# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=653

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 654

---

## [Can't install logstash-output-influxdb plugin](https://discuss.elastic.co/t/cant-install-logstash-output-influxdb-plugin/323890)

<div class="topic-metadata">

**Author:** [@AlanChan](https://discuss.elastic.co/u/AlanChan)\
**Replies:** 19\
**Last updated:** [January 27, 2023, 6:23am UTC](https://discuss.elastic.co/t/cant-install-logstash-output-influxdb-plugin/323890 "2023-01-27T06:23:37Z")

</div>

Hi, I'm using Logstash (8.6.0) and want to send data to influxdb2 (2.6.1). But I find that logstash-output-infludb isn't installed by default, so I'm trying to install it. Some errors happen but no details are shown. C…

---

## [Restricting Kibana access](https://discuss.elastic.co/t/restricting-kibana-access/324080)

<div class="topic-metadata">

**Author:** [@aneeshks1982](https://discuss.elastic.co/u/aneeshks1982)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 2:23am UTC](https://discuss.elastic.co/t/restricting-kibana-access/324080 "2023-01-27T02:23:53Z")

</div>

Hi, I'm using Elastic cloud and Elasticsearch version-8.6.0. Elastic cloud and Kibana are now accessible from anywhere. Can I restrict the access to Elastic/Kibana only from a specific IP source? because I like to restr…

---

## [Docker logstash 8.6.0 + logstash-input-cloudwatch\_logs does not build](https://discuss.elastic.co/t/docker-logstash-8-6-0-logstash-input-cloudwatch-logs-does-not-build/324077)

<div class="topic-metadata">

**Author:** [@francisco\_eguiguren](https://discuss.elastic.co/u/francisco_eguiguren)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 12:18am UTC](https://discuss.elastic.co/t/docker-logstash-8-6-0-logstash-input-cloudwatch-logs-does-not-build/324077 "2023-01-27T00:18:44Z")

</div>

Hi Folks, I'm trying to build a Docker image that includes logstash-input-cloudwatch\_logs plugin as I need to insert logs from Cloudwatch into my pipeline. I've tried multiple combinations of commands and JAVA\_OPTS, on…

---

## [Confluent cloud from prometheus to elastic search](https://discuss.elastic.co/t/confluent-cloud-from-prometheus-to-elastic-search/324045)

<div class="topic-metadata">

**Author:** [@ch7247](https://discuss.elastic.co/u/ch7247)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 12:07am UTC](https://discuss.elastic.co/t/confluent-cloud-from-prometheus-to-elastic-search/324045 "2023-01-27T00:07:27Z")

</div>

Hello everyone, I'm completely new to elk, planning to have a dashboard in kibana to visualize confluent cloud metric. Currently, i'm successful in getting the metrics to prometheus, i'm having some issue with getting t…

---

## [Logstash plugins still displaying ECS v8 warnings](https://discuss.elastic.co/t/logstash-plugins-still-displaying-ecs-v8-warnings/324030)

<div class="topic-metadata">

**Author:** [@Oddly](https://discuss.elastic.co/u/Oddly)\
**Replies:** 4\
**Last updated:** [January 26, 2023, 10:18pm UTC](https://discuss.elastic.co/t/logstash-plugins-still-displaying-ecs-v8-warnings/324030 "2023-01-26T22:18:20Z")

</div>

I noticed that several plugins (grok and outputs.elasticsearchmonitoring to name a few) are still displaying warning messages like the following: \[WARN\]\[logstash.filters.grok\]\[\<pipeline\_redacted\] ECS v8 support is a pre…

---

## [Failed to perform request](https://discuss.elastic.co/t/failed-to-perform-request/324071)

<div class="topic-metadata">

**Author:** [@test\_qweqwe](https://discuss.elastic.co/u/test_qweqwe)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 10:15pm UTC](https://discuss.elastic.co/t/failed-to-perform-request/324071 "2023-01-26T22:15:18Z")

</div>

\[2023-01-26T19:51:43,271\]\[INFO \]\[logstash.outputs.elasticsearch\]\[main\] Failed to perform request {:message=\>"192.168.0.108:9200 failed to respond", :exception=\>Manticore::ClientProtocolException, :cause=\>#\<Java::OrgApach…

---

## [Two types under one filter](https://discuss.elastic.co/t/two-types-under-one-filter/323978)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 3\
**Last updated:** [January 26, 2023, 9:54pm UTC](https://discuss.elastic.co/t/two-types-under-one-filter/323978 "2023-01-26T21:54:30Z")

</div>

Can I have two types (plain txt log & json )under one filter in the logstash.yml file? input { beats { port =\> "5044" } } filter { if \[fields=='access'\] { grok { remove\_field =\> "message" } …

---

## [Forecasting holidays](https://discuss.elastic.co/t/forecasting-holidays/323854)

<div class="topic-metadata">

**Author:** [@Patrick\_P](https://discuss.elastic.co/u/Patrick_P)\
**Replies:** 3\
**Last updated:** [January 26, 2023, 8:05pm UTC](https://discuss.elastic.co/t/forecasting-holidays/323854 "2023-01-26T20:05:53Z")

</div>

I'm trying to create a forecast from an anomaly detection job in Kibana. It tracks the number of events in certain intervals, and we always have lower volume on certain holidays. I have applied a Calendar that I created …

---

## [How to disable the traceparent and tracestate headers](https://discuss.elastic.co/t/how-to-disable-the-traceparent-and-tracestate-headers/324058)

<div class="topic-metadata">

**Author:** [@e03c5fccb551b6833a65](https://discuss.elastic.co/u/e03c5fccb551b6833a65)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 6:23pm UTC](https://discuss.elastic.co/t/how-to-disable-the-traceparent-and-tracestate-headers/324058 "2023-01-26T18:23:08Z")

</div>

One of our services connects with a bank, and it's not allowing any requests with the tracepearent, tracestate header. I tried using the property use\_elastic\_traceparent\_header as false, but still I see the headers in t…

---

## [How many of you are using Otel for your K8S apps on Elastic vs docker?](https://discuss.elastic.co/t/how-many-of-you-are-using-otel-for-your-k8s-apps-on-elastic-vs-docker/324056)

<div class="topic-metadata">

**Author:** [@Bahubali\_Shetti](https://discuss.elastic.co/u/Bahubali_Shetti)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 6:02pm UTC](https://discuss.elastic.co/t/how-many-of-you-are-using-otel-for-your-k8s-apps-on-elastic-vs-docker/324056 "2023-01-26T18:02:33Z")

</div>

OpenTelemetry and Elastic: An unbeatable combination for observability | Elastic Blog covers the baseline of what's being supported. Curious what people's experiences are on Otel with Elastic. Any interesting examples, e…

---

## [How to create a GeoShape intersect query with elastic java client v8.6.0](https://discuss.elastic.co/t/how-to-create-a-geoshape-intersect-query-with-elastic-java-client-v8-6-0/324025)

<div class="topic-metadata">

**Author:** [@yusufozcan](https://discuss.elastic.co/u/yusufozcan)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 5:53pm UTC](https://discuss.elastic.co/t/how-to-create-a-geoshape-intersect-query-with-elastic-java-client-v8-6-0/324025 "2023-01-26T17:53:30Z")

</div>

Hi! We have a geo shape field which we store multi polygons and we want to filter it with a coordinate. Desired search request is: "geo\_shape": { "area": { "shape": { "type": "point", "coordinates": …

---

## [Completion-Suggester that respects the number of word occurences](https://discuss.elastic.co/t/completion-suggester-that-respects-the-number-of-word-occurences/324031)

<div class="topic-metadata">

**Author:** [@Andromeda](https://discuss.elastic.co/u/Andromeda)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 2:59pm UTC](https://discuss.elastic.co/t/completion-suggester-that-respects-the-number-of-word-occurences/324031 "2023-01-26T14:59:21Z")

</div>

Hello there, is there a way that Completion-Suggesters deliver suggests depending on how often matching words appear in the completion fields of all documents? For example, imagine "thinks" appears in completion fields…

---

## [Number of Nested objects](https://discuss.elastic.co/t/number-of-nested-objects/324050)

<div class="topic-metadata">

**Author:** [@ewolfman](https://discuss.elastic.co/u/ewolfman)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 5:18pm UTC](https://discuss.elastic.co/t/number-of-nested-objects/324050 "2023-01-26T17:18:41Z")

</div>

Hi, Looking for a way to get the number of nested objects, for querying, sorting etc. For example: PUT my-index-000001 { "mappings": { "properties": { "some\_id": {"type": "long"}, "user": { "…

---

## [Access global document count from inside bucket script](https://discuss.elastic.co/t/access-global-document-count-from-inside-bucket-script/324040)

<div class="topic-metadata">

**Author:** [@bpax51](https://discuss.elastic.co/u/bpax51)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 3:48pm UTC](https://discuss.elastic.co/t/access-global-document-count-from-inside-bucket-script/324040 "2023-01-26T15:48:42Z")

</div>

Hello guys, I'm new to Elasticsearch and already having fun with aggregations but I'm facing an issue that I couldn't figure out. I have the following query, that will search my index within a date range, give me a lis…

---

## [Kibana markdown - clickable location for an image linked to URL](https://discuss.elastic.co/t/kibana-markdown-clickable-location-for-an-image-linked-to-url/323967)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 3\
**Last updated:** [January 26, 2023, 3:39pm UTC](https://discuss.elastic.co/t/kibana-markdown-clickable-location-for-an-image-linked-to-url/323967 "2023-01-26T15:39:05Z")

</div>

Hello, I am seeing an issue with my current deployment of version 8.6.0 where a linked image is only clickable in a small portion at bottom. When editing the visual, the behaviour was correct where I was able to click …

---

## [Logstash configuration to IBM MQ using TLS and Cipher](https://discuss.elastic.co/t/logstash-configuration-to-ibm-mq-using-tls-and-cipher/323995)

<div class="topic-metadata">

**Author:** [@JHE](https://discuss.elastic.co/u/JHE)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 7:43am UTC](https://discuss.elastic.co/t/logstash-configuration-to-ibm-mq-using-tls-and-cipher/323995 "2023-01-26T07:43:45Z")

</div>

Hi, I'm trying to connect logstash to IBM MQ using jms input. It's OK for an non secured connection. However I didn't find any example to configure a TLS connection and to specify a cipher suites. Here bellow my confi…

---

## [Kibana Action failed with 'search\_phase\_execution\_exception](https://discuss.elastic.co/t/kibana-action-failed-with-search-phase-execution-exception/324024)

<div class="topic-metadata">

**Author:** [@darinka.mandarinka](https://discuss.elastic.co/u/darinka.mandarinka)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 2:27pm UTC](https://discuss.elastic.co/t/kibana-action-failed-with-search-phase-execution-exception/324024 "2023-01-26T14:27:31Z")

</div>

I have Elasticsearh, Kibana, Filebeat in our cluster. In kibana logs I see error Action failed with 'search\_phase\_execution\_exception How I can solve it? I'm new, first time working with this.

---

## [Migrating from ES 5 to ES 8, problems in index](https://discuss.elastic.co/t/migrating-from-es-5-to-es-8-problems-in-index/323454)

<div class="topic-metadata">

**Author:** [@Anibal\_Ardid](https://discuss.elastic.co/u/Anibal_Ardid)\
**Replies:** 4\
**Last updated:** [January 26, 2023, 2:17pm UTC](https://discuss.elastic.co/t/migrating-from-es-5-to-es-8-problems-in-index/323454 "2023-01-26T14:17:51Z")

</div>

Hi ! I have this json that i use to index { "settings":{ "number\_of\_shards":1, "number\_of\_replicas":0, "index.mapping.total\_fields.limit":100000, "analysis":{ "filter":{ …

---

## [Zscaler logs mapped to ECS](https://discuss.elastic.co/t/zscaler-logs-mapped-to-ecs/323963)

<div class="topic-metadata">

**Author:** [@reswob](https://discuss.elastic.co/u/reswob)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 1:40pm UTC](https://discuss.elastic.co/t/zscaler-logs-mapped-to-ecs/323963 "2023-01-26T13:40:54Z")

</div>

I'm working on ingesting zscaler zia logs and I'm trying to understand the mapping. I'm looking at the following websites: Zscaler Internet Access | Elastic docs for what happens inside Elastic/Kibana and NSS Feed Out…

---

## [In ES 7.0, when using sequence numbers based recovery,primary and replica shard will be inconsistent](https://discuss.elastic.co/t/in-es-7-0-when-using-sequence-numbers-based-recovery-primary-and-replica-shard-will-be-inconsistent/324006)

<div class="topic-metadata">

**Author:** [@warriorswin](https://discuss.elastic.co/u/warriorswin)\
**Replies:** 3\
**Last updated:** [January 26, 2023, 1:29pm UTC](https://discuss.elastic.co/t/in-es-7-0-when-using-sequence-numbers-based-recovery-primary-and-replica-shard-will-be-inconsistent/324006 "2023-01-26T13:29:15Z")

</div>

add data=A node1 primary data=A seqNo=1 No persistence node2 replica data=A seqNo=1 Persistence node1,node2 shutdown node1 restart and add data=B node1 primary data=B seqNo=1 node2 restart When using sequence numb…

---

## [Role to ingesting for custom user](https://discuss.elastic.co/t/role-to-ingesting-for-custom-user/324020)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 2\
**Last updated:** [January 26, 2023, 12:34pm UTC](https://discuss.elastic.co/t/role-to-ingesting-for-custom-user/324020 "2023-01-26T12:34:36Z")

</div>

Hi everyone, i want to know what exactly roles required for ingesting if i want to create custom user only for ingesting? fyi, i'm using elastic v7.13 i've been read this page but i'm so confused. what privileges that…

---

## [ES\_TMPDIR not setting all temporary files](https://discuss.elastic.co/t/es-tmpdir-not-setting-all-temporary-files/324019)

<div class="topic-metadata">

**Author:** [@lquenti](https://discuss.elastic.co/u/lquenti)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 12:00pm UTC](https://discuss.elastic.co/t/es-tmpdir-not-setting-all-temporary-files/324019 "2023-01-26T12:00:42Z")

</div>

Hi all, I am currently trying to set up elasticsearch with a read-only config directory within a docker based on the elasticsearch image. After thoroughly reading the docs, the only related Option I found was the ES\_TMP…

---

## [Can i sort my documents by date several conditions?](https://discuss.elastic.co/t/can-i-sort-my-documents-by-date-several-conditions/324015)

<div class="topic-metadata">

**Author:** [@Volodymyr\_Dzhuryn](https://discuss.elastic.co/u/Volodymyr_Dzhuryn)\
**Replies:** 2\
**Last updated:** [January 26, 2023, 11:55am UTC](https://discuss.elastic.co/t/can-i-sort-my-documents-by-date-several-conditions/324015 "2023-01-26T11:55:34Z")

</div>

I have index with document which have two field with dates "match\_date\_time" and "created\_at". I need query for getting documents sorted by next criteria 1. \[ASC order\] articles with future match date and time (sorted …

---

## [Not enough nodes to allocate all shard replicas](https://discuss.elastic.co/t/not-enough-nodes-to-allocate-all-shard-replicas/323360)

<div class="topic-metadata">

**Author:** [@michielswaanen](https://discuss.elastic.co/u/michielswaanen)\
**Replies:** 11\
**Last updated:** [January 26, 2023, 11:40am UTC](https://discuss.elastic.co/t/not-enough-nodes-to-allocate-all-shard-replicas/323360 "2023-01-26T11:40:18Z")

</div>

Hey all, My Elasticsearch deployment is showing the following health issue: I tried to fix the issue by following the suggested guide. I scaled our deployment up by increasing the availability zones (from 1 to 2), l…

---

## [Delete index](https://discuss.elastic.co/t/delete-index/324016)

<div class="topic-metadata">

**Author:** [@mezzetto\_mezzetto](https://discuss.elastic.co/u/mezzetto_mezzetto)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 11:19am UTC](https://discuss.elastic.co/t/delete-index/324016 "2023-01-26T11:19:17Z")

</div>

Hi all, I'm newbie on elastic. I've a custom installation an I need to free storage space; I've a rollover policy that creates a new index after 30 days or if it reach 50GB; I have 14 index, if I try to close a very old …

---

## [Change Elasticsearch and Kibana communication certificate](https://discuss.elastic.co/t/change-elasticsearch-and-kibana-communication-certificate/324000)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 2\
**Last updated:** [January 26, 2023, 10:46am UTC](https://discuss.elastic.co/t/change-elasticsearch-and-kibana-communication-certificate/324000 "2023-01-26T10:46:49Z")

</div>

Hi All, Our certificates which are assign to Elasticsearch and Kibana are expired and seem like self sign certs are there, so I would appreciate that if anyone can guide how to do that? We have 3 ES and 1 Kibana server…

---

## [Using --run-examples doesn't show all examples](https://discuss.elastic.co/t/using-run-examples-doesnt-show-all-examples/323881)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 3\
**Last updated:** [January 26, 2023, 10:08am UTC](https://discuss.elastic.co/t/using-run-examples-doesnt-show-all-examples/323881 "2023-01-26T10:08:25Z")

</div>

Hi, I am running kibana in dev mode, with --run-examples But it doesn't show all examples... shows only 3 examples (hello world, 3rd part integration, user profile components) I want to see the embeddable example Tha…

---

## [Log files are not cleared from the registry when harvested Kubernetes container is restarted](https://discuss.elastic.co/t/log-files-are-not-cleared-from-the-registry-when-harvested-kubernetes-container-is-restarted/322827)

<div class="topic-metadata">

**Author:** [@melkamar](https://discuss.elastic.co/u/melkamar)\
**Replies:** 4\
**Last updated:** [January 26, 2023, 10:00am UTC](https://discuss.elastic.co/t/log-files-are-not-cleared-from-the-registry-when-harvested-kubernetes-container-is-restarted/322827 "2023-01-26T10:00:13Z")

</div>

Background: we are running Filebeat as a DaemonSet in a self-managed Microk8s Kubernetes cluster. I noticed extreme CPU usage and failures/delays with delivering logs after a while. More details in this Slack thread but …

---

## [Elasticsearch and Kibana Zero SSL Certificate Issue](https://discuss.elastic.co/t/elasticsearch-and-kibana-zero-ssl-certificate-issue/324004)

<div class="topic-metadata">

**Author:** [@ali.sharjeel](https://discuss.elastic.co/u/ali.sharjeel)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 9:10am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-zero-ssl-certificate-issue/324004 "2023-01-26T09:10:59Z")

</div>

Hi Team! I am trying to install ZeroSSL certificate on Elasticsearch and Kibana node with the domain (www.secure-unified.tk). I have obtained the certificate from the ZeroSSL and got three files (private.key, certificate…

---

## [Just 1 docker swarm node is visible in Kibana](https://discuss.elastic.co/t/just-1-docker-swarm-node-is-visible-in-kibana/324002)

<div class="topic-metadata">

**Author:** [@albert2022](https://discuss.elastic.co/u/albert2022)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 8:55am UTC](https://discuss.elastic.co/t/just-1-docker-swarm-node-is-visible-in-kibana/324002 "2023-01-26T08:55:56Z")

</div>

Hi, We configured a cluster using the docker swarm based on the following yml file: version: '3.8' services: node-master: deploy: replicas: 1 placement: constraints: - node.labels.e…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=652)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=654)
