "id" : "1", "numValue": 9.7 } { "id" : "1", "numValue": 9.7 } { "id" : "1", "numValue": 9.7 } { "id" : "2", "numValue": 7 } { "id" : "2", "numValue": 7 } { "id" : "3",…

---

## [Query on Logstash to Elasticsearch and third party](https://discuss.elastic.co/t/query-on-logstash-to-elasticsearch-and-third-party/325990)

<div class="topic-metadata">

**Author:** [@ianrobo](https://discuss.elastic.co/u/ianrobo)\
**Replies:** 3\
**Last updated:** [February 21, 2023, 7:36am UTC](https://discuss.elastic.co/t/query-on-logstash-to-elasticsearch-and-third-party/325990 "2023-02-21T07:36:39Z")

</div>

Hi, I have an isue which should be simple to resolve but can not. Basically we send all our log data to a beat on a server in the DMZ an then that forwards onto Elastic. However we now have a requirement to forward on…

---

## [Confirmation please](https://discuss.elastic.co/t/confirmation-please/325956)

<div class="topic-metadata">

**Author:** [@jomaguca](https://discuss.elastic.co/u/jomaguca)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 6:56am UTC](https://discuss.elastic.co/t/confirmation-please/325956 "2023-02-21T06:56:41Z")

</div>

Hello again I have not still could connect filebeat to elasticsearch buy the error that is showed to me is that "the proxy needs autentification" so, Can anybody confirm to me that filebeat can not pass HTTP proxies? If…

---

## [Information on the elk suite](https://discuss.elastic.co/t/information-on-the-elk-suite/325978)

<div class="topic-metadata">

**Author:** [@Baudillon\_Remy](https://discuss.elastic.co/u/Baudillon_Remy)\
**Replies:** 3\
**Last updated:** [February 21, 2023, 6:36am UTC](https://discuss.elastic.co/t/information-on-the-elk-suite/325978 "2023-02-21T06:36:17Z")

</div>

Hello, I would like to set up an infrastructure with the ELK suite. It will be a distributed architecture. I would like to have some information about the configuration required. In your opinion, how much RAM / CPU /…

---

## [Ingest data directly from Google Cloud Storage into Elastic using Google](https://discuss.elastic.co/t/ingest-data-directly-from-google-cloud-storage-into-elastic-using-google/325769)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 8\
**Last updated:** [February 21, 2023, 6:32am UTC](https://discuss.elastic.co/t/ingest-data-directly-from-google-cloud-storage-into-elastic-using-google/325769 "2023-02-21T06:32:49Z")

</div>

Hi, I was reading this article and read this line: Currently, CSV file format is supported and we’ll be adding support for JSON soon. I know that it doesn't mean "the next day" but after 17 months, I checked and sti…

---

## [How to collect log of NVR Hikvision (all camera's log) to Elastic?](https://discuss.elastic.co/t/how-to-collect-log-of-nvr-hikvision-all-cameras-log-to-elastic/326018)

<div class="topic-metadata">

**Author:** [@Anh\_Nguyen](https://discuss.elastic.co/u/Anh_Nguyen)\
**Replies:** 4\
**Last updated:** [February 21, 2023, 6:28am UTC](https://discuss.elastic.co/t/how-to-collect-log-of-nvr-hikvision-all-cameras-log-to-elastic/326018 "2023-02-21T06:28:18Z")

</div>

Hello everyone, I want to collect all logs (all type logs) of the cameras to my SIEM system. I have a NVR and it have function "Logs Server Configuration" but it always failed. ( UDP port use to collect logs on the linux…

---

## [How di I map Timestamp to event Timestamp from filebeat thru logstash](https://discuss.elastic.co/t/how-di-i-map-timestamp-to-event-timestamp-from-filebeat-thru-logstash/325577)

<div class="topic-metadata">

**Author:** [@jkingstone](https://discuss.elastic.co/u/jkingstone)\
**Replies:** 9\
**Last updated:** [February 21, 2023, 6:23am UTC](https://discuss.elastic.co/t/how-di-i-map-timestamp-to-event-timestamp-from-filebeat-thru-logstash/325577 "2023-02-21T06:23:25Z")

</div>

Hi, I want to change the @timestamp to the timestamp out of event.original or message. I don't know what I do wrong. right now the @timestamp is the time where the filebeat logfile ist importet thru logstash into elast…

---

## [Esrally benchmark takes longer time to run while the report service time doesn't change](https://discuss.elastic.co/t/esrally-benchmark-takes-longer-time-to-run-while-the-report-service-time-doesnt-change/324597)

<div class="topic-metadata">

**Author:** [@fatcloud](https://discuss.elastic.co/u/fatcloud)\
**Replies:** 9\
**Last updated:** [February 21, 2023, 5:34am UTC](https://discuss.elastic.co/t/esrally-benchmark-takes-longer-time-to-run-while-the-report-service-time-doesnt-change/324597 "2023-02-21T05:34:52Z")

</div>

Hi, I'm trying to run some test to see how the number of index affect the elasticsearch cluster performance. I tested from 1k indices to 8k indices, and ran some random requests against those indices. One weird thing …

---

## [Ingesting Delinea Audit/event Logs into Elasticsearch](https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870)

<div class="topic-metadata">

**Author:** [@tthiry](https://discuss.elastic.co/u/tthiry)\
**Replies:** 4\
**Last updated:** [February 21, 2023, 1:58am UTC](https://discuss.elastic.co/t/ingesting-delinea-audit-event-logs-into-elasticsearch/325870 "2023-02-21T01:58:11Z")

</div>

Hello, I am wondering if anyone has tried ingesting Delinea Secret Server logs into Elasticsearch. I'm not quite sure where to start. We are using the cloud version of both Elastic and Delinea. Any helpful hints would …

---

## [Fleet-server can not running, "only 1 fleet-server input can be defined accessing config" occur in the log files](https://discuss.elastic.co/t/fleet-server-can-not-running-only-1-fleet-server-input-can-be-defined-accessing-config-occur-in-the-log-files/325951)

<div class="topic-metadata">

**Author:** [@hds1989824](https://discuss.elastic.co/u/hds1989824)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 1:56am UTC](https://discuss.elastic.co/t/fleet-server-can-not-running-only-1-fleet-server-input-can-be-defined-accessing-config-occur-in-the-log-files/325951 "2023-02-21T01:56:10Z")

</div>

first, my elk server version is 7.17.7,and deploy by docker ,such as logstach,kibana,elasticsearch,server ip is 10.30.25.223 。port forward has added to the firewall (sonicwall), 10.30.25.223: 5601，10.30.25.223:920…

---

## [Nginx access log using grok filter](https://discuss.elastic.co/t/nginx-access-log-using-grok-filter/324877)

<div class="topic-metadata">

**Author:** [@yc99](https://discuss.elastic.co/u/yc99)\
**Replies:** 1\
**Last updated:** [February 21, 2023, 12:36am UTC](https://discuss.elastic.co/t/nginx-access-log-using-grok-filter/324877 "2023-02-21T00:36:14Z")

</div>

My nginx access log format as below, there certain access log without the "$request\_time" "$http\_x\_forwarded\_for" $http\_host ' field, therefore, for certain access log, the grok filter not working, is there anyway to a…

---

## [Filebeat azure module multiple eventhubs in self managed elastic version 8.6.1](https://discuss.elastic.co/t/filebeat-azure-module-multiple-eventhubs-in-self-managed-elastic-version-8-6-1/325455)

<div class="topic-metadata">

**Author:** [@Dov\_Zelinger](https://discuss.elastic.co/u/Dov_Zelinger)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 10:19pm UTC](https://discuss.elastic.co/t/filebeat-azure-module-multiple-eventhubs-in-self-managed-elastic-version-8-6-1/325455 "2023-02-20T22:19:30Z")

</div>

Hi, As written in the below link, the issue was resolved. multiple-event-hubs Unfortunately, the issue still exists. When configuring multiple platformlogs as can be seen below, only one of them gets active and that …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=625)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=627)
