# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=657

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 658

---

## [Logstash Module](https://discuss.elastic.co/t/logstash-module/323715)

<div class="topic-metadata">

**Author:** [@Adedolapo\_Okunsanmi](https://discuss.elastic.co/u/Adedolapo_Okunsanmi)\
**Replies:** 3\
**Last updated:** [January 24, 2023, 7:44am UTC](https://discuss.elastic.co/t/logstash-module/323715 "2023-01-24T07:44:50Z")

</div>

Hi Guys, I use the Cloud-Based Elastic/Kibana. I would like to know if there is a difference between Logstash module in Filebeats and Logstash installed directly on server,

---

## [How do we get scroll up/down option on Controls (Filters)](https://discuss.elastic.co/t/how-do-we-get-scroll-up-down-option-on-controls-filters/323720)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 2\
**Last updated:** [January 24, 2023, 6:52am UTC](https://discuss.elastic.co/t/how-do-we-get-scroll-up-down-option-on-controls-filters/323720 "2023-01-24T06:52:35Z")

</div>

Hi Team, We created one control having total 20 options, but its showing only 10 (It's not showing any scroll bar also). But, we are expecting here to view all 20 available options or at least scroll up/down. Please fin…

---

## [Alert for paused indices on CCR](https://discuss.elastic.co/t/alert-for-paused-indices-on-ccr/323777)

<div class="topic-metadata">

**Author:** [@Jairam\_Gauns](https://discuss.elastic.co/u/Jairam_Gauns)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 5:30am UTC](https://discuss.elastic.co/t/alert-for-paused-indices-on-ccr/323777 "2023-01-24T05:30:52Z")

</div>

I would like to know if we can get alerts of paused indices in CCR from the DR site. So that we can then check and resume the indices/pattern. Or any other way one could recommend to know if indices getting paused on DR…

---

## [Node Left Cluster After enabling X-Pack](https://discuss.elastic.co/t/node-left-cluster-after-enabling-x-pack/323745)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 2\
**Last updated:** [January 24, 2023, 4:13am UTC](https://discuss.elastic.co/t/node-left-cluster-after-enabling-x-pack/323745 "2023-01-24T04:13:41Z")

</div>

Hello, I have formed a cluster of 2 Nodes, one is master-data and the other is data. Everything was working perfectly until I decided to enable X-Pack minimal security. Below is the config file for both Nodes. Curling t…

---

## [GCLocker too often allocating 256 words](https://discuss.elastic.co/t/gclocker-too-often-allocating-256-words/323769)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 12:33am UTC](https://discuss.elastic.co/t/gclocker-too-often-allocating-256-words/323769 "2023-01-24T00:33:00Z")

</div>

How I can tune up config due to warning \[1154.233s\]\[warning\]\[gc,alloc\] \[npdb\_dns\]\>worker20: Retried waiting for GCLocker too often allocating 256 words \[1154.233s\]\[warning\]\[gc,alloc\] \[npdb\_network\]\>worker7: Retried wai…

---

## [Import \`integer\_range\` from CSV with kibana \`Visualize data from a file\`?](https://discuss.elastic.co/t/import-integer-range-from-csv-with-kibana-visualize-data-from-a-file/323765)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 2:00am UTC](https://discuss.elastic.co/t/import-integer-range-from-csv-with-kibana-visualize-data-from-a-file/323765 "2023-01-24T02:00:55Z")

</div>

Is it possible for the Machine Learning\>Data Visualizer\>Visualize data from file to import a csv file where one of the columns is an integer\_range? If so, what is the syntax that should be used in the integer\_range colu…

---

## [How to send data in index from ELK Stack to Prometheus?](https://discuss.elastic.co/t/how-to-send-data-in-index-from-elk-stack-to-prometheus/323708)

<div class="topic-metadata">

**Author:** [@jom0](https://discuss.elastic.co/u/jom0)\
**Replies:** 2\
**Last updated:** [January 24, 2023, 12:29am UTC](https://discuss.elastic.co/t/how-to-send-data-in-index-from-elk-stack-to-prometheus/323708 "2023-01-24T00:29:40Z")

</div>

Hello, I'm working on my project that use ELK Stack to receive syslog from network devices (router and switch) and then send them to Prometheus. Now I'm tried using Elasticsearch exporter but I can't find syslog in Prome…

---

## [Reindexing fails because missing shards](https://discuss.elastic.co/t/reindexing-fails-because-missing-shards/323773)

<div class="topic-metadata">

**Author:** [@EthanJ1999](https://discuss.elastic.co/u/EthanJ1999)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 11:15pm UTC](https://discuss.elastic.co/t/reindexing-fails-because-missing-shards/323773 "2023-01-23T23:15:20Z")

</div>

Hi everyone hope you doing ok. We are trying to reindex data from an index with one missing shard, but we get this error: { "completed":true, "task":{ "node":"node", "id":7297895, "type":"transp…

---

## [Timelion query filter returning constant 0 results](https://discuss.elastic.co/t/timelion-query-filter-returning-constant-0-results/323625)

<div class="topic-metadata">

**Author:** [@vector\_prime](https://discuss.elastic.co/u/vector_prime)\
**Replies:** 1\
**Last updated:** [January 23, 2023, 9:52pm UTC](https://discuss.elastic.co/t/timelion-query-filter-returning-constant-0-results/323625 "2023-01-23T21:52:50Z")

</div>

I have an index with the following document structure: "\_source": { "installcreatedbyusername": "xxxx", "@timestamp": "2023-01-20T16:30:03.840332Z", "type": "aegis", "num\_packages": 2, "num\_environme…

---

## [Internal settings for data limit/transfer between data tier](https://discuss.elastic.co/t/internal-settings-for-data-limit-transfer-between-data-tier/323766)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 9:29pm UTC](https://discuss.elastic.co/t/internal-settings-for-data-limit-transfer-between-data-tier/323766 "2023-01-23T21:29:15Z")

</div>

would like to share my case " what's going on? I'm shooting the date to node which have 16GB of mem limit so we have 8GB of heap size so what I got circuit\_breaking\_exception for 3.9 GB??? Yes because this date was to …

---

## [Extract @datetime field from a string in an index pattern and make it filterable using datetime](https://discuss.elastic.co/t/extract-datetime-field-from-a-string-in-an-index-pattern-and-make-it-filterable-using-datetime/323640)

<div class="topic-metadata">

**Author:** [@Amit\_Bhushan](https://discuss.elastic.co/u/Amit_Bhushan)\
**Replies:** 5\
**Last updated:** [January 23, 2023, 8:55pm UTC](https://discuss.elastic.co/t/extract-datetime-field-from-a-string-in-an-index-pattern-and-make-it-filterable-using-datetime/323640 "2023-01-23T20:55:29Z")

</div>

The orignal task is to make an index pattern (here alb-logs\*) in Elasticsearch searchable in datetime field (get those histogram). So I approached this problem and found out that this index does not have any datetime fi…

---

## [Error "Event created before query" using o365 module](https://discuss.elastic.co/t/error-event-created-before-query-using-o365-module/323759)

<div class="topic-metadata">

**Author:** [@Apaquette](https://discuss.elastic.co/u/Apaquette)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 7:28pm UTC](https://discuss.elastic.co/t/error-event-created-before-query-using-o365-module/323759 "2023-01-23T19:28:36Z")

</div>

Hello, We use Filebeat's module for Office 365 to gather audit logs and send them to our SIEM. We detected multiple errors in the module's logs. We can read "Event created before query" (with a little bit more informat…

---

## [Async Background Search with .NET NEST Client](https://discuss.elastic.co/t/async-background-search-with-net-nest-client/323271)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 12\
**Last updated:** [January 23, 2023, 6:25pm UTC](https://discuss.elastic.co/t/async-background-search-with-net-nest-client/323271 "2023-01-23T18:25:03Z")

</div>

How does one use the Elasticsearch Async Background search facility using the NEST Library. We cannot find any documentation on the syntax. Any help would be appreciated.

---

## [Aggregation of sums instead of sum of aggregation](https://discuss.elastic.co/t/aggregation-of-sums-instead-of-sum-of-aggregation/323751)

<div class="topic-metadata">

**Author:** [@rxtx](https://discuss.elastic.co/u/rxtx)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 5:04pm UTC](https://discuss.elastic.co/t/aggregation-of-sums-instead-of-sum-of-aggregation/323751 "2023-01-23T17:04:46Z")

</div>

I'm trying to figure out if I can aggregate something by the sum of a value field rather than the number of value fields. I have an events index The events has the following fields: property\_id, name, value, timestamp I…

---

## [Elastic agent integration stuck on upgrade | fleet affected](https://discuss.elastic.co/t/elastic-agent-integration-stuck-on-upgrade-fleet-affected/322447)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 4\
**Last updated:** [January 23, 2023, 4:44pm UTC](https://discuss.elastic.co/t/elastic-agent-integration-stuck-on-upgrade-fleet-affected/322447 "2023-01-23T16:44:10Z")

</div>

any idea how to stop the update process or update it properly

---

## [Fleet Server is Not Healthy](https://discuss.elastic.co/t/fleet-server-is-not-healthy/322215)

<div class="topic-metadata">

**Author:** [@Coder\_HK](https://discuss.elastic.co/u/Coder_HK)\
**Replies:** 3\
**Last updated:** [January 23, 2023, 4:41pm UTC](https://discuss.elastic.co/t/fleet-server-is-not-healthy/322215 "2023-01-23T16:41:38Z")

</div>

I am getting the error, and becuase of that I can't add any agent.. what is causing the error. and How do i Resolve it. Is it becuause of the SSL certificate ?

---

## [How to discount index who change from a Transform](https://discuss.elastic.co/t/how-to-discount-index-who-change-from-a-transform/323449)

<div class="topic-metadata">

**Author:** [@solrac97gr](https://discuss.elastic.co/u/solrac97gr)\
**Replies:** 5\
**Last updated:** [January 23, 2023, 4:34pm UTC](https://discuss.elastic.co/t/how-to-discount-index-who-change-from-a-transform/323449 "2023-01-23T16:34:34Z")

</div>

I have a specific task and we decided to solved it using transform Our Case: We need to count and aggregate by status a index like this { created\_at: "2023-01-15" accepted:10, review: 15, } On…

---

## [Elasticsearch exited unexpectedly ES exited with code 1](https://discuss.elastic.co/t/elasticsearch-exited-unexpectedly-es-exited-with-code-1/323638)

<div class="topic-metadata">

**Author:** [@jdso1988](https://discuss.elastic.co/u/jdso1988)\
**Replies:** 3\
**Last updated:** [January 23, 2023, 4:22pm UTC](https://discuss.elastic.co/t/elasticsearch-exited-unexpectedly-es-exited-with-code-1/323638 "2023-01-23T16:22:00Z")

</div>

After running: yarn es snapshot i get the following error yarn run v1.22.19 warning ../../package.json: No license field $ node scripts/es snapshot info Installing from snapshot │ info version: 8.5.0 │ info inst…

---

## [Watcher http input : What is the expected response?](https://discuss.elastic.co/t/watcher-http-input-what-is-the-expected-response/323608)

<div class="topic-metadata">

**Author:** [@Javier\_Molina\_Sanz](https://discuss.elastic.co/u/Javier_Molina_Sanz)\
**Replies:** 1\
**Last updated:** [January 23, 2023, 4:20pm UTC](https://discuss.elastic.co/t/watcher-http-input-what-is-the-expected-response/323608 "2023-01-23T16:20:17Z")

</div>

Hi team, I am trying to build a watcher that calls an external web service to build the query and then fire an action. "input": { "http": { "request": { "scheme": "https", "host": "myhost", …

---

## [Reindexing of old v.6 index keeps stopping with reason kibana was restarted](https://discuss.elastic.co/t/reindexing-of-old-v-6-index-keeps-stopping-with-reason-kibana-was-restarted/323749)

<div class="topic-metadata">

**Author:** [@teesr5](https://discuss.elastic.co/u/teesr5)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 4:05pm UTC](https://discuss.elastic.co/t/reindexing-of-old-v-6-index-keeps-stopping-with-reason-kibana-was-restarted/323749 "2023-01-23T16:05:46Z")

</div>

Hi, we're preparing to upgrade from v.7.10.0, the elk stack is running on an Ubuntu cluster with 3 nodes, although we have an index which we have to prepare for the upgrade, it keeps on looping: Details \[some\]-alias …

---

## [Restore snapshot from another cluster (7.8 to 8.5)](https://discuss.elastic.co/t/restore-snapshot-from-another-cluster-7-8-to-8-5/322747)

<div class="topic-metadata">

**Author:** [@Maria\_Gabriela\_Perez](https://discuss.elastic.co/u/Maria_Gabriela_Perez)\
**Replies:** 4\
**Last updated:** [January 23, 2023, 3:24pm UTC](https://discuss.elastic.co/t/restore-snapshot-from-another-cluster-7-8-to-8-5/322747 "2023-01-23T15:24:21Z")

</div>

I have a question/problem. I have a GCP bucket with tons of snapshots taken from a kibana 7.8, A new kibana has been deployed in another cluster v8.5, that kibana has been connected to the GCP bucket where the old kiban…

---

## [Unable to Reload certificates on filebeat container for Kafka](https://discuss.elastic.co/t/unable-to-reload-certificates-on-filebeat-container-for-kafka/323742)

<div class="topic-metadata">

**Author:** [@kadalin](https://discuss.elastic.co/u/kadalin)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 3:02pm UTC](https://discuss.elastic.co/t/unable-to-reload-certificates-on-filebeat-container-for-kafka/323742 "2023-01-23T15:02:11Z")

</div>

I'm trying to integrate filebeat with Kafka with SSL Handshake. The certificates are obtained from vault and they are valid for only 7 days. A different mechanism is applied to get the certificates renewed with a new pri…

---

## [How to change "index.refresh\_interval" value](https://discuss.elastic.co/t/how-to-change-index-refresh-interval-value/323310)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 5\
**Last updated:** [January 23, 2023, 2:08pm UTC](https://discuss.elastic.co/t/how-to-change-index-refresh-interval-value/323310 "2023-01-23T14:08:46Z")

</div>

Hello, We would like to set index.refresh\_interval --\> 120s as we are seeing write rejections on the data nodes. But how to se this value on all the current indices (Fleet Managed) and the new indices which are going t…

---

## [Remote Connection to Elastic](https://discuss.elastic.co/t/remote-connection-to-elastic/323732)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 1:49pm UTC](https://discuss.elastic.co/t/remote-connection-to-elastic/323732 "2023-01-23T13:49:58Z")

</div>

Hello, I have problem, and I cannot find solution of my problem. I have standalone Elasticsearch on 10.1.251.1, and hosts (Ubuntu 20) with Suricata on 10.2.251.5 and 10.1.251.5. When I try connect fro 10.1.251.1 to my e…

---

## [Monitor ELK Snaphot](https://discuss.elastic.co/t/monitor-elk-snaphot/323719)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 2\
**Last updated:** [January 23, 2023, 1:42pm UTC](https://discuss.elastic.co/t/monitor-elk-snaphot/323719 "2023-01-23T13:42:11Z")

</div>

Hello! Im trying to monitor my snapshots. When i exec GET \_snapshot/\_all/status it doesnt show anything. Does anyone how to create a watcher or a query to see if a snapshot fail or if some of their shards fails ? Tha…

---

## [Update\_by\_query](https://discuss.elastic.co/t/update-by-query/323730)

<div class="topic-metadata">

**Author:** [@Srujan](https://discuss.elastic.co/u/Srujan)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 1:06pm UTC](https://discuss.elastic.co/t/update-by-query/323730 "2023-01-23T13:06:58Z")

</div>

I am new to Elasticsearch. I have a huge index with around 50k documents. I have to update all the document, when I run the update\_by\_query function it is throwing an error Traceback (most recent call last): File "E:\\A…

---

## [How to configure Cluster Filter - Cluster Name](https://discuss.elastic.co/t/how-to-configure-cluster-filter-cluster-name/323725)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 12:31pm UTC](https://discuss.elastic.co/t/how-to-configure-cluster-filter-cluster-name/323725 "2023-01-23T12:31:25Z")

</div>

Hello, i am just find out how to configure the Cluster Filter here. Does anyone can help me ?

---

## [Example Angular plugin](https://discuss.elastic.co/t/example-angular-plugin/323706)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [January 23, 2023, 10:37am UTC](https://discuss.elastic.co/t/example-angular-plugin/323706 "2023-01-23T10:37:52Z")

</div>

Hi, I am creating an external plugin using Angular Is there and example plugin I can use for reference? Thanks

---

## [How to use elastic ui within angular plugin](https://discuss.elastic.co/t/how-to-use-elastic-ui-within-angular-plugin/321973)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 3\
**Last updated:** [January 23, 2023, 10:36am UTC](https://discuss.elastic.co/t/how-to-use-elastic-ui-within-angular-plugin/321973 "2023-01-23T10:36:02Z")

</div>

Hi, I am building a custom external plugin using Angular. I want to use Elastic UI for styling. How can I use it within angular? Thanks

---

## [How to find the time taken to upload/write a file from filebeat to logstash to elastic search(pipeline)?](https://discuss.elastic.co/t/how-to-find-the-time-taken-to-upload-write-a-file-from-filebeat-to-logstash-to-elastic-search-pipeline/323716)

<div class="topic-metadata">

**Author:** [@greg\_deg](https://discuss.elastic.co/u/greg_deg)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 10:22am UTC](https://discuss.elastic.co/t/how-to-find-the-time-taken-to-upload-write-a-file-from-filebeat-to-logstash-to-elastic-search-pipeline/323716 "2023-01-23T10:22:23Z")

</div>

So I have a log file that is taken as an input by filebeat which is then outputted to logstash and from there to Elasticsearch. I need to calculate the time required/elapsed from the time I start filbeat and its reading …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=656)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=658)
