# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=663

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 664

---

## [Elasticsearch service keep restarting time to time](https://discuss.elastic.co/t/elasticsearch-service-keep-restarting-time-to-time/323387)

<div class="topic-metadata">

**Author:** [@Gihan\_Indrajith](https://discuss.elastic.co/u/Gihan_Indrajith)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 8:28am UTC](https://discuss.elastic.co/t/elasticsearch-service-keep-restarting-time-to-time/323387 "2023-01-18T08:28:46Z")

</div>

Observed that elasticsearch service keep restarting time to time. Node has 16GB memory and allocated 8GB for the heap. Elasticsearch version - 7.13 Below is the log. This is one of the nodes from 5 node cluster. \[2023…

---

## [Logstash Pipeline terminate after one output plugin error](https://discuss.elastic.co/t/logstash-pipeline-terminate-after-one-output-plugin-error/323386)

<div class="topic-metadata">

**Author:** [@Bert\_Van\_der\_Heyden](https://discuss.elastic.co/u/Bert_Van_der_Heyden)\
**Replies:** 0\
**Last updated:** [January 18, 2023, 7:59am UTC](https://discuss.elastic.co/t/logstash-pipeline-terminate-after-one-output-plugin-error/323386 "2023-01-18T07:59:16Z")

</div>

Context: Logstash 8.6.0 \[2023-01-18T08:07:30,522\]\[ERROR\]\[logstash.javapipeline \]\[test\_pipeline\] Pipeline worker error, the pipeline will be stopped {:pipeline\_id=\>"test\_pipeline", :error=\>"(IOError) An established co…

---

## [Error regarding updation of dashboard through python using elasticsearch-dsl library](https://discuss.elastic.co/t/error-regarding-updation-of-dashboard-through-python-using-elasticsearch-dsl-library/323383)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 0\
**Last updated:** [January 18, 2023, 7:13am UTC](https://discuss.elastic.co/t/error-regarding-updation-of-dashboard-through-python-using-elasticsearch-dsl-library/323383 "2023-01-18T07:13:32Z")

</div>

This is the error that I am getting while I am trying to update my Kibana dashboard using the elasticsearchdsl library for python: b'{"statusCode":404,"error":"Not Found","message":"Saved object \[visualization/166353692…

---

## [Unable to convert date to specified timezone](https://discuss.elastic.co/t/unable-to-convert-date-to-specified-timezone/322398)

<div class="topic-metadata">

**Author:** [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Replies:** 10\
**Last updated:** [January 18, 2023, 6:46am UTC](https://discuss.elastic.co/t/unable-to-convert-date-to-specified-timezone/322398 "2023-01-18T06:46:18Z")

</div>

Hi All, I am trying to convert the date UTC time to different timezone (Asia/Tokyo) in logstash and below is the configuration I have tried, input { stdin { id =\> "logstash-rae" add\_field =\> { "log\_or…

---

## [Indices generated lately than real time several hours](https://discuss.elastic.co/t/indices-generated-lately-than-real-time-several-hours/323206)

<div class="topic-metadata">

**Author:** [@Anh\_Nguyen](https://discuss.elastic.co/u/Anh_Nguyen)\
**Replies:** 12\
**Last updated:** [January 18, 2023, 6:44am UTC](https://discuss.elastic.co/t/indices-generated-lately-than-real-time-several-hours/323206 "2023-01-18T06:44:25Z")

</div>

I got some problems with Datastream's Indices Generating. In detail, the indices are generated more lately than real time 1 day or a few hours. I want to have an index for the right date of the generated index but i coul…

---

## [Metricbeat' logstash module is NOT working properly (no errors)](https://discuss.elastic.co/t/metricbeat-logstash-module-is-not-working-properly-no-errors/322763)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 2\
**Last updated:** [January 14, 2023, 3:33pm UTC](https://discuss.elastic.co/t/metricbeat-logstash-module-is-not-working-properly-no-errors/322763 "2023-01-14T15:33:15Z")

</div>

Hello World! I'm running same setup: metricbeat.yml and modules.d/logstash-xpack.yml, yet one of the instance everything works fine, yet in another (almost identical) instance it is not working at all: NOT properly wor…

---

## [Which version of Elasticsearch can be migrated to Open search 1.3.6](https://discuss.elastic.co/t/which-version-of-elasticsearch-can-be-migrated-to-open-search-1-3-6/323374)

<div class="topic-metadata">

**Author:** [@sameer\_khamkar](https://discuss.elastic.co/u/sameer_khamkar)\
**Replies:** 2\
**Last updated:** [January 18, 2023, 5:38am UTC](https://discuss.elastic.co/t/which-version-of-elasticsearch-can-be-migrated-to-open-search-1-3-6/323374 "2023-01-18T05:38:00Z")

</div>

Hello Team, I wanted to know which version of Elasticsearch can be migrated to Open search 1.3.6, we are using Graylog with Elasticsearch 7.16 and we wanted to move to OS from ES. from Graylog it says that anything bey…

---

## [Got response code '403' contacting Elasticsearch at URL](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url/323368)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 4\
**Last updated:** [January 18, 2023, 2:27am UTC](https://discuss.elastic.co/t/got-response-code-403-contacting-elasticsearch-at-url/323368 "2023-01-18T02:27:40Z")

</div>

Hello World! I'm trying to follow Configuring Security in Logstash | Logstash Reference \[7.17\] | Elastic, specifically these: Configuring Logstash to use Basic Authentication Granting Users Access to the Logstash Indi…

---

## [Has anyone made a "serverless" elasticsearch?](https://discuss.elastic.co/t/has-anyone-made-a-serverless-elasticsearch/168468)

<div class="topic-metadata">

**Author:** [@hacker\_21](https://discuss.elastic.co/u/hacker_21)\
**Replies:** 4\
**Last updated:** [January 18, 2023, 2:08am UTC](https://discuss.elastic.co/t/has-anyone-made-a-serverless-elasticsearch/168468 "2023-01-18T02:08:00Z")

</div>

hello, I'm a big fan of ES and have been using it for years now. Just wondering if anyone has made an attempt to make a serverless approach to ES? Let me expand on what I mean: I personally use Elasticsearch for a pr…

---

## [Elasticsearch kubernetes deployment](https://discuss.elastic.co/t/elasticsearch-kubernetes-deployment/323308)

<div class="topic-metadata">

**Author:** [@Ayyappan](https://discuss.elastic.co/u/Ayyappan)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 1:36am UTC](https://discuss.elastic.co/t/elasticsearch-kubernetes-deployment/323308 "2023-01-18T01:36:09Z")

</div>

is it possible to restore the data from the cache once its cleared/overwritten?

---

## [Elastic Search Docker upgrade to latest](https://discuss.elastic.co/t/elastic-search-docker-upgrade-to-latest/323341)

<div class="topic-metadata">

**Author:** [@gjahagir](https://discuss.elastic.co/u/gjahagir)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 1:31am UTC](https://discuss.elastic.co/t/elastic-search-docker-upgrade-to-latest/323341 "2023-01-18T01:31:46Z")

</div>

Hi, I'm new to Elasticsearch as well as docker. I spinned up a 3 node elastic cluster following the documentation here I used stack version as 8.0.1 to test the upgrade process. I followed the documentation on upgrade…

---

## [Broken documentation links in Metricbeat modules.d yml files](https://discuss.elastic.co/t/broken-documentation-links-in-metricbeat-modules-d-yml-files/323347)

<div class="topic-metadata">

**Author:** [@AndyPC](https://discuss.elastic.co/u/AndyPC)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 1:27am UTC](https://discuss.elastic.co/t/broken-documentation-links-in-metricbeat-modules-d-yml-files/323347 "2023-01-18T01:27:27Z")

</div>

Posting here per instructions to do so before filing a bug on github: All of the modules yml files in metricbeat/modules.d (version 8.6.0) have broken documentation links in the top-of file comment. The links in the do…

---

## [On-premises fleet server install: es bad\_certificate](https://discuss.elastic.co/t/on-premises-fleet-server-install-es-bad-certificate/323090)

<div class="topic-metadata">

**Author:** [@dms6978](https://discuss.elastic.co/u/dms6978)\
**Replies:** 2\
**Last updated:** [January 18, 2023, 12:27am UTC](https://discuss.elastic.co/t/on-premises-fleet-server-install-es-bad-certificate/323090 "2023-01-18T00:27:29Z")

</div>

I am installing the Fleet server in the on-premises environment. It's all connected, so fleet server is completed with healthy. Then, Elasticsearch is sending an warning called bad\_certificate. Is it because I sent ht…

---

## [The button 'Copy cluster ID' for Kibana is no longer visible](https://discuss.elastic.co/t/the-button-copy-cluster-id-for-kibana-is-no-longer-visible/322982)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 2\
**Last updated:** [January 18, 2023, 12:05am UTC](https://discuss.elastic.co/t/the-button-copy-cluster-id-for-kibana-is-no-longer-visible/322982 "2023-01-18T00:05:59Z")

</div>

I used to copy the Kibana Cluster ID from Elastic Cloud Console, but the button has disappeared! before after

---

## [Logstash with ILM configuration](https://discuss.elastic.co/t/logstash-with-ilm-configuration/323363)

<div class="topic-metadata">

**Author:** [@Erates](https://discuss.elastic.co/u/Erates)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 9:39pm UTC](https://discuss.elastic.co/t/logstash-with-ilm-configuration/323363 "2023-01-17T21:39:27Z")

</div>

Hi, we have an ELK stack running (I have no say in which version, which is currently 7.x) to get the logs of our applications running in a Kubernetes cluster all combined in 1 place. The applications are pushing their lo…

---

## [Error: disk usage exceeded flood-stage watermark, index has read-only-allow-delete block](https://discuss.elastic.co/t/error-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/323357)

<div class="topic-metadata">

**Author:** [@pmono](https://discuss.elastic.co/u/pmono)\
**Replies:** 5\
**Last updated:** [January 17, 2023, 9:14pm UTC](https://discuss.elastic.co/t/error-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/323357 "2023-01-17T21:14:59Z")

</div>

Hello, I'm getting a weird error: \[2023-01-17T18:18:32.398997+00:00\] main.ERROR: Child process failed with message: Elasticsearch engine returned an error response. item id: 20. Error type: "cluster\_block\_exception", r…

---

## [More master node?](https://discuss.elastic.co/t/more-master-node/323348)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 6\
**Last updated:** [January 17, 2023, 8:02pm UTC](https://discuss.elastic.co/t/more-master-node/323348 "2023-01-17T20:02:54Z")

</div>

Hello everyone, I explain my context. I am designing an architecture with 18 nodes where everyone can be master (of the 18 nodes, only 1 master remains) if necessary, but I feel that 1 for 17 is too little and I want to…

---

## [Log incoming connection IP?](https://discuss.elastic.co/t/log-incoming-connection-ip/323359)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 2\
**Last updated:** [January 17, 2023, 7:55pm UTC](https://discuss.elastic.co/t/log-incoming-connection-ip/323359 "2023-01-17T19:55:17Z")

</div>

Maybe this has been answered before. But I can't seem to find it. Does anybody know how to enable logging in ES to show the IP address an API is invoked from? Things like when an index is created, I see the log with t…

---

## [Cant collapse/fold lengthy fields in Kibana Console](https://discuss.elastic.co/t/cant-collapse-fold-lengthy-fields-in-kibana-console/322229)

<div class="topic-metadata">

**Author:** [@nickchomey](https://discuss.elastic.co/u/nickchomey)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 5:59pm UTC](https://discuss.elastic.co/t/cant-collapse-fold-lengthy-fields-in-kibana-console/322229 "2023-01-17T17:59:49Z")

</div>

I am storing some lengthy HTML strings in a binary field (don't need to search it with text and keyword has a 32766 character limit). When I click in Kibana to collapse/fold the field, the button turns red and doesn't do…

---

## [Elasticsearch Java API client 8.5, does generate the correct format for source ordering for composition aggregation](https://discuss.elastic.co/t/elasticsearch-java-api-client-8-5-does-generate-the-correct-format-for-source-ordering-for-composition-aggregation/323352)

<div class="topic-metadata">

**Author:** [@snguyen](https://discuss.elastic.co/u/snguyen)\
**Replies:** 0\
**Last updated:** [January 17, 2023, 4:55pm UTC](https://discuss.elastic.co/t/elasticsearch-java-api-client-8-5-does-generate-the-correct-format-for-source-ordering-for-composition-aggregation/323352 "2023-01-17T16:55:22Z")

</div>

Hi, I am using Elasticsearch Java API client 8.5. I need to be able to specified the order for the sources such as for date histogram aggregation as the source. However the issue is that it generates array as the value …

---

## [GROK pattern issue](https://discuss.elastic.co/t/grok-pattern-issue/323330)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 4\
**Last updated:** [January 17, 2023, 4:00pm UTC](https://discuss.elastic.co/t/grok-pattern-issue/323330 "2023-01-17T16:00:54Z")

</div>

Hello, I am using filebeat to send logs from a DNS server to logstash before being ingested in Elasticsearch. The same pattern is repeated with two spaces and one space due to the variation in logs over updates which is…

---

## [Eland, when querying an index it will store the whole index in a dataframe?](https://discuss.elastic.co/t/eland-when-querying-an-index-it-will-store-the-whole-index-in-a-dataframe/323340)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [January 17, 2023, 3:33pm UTC](https://discuss.elastic.co/t/eland-when-querying-an-index-it-will-store-the-whole-index-in-a-dataframe/323340 "2023-01-17T15:33:45Z")

</div>

Using Eland, When querying an index it will store the whole index in a dataframe? or only the elasticsearch limit 10000 documents? these dataframes are stored in the memory of the server? Any strategy you recomend when…

---

## [KQL syntax with python](https://discuss.elastic.co/t/kql-syntax-with-python/323218)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 2:33pm UTC](https://discuss.elastic.co/t/kql-syntax-with-python/323218 "2023-01-17T14:33:13Z")

</div>

I have this idea of using KQL syntax through python or javascript. I have a dashboard named "main" and in that, we have a field called "topic". So, on the dashboard page when I use the KQL syntax and type in the search b…

---

## [How to add specific windows services, applications, webservers for monitoring purpose](https://discuss.elastic.co/t/how-to-add-specific-windows-services-applications-webservers-for-monitoring-purpose/322094)

<div class="topic-metadata">

**Author:** [@rakeshsid01](https://discuss.elastic.co/u/rakeshsid01)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 2:25pm UTC](https://discuss.elastic.co/t/how-to-add-specific-windows-services-applications-webservers-for-monitoring-purpose/322094 "2023-01-17T14:25:41Z")

</div>

We have added windows servers or agents in fleet for monitoring checking alerts. We want to add specific services . And we want to alert when it is down how can we achieve this.

---

## [Status of elastic agent dont change updating to Healthy](https://discuss.elastic.co/t/status-of-elastic-agent-dont-change-updating-to-healthy/322706)

<div class="topic-metadata">

**Author:** [@qwerasdf](https://discuss.elastic.co/u/qwerasdf)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 2:19pm UTC](https://discuss.elastic.co/t/status-of-elastic-agent-dont-change-updating-to-healthy/322706 "2023-01-17T14:19:07Z")

</div>

I define elastic agent policy with logstash output but when i install agent on assets, status of agents remains on updating but when output set to elasticsearch I dont have any problem and status is Healthy? Please Help…

---

## [Can I create timeline chart in Kibana?](https://discuss.elastic.co/t/can-i-create-timeline-chart-in-kibana/323301)

<div class="topic-metadata">

**Author:** [@Kamil\_BdBelfort](https://discuss.elastic.co/u/Kamil_BdBelfort)\
**Replies:** 3\
**Last updated:** [January 17, 2023, 1:59pm UTC](https://discuss.elastic.co/t/can-i-create-timeline-chart-in-kibana/323301 "2023-01-17T13:59:04Z")

</div>

Hi all, I would like to create a timeline chart. I have projects that have start-date and end-date values that I would like to visualize. I've been struggling to find a solution for a while now. My data looks like th…

---

## [Kibana Saved Search autosize on a Dashboard](https://discuss.elastic.co/t/kibana-saved-search-autosize-on-a-dashboard/323266)

<div class="topic-metadata">

**Author:** [@andreatera](https://discuss.elastic.co/u/andreatera)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 1:58pm UTC](https://discuss.elastic.co/t/kibana-saved-search-autosize-on-a-dashboard/323266 "2023-01-17T13:58:34Z")

</div>

Hello all, we're using Kibana 7.17.3 with a simple Dashboard having inside a Saved Search. This search frame have not the possibility to autosize its height when you resize the Window of your client browser. Is there …

---

## [Auditbeat data not being indexed](https://discuss.elastic.co/t/auditbeat-data-not-being-indexed/323294)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 2\
**Last updated:** [January 17, 2023, 1:34pm UTC](https://discuss.elastic.co/t/auditbeat-data-not-being-indexed/323294 "2023-01-17T13:34:12Z")

</div>

Hello, I can ingest the logs if I set up the output.destination to Elasticsearch but when routing the logs via Logstash I am unable to receive/view them at Elasticsearch (through Kibana) THe following the setup with Lo…

---

## [SMB traffic spike](https://discuss.elastic.co/t/smb-traffic-spike/323318)

<div class="topic-metadata">

**Author:** [@Elnur\_Abbasov](https://discuss.elastic.co/u/Elnur_Abbasov)\
**Replies:** 1\
**Last updated:** [January 17, 2023, 1:22pm UTC](https://discuss.elastic.co/t/smb-traffic-spike/323318 "2023-01-17T13:22:26Z")

</div>

Hi, we have Palo Alto logs in our elasticsearch database. I need to do anomaly detection based on SMB traffic. How can I do that ? My first attempt was to set destination.port to 445 or 139, but couldn't find a way to sp…

---

## [Heap usage in versions 6 and 7](https://discuss.elastic.co/t/heap-usage-in-versions-6-and-7/322127)

<div class="topic-metadata">

**Author:** [@casterQ](https://discuss.elastic.co/u/casterQ)\
**Replies:** 5\
**Last updated:** [January 17, 2023, 12:53pm UTC](https://discuss.elastic.co/t/heap-usage-in-versions-6-and-7/322127 "2023-01-17T12:53:56Z")

</div>

After upgrading from 6.7.0 to 7.10.2, the amount of data in each data node has decreased, but the heap utilization rate has increased, leading to frequent circuit\_breaking. The 7 version FST has moved to the off heap mem…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=662)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=664)
