# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=641

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 642

---

## [Ssl\_certificate\_authorities seems to have no effect](https://discuss.elastic.co/t/ssl-certificate-authorities-seems-to-have-no-effect/324934)

<div class="topic-metadata">

**Author:** [@hexoffender](https://discuss.elastic.co/u/hexoffender)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 10:44pm UTC](https://discuss.elastic.co/t/ssl-certificate-authorities-seems-to-have-no-effect/324934 "2023-02-07T22:44:36Z")

</div>

I'm getting an error in filebeat: ERROR \[publisher\_pipeline\_output\] pipeline/output.go:154 Failed to connect to backoff(async(tcp://localhost:5044)): x509: certificate signed by unknown authority Here is my logstash co…

---

## [Problems with ELK over EKS Amazon and kubernetes](https://discuss.elastic.co/t/problems-with-elk-over-eks-amazon-and-kubernetes/324851)

<div class="topic-metadata">

**Author:** [@Milton](https://discuss.elastic.co/u/Milton)\
**Replies:** 3\
**Last updated:** [February 7, 2023, 10:08pm UTC](https://discuss.elastic.co/t/problems-with-elk-over-eks-amazon-and-kubernetes/324851 "2023-02-07T22:08:15Z")

</div>

How can I configure an Elasticksearch ELK over EKS for claim persistent volumes, I have disk problems. kubectl get pods -A NAMESPACE NAME READY STATUS RESTARTS AGE default counter 1/1 Running 0 112m kube-logging is-c…

---

## [These two nested aggregations produce the same result, but is one approach better than the other?](https://discuss.elastic.co/t/these-two-nested-aggregations-produce-the-same-result-but-is-one-approach-better-than-the-other/324941)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 9:59pm UTC](https://discuss.elastic.co/t/these-two-nested-aggregations-produce-the-same-result-but-is-one-approach-better-than-the-other/324941 "2023-02-07T21:59:00Z")

</div>

I have two scenarios that produce identical aggregation results in the final GET order/\_search query. The only difference between the two scenarios is where I choose to declare the type: nested in the mapping and what I…

---

## [Confirm that I don't need \`type: nested\` on every node of my index mapping for the document tree?](https://discuss.elastic.co/t/confirm-that-i-dont-need-type-nested-on-every-node-of-my-index-mapping-for-the-document-tree/324907)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 7\
**Last updated:** [February 7, 2023, 9:53pm UTC](https://discuss.elastic.co/t/confirm-that-i-dont-need-type-nested-on-every-node-of-my-index-mapping-for-the-document-tree/324907 "2023-02-07T21:53:28Z")

</div>

I just have a question about the type: nested in the index mappings. Let's say I have documents where I want to aggregate on order.order\_items.product.manufacturer.contact.name. Initially I made my mapping like this {…

---

## [Does anyone have a good tutorial for setting up python flask with elasticsearch in windows 11?](https://discuss.elastic.co/t/does-anyone-have-a-good-tutorial-for-setting-up-python-flask-with-elasticsearch-in-windows-11/324938)

<div class="topic-metadata">

**Author:** [@aaaaaaaaaaaa](https://discuss.elastic.co/u/aaaaaaaaaaaa)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 9:20pm UTC](https://discuss.elastic.co/t/does-anyone-have-a-good-tutorial-for-setting-up-python-flask-with-elasticsearch-in-windows-11/324938 "2023-02-07T21:20:34Z")

</div>

I found this tutorial The Flask Mega-Tutorial Part XVI: Full-Text Search - miguelgrinberg.com which I am using. When asking for a tutorial I am asking for setting up of Elasticsearch not the actual code for Elasticsearch…

---

## [I am trying to connect to http://localhost:9200 in my browser and I am getting an error that says check the proxy or firewall. I am using windows 11](https://discuss.elastic.co/t/i-am-trying-to-connect-to-http-localhost-9200-in-my-browser-and-i-am-getting-an-error-that-says-check-the-proxy-or-firewall-i-am-using-windows-11/323876)

<div class="topic-metadata">

**Author:** [@aaaaaaaaaaaa](https://discuss.elastic.co/u/aaaaaaaaaaaa)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 9:16pm UTC](https://discuss.elastic.co/t/i-am-trying-to-connect-to-http-localhost-9200-in-my-browser-and-i-am-getting-an-error-that-says-check-the-proxy-or-firewall-i-am-using-windows-11/323876 "2023-02-07T21:16:20Z")

</div>

I am using windows 11 and google chrome. I followed all the steps in the video above. It was working . Then I try again a few days later when I try to go http://localhost:9200. I even tried https://localh…

---

## [Vega Scatterplot for Transform Index](https://discuss.elastic.co/t/vega-scatterplot-for-transform-index/324936)

<div class="topic-metadata">

**Author:** [@mundruid](https://discuss.elastic.co/u/mundruid)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 8:55pm UTC](https://discuss.elastic.co/t/vega-scatterplot-for-transform-index/324936 "2023-02-07T20:55:56Z")

</div>

I am creating a scatter plot for an index that was generated by a pivot transform and it does not have timestamps. I saw some similar posts and my schema followed these: { $schema: https://vega.github.io/schema/vega-l…

---

## [When I create a report it shows something that is not part of the dashboard](https://discuss.elastic.co/t/when-i-create-a-report-it-shows-something-that-is-not-part-of-the-dashboard/324919)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 6\
**Last updated:** [February 7, 2023, 8:05pm UTC](https://discuss.elastic.co/t/when-i-create-a-report-it-shows-something-that-is-not-part-of-the-dashboard/324919 "2023-02-07T20:05:40Z")

</div>

Hi, when I create a report it shows this box (Save session Manage sessions) that is not part of the dashboard how can I avoid this?

---

## [How to avoid duplicate data when switching from filebeat's log-input to filestream-input?](https://discuss.elastic.co/t/how-to-avoid-duplicate-data-when-switching-from-filebeats-log-input-to-filestream-input/324878)

<div class="topic-metadata">

**Author:** [@apt-get\_install\_skil](https://discuss.elastic.co/u/apt-get_install_skil)\
**Replies:** 6\
**Last updated:** [February 7, 2023, 6:43pm UTC](https://discuss.elastic.co/t/how-to-avoid-duplicate-data-when-switching-from-filebeats-log-input-to-filestream-input/324878 "2023-02-07T18:43:58Z")

</div>

Hey guys, right now, I'm planning the switch from filebeat's log-input to filestream-input. We have many filebeats running on our numerous servers that are harvesting many log files. We deploy them with an Ansible Play…

---

## [Packetbeat npac version and Defender for Identity](https://discuss.elastic.co/t/packetbeat-npac-version-and-defender-for-identity/323230)

<div class="topic-metadata">

**Author:** [@jaegerschnitzel](https://discuss.elastic.co/u/jaegerschnitzel)\
**Replies:** 8\
**Last updated:** [February 7, 2023, 6:42pm UTC](https://discuss.elastic.co/t/packetbeat-npac-version-and-defender-for-identity/323230 "2023-02-07T18:42:28Z")

</div>

Hi all, we are using Packetbeat for capturing DNS traffic from some of our Windows servers. Defender for Identity is also installed on these servers. Defender for Identity uses npcap OEM 1.00. Packetbeat somehow upda…

---

## [High HEAP and CPU utilization due to long and inefficient Garbage Collector (GC)](https://discuss.elastic.co/t/high-heap-and-cpu-utilization-due-to-long-and-inefficient-garbage-collector-gc/324669)

<div class="topic-metadata">

**Author:** [@GustavoSantos](https://discuss.elastic.co/u/GustavoSantos)\
**Replies:** 5\
**Last updated:** [February 7, 2023, 1:33pm UTC](https://discuss.elastic.co/t/high-heap-and-cpu-utilization-due-to-long-and-inefficient-garbage-collector-gc/324669 "2023-02-07T13:33:00Z")

</div>

Hi all, We constantly get Circuit Breaker errors and GC overhead logs in clusters with high indexation load. Looking at the Kibana dashboards and analyzing the logs, it is clear that the GC is one of our main bottleneck…

---

## [Tune Elasticsearch to process thousands of simultaneous searches](https://discuss.elastic.co/t/tune-elasticsearch-to-process-thousands-of-simultaneous-searches/324438)

<div class="topic-metadata">

**Author:** [@aldoorozco](https://discuss.elastic.co/u/aldoorozco)\
**Replies:** 15\
**Last updated:** [February 7, 2023, 6:17pm UTC](https://discuss.elastic.co/t/tune-elasticsearch-to-process-thousands-of-simultaneous-searches/324438 "2023-02-07T18:17:28Z")

</div>

I have a question about Elastic Cloud deployments. I created a 3-zone 32 CPU compute-optimized deployment on GCP with just Elasticsearch (hot data nodes and coordinating nodes only) and Kibana enabled, and loaded, using …

---

## [Get logs from an application via elastic agent using stdout](https://discuss.elastic.co/t/get-logs-from-an-application-via-elastic-agent-using-stdout/324897)

<div class="topic-metadata">

**Author:** [@Bhrugu\_Sharma](https://discuss.elastic.co/u/Bhrugu_Sharma)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 12:45pm UTC](https://discuss.elastic.co/t/get-logs-from-an-application-via-elastic-agent-using-stdout/324897 "2023-02-07T12:45:13Z")

</div>

I have a sample application which generates sample logs Sample log line 1 Sample log line 2 this application is running in a sperate namespace as compared to the elastic agent which is not an issue as the agent is a…

---

## [Version Incompatibility Logstash and Opensearch service Elastic](https://discuss.elastic.co/t/version-incompatibility-logstash-and-opensearch-service-elastic/324928)

<div class="topic-metadata">

**Author:** [@cgcats](https://discuss.elastic.co/u/cgcats)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 5:34pm UTC](https://discuss.elastic.co/t/version-incompatibility-logstash-and-opensearch-service-elastic/324928 "2023-02-07T17:34:32Z")

</div>

I am trying to bring up logstash in kubernetes using the v7.16.1 chart and connecting to v7.4 elasticsearch that is an aws opensearch service. According to the compatibility matrix, this should be fine. but I am seeing t…

---

## [How to Freeze the Filters on Kibana dashboard](https://discuss.elastic.co/t/how-to-freeze-the-filters-on-kibana-dashboard/324918)

<div class="topic-metadata">

**Author:** [@riddhipatel259](https://discuss.elastic.co/u/riddhipatel259)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 3:47pm UTC](https://discuss.elastic.co/t/how-to-freeze-the-filters-on-kibana-dashboard/324918 "2023-02-07T15:47:42Z")

</div>

Is there a way we can freeze/Lock the filters on kibana dashboard -so As users scroll down that top filters stays there on the page ? Thank you!

---

## [Kibana all of a sudden requesting a larger result\_window?](https://discuss.elastic.co/t/kibana-all-of-a-sudden-requesting-a-larger-result-window/322945)

<div class="topic-metadata">

**Author:** [@gborg](https://discuss.elastic.co/u/gborg)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 3:41pm UTC](https://discuss.elastic.co/t/kibana-all-of-a-sudden-requesting-a-larger-result-window/322945 "2023-02-07T15:41:37Z")

</div>

Hello I have a cluster with multiple elasticsearch nodes and a kibana server I have not made any modifications to kibana recently, nor the indexing settings but all of a sudden one day I get "X of Y shards failed" and …

---

## [Rename all index pattern name](https://discuss.elastic.co/t/rename-all-index-pattern-name/324872)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 5\
**Last updated:** [February 7, 2023, 3:29pm UTC](https://discuss.elastic.co/t/rename-all-index-pattern-name/324872 "2023-02-07T15:29:36Z")

</div>

Hello All, I'd like to rename my index pattern,what would be best way to do it correctly.I just want that duplicate dashboards or visuals are not created. current index pattern cahnged index pattern(Rename to…

---

## [Aggregating articles by mentions of games between two dates](https://discuss.elastic.co/t/aggregating-articles-by-mentions-of-games-between-two-dates/324889)

<div class="topic-metadata">

**Author:** [@Matthew\_Hammond](https://discuss.elastic.co/u/Matthew_Hammond)\
**Replies:** 3\
**Last updated:** [February 7, 2023, 3:02pm UTC](https://discuss.elastic.co/t/aggregating-articles-by-mentions-of-games-between-two-dates/324889 "2023-02-07T15:02:01Z")

</div>

I have the following query which returns data from a database of articles published about different video games. GET articles/\_search { "query": { "bool": { "must": \[ { "term": { …

---

## [GET Document from Index with Kibana API](https://discuss.elastic.co/t/get-document-from-index-with-kibana-api/324887)

<div class="topic-metadata">

**Author:** [@Jonathan\_Emami](https://discuss.elastic.co/u/Jonathan_Emami)\
**Replies:** 3\
**Last updated:** [February 7, 2023, 2:58pm UTC](https://discuss.elastic.co/t/get-document-from-index-with-kibana-api/324887 "2023-02-07T14:58:21Z")

</div>

Hi, I'm writing here cause I've read through all of the Kibana REST API, but I still have not found an answer to my question REST API | Kibana Guide \[8.6\] | Elastic I basically want to access a document in the index, i…

---

## [How much time by the query is spent in Disk I/O?](https://discuss.elastic.co/t/how-much-time-by-the-query-is-spent-in-disk-i-o/324915)

<div class="topic-metadata">

**Author:** [@Sheharyar\_Khalid](https://discuss.elastic.co/u/Sheharyar_Khalid)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 2:17pm UTC](https://discuss.elastic.co/t/how-much-time-by-the-query-is-spent-in-disk-i-o/324915 "2023-02-07T14:17:50Z")

</div>

Hello, I am trying to optimize my hardware for elasticsearch deployment. I am getting inconsistent results on the time by changing the JVM settings. I wanted to know if there is any other measure apart from the "took" i…

---

## [Kibana 7.10.2 --version in linux - not working](https://discuss.elastic.co/t/kibana-7-10-2-version-in-linux-not-working/324913)

<div class="topic-metadata">

**Author:** [@slashlinux](https://discuss.elastic.co/u/slashlinux)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 2:05pm UTC](https://discuss.elastic.co/t/kibana-7-10-2-version-in-linux-not-working/324913 "2023-02-07T14:05:41Z")

</div>

Hi team, I'mt trying to get version of the kibana 7.10.2 but I'm encountering an error, is there anything I can do ? root@test-kibana-:/home/cloud# sudo -u kibana /usr/share/kibana/bin/kibana --version fs.js:114 th…

---

## [Filebeat locking application logs](https://discuss.elastic.co/t/filebeat-locking-application-logs/324912)

<div class="topic-metadata">

**Author:** [@Anirbaan\_Chowdhury](https://discuss.elastic.co/u/Anirbaan_Chowdhury)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 2:04pm UTC](https://discuss.elastic.co/t/filebeat-locking-application-logs/324912 "2023-02-07T14:04:55Z")

</div>

Fillebeat in Windows. I have read topic Filebeat locking files - Elastic Stack / Beats - Discuss the Elastic Stack Hi Experts, Our application (whose logs are harvested by filebeat) repeatedly throws permission denied …

---

## [Json processor fails when processing some fields without quotes](https://discuss.elastic.co/t/json-processor-fails-when-processing-some-fields-without-quotes/324891)

<div class="topic-metadata">

**Author:** [@mmartinez](https://discuss.elastic.co/u/mmartinez)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 1:49pm UTC](https://discuss.elastic.co/t/json-processor-fails-when-processing-some-fields-without-quotes/324891 "2023-02-07T13:49:16Z")

</div>

Hello, We are sending logs to escloud using fluentbit 2.0.6 with the field message in JSON format but when we use the JSON processor in that field it fails in different ways. As some field values come without quotes …

---

## [Can't connect to Kibana API with CURL. I keep receiving {"statusCode":404,"error":"Not Found","message":"Not Found"}](https://discuss.elastic.co/t/cant-connect-to-kibana-api-with-curl-i-keep-receiving-statuscode-404-error-not-found-message-not-found/324804)

<div class="topic-metadata">

**Author:** [@Piotrek](https://discuss.elastic.co/u/Piotrek)\
**Replies:** 4\
**Last updated:** [February 7, 2023, 1:17pm UTC](https://discuss.elastic.co/t/cant-connect-to-kibana-api-with-curl-i-keep-receiving-statuscode-404-error-not-found-message-not-found/324804 "2023-02-07T13:17:06Z")

</div>

I'm trying to connect to Kibana API via CURL: curl -X "GET" "http://\<my-elastic-host\>:5601/status" --user \<my-username\> --noproxy '\*' -H 'kbn-xsrf: true' But all I receive is: {"statusCode":404,"error":"Not Found",…

---

## [Docker Desktop Elasticsearch nodes. socket hang up](https://discuss.elastic.co/t/docker-desktop-elasticsearch-nodes-socket-hang-up/324904)

<div class="topic-metadata">

**Author:** [@goforebroke](https://discuss.elastic.co/u/goforebroke)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 1:15pm UTC](https://discuss.elastic.co/t/docker-desktop-elasticsearch-nodes-socket-hang-up/324904 "2023-02-07T13:15:42Z")

</div>

I have my docker-compose.override.yml set up below in Visual Studio 2022 for development purposes. elasticsearch: container\_name: elasticsearch environment: - "ES\_JAVA\_OPTS=-Xms512m -Xmx512m" - d…

---

## [About the integration between elasticsearch and logstash](https://discuss.elastic.co/t/about-the-integration-between-elasticsearch-and-logstash/324845)

<div class="topic-metadata">

**Author:** [@choilee](https://discuss.elastic.co/u/choilee)\
**Replies:** 5\
**Last updated:** [February 7, 2023, 1:07pm UTC](https://discuss.elastic.co/t/about-the-integration-between-elasticsearch-and-logstash/324845 "2023-02-07T13:07:23Z")

</div>

Hi, I am creating log analizing system using logstash and elasticsearch. But I couldn't send any data to elastic from logstash. (But Delete prune fillter, then could send data) I found under this error message, but i c…

---

## [elasticsearch.ssl.verificationMode is not working in Kibana 8.3.2](https://discuss.elastic.co/t/elasticsearch-ssl-verificationmode-is-not-working-in-kibana-8-3-2/324847)

<div class="topic-metadata">

**Author:** [@Leonardo\_Henrique](https://discuss.elastic.co/u/Leonardo_Henrique)\
**Replies:** 7\
**Last updated:** [February 7, 2023, 11:40am UTC](https://discuss.elastic.co/t/elasticsearch-ssl-verificationmode-is-not-working-in-kibana-8-3-2/324847 "2023-02-07T11:40:59Z")

</div>

Hello everyone. I set the ssl configuration for my cluster using the elasticsearch-certutil, but my Kibana is unable to reach https://epr.elastic.co so I can not install any integration since it depends on loading from …

---

## [Logstash CSV output plugin not flushing to disk](https://discuss.elastic.co/t/logstash-csv-output-plugin-not-flushing-to-disk/324413)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 4\
**Last updated:** [February 7, 2023, 11:31am UTC](https://discuss.elastic.co/t/logstash-csv-output-plugin-not-flushing-to-disk/324413 "2023-02-07T11:31:37Z")

</div>

Hey Everyone, I'm having some trouble with my Logstash config for exporting Elasticsearch data to CSV after upgrading my ELK stack from 7 to 8.6. When running my exporter.conf file it just never flushes to disk. It fil…

---

## [Java time migration guide (upgrading to ES 8.x)](https://discuss.elastic.co/t/java-time-migration-guide-upgrading-to-es-8-x/323942)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 5\
**Last updated:** [February 7, 2023, 10:35am UTC](https://discuss.elastic.co/t/java-time-migration-guide-upgrading-to-es-8-x/323942 "2023-02-07T10:35:09Z")

</div>

Hi, During reading release notes and breaking changes, I stumbled upon this guide: Java time migration guide | Elasticsearch Guide \[8.0\] | Elastic At the bottom, it says that the format "yyyy/MM/dd HH:mm:ss||yyyy/MM/…

---

## [Metadata missing on startup](https://discuss.elastic.co/t/metadata-missing-on-startup/324886)

<div class="topic-metadata">

**Author:** [@hdost](https://discuss.elastic.co/u/hdost)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 10:33am UTC](https://discuss.elastic.co/t/metadata-missing-on-startup/324886 "2023-02-07T10:33:25Z")

</div>

This question seems to be in a similar vein to a different application, but I have more than just "random" My config is similar to theirs: filebeat.inputs: - type: container paths: - /var/log/con…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=640)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=642)
