# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=659

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 660

---

## [Elasticsearch search response time / latency metrics](https://discuss.elastic.co/t/elasticsearch-search-response-time-latency-metrics/323613)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [January 20, 2023, 9:55pm UTC](https://discuss.elastic.co/t/elasticsearch-search-response-time-latency-metrics/323613 "2023-01-20T21:55:33Z")

</div>

We are trying to use elasticsearch-exporter (GitHub - prometheus-community/elasticsearch\_exporter: Elasticsearch stats exporter for Prometheus) for monitoring our clusters(v7.17) and we want to monitor the cluster perfor…

---

## [151209 (4) - OpenJDK 7 \<= 7u281 / 8 \<= 8u272 / 11.0.0 \<= 11.0.9 / 13.0.0 \<= 13.0.5 / 15.0.0 \<= 15.0.1 Vulnerability (2021-01-19)](https://discuss.elastic.co/t/151209-4-openjdk-7-7u281-8-8u272-11-0-0-11-0-9-13-0-0-13-0-5-15-0-0-15-0-1-vulnerability-2021-01-19/323620)

<div class="topic-metadata">

**Author:** [@khadija70](https://discuss.elastic.co/u/khadija70)\
**Replies:** 7\
**Last updated:** [January 20, 2023, 10:04pm UTC](https://discuss.elastic.co/t/151209-4-openjdk-7-7u281-8-8u272-11-0-0-11-0-9-13-0-0-13-0-5-15-0-0-15-0-1-vulnerability-2021-01-19/323620 "2023-01-20T22:04:22Z")

</div>

Hi , We have receive vulnerabilities affecting elasticksearch servers : 151209 (4) - OpenJDK 7 \<= 7u281 / 8 \<= 8u272 / 11.0.0 \<= 11.0.9 / 13.0.0 \<= 13.0.5 / 15.0.0 \<= 15.0.1 Vulnerability (2021-01-19) The solution pr…

---

## [Java.io.tmpdir](https://discuss.elastic.co/t/java-io-tmpdir/323534)

<div class="topic-metadata">

**Author:** [@chuck1](https://discuss.elastic.co/u/chuck1)\
**Replies:** 10\
**Last updated:** [January 20, 2023, 9:35pm UTC](https://discuss.elastic.co/t/java-io-tmpdir/323534 "2023-01-20T21:35:27Z")

</div>

Hello, My elasticsearch version is 8.5.3-1 I have a hardened RHEL 8 system which requires that /tmp be mounted with the "noexec" option. I have tried to adjust my jvm.options file in /etc/elasticsearch/jvm.options to s…

---

## [Loading large table from Mysql to ES via Logstash](https://discuss.elastic.co/t/loading-large-table-from-mysql-to-es-via-logstash/323442)

<div class="topic-metadata">

**Author:** [@Het\_Desai](https://discuss.elastic.co/u/Het_Desai)\
**Replies:** 7\
**Last updated:** [January 20, 2023, 7:07pm UTC](https://discuss.elastic.co/t/loading-large-table-from-mysql-to-es-via-logstash/323442 "2023-01-20T19:07:53Z")

</div>

Hello, I have multiple large tables (each table contains ~15M records and consumes ~70GB of data). My logstash configuration is as given below. input { jdbc { jdbc\_connection\_string =\> "jdbc:mysql:…

---

## [Apache Log4j 2.0 \< 2.3.2 / 2.4 \< 2.12.4 / 2.13 \< 2.17.1 RCE](https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614)

<div class="topic-metadata">

**Author:** [@khadija70](https://discuss.elastic.co/u/khadija70)\
**Replies:** 6\
**Last updated:** [January 20, 2023, 6:51pm UTC](https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614 "2023-01-20T18:51:19Z")

</div>

Hi , We have recently receive security vulnerabilities related to Log4j , as solution proposed is to Upgrade to Apache Log4j version 2.17.1, 2.12.4, or 2.3.2 or later. Could you please confirm if there is a patch to …

---

## [How to sum fieds of collapsed results?](https://discuss.elastic.co/t/how-to-sum-fieds-of-collapsed-results/323617)

<div class="topic-metadata">

**Author:** [@denise.castagna](https://discuss.elastic.co/u/denise.castagna)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 5:04pm UTC](https://discuss.elastic.co/t/how-to-sum-fieds-of-collapsed-results/323617 "2023-01-20T17:04:54Z")

</div>

Hi, I need to do a sum aggregation on a collapsed result. I know that collapse does not effect on aggregation but there are other ways? For example: Field1 = A, Field2 = 50, Order = 1 Field1 = A, Field2 = 30, Order =…

---

## [Calculations inside ES Query](https://discuss.elastic.co/t/calculations-inside-es-query/323610)

<div class="topic-metadata">

**Author:** [@bpax51](https://discuss.elastic.co/u/bpax51)\
**Replies:** 1\
**Last updated:** [January 20, 2023, 4:43pm UTC](https://discuss.elastic.co/t/calculations-inside-es-query/323610 "2023-01-20T16:43:07Z")

</div>

So I have to following query that gives me to count of successful and failed http queries using aggregations. { "size": 0, "query": { "bool": { "filter": \[ { …

---

## [Clean old indexes automatically in elasticsearch](https://discuss.elastic.co/t/clean-old-indexes-automatically-in-elasticsearch/323551)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 5\
**Last updated:** [January 20, 2023, 4:38pm UTC](https://discuss.elastic.co/t/clean-old-indexes-automatically-in-elasticsearch/323551 "2023-01-20T16:38:05Z")

</div>

Hello friends, I'm having problems with the storage where elasticsearch is installed... I'm constantly having a full disk. What can I do to delete or clean up old indexes?

---

## [Kibana - Metric Threshold Alert - {{context.group}}](https://discuss.elastic.co/t/kibana-metric-threshold-alert-context-group/323544)

<div class="topic-metadata">

**Author:** [@TXBigDawg1836](https://discuss.elastic.co/u/TXBigDawg1836)\
**Replies:** 1\
**Last updated:** [January 20, 2023, 3:50pm UTC](https://discuss.elastic.co/t/kibana-metric-threshold-alert-context-group/323544 "2023-01-20T15:50:54Z")

</div>

Have configured a Metric Threshold Alert using a field within the results called "Provider-City" in the Group Alerts By. In the message body we have a key/value pair "Provider-City": "{{context.group}}" which is worki…

---

## [Install Metricbeat on Kubernetes Cluster ( Azure)](https://discuss.elastic.co/t/install-metricbeat-on-kubernetes-cluster-azure/323328)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 5\
**Last updated:** [January 20, 2023, 3:30pm UTC](https://discuss.elastic.co/t/install-metricbeat-on-kubernetes-cluster-azure/323328 "2023-01-20T15:30:27Z")

</div>

Hi team, i am trying for several weeks to install metricbeat on kubernetes cluster (azure) and i following these instructions: Run Metricbeat on Kubernetes | Metricbeat Reference \[8.6\] | Elastic i edited the metricbea…

---

## [Elastic cluster is getting overloaded by incorrect shard allocation](https://discuss.elastic.co/t/elastic-cluster-is-getting-overloaded-by-incorrect-shard-allocation/323595)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 2\
**Last updated:** [January 20, 2023, 2:12pm UTC](https://discuss.elastic.co/t/elastic-cluster-is-getting-overloaded-by-incorrect-shard-allocation/323595 "2023-01-20T14:12:55Z")

</div>

Hi Community, May I ask for help: We have elastic v7.17.0 with 43 nodes. Sizing 2TB SSD, 8cores, 32GB RAM, 16GB Heap. Currently about 2400 indices and 6400shards. some nodes have less shards but have disk full which …

---

## [Using LDAP to set up Users and Roles in elasticsearch.yml file](https://discuss.elastic.co/t/using-ldap-to-set-up-users-and-roles-in-elasticsearch-yml-file/323440)

<div class="topic-metadata">

**Author:** [@sswilley88](https://discuss.elastic.co/u/sswilley88)\
**Replies:** 15\
**Last updated:** [January 20, 2023, 2:06pm UTC](https://discuss.elastic.co/t/using-ldap-to-set-up-users-and-roles-in-elasticsearch-yml-file/323440 "2023-01-20T14:06:44Z")

</div>

I am trying to set up user/role details in the elasticsearch.yaml file with LDAP settings, and need some support. I have followed elastic documentation, but it’s not working. I have added below details (with our own deta…

---

## [I am getting below error while setting elastic search](https://discuss.elastic.co/t/i-am-getting-below-error-while-setting-elastic-search/323019)

<div class="topic-metadata">

**Author:** [@devdev7711](https://discuss.elastic.co/u/devdev7711)\
**Replies:** 9\
**Last updated:** [January 20, 2023, 1:50pm UTC](https://discuss.elastic.co/t/i-am-getting-below-error-while-setting-elastic-search/323019 "2023-01-20T13:50:20Z")

</div>

I am installing 8.5.3 elastic. after yml file change I am double clicking elasticsearch.bat file and service is not starting looks like. \[2023-01-12T14:38:25,268\]\[INFO \]\[o.e.n.Node \] \[node-1\] node name \[…

---

## [Unable to authenticate user \[elastic\] for REST request](https://discuss.elastic.co/t/unable-to-authenticate-user-elastic-for-rest-request/323593)

<div class="topic-metadata">

**Author:** [@vidvar](https://discuss.elastic.co/u/vidvar)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 1:03pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-elastic-for-rest-request/323593 "2023-01-20T13:03:56Z")

</div>

Hello @warkolm Since few weeks, all of sudden, getting below while I am trying to curl to one of my elastic nodes. And latest data is not getting updated in Kibana dashboards. Elastic search version is 7.8.0. curl --u…

---

## [Can not create index pattern Uncaught TypeError: Cannot read properties of null](https://discuss.elastic.co/t/can-not-create-index-pattern-uncaught-typeerror-cannot-read-properties-of-null/323592)

<div class="topic-metadata">

**Author:** [@pi314](https://discuss.elastic.co/u/pi314)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 12:54pm UTC](https://discuss.elastic.co/t/can-not-create-index-pattern-uncaught-typeerror-cannot-read-properties-of-null/323592 "2023-01-20T12:54:41Z")

</div>

Hi everyone, i use Version: 6.3.2, when i try to create a new index pattern i see this error: Any ideas?

---

## [Read-Only User With Save Query Priviieges](https://discuss.elastic.co/t/read-only-user-with-save-query-priviieges/323591)

<div class="topic-metadata">

**Author:** [@bigverm23](https://discuss.elastic.co/u/bigverm23)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 12:53pm UTC](https://discuss.elastic.co/t/read-only-user-with-save-query-priviieges/323591 "2023-01-20T12:53:39Z")

</div>

I would like a read-only Dashboard user to be able to save a query, how can enable that? I cant seem to make it work but it's essential to our processes internally.

---

## [Could or Should?](https://discuss.elastic.co/t/could-or-should/322473)

<div class="topic-metadata">

**Author:** [@ChrizK](https://discuss.elastic.co/u/ChrizK)\
**Replies:** 3\
**Last updated:** [January 20, 2023, 12:19pm UTC](https://discuss.elastic.co/t/could-or-should/322473 "2023-01-20T12:19:14Z")

</div>

Sorry, the title is a bit tongue-in-cheek :unamused: I have a dashboard which shows test results. The tests are IP related and I use the IP address to identify if the destination address is a Proxy Server or NOT. (I h…

---

## [Privileged containers should be avoided](https://discuss.elastic.co/t/privileged-containers-should-be-avoided/323382)

<div class="topic-metadata">

**Author:** [@ddhote](https://discuss.elastic.co/u/ddhote)\
**Replies:** 2\
**Last updated:** [January 20, 2023, 11:52am UTC](https://discuss.elastic.co/t/privileged-containers-should-be-avoided/323382 "2023-01-20T11:52:44Z")

</div>

Hello Team, We have Elasticsearch containers in AKS where initial container has "Privileged= True" which is against our security policy. But, init container is failing with "Privileged=False", can someone please help ho…

---

## [TSVB aggregation impossible](https://discuss.elastic.co/t/tsvb-aggregation-impossible/323586)

<div class="topic-metadata">

**Author:** [@NickLudd](https://discuss.elastic.co/u/NickLudd)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 11:05am UTC](https://discuss.elastic.co/t/tsvb-aggregation-impossible/323586 "2023-01-20T11:05:03Z")

</div>

Hi all, I have created a TSVB visualization that represents thousands of operations(count aggregation & math aggregation grouped by filter) and a specific error(count aggregation filtered by query string), in a single c…

---

## [Alert recovery not triggering connector action](https://discuss.elastic.co/t/alert-recovery-not-triggering-connector-action/323584)

<div class="topic-metadata">

**Author:** [@RaJiska](https://discuss.elastic.co/u/RaJiska)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 11:01am UTC](https://discuss.elastic.co/t/alert-recovery-not-triggering-connector-action/323584 "2023-01-20T11:01:11Z")

</div>

Hi, I am trying to have Kibana send active and recovered alerts into an index, however only active alerts get sent there while recovered alert do not generate an entry inside the index. The following configuration is u…

---

## [Indexing Kibana visualization](https://discuss.elastic.co/t/indexing-kibana-visualization/323568)

<div class="topic-metadata">

**Author:** [@Chirag\_Gupta](https://discuss.elastic.co/u/Chirag_Gupta)\
**Replies:** 5\
**Last updated:** [January 20, 2023, 9:57am UTC](https://discuss.elastic.co/t/indexing-kibana-visualization/323568 "2023-01-20T09:57:21Z")

</div>

Is there any method through which we can directly create a bar-graph with supplied data in spring code in kibana. Without using any kibana interface.

---

## [Grey out "elastic-agent" in login items in Ventura](https://discuss.elastic.co/t/grey-out-elastic-agent-in-login-items-in-ventura/323578)

<div class="topic-metadata">

**Author:** [@jadi](https://discuss.elastic.co/u/jadi)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 9:49am UTC](https://discuss.elastic.co/t/grey-out-elastic-agent-in-login-items-in-ventura/323578 "2023-01-20T09:49:02Z")

</div>

Hey guys, Anyone managed to hide/grey out the "elastic-agent" that appears in login items in macOS Ventura? I created a service management profile with the bundleID "co.elastic.elastic-agent" but it's still doesn't wor…

---

## [Différence entre le Grok Debugger et le grok dans le filter](https://discuss.elastic.co/t/difference-entre-le-grok-debugger-et-le-grok-dans-le-filter/323507)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 3\
**Last updated:** [January 20, 2023, 9:30am UTC](https://discuss.elastic.co/t/difference-entre-le-grok-debugger-et-le-grok-dans-le-filter/323507 "2023-01-20T09:30:15Z")

</div>

Bonjour, Je ne trouve pas la bonne manière de faire remplacer ce @timestamp par celui qui se trouve dans mon message. Le principe est simple 1 log = 1 ligne, c'est au format JSON {"startTime":"2023-01-17 14:17:50.238"…

---

## [Reading APM and Uptime data in C#](https://discuss.elastic.co/t/reading-apm-and-uptime-data-in-c/323575)

<div class="topic-metadata">

**Author:** [@basavaraja\_c\_n](https://discuss.elastic.co/u/basavaraja_c_n)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 9:20am UTC](https://discuss.elastic.co/t/reading-apm-and-uptime-data-in-c/323575 "2023-01-20T09:20:15Z")

</div>

I want to read the uptime and APM services data in a C# Application, Not seeing any api's exposed or i am not getting how to read? Any clue??

---

## [Data loss without my consent](https://discuss.elastic.co/t/data-loss-without-my-consent/323319)

<div class="topic-metadata">

**Author:** [@smam](https://discuss.elastic.co/u/smam)\
**Replies:** 2\
**Last updated:** [January 20, 2023, 8:52am UTC](https://discuss.elastic.co/t/data-loss-without-my-consent/323319 "2023-01-20T08:52:41Z")

</div>

Hello, I have a logstash script that takes files as input and sends them to an according elasticsearch index. Said script is run at 1am every night as a scheduled task, which worked in the beginning.But now, every time …

---

## [About built in dashboard](https://discuss.elastic.co/t/about-built-in-dashboard/323512)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 3\
**Last updated:** [January 20, 2023, 8:28am UTC](https://discuss.elastic.co/t/about-built-in-dashboard/323512 "2023-01-20T08:28:48Z")

</div>

Hi team, I am using ELK 8.5.3 and I have multiple servers and I am using metricbeat system module to collect the metrics and the dashboards were doing good. But I want group my servers. Is it possible to group the monit…

---

## [Winlogbeat performance](https://discuss.elastic.co/t/winlogbeat-performance/323571)

<div class="topic-metadata">

**Author:** [@MarcoVu](https://discuss.elastic.co/u/MarcoVu)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 8:11am UTC](https://discuss.elastic.co/t/winlogbeat-performance/323571 "2023-01-20T08:11:05Z")

</div>

So i have some Windows Event collector servers which collects events from workstations, and decided to send all collected events to Elasticsearch with Winlogbeat (8.4.1 version), but regardless of any of settings that i …

---

## [Kibana is extremely slow](https://discuss.elastic.co/t/kibana-is-extremely-slow/323485)

<div class="topic-metadata">

**Author:** [@mammodde](https://discuss.elastic.co/u/mammodde)\
**Replies:** 6\
**Last updated:** [January 20, 2023, 8:00am UTC](https://discuss.elastic.co/t/kibana-is-extremely-slow/323485 "2023-01-20T08:00:48Z")

</div>

Hi everyone, I am trying to set up elk in my system but I am noticing that kibana is very very slow, from researches that I did, it could be that I have too many shards, but I really don't know how to deal with them. i…

---

## [Elastic index template and ilm policy configuracion reset by no reason](https://discuss.elastic.co/t/elastic-index-template-and-ilm-policy-configuracion-reset-by-no-reason/323566)

<div class="topic-metadata">

**Author:** [@Samuel\_Ruiz](https://discuss.elastic.co/u/Samuel_Ruiz)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 7:38am UTC](https://discuss.elastic.co/t/elastic-index-template-and-ilm-policy-configuracion-reset-by-no-reason/323566 "2023-01-20T07:38:41Z")

</div>

Hey. We have a docker cluster deploy of various nodes of elasticsearch (7.17.6) and a kibana node (7.17.6). In addition we have two Wazuh nodes, master-worker. This ELK-Wazuh implementation don't let us update the cluste…

---

## [Unable to use 2 fie log and 2 different index for them](https://discuss.elastic.co/t/unable-to-use-2-fie-log-and-2-different-index-for-them/323563)

<div class="topic-metadata">

**Author:** [@devdev7711](https://discuss.elastic.co/u/devdev7711)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 5:39am UTC](https://discuss.elastic.co/t/unable-to-use-2-fie-log-and-2-different-index-for-them/323563 "2023-01-20T05:39:21Z")

</div>

below is my filebeat it is working fine for 1 log location and 1 index but i want to use 2 file log location and 2 diifferent index 1 index for 1 log path. how can we do this filebeat.inputs: type: log enabled: true …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=658)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=660)
