# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=646

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 647

---

## [Kibana: FATAL Error: error:0909006C:PEM routines:get\_name:no start line](https://discuss.elastic.co/t/kibana-fatal-error-errorpem-routinesno-start-line/324595)

<div class="topic-metadata">

**Author:** [@candy609](https://discuss.elastic.co/u/candy609)\
**Replies:** 1\
**Last updated:** [February 3, 2023, 7:34am UTC](https://discuss.elastic.co/t/kibana-fatal-error-errorpem-routinesno-start-line/324595 "2023-02-03T07:34:04Z")

</div>

Environment: Centos 7 ES verion: 7.17.8 Kibana: 7.17.8 I created a 3 nodes Elastic-cluster with xpack-security configured. I then add Kibana, Elasticseach \<-\> Kibana SSL is working, certificates were generated using e…

---

## [Elastic search does not work during operation, causing problems in restarting](https://discuss.elastic.co/t/elastic-search-does-not-work-during-operation-causing-problems-in-restarting/324556)

<div class="topic-metadata">

**Author:** [@sramana235](https://discuss.elastic.co/u/sramana235)\
**Replies:** 3\
**Last updated:** [February 3, 2023, 7:22am UTC](https://discuss.elastic.co/t/elastic-search-does-not-work-during-operation-causing-problems-in-restarting/324556 "2023-02-03T07:22:33Z")

</div>

\[2023-02-02T18:22:39,230\]\[INFO \]\[o.e.e.NodeEnvironment \] \[name\] using \[1\] data paths, mounts \[\[/data (/dev/data)\]\], net usable\_space \[55.9gb\], net total\_space \[98.4gb\], types \[ext4\] \[2023-02-02T18:22:39,231\]\[INFO \]\[o.…

---

## [Search returning zero document and zero shards | Index was closed and then opened](https://discuss.elastic.co/t/search-returning-zero-document-and-zero-shards-index-was-closed-and-then-opened/324603)

<div class="topic-metadata">

**Author:** [@esuser27](https://discuss.elastic.co/u/esuser27)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 6:42am UTC](https://discuss.elastic.co/t/search-returning-zero-document-and-zero-shards-index-was-closed-and-then-opened/324603 "2023-02-03T06:42:05Z")

</div>

Hi Folks, I had closed few of my indices for maintenance activity and I opened them after some time. Health wise the index is green and has a shard, but my search query is getting empty results even though there are do…

---

## [Which privilege is necessary for creation of runtime field](https://discuss.elastic.co/t/which-privilege-is-necessary-for-creation-of-runtime-field/324507)

<div class="topic-metadata">

**Author:** [@shinki927](https://discuss.elastic.co/u/shinki927)\
**Replies:** 4\
**Last updated:** [February 3, 2023, 6:17am UTC](https://discuss.elastic.co/t/which-privilege-is-necessary-for-creation-of-runtime-field/324507 "2023-02-03T06:17:46Z")

</div>

Hello, I'd like to know which cluster and index privilege are needed to create runtime field. I didn't find it in the doc. Thanks in advance

---

## [I am also facing the same issue, did someone found the solution or workaround for this](https://discuss.elastic.co/t/i-am-also-facing-the-same-issue-did-someone-found-the-solution-or-workaround-for-this/324342)

<div class="topic-metadata">

**Author:** [@mohit\_bairagi](https://discuss.elastic.co/u/mohit_bairagi)\
**Replies:** 1\
**Last updated:** [February 3, 2023, 3:50am UTC](https://discuss.elastic.co/t/i-am-also-facing-the-same-issue-did-someone-found-the-solution-or-workaround-for-this/324342 "2023-02-03T03:50:27Z")

</div>

Continuing the discussion from S3 Input Plugin Following Errors Execution Expired and Net::OpenTimeout:

---

## [How to collect multiline java stack traces from docker container stout](https://discuss.elastic.co/t/how-to-collect-multiline-java-stack-traces-from-docker-container-stout/324497)

<div class="topic-metadata">

**Author:** [@JocelynFloresz](https://discuss.elastic.co/u/JocelynFloresz)\
**Replies:** 2\
**Last updated:** [February 3, 2023, 3:21am UTC](https://discuss.elastic.co/t/how-to-collect-multiline-java-stack-traces-from-docker-container-stout/324497 "2023-02-03T03:21:09Z")

</div>

Commonly I can use the below pattern to collect logs from multiline. multiline.pattern: '^\[\[:space:\]\]+(at|\\.{3})\[\[:space:\]\]+\\b|^Caused by:' multiline.negate: false multiline.match: after But in my use case,…

---

## [Failed to find a X509ExtendedTrustManager](https://discuss.elastic.co/t/failed-to-find-a-x509extendedtrustmanager/324593)

<div class="topic-metadata">

**Author:** [@hitlll](https://discuss.elastic.co/u/hitlll)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 2:35am UTC](https://discuss.elastic.co/t/failed-to-find-a-x509extendedtrustmanager/324593 "2023-02-03T02:35:36Z")

</div>

Environment : Dokcer Image elasticsearch-7.17.8 JDK: openjdk:8u342-jdk How should I solve the problem？

---

## [Logstash ruby filter](https://discuss.elastic.co/t/logstash-ruby-filter/324590)

<div class="topic-metadata">

**Author:** [@sheetal3](https://discuss.elastic.co/u/sheetal3)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 2:20am UTC](https://discuss.elastic.co/t/logstash-ruby-filter/324590 "2023-02-03T02:20:15Z")

</div>

Getting Error: \[2023-02-02T19:25:48,535\]\[ERROR\]\[logstash.filters.ruby \]\[main\]\[b7126651d97050c2a450765cb1ad946624dc0b4a1ea72baecc762eb17b892bdd\] Ruby exception occurred: undefined method each' for #\<String:0xa01d55c\> …

---

## [Nested Aggregation to just get some nested type without aggregatioon](https://discuss.elastic.co/t/nested-aggregation-to-just-get-some-nested-type-without-aggregatioon/324588)

<div class="topic-metadata">

**Author:** [@Jason\_Yu1](https://discuss.elastic.co/u/Jason_Yu1)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 1:59am UTC](https://discuss.elastic.co/t/nested-aggregation-to-just-get-some-nested-type-without-aggregatioon/324588 "2023-02-03T01:59:06Z")

</div>

I am not sure if is that possible. We have a set of documents with the same testId, and each set of those docs, always only have 1 of them has the frames nested type. So I want to do the aggression with the data, there …

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/322684)

<div class="topic-metadata">

**Author:** [@magen\_lahat](https://discuss.elastic.co/u/magen_lahat)\
**Replies:** 31\
**Last updated:** [February 2, 2023, 9:16pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/322684 "2023-02-02T21:16:29Z")

</div>

hello, im a new user to elasticsearch and hoping to explore it further for my project, So I just installed elasticsearch and kibana on my ubuntu and im getting "Kibana server is not ready yet." after runnig http://loca…

---

## [Issue in Controls](https://discuss.elastic.co/t/issue-in-controls/320882)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 27\
**Last updated:** [February 2, 2023, 7:06pm UTC](https://discuss.elastic.co/t/issue-in-controls/320882 "2023-02-02T19:06:34Z")

</div>

Dear Community, Im running Kibana 8.4.3 and I noticed a deprecation warning. So I used the new way for Controls. I have two fields, where I can add email addresses (sender and recipient). When Im looking for "jira@" th…

---

## [Create 1 alert monitor for missing logs on multiple index](https://discuss.elastic.co/t/create-1-alert-monitor-for-missing-logs-on-multiple-index/324526)

<div class="topic-metadata">

**Author:** [@crimson589](https://discuss.elastic.co/u/crimson589)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 6:47pm UTC](https://discuss.elastic.co/t/create-1-alert-monitor-for-missing-logs-on-multiple-index/324526 "2023-02-02T18:47:11Z")

</div>

v7.8.0 I have a monitor setup on one index that basically checks if the count of a log is not 0 for the past 10 minutes. I just pick one index and setup the query like below. I set the trigger condition to (ctx.results\[…

---

## [Kibana is unable to connect to ElasticSearch](https://discuss.elastic.co/t/kibana-is-unable-to-connect-to-elasticsearch/324561)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 6:46pm UTC](https://discuss.elastic.co/t/kibana-is-unable-to-connect-to-elasticsearch/324561 "2023-02-02T18:46:07Z")

</div>

I have been using ELK now for about a year and half. I decided it was time to re-install my lab for better troubleshooting of the main environment. Now I am unable to get kibana to open. Both the Elasticsearch and Log…

---

## [Vega with conditionnal coloring depending on filter](https://discuss.elastic.co/t/vega-with-conditionnal-coloring-depending-on-filter/324205)

<div class="topic-metadata">

**Author:** [@vincent2mots](https://discuss.elastic.co/u/vincent2mots)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 6:27pm UTC](https://discuss.elastic.co/t/vega-with-conditionnal-coloring-depending-on-filter/324205 "2023-02-02T18:27:16Z")

</div>

Hi there! I'm not an expert in Vega language but I would like to make a visualization which background color would depend on the filter in the dashboard. Let's say I have a Vega with a text and a background color. If a…

---

## [Kibana dashboard](https://discuss.elastic.co/t/kibana-dashboard/324170)

<div class="topic-metadata">

**Author:** [@Swetha.B](https://discuss.elastic.co/u/Swetha.B)\
**Replies:** 2\
**Last updated:** [February 2, 2023, 6:12pm UTC](https://discuss.elastic.co/t/kibana-dashboard/324170 "2023-02-02T18:12:00Z")

</div>

We recently started using Kibana dashboard to analyze the logs for our QnAbot. In Kibana discover what is the tag name that represents whether the user has navigated(via clicking on the buttons) through the QnAbot or if…

---

## [How to Import a Kibana Dashboard with Ansible?](https://discuss.elastic.co/t/how-to-import-a-kibana-dashboard-with-ansible/324487)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 2\
**Last updated:** [February 2, 2023, 5:56pm UTC](https://discuss.elastic.co/t/how-to-import-a-kibana-dashboard-with-ansible/324487 "2023-02-02T17:56:33Z")

</div>

We are upgrading from 7.9.3 to 7.17.8. I see that the method to import Kibana dashboards has changed. I can successfully import a dashboard using curl and using Postman. curl -k -u \<username\>:\<password\> -X POST https:…

---

## [Different aggregation count for the same value](https://discuss.elastic.co/t/different-aggregation-count-for-the-same-value/324566)

<div class="topic-metadata">

**Author:** [@mbklein](https://discuss.elastic.co/u/mbklein)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 4:47pm UTC](https://discuss.elastic.co/t/different-aggregation-count-for-the-same-value/324566 "2023-02-02T16:47:22Z")

</div>

I don't understand the results I'm seeing. I am asking for two different aggs in the same query. The first is “show me the doc counts for subject.label for these specific values,” and the second is “show me the doc count…

---

## [Filebeat multiline - how to tell filebeat when a message ends while parsing Microsoft Defender ATP logs](https://discuss.elastic.co/t/filebeat-multiline-how-to-tell-filebeat-when-a-message-ends-while-parsing-microsoft-defender-atp-logs/324564)

<div class="topic-metadata">

**Author:** [@Sal\_C](https://discuss.elastic.co/u/Sal_C)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 4:18pm UTC](https://discuss.elastic.co/t/filebeat-multiline-how-to-tell-filebeat-when-a-message-ends-while-parsing-microsoft-defender-atp-logs/324564 "2023-02-02T16:18:13Z")

</div>

Hello, I'm trying to integrate Microsoft Defender ATP with Graylog, and I'm pulling in events using the Microsoft API. The output is spread across multiple lines, so I'm using the multiline function within filebeat to p…

---

## [Tags written to .monitoring-es-8-mb by metricbeat is not searchable](https://discuss.elastic.co/t/tags-written-to-monitoring-es-8-mb-by-metricbeat-is-not-searchable/324562)

<div class="topic-metadata">

**Author:** [@Abhi\_Abhishek](https://discuss.elastic.co/u/Abhi_Abhishek)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 4:07pm UTC](https://discuss.elastic.co/t/tags-written-to-monitoring-es-8-mb-by-metricbeat-is-not-searchable/324562 "2023-02-02T16:07:07Z")

</div>

The tags added through processors in metricbeat.yml writes to monitoring-es-8-mb index which shows tags field when searched with only index name. Metricbeat.yml config processors: - add\_tags: tags: \[Earth\] …

---

## [Winlogbeat read Windows Event id 4732 but not Member Security ID?](https://discuss.elastic.co/t/winlogbeat-read-windows-event-id-4732-but-not-member-security-id/322759)

<div class="topic-metadata">

**Author:** [@hansbrah7](https://discuss.elastic.co/u/hansbrah7)\
**Replies:** 2\
**Last updated:** [February 2, 2023, 3:06pm UTC](https://discuss.elastic.co/t/winlogbeat-read-windows-event-id-4732-but-not-member-security-id/322759 "2023-02-02T15:06:32Z")

</div>

We have noticed that the Winlogbeat agent will read and ship up the event id 4732 (User added to local Security Group) but we noticed that it is missing the Member Security ID (which is the user that is getting added). …

---

## [Common points in two geo\_bounding\_box](https://discuss.elastic.co/t/common-points-in-two-geo-bounding-box/324387)

<div class="topic-metadata">

**Author:** [@maya\_khan](https://discuss.elastic.co/u/maya_khan)\
**Replies:** 10\
**Last updated:** [February 2, 2023, 7:00am UTC](https://discuss.elastic.co/t/common-points-in-two-geo-bounding-box/324387 "2023-02-02T07:00:17Z")

</div>

I have two geo\_bounding\_box within these two shapes many points exist. i want only those points that are common in both geo\_bounding\_box. { "bool":{ "should":\[ { "geo\_bounding\_box":{ "geo\_coords":{ "top\_left": { …

---

## [Query in rated requests should not contain aggregations](https://discuss.elastic.co/t/query-in-rated-requests-should-not-contain-aggregations/324559)

<div class="topic-metadata">

**Author:** [@ocastaneda](https://discuss.elastic.co/u/ocastaneda)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 2:51pm UTC](https://discuss.elastic.co/t/query-in-rated-requests-should-not-contain-aggregations/324559 "2023-02-02T14:51:07Z")

</div>

Hello! Our search team is considering diversifying search results with diversified\_sampler aggregation and child top\_hits aggregation. I noticed that aggregations don’t work with the ranking evaluation API. Anyone got s…

---

## [Rollover for Daily indices in Elasticsearch](https://discuss.elastic.co/t/rollover-for-daily-indices-in-elasticsearch/324558)

<div class="topic-metadata">

**Author:** [@Veysel\_yuksel](https://discuss.elastic.co/u/Veysel_yuksel)\
**Replies:** 2\
**Last updated:** [February 2, 2023, 2:42pm UTC](https://discuss.elastic.co/t/rollover-for-daily-indices-in-elasticsearch/324558 "2023-02-02T14:42:25Z")

</div>

Hello, I am trying to implement rollover mechanism to my environments. Let me explain as is and to be design; Log data stores in syslog-%{+YYYY.MM.dd} indices right now. I keep data for 3 days. No rollover - No warm or…

---

## [Restoring indices from S3 repository](https://discuss.elastic.co/t/restoring-indices-from-s3-repository/324464)

<div class="topic-metadata">

**Author:** [@iyin](https://discuss.elastic.co/u/iyin)\
**Replies:** 3\
**Last updated:** [February 2, 2023, 2:20pm UTC](https://discuss.elastic.co/t/restoring-indices-from-s3-repository/324464 "2023-02-02T14:20:21Z")

</div>

Hi, I took a snapshot of an elastic cluster (version 7.17.8) and saved it on an Amazon S3 repository before the cluster was deleted. Although, I am able to see the backup files in the s3 bucket, I have been unable to re…

---

## [Fleet server data stream is not populating data](https://discuss.elastic.co/t/fleet-server-data-stream-is-not-populating-data/324554)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 1:49pm UTC](https://discuss.elastic.co/t/fleet-server-data-stream-is-not-populating-data/324554 "2023-02-02T13:49:43Z")

</div>

Hi, We have configured fleet server and enrolled elastic agents to that but we can not see any data in Data Stream tab, anyone has an idea what was the issue?

---

## [How to fix retention log and how to manage data retention time in Elasticsearch](https://discuss.elastic.co/t/how-to-fix-retention-log-and-how-to-manage-data-retention-time-in-elasticsearch/324323)

<div class="topic-metadata">

**Author:** [@Mosa](https://discuss.elastic.co/u/Mosa)\
**Replies:** 6\
**Last updated:** [February 2, 2023, 1:44pm UTC](https://discuss.elastic.co/t/how-to-fix-retention-log-and-how-to-manage-data-retention-time-in-elasticsearch/324323 "2023-02-02T13:44:29Z")

</div>

Hi Team, I've configured my retention log in my Elasticsearch and I hope managing my data retention time. But no thing is changed after 3 days in my configuration just to test it. And no data is deleted too after 3 days…

---

## [Hardware Specifications for Storage Types](https://discuss.elastic.co/t/hardware-specifications-for-storage-types/324553)

<div class="topic-metadata">

**Author:** [@federica.forti](https://discuss.elastic.co/u/federica.forti)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 1:44pm UTC](https://discuss.elastic.co/t/hardware-specifications-for-storage-types/324553 "2023-02-02T13:44:21Z")

</div>

Hi, we have choose the type of storage to associate to an Elasticsearch cluster. In particular, we wonder if there is any indication of the minimum characteristics that a certain type of storage must have; for example …

---

## [RBAC on multiple project RUM data](https://discuss.elastic.co/t/rbac-on-multiple-project-rum-data/323688)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 8\
**Last updated:** [February 2, 2023, 12:36pm UTC](https://discuss.elastic.co/t/rbac-on-multiple-project-rum-data/323688 "2023-02-02T12:36:20Z")

</div>

Hello Team, We have formed observability setup receiving data from multiple projects with basic license. and all projects data going to common index of APM & RUM. Elasticsearch - 8.4.3 Kibana - 8.4.3 APM - 8.4.3 We …

---

## [Filter and Count on a field](https://discuss.elastic.co/t/filter-and-count-on-a-field/324546)

<div class="topic-metadata">

**Author:** [@mayur](https://discuss.elastic.co/u/mayur)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 12:31pm UTC](https://discuss.elastic.co/t/filter-and-count-on-a-field/324546 "2023-02-02T12:31:45Z")

</div>

I am trying to calculate Recall from a field, which is populated with two values, TP and FN. Recall formula is Count(TP) / (Count(TP) + Count(FN)). How to achieve this opensearch?

---

## [Anyway to load custom javascript files before loading kibana UI in the browser?](https://discuss.elastic.co/t/anyway-to-load-custom-javascript-files-before-loading-kibana-ui-in-the-browser/324483)

<div class="topic-metadata">

**Author:** [@Joe\_Kuan](https://discuss.elastic.co/u/Joe_Kuan)\
**Replies:** 3\
**Last updated:** [February 2, 2023, 12:01pm UTC](https://discuss.elastic.co/t/anyway-to-load-custom-javascript-files-before-loading-kibana-ui-in-the-browser/324483 "2023-02-02T12:01:55Z")

</div>

Is there any configurations or method to load custom javascript files before any plugin startup? Thanks Joe

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=645)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=647)
