# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=661

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 662

---

## [Packetbeat not working & showin only one interface](https://discuss.elastic.co/t/packetbeat-not-working-showin-only-one-interface/323510)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 12:31pm UTC](https://discuss.elastic.co/t/packetbeat-not-working-showin-only-one-interface/323510 "2023-01-19T12:31:25Z")

</div>

Hello, I am attempting to run Packetbeat (8.6.0) on Microsoft Windows 11 (professional 22H2 version, latest). I have Npcap as part of NMAP installation, which I refreshed today - specially ticking to enable the WinPcap…

---

## [Customise the field that a option list is applied to](https://discuss.elastic.co/t/customise-the-field-that-a-option-list-is-applied-to/322950)

<div class="topic-metadata">

**Author:** [@Jan\_De\_Smet](https://discuss.elastic.co/u/Jan_De_Smet)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 12:20pm UTC](https://discuss.elastic.co/t/customise-the-field-that-a-option-list-is-applied-to/322950 "2023-01-19T12:20:15Z")

</div>

Hi, I have a data set containing containing objects in the following format: { "id": 123, "displayName": "foo" } I would like to use this to populate an option list. It is important that the user only sees the dis…

---

## [Logstash from multiple beats server](https://discuss.elastic.co/t/logstash-from-multiple-beats-server/323491)

<div class="topic-metadata">

**Author:** [@hasan.idriss](https://discuss.elastic.co/u/hasan.idriss)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 12:08pm UTC](https://discuss.elastic.co/t/logstash-from-multiple-beats-server/323491 "2023-01-19T12:08:45Z")

</div>

hello every one, i am using logstash to receive data from multiple server using winlogbeats over the port 5044 I want to create an index for each server based on the server name can some one provide me with the logsta…

---

## [Dev Tools Console can't retrieve data - Error Bad Gateway 502](https://discuss.elastic.co/t/dev-tools-console-cant-retrieve-data-error-bad-gateway-502/323500)

<div class="topic-metadata">

**Author:** [@Kamil\_BdBelfort](https://discuss.elastic.co/u/Kamil_BdBelfort)\
**Replies:** 3\
**Last updated:** [January 19, 2023, 11:51am UTC](https://discuss.elastic.co/t/dev-tools-console-cant-retrieve-data-error-bad-gateway-502/323500 "2023-01-19T11:51:09Z")

</div>

Hi there, Can anyone explain me please why do I get this error when I am running elasticsearch on localhost? See screenshot: Thanks a lot, Kamil

---

## [elasticsearch.AuthorizationException: AuthorizationException(403, 'security\_exception', 'action \[cluster:monitor/main\] is unauthorized for user\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*this action is grante d by the cluster privileges \[monitor,manage,all\]')](https://discuss.elastic.co/t/elasticsearch-authorizationexception-authorizationexception-403-security-exception-action-cluster-monitor-main-is-unauthorized-for-user-this-action-is-grante-d-by-the-cluster-privileges-monitor-manage-all/323499)

<div class="topic-metadata">

**Author:** [@savitaSUtar](https://discuss.elastic.co/u/savitaSUtar)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 11:42am UTC](https://discuss.elastic.co/t/elasticsearch-authorizationexception-authorizationexception-403-security-exception-action-cluster-monitor-main-is-unauthorized-for-user-this-action-is-grante-d-by-the-cluster-privileges-monitor-manage-all/323499 "2023-01-19T11:42:54Z")

</div>

I am writting a Elastic search connection code from python like : es = Elasticsearch("url", basic\_auth=("Username", "password")) print(es.info()) but getting error as : elasticsearch.AuthorizationException: Authorizat…

---

## [How to visualize max aggregation inside terms aggregation in Kibana?](https://discuss.elastic.co/t/how-to-visualize-max-aggregation-inside-terms-aggregation-in-kibana/323406)

<div class="topic-metadata">

**Author:** [@cr\_168328](https://discuss.elastic.co/u/cr_168328)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 11:25am UTC](https://discuss.elastic.co/t/how-to-visualize-max-aggregation-inside-terms-aggregation-in-kibana/323406 "2023-01-19T11:25:57Z")

</div>

I have an index exams which contains data related to students who passed some exams. A student can attempt an exam multiple times. Hence there may be more than one document in the index for a particular student and exam…

---

## [No such file kbn\_canvas.js](https://discuss.elastic.co/t/no-such-file-kbn-canvas-js/323455)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 11:25am UTC](https://discuss.elastic.co/t/no-such-file-kbn-canvas-js/323455 "2023-01-19T11:25:50Z")

</div>

I clicked on the link Download runtime as shown in this image: This brought me to a page: When I look in my /var/log/kibana/kibana.log, I see this error: "ENOENT: no such file or directory, open '/usr/share/kiban…

---

## [org.elasticsearch.action.UnavailableShardsException: \[ . async—searchl \[01 primary shard is not active Timeout: \[1m](https://discuss.elastic.co/t/org-elasticsearch-action-unavailableshardsexception-async-searchl-01-primary-shard-is-not-active-timeout-1m/323466)

<div class="topic-metadata">

**Author:** [@forabraham1](https://discuss.elastic.co/u/forabraham1)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 11:17am UTC](https://discuss.elastic.co/t/org-elasticsearch-action-unavailableshardsexception-async-searchl-01-primary-shard-is-not-active-timeout-1m/323466 "2023-01-19T11:17:19Z")

</div>

After upgrading ES from 7.9 to 7.17 ES is throwing this exception "org.elasticsearch.action.UnavailableShardsException: \[ . async—searchl \[01 primary shard is not active Timeout: \[1m". Due to which Kibana isn't returnin…

---

## [Error occurrences per 1000 requests - Multiple queries on a single graph](https://discuss.elastic.co/t/error-occurrences-per-1000-requests-multiple-queries-on-a-single-graph/323421)

<div class="topic-metadata">

**Author:** [@Nefeli\_Tavoulari](https://discuss.elastic.co/u/Nefeli_Tavoulari)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 11:05am UTC](https://discuss.elastic.co/t/error-occurrences-per-1000-requests-multiple-queries-on-a-single-graph/323421 "2023-01-19T11:05:20Z")

</div>

Is it possible displaying the frequency of a specific error per 1000 operations on a visualization on Kibana, without Kibana Lens? Using filters I can get the count of errors and the count of operations and display them …

---

## [TreeMap Vega trouble create nested date for index](https://discuss.elastic.co/t/treemap-vega-trouble-create-nested-date-for-index/323490)

<div class="topic-metadata">

**Author:** [@EugenHo](https://discuss.elastic.co/u/EugenHo)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 8:58am UTC](https://discuss.elastic.co/t/treemap-vega-trouble-create-nested-date-for-index/323490 "2023-01-19T08:58:37Z")

</div>

HI all, we have som trouble to transform data for a Treemap in vega visualization. I create data from Elastic like { "\_index": "eu-metricbeat-2023.01.18-000021", "\_type": "\_doc", "\_id": "H6YsyYUBmEzuaZBQ…

---

## [Would turning off swap require extra configuration](https://discuss.elastic.co/t/would-turning-off-swap-require-extra-configuration/323342)

<div class="topic-metadata">

**Author:** [@hasancansaral](https://discuss.elastic.co/u/hasancansaral)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 10:46am UTC](https://discuss.elastic.co/t/would-turning-off-swap-require-extra-configuration/323342 "2023-01-19T10:46:43Z")

</div>

I have a 3 node cluster, all master eligible and all having 4 cores, 16gb memory. I have 2 read/write indexes with none of them above 1 GB/1 million documents. Each index is 1 primary shard and 2 replicas. I've recently…

---

## [No data is generated Observability](https://discuss.elastic.co/t/no-data-is-generated-observability/323288)

<div class="topic-metadata">

**Author:** [@den2](https://discuss.elastic.co/u/den2)\
**Replies:** 6\
**Last updated:** [January 19, 2023, 10:24am UTC](https://discuss.elastic.co/t/no-data-is-generated-observability/323288 "2023-01-19T10:24:23Z")

</div>

Hello! I can’t create data, it constantly throws me to the start page, I need help

---

## [Failed to save to index due to maximum shard overlimit](https://discuss.elastic.co/t/failed-to-save-to-index-due-to-maximum-shard-overlimit/323424)

<div class="topic-metadata">

**Author:** [@aagirre92](https://discuss.elastic.co/u/aagirre92)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 10:13am UTC](https://discuss.elastic.co/t/failed-to-save-to-index-due-to-maximum-shard-overlimit/323424 "2023-01-19T10:13:29Z")

</div>

Hello, I am running a web application (in my own windows server machine) called Automation Anywhere A360. This web application uses a local Elasticsearch instance to handle its Audit Logs. Cluster health endpoint shows…

---

## [Custom log integration with Text & json file](https://discuss.elastic.co/t/custom-log-integration-with-text-json-file/323492)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 9:39am UTC](https://discuss.elastic.co/t/custom-log-integration-with-text-json-file/323492 "2023-01-19T09:39:51Z")

</div>

Hi, We have text files which are getting created on Windows VM's and Linux VM's in certain location. Here is the sample text file which is getting created. So, we i would like to get the log and parse into different fie…

---

## [Unassigned Shards when New Index was created: Cluster Yellow](https://discuss.elastic.co/t/unassigned-shards-when-new-index-was-created-cluster-yellow/323483)

<div class="topic-metadata">

**Author:** [@rpraveenverma](https://discuss.elastic.co/u/rpraveenverma)\
**Replies:** 3\
**Last updated:** [January 19, 2023, 9:32am UTC](https://discuss.elastic.co/t/unassigned-shards-when-new-index-was-created-cluster-yellow/323483 "2023-01-19T09:32:54Z")

</div>

New Index Creation led to Unassigned Shards and Yellow Cluster State. Context : It happened when relocation for one node was already in progress. Checked explanation for its state. It says : Relocation Throttled , rea…

---

## [Migrate to datastreams withou aliases + datastreams filter](https://discuss.elastic.co/t/migrate-to-datastreams-withou-aliases-datastreams-filter/323401)

<div class="topic-metadata">

**Author:** [@bilak](https://discuss.elastic.co/u/bilak)\
**Replies:** 3\
**Last updated:** [January 19, 2023, 9:28am UTC](https://discuss.elastic.co/t/migrate-to-datastreams-withou-aliases-datastreams-filter/323401 "2023-01-19T09:28:49Z")

</div>

Hello, I'd like to use data streams and migrate our indices to it. However currently we don't use aliases. Do I have to create an alias for given indices pattern (technical-logs\*) at first and only after that I'm able t…

---

## [Kibana bar chart legend set constant color](https://discuss.elastic.co/t/kibana-bar-chart-legend-set-constant-color/322288)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 7\
**Last updated:** [January 19, 2023, 8:34am UTC](https://discuss.elastic.co/t/kibana-bar-chart-legend-set-constant-color/322288 "2023-01-19T08:34:13Z")

</div>

Hello, I've a simple requirement where in I need to set constant color for bar and legends. ex: Error:Always red, Success:Always greeen,Initialize:Always yellow...etc The current behaviour of kibana dosen't fullfill …

---

## [Using premade dashboard with Logstash](https://discuss.elastic.co/t/using-premade-dashboard-with-logstash/323315)

<div class="topic-metadata">

**Author:** [@TonisSaarjoe](https://discuss.elastic.co/u/TonisSaarjoe)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 7:48am UTC](https://discuss.elastic.co/t/using-premade-dashboard-with-logstash/323315 "2023-01-19T07:48:23Z")

</div>

Hello there, Some what new to ELK. So I have 3 different machines Monitoring, Logstash and Beats Monitoring - hosts Kibana and Elasticsearch. secure machine allows only Logstash Logstash - hosts only Logstash. Beats…

---

## [I can't connect my Logstash to ES Stack Monitoring please help](https://discuss.elastic.co/t/i-cant-connect-my-logstash-to-es-stack-monitoring-please-help/323465)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 6\
**Last updated:** [January 19, 2023, 7:43am UTC](https://discuss.elastic.co/t/i-cant-connect-my-logstash-to-es-stack-monitoring-please-help/323465 "2023-01-19T07:43:22Z")

</div>

I check the status of metricbeat, it says node\_stats/node\_stats.go:73 json: cannot unmarshal object into Go struct field .version of type string and could not fetch node pipelines: HTTP error 405 in : 405 Method…

---

## [Scaling of cardinality sub-aggregation](https://discuss.elastic.co/t/scaling-of-cardinality-sub-aggregation/320264)

<div class="topic-metadata">

**Author:** [@astrodi](https://discuss.elastic.co/u/astrodi)\
**Replies:** 16\
**Last updated:** [January 19, 2023, 7:20am UTC](https://discuss.elastic.co/t/scaling-of-cardinality-sub-aggregation/320264 "2023-01-19T07:20:55Z")

</div>

Hello there, as continuation of this discussion thread, what other options are there in Elasticsearch to scale aggregation? I have experimented with: adding client nodes (didn't help for big result-set) playing wit…

---

## [Logstash stops elasticsearch](https://discuss.elastic.co/t/logstash-stops-elasticsearch/323017)

<div class="topic-metadata">

**Author:** [@bas\_kos](https://discuss.elastic.co/u/bas_kos)\
**Replies:** 27\
**Last updated:** [January 19, 2023, 7:17am UTC](https://discuss.elastic.co/t/logstash-stops-elasticsearch/323017 "2023-01-19T07:17:45Z")

</div>

After starting logstash, elasticsearch stops. If logstash is not running, then elasticsearch and kibana work and I go to the kibana web interface. I tried to cleanly remove logstash and install with default settings, I…

---

## [Logstash JSON parser error](https://discuss.elastic.co/t/logstash-json-parser-error/323356)

<div class="topic-metadata">

**Author:** [@Ramesh\_Perumal](https://discuss.elastic.co/u/Ramesh_Perumal)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 7:01am UTC](https://discuss.elastic.co/t/logstash-json-parser-error/323356 "2023-01-19T07:01:29Z")

</div>

Hi, We are getting json parser warning message as below: \[2023-01-08T13:21:12,936\]\[WARN \]\[logstash.filters.json \] Error parsing json {:source=\>"slmPart", :raw=\>"{"action":UPDATE,"information":"Signing CSR for root …

---

## [Why are 3 zones less expensive than 2 zones?](https://discuss.elastic.co/t/why-are-3-zones-less-expensive-than-2-zones/323453)

<div class="topic-metadata">

**Author:** [@michielswaanen](https://discuss.elastic.co/u/michielswaanen)\
**Replies:** 3\
**Last updated:** [January 19, 2023, 6:53am UTC](https://discuss.elastic.co/t/why-are-3-zones-less-expensive-than-2-zones/323453 "2023-01-19T06:53:11Z")

</div>

Why is tiebreaker only needed in a 2 zone setup? Pricing for 2 zones: Pricing for 3 zones:

---

## [Data flows through nodes](https://discuss.elastic.co/t/data-flows-through-nodes/323078)

<div class="topic-metadata">

**Author:** [@yinbucheng](https://discuss.elastic.co/u/yinbucheng)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 6:19am UTC](https://discuss.elastic.co/t/data-flows-through-nodes/323078 "2023-01-19T06:19:14Z")

</div>

The elastic cluster node I built has a separate data role master role coordinate role ingest role. I also configured the ingest pipeline, which nodes I will pass through when I insert data. The exposed cluster link is …

---

## [Elastic search and kibana configuration](https://discuss.elastic.co/t/elastic-search-and-kibana-configuration/323091)

<div class="topic-metadata">

**Author:** [@keerthana7](https://discuss.elastic.co/u/keerthana7)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 5:58am UTC](https://discuss.elastic.co/t/elastic-search-and-kibana-configuration/323091 "2023-01-19T05:58:48Z")

</div>

I couldn't configure elastic. Can anyone tell me what is the problem here and how to solve it?

---

## [Is there a limit on the number of ILM Policies that can be created in a Cluster?](https://discuss.elastic.co/t/is-there-a-limit-on-the-number-of-ilm-policies-that-can-be-created-in-a-cluster/323398)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 5:40am UTC](https://discuss.elastic.co/t/is-there-a-limit-on-the-number-of-ilm-policies-that-can-be-created-in-a-cluster/323398 "2023-01-19T05:40:57Z")

</div>

I have a situation where I need to create 120 indices , wherein each index has the data for a particular month. The data is stored for past 10 years (12 month\*10 year = 120 indices). Each index hold 1 month Data. I ha…

---

## [Copy users and roles created in kibana to new cluster](https://discuss.elastic.co/t/copy-users-and-roles-created-in-kibana-to-new-cluster/323392)

<div class="topic-metadata">

**Author:** [@dadiasish](https://discuss.elastic.co/u/dadiasish)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 5:34am UTC](https://discuss.elastic.co/t/copy-users-and-roles-created-in-kibana-to-new-cluster/323392 "2023-01-19T05:34:43Z")

</div>

Hi, I've multiple users which are created to access Kibana in my current cluster. Now, we have planned to have a new cluster and I would like to have all these existing users copied from my previous cluster to the new …

---

## [Bulk indexing of signals failed: no such index \[.alerts-security.alerts-default\] and \[require\_alias\] request flag is \[true\]](https://discuss.elastic.co/t/bulk-indexing-of-signals-failed-no-such-index-alerts-security-alerts-default-and-require-alias-request-flag-is-true/323437)

<div class="topic-metadata">

**Author:** [@raghiboon](https://discuss.elastic.co/u/raghiboon)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 4:48am UTC](https://discuss.elastic.co/t/bulk-indexing-of-signals-failed-no-such-index-alerts-security-alerts-default-and-require-alias-request-flag-is-true/323437 "2023-01-19T04:48:35Z")

</div>

Hi everybody. i just removed .alerts-security.alerts-default-0000 suddenly after i was working with rules and made my dashboards. is there a way to recreate it? because it gives me this error: Bulk indexing of signals…

---

## [How to build QueryBuilder to search for the map of entry's in ElasticSearch index](https://discuss.elastic.co/t/how-to-build-querybuilder-to-search-for-the-map-of-entrys-in-elasticsearch-index/323469)

<div class="topic-metadata">

**Author:** [@SandhyaRani](https://discuss.elastic.co/u/SandhyaRani)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 4:40am UTC](https://discuss.elastic.co/t/how-to-build-querybuilder-to-search-for-the-map-of-entrys-in-elasticsearch-index/323469 "2023-01-19T04:40:10Z")

</div>

I would need queryBuilder to search the index with entire map of values and return documents only if all map values matched in ES index. I could do for set of values like below val sampleSet = setOf("foo", "bar") val …

---

## [Problem with element BY.ID for autologin to kibana using python selenium webdriver](https://discuss.elastic.co/t/problem-with-element-by-id-for-autologin-to-kibana-using-python-selenium-webdriver/322355)

<div class="topic-metadata">

**Author:** [@Reka\_Novana](https://discuss.elastic.co/u/Reka_Novana)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 3:43am UTC](https://discuss.elastic.co/t/problem-with-element-by-id-for-autologin-to-kibana-using-python-selenium-webdriver/322355 "2023-01-19T03:43:14Z")

</div>

I want to make an auto screenshot script using selenium python but I can't find element id of the username and password that I found is only random element id for username and password. Could you please inform me if I ca…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=660)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=662)
