# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=665

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 666

---

## [How use disk-aware allocator setting?](https://discuss.elastic.co/t/how-use-disk-aware-allocator-setting/323190)

<div class="topic-metadata">

**Author:** [@RichiCoder](https://discuss.elastic.co/u/RichiCoder)\
**Replies:** 4\
**Last updated:** [January 17, 2023, 12:26am UTC](https://discuss.elastic.co/t/how-use-disk-aware-allocator-setting/323190 "2023-01-17T00:26:06Z")

</div>

Howdy! I'd love to use the recently added support for disk usage in the desired balance allocator as I just upgraded to 8.6 in Elastic Cloud. However, it looks like by default cluster.routing.allocation.balance.disk\_usa…

---

## [Logstash with stomp plugin](https://discuss.elastic.co/t/logstash-with-stomp-plugin/323279)

<div class="topic-metadata">

**Author:** [@bulaklak](https://discuss.elastic.co/u/bulaklak)\
**Replies:** 5\
**Last updated:** [January 16, 2023, 11:34pm UTC](https://discuss.elastic.co/t/logstash-with-stomp-plugin/323279 "2023-01-16T23:34:51Z")

</div>

Hi all, I'm looking into connecting Logstash with ActiveMQ. However, the stomp plugin I need isn't included with default Logstash. I have tried to install the logstash-input-stomp plugin, but it isn't working. Any direc…

---

## [Err Empty Response From Kibana](https://discuss.elastic.co/t/err-empty-response-from-kibana/322677)

<div class="topic-metadata">

**Author:** [@Surendra\_Gupta](https://discuss.elastic.co/u/Surendra_Gupta)\
**Replies:** 3\
**Last updated:** [January 16, 2023, 11:28pm UTC](https://discuss.elastic.co/t/err-empty-response-from-kibana/322677 "2023-01-16T23:28:42Z")

</div>

Hi @xeraa I am getting Err Empty Response from Kibana after multiple refresh i am getting elk screen and after that while fetching apm i am getting this issue can you please hlep me to solve this we have 16 gb ram …

---

## [Garbage Collection of my java/spring application keeps spiking](https://discuss.elastic.co/t/garbage-collection-of-my-java-spring-application-keeps-spiking/323277)

<div class="topic-metadata">

**Author:** [@RuchikG](https://discuss.elastic.co/u/RuchikG)\
**Replies:** 2\
**Last updated:** [January 16, 2023, 10:40pm UTC](https://discuss.elastic.co/t/garbage-collection-of-my-java-spring-application-keeps-spiking/323277 "2023-01-16T22:40:56Z")

</div>

We have a java application built on java and spring which connects to Elastic Search cluster with version 7.6.1. We are using spring-data-elasticsearch dependency with version 4.0.0 RELEASE and elasticsearch dependecy wi…

---

## [Import CSV file into nested fields](https://discuss.elastic.co/t/import-csv-file-into-nested-fields/323278)

<div class="topic-metadata">

**Author:** [@markedperf](https://discuss.elastic.co/u/markedperf)\
**Replies:** 4\
**Last updated:** [January 16, 2023, 10:00pm UTC](https://discuss.elastic.co/t/import-csv-file-into-nested-fields/323278 "2023-01-16T22:00:41Z")

</div>

I'm trying to import a CSV file into nested fields. Trying to follow the aggregate example #4, is coming up short for me. This partially works, but not really what I'm looking for. I'd just like the values grouped in …

---

## [Help with grok filter on ingest pipeline](https://discuss.elastic.co/t/help-with-grok-filter-on-ingest-pipeline/321568)

<div class="topic-metadata">

**Author:** [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Replies:** 4\
**Last updated:** [January 16, 2023, 8:17pm UTC](https://discuss.elastic.co/t/help-with-grok-filter-on-ingest-pipeline/321568 "2023-01-16T20:17:51Z")

</div>

Hello, I'm trying to use the following grok filter, but I'm getting a message saying it's in an invalid json format, but I think my filter is written correctly. can you help me with this? filter: (%{TIMESTAMP\_ISO8601:t…

---

## [Dashboard: "options list" entries sorting](https://discuss.elastic.co/t/dashboard-options-list-entries-sorting/322753)

<div class="topic-metadata">

**Author:** [@hkhalil](https://discuss.elastic.co/u/hkhalil)\
**Replies:** 3\
**Last updated:** [January 16, 2023, 8:01pm UTC](https://discuss.elastic.co/t/dashboard-options-list-entries-sorting/322753 "2023-01-16T20:01:57Z")

</div>

Hi, We are using filtering controls in our dashboards ("Options List"). Specifically, one of our controls is for the following field: "session\_id": { "type": "text", "fields": { "keyword": { …

---

## [Is it possible to delete security index and then create it automatically on restart of Elasticsearch](https://discuss.elastic.co/t/is-it-possible-to-delete-security-index-and-then-create-it-automatically-on-restart-of-elasticsearch/322434)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 9\
**Last updated:** [January 16, 2023, 7:57pm UTC](https://discuss.elastic.co/t/is-it-possible-to-delete-security-index-and-then-create-it-automatically-on-restart-of-elasticsearch/322434 "2023-01-16T19:57:34Z")

</div>

x pack is enabled and now I want to delete security index. Then will it be automatically created on restart of Elasticsearch and will all the built users be created?

---

## [Generate xpack SSL certificates with longer expiry date](https://discuss.elastic.co/t/generate-xpack-ssl-certificates-with-longer-expiry-date/323275)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 2\
**Last updated:** [January 16, 2023, 7:56pm UTC](https://discuss.elastic.co/t/generate-xpack-ssl-certificates-with-longer-expiry-date/323275 "2023-01-16T19:56:39Z")

</div>

When we generate SSL certificates with elasticsearch-certutil, we get them with the expiry of 3 years Is there a way that we can generate the certificates with longer expiry date such as 5 years or so. Is it possible t…

---

## [Cant seem to connect to Elastic Search or Kibana](https://discuss.elastic.co/t/cant-seem-to-connect-to-elastic-search-or-kibana/323200)

<div class="topic-metadata">

**Author:** [@jrp30506](https://discuss.elastic.co/u/jrp30506)\
**Replies:** 7\
**Last updated:** [January 16, 2023, 7:24pm UTC](https://discuss.elastic.co/t/cant-seem-to-connect-to-elastic-search-or-kibana/323200 "2023-01-16T19:24:05Z")

</div>

Afternoon everyone. I recently built an ELK stack on Ubuntu 22.04 by following instructions I found by searching for the installation procedure. I followed the article to the letter and after completion, when trying to c…

---

## [A question about a potential vulnerability in Kibana](https://discuss.elastic.co/t/a-question-about-a-potential-vulnerability-in-kibana/323195)

<div class="topic-metadata">

**Author:** [@frenkel](https://discuss.elastic.co/u/frenkel)\
**Replies:** 3\
**Last updated:** [January 16, 2023, 7:23pm UTC](https://discuss.elastic.co/t/a-question-about-a-potential-vulnerability-in-kibana/323195 "2023-01-16T19:23:20Z")

</div>

Hi, There is this CVE about a vulnerability in JsonWebToken: https://nvd.nist.gov/vuln/detail/CVE-2022-23529 This is a vulnerability about insecure input validation in jwt.verify function, in JsonWebToken versions \<= …

---

## [Upgrade from version 8.5 to 8.6 - license error](https://discuss.elastic.co/t/upgrade-from-version-8-5-to-8-6-license-error/323032)

<div class="topic-metadata">

**Author:** [@thiavs](https://discuss.elastic.co/u/thiavs)\
**Replies:** 6\
**Last updated:** [January 16, 2023, 5:14pm UTC](https://discuss.elastic.co/t/upgrade-from-version-8-5-to-8-6-license-error/323032 "2023-01-16T17:14:03Z")

</div>

After updating from version 8.5 to 8.6, my fleet server does not work, I cannot see my agents online, in the logs I have the following situation: Reason: current license is non-compliant for \[categorize-text-agg\]","l…

---

## [Anonymous login for kibana embed fix](https://discuss.elastic.co/t/anonymous-login-for-kibana-embed-fix/323060)

<div class="topic-metadata">

**Author:** [@Prashant2](https://discuss.elastic.co/u/Prashant2)\
**Replies:** 1\
**Last updated:** [January 16, 2023, 5:09pm UTC](https://discuss.elastic.co/t/anonymous-login-for-kibana-embed-fix/323060 "2023-01-16T17:09:56Z")

</div>

I need to embed the kibana dashboard to. my react app. Where do I need to add the kibana.yml file anonymous login https://dub-test-new.kb.us-central1.gcp.cloud.es.io:9243/ this is the link to my kibana dashboard.

---

## [In Kibana Agg Based Metric, how to show in the results only the highest (doc\_count wise) '1 min' bucket?](https://discuss.elastic.co/t/in-kibana-agg-based-metric-how-to-show-in-the-results-only-the-highest-doc-count-wise-1-min-bucket/322257)

<div class="topic-metadata">

**Author:** [@tds21](https://discuss.elastic.co/u/tds21)\
**Replies:** 1\
**Last updated:** [January 16, 2023, 5:04pm UTC](https://discuss.elastic.co/t/in-kibana-agg-based-metric-how-to-show-in-the-results-only-the-highest-doc-count-wise-1-min-bucket/322257 "2023-01-16T17:04:49Z")

</div>

I created an Agg Based Metric with: METRICS - Max Bucket aggregation, that has bucket terms agg for source IP, which basically counts the top source IP and returns it BUCKETS - Date Histogram with timestamp field, wi…

---

## [Logstash doesn't work in Windows correctly Please help!](https://discuss.elastic.co/t/logstash-doesnt-work-in-windows-correctly-please-help/323161)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 3\
**Last updated:** [January 16, 2023, 4:07pm UTC](https://discuss.elastic.co/t/logstash-doesnt-work-in-windows-correctly-please-help/323161 "2023-01-16T16:07:14Z")

</div>

Hi, I try to run logstash in windows with the command: .\\bin\\logstash.bat -f D:\\Elastic\\logstash-8.6.0\\config\\conf.d\\bo\_firmas\_electronicas.conf But I have this message: \[2023-01-13T16:01:57,544\]\[ERROR\]\[logstash.agent…

---

## [Increased Search Latency post enabling writes to index](https://discuss.elastic.co/t/increased-search-latency-post-enabling-writes-to-index/323258)

<div class="topic-metadata">

**Author:** [@zeus7](https://discuss.elastic.co/u/zeus7)\
**Replies:** 3\
**Last updated:** [January 16, 2023, 4:01pm UTC](https://discuss.elastic.co/t/increased-search-latency-post-enabling-writes-to-index/323258 "2023-01-16T16:01:32Z")

</div>

Hi, I m observing high search latency (8x-10x) post enabling writes on an index. I m having an index on production having continuous writes (avg write operations/sec = ~5k) and it is having search latency of 2-4sec. I…

---

## [Where is Filestream integration?](https://discuss.elastic.co/t/where-is-filestream-integration/323245)

<div class="topic-metadata">

**Author:** [@Guillaume\_Bouchez](https://discuss.elastic.co/u/Guillaume_Bouchez)\
**Replies:** 1\
**Last updated:** [January 16, 2023, 3:58pm UTC](https://discuss.elastic.co/t/where-is-filestream-integration/323245 "2023-01-16T15:58:25Z")

</div>

I'm Using fleet and elastic-agent integration for collecting logs, and I recently discovered a warning from elastic\_agent.filebeat, stating that logs inputs are deprecated and to use filetream inputs instead. Fine with…

---

## [Kibana Visualize Lens not showing nested fields](https://discuss.elastic.co/t/kibana-visualize-lens-not-showing-nested-fields/322691)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 3\
**Last updated:** [January 16, 2023, 3:47pm UTC](https://discuss.elastic.co/t/kibana-visualize-lens-not-showing-nested-fields/322691 "2023-01-16T15:47:26Z")

</div>

I'm not sure what I did wrong, but Kibana Lenses aren't showing me the nested field inventory.equipment. In terms of what I did, I set up an index and added a document with this script: PUT warehouse POST warehouse/\_ma…

---

## [Failed to start Elasticsearch on windows](https://discuss.elastic.co/t/failed-to-start-elasticsearch-on-windows/323211)

<div class="topic-metadata">

**Author:** [@FoamQuicksand](https://discuss.elastic.co/u/FoamQuicksand)\
**Replies:** 5\
**Last updated:** [January 16, 2023, 3:26pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch-on-windows/323211 "2023-01-16T15:26:36Z")

</div>

I failed to start Elasticsearch8.5.1 and 8.6.0 locally, but 8.2.2 and 8.4.1 can start normally. anyone know what the problem？ report errors: warning: ignoring JAVA\_HOME=C:\\Program Files\\Java\\jdk-17.0.4.1; using bundle…

---

## [Kibana Kubernetes Dashboard - Metric issue](https://discuss.elastic.co/t/kibana-kubernetes-dashboard-metric-issue/323252)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 5\
**Last updated:** [January 16, 2023, 2:31pm UTC](https://discuss.elastic.co/t/kibana-kubernetes-dashboard-metric-issue/323252 "2023-01-16T14:31:09Z")

</div>

Hi, i am currently working on kubernetes-metricbeat and in kibana dashboard the metrics in kibana are available only on weekdays. At the weekend the metrics are not anymore available and everything is crashed.... Does …

---

## [Kibana development server up and running, but not picking up changes](https://discuss.elastic.co/t/kibana-development-server-up-and-running-but-not-picking-up-changes/323253)

<div class="topic-metadata">

**Author:** [@mpjjonker](https://discuss.elastic.co/u/mpjjonker)\
**Replies:** 6\
**Last updated:** [January 16, 2023, 2:17pm UTC](https://discuss.elastic.co/t/kibana-development-server-up-and-running-but-not-picking-up-changes/323253 "2023-01-16T14:17:20Z")

</div>

Hi, I have followed the instructions to setup a development environment for plugin development. I also do see the first attempt (created by the create-plugin-script), but when I make a change to any of the files (publi…

---

## [Logstash horizontal autoscaling](https://discuss.elastic.co/t/logstash-horizontal-autoscaling/323256)

<div class="topic-metadata">

**Author:** [@yuvalweber](https://discuss.elastic.co/u/yuvalweber)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 2:10pm UTC](https://discuss.elastic.co/t/logstash-horizontal-autoscaling/323256 "2023-01-16T14:10:50Z")

</div>

I want to create autoscaling for our logstash based on prometheus queries we have from the api of logstash. I am using Persistent Queue has a way for backing up our messages in case of disaster and I thought that based …

---

## [Coremigration error while importing dashboards from dev instance to prod instance](https://discuss.elastic.co/t/coremigration-error-while-importing-dashboards-from-dev-instance-to-prod-instance/323239)

<div class="topic-metadata">

**Author:** [@krishnaabylle](https://discuss.elastic.co/u/krishnaabylle)\
**Replies:** 2\
**Last updated:** [January 16, 2023, 2:08pm UTC](https://discuss.elastic.co/t/coremigration-error-while-importing-dashboards-from-dev-instance-to-prod-instance/323239 "2023-01-16T14:08:13Z")

</div>

Hi everyone Can anyone help me with this error.We have a dev and prod instance.i exported one dashboard in dev and While migrating dashboard from dev instance to prod instane getting the error as …

---

## [How to add new node to Elasticsearch cluster with Https](https://discuss.elastic.co/t/how-to-add-new-node-to-elasticsearch-cluster-with-https/322942)

<div class="topic-metadata">

**Author:** [@makkaroni8](https://discuss.elastic.co/u/makkaroni8)\
**Replies:** 7\
**Last updated:** [January 16, 2023, 2:00pm UTC](https://discuss.elastic.co/t/how-to-add-new-node-to-elasticsearch-cluster-with-https/322942 "2023-01-16T14:00:19Z")

</div>

Hi, I'm using a single-node Elasticsearch instance. I want to add another node to my cluster by Enrolling the new node. But I have the same Issue: ERROR: Failed to determine the health of the cluster with elasticsearc…

---

## [Winlogbeat to Logstash over SSL](https://discuss.elastic.co/t/winlogbeat-to-logstash-over-ssl/322705)

<div class="topic-metadata">

**Author:** [@Mark\_Marais](https://discuss.elastic.co/u/Mark_Marais)\
**Replies:** 11\
**Last updated:** [January 16, 2023, 1:56pm UTC](https://discuss.elastic.co/t/winlogbeat-to-logstash-over-ssl/322705 "2023-01-16T13:56:11Z")

</div>

Good day, Can someone assist me with a secure connection from my beats to my logstash instances. Thanks.

---

## [Query dsl span\_or vs bool should](https://discuss.elastic.co/t/query-dsl-span-or-vs-bool-should/323254)

<div class="topic-metadata">

**Author:** [@IvanTushin](https://discuss.elastic.co/u/IvanTushin)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 1:34pm UTC](https://discuss.elastic.co/t/query-dsl-span-or-vs-bool-should/323254 "2023-01-16T13:34:13Z")

</div>

Hi! I have two "span\_near" queries. What's the difference between bool-\>should and span\_or? Does it affect on "index.query.bool.max\_clause\_count" limit or query performance? { "span\_or": { "clauses": \[ …

---

## [Kibana REST API for integrations setup](https://discuss.elastic.co/t/kibana-rest-api-for-integrations-setup/322151)

<div class="topic-metadata">

**Author:** [@OlLap](https://discuss.elastic.co/u/OlLap)\
**Replies:** 16\
**Last updated:** [January 16, 2023, 12:49pm UTC](https://discuss.elastic.co/t/kibana-rest-api-for-integrations-setup/322151 "2023-01-16T12:49:24Z")

</div>

Hello, I have installed Elastic stack using ECK (Elasticsearch, Kibana, Beats, APM Server + agents), and trying to automate setup moving manual configuration steps to Kubernetes jobs that use Elasticsearch REST API. Bu…

---

## [Elasticearch and Power BI](https://discuss.elastic.co/t/elasticearch-and-power-bi/323250)

<div class="topic-metadata">

**Author:** [@palko.balazs](https://discuss.elastic.co/u/palko.balazs)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 12:35pm UTC](https://discuss.elastic.co/t/elasticearch-and-power-bi/323250 "2023-01-16T12:35:02Z")

</div>

Hi, I'm trying to import our data stored in Elasticsearch into a BI Tool. I tried Power BI with ODBC using this guide and this guide for Tableau. I was able to get our data into both PowerBi and Tableau, however I'm st…

---

## [Need proper example and resource for xml filter plugin](https://discuss.elastic.co/t/need-proper-example-and-resource-for-xml-filter-plugin/323087)

<div class="topic-metadata">

**Author:** [@Nikhil27](https://discuss.elastic.co/u/Nikhil27)\
**Replies:** 3\
**Last updated:** [January 16, 2023, 12:25pm UTC](https://discuss.elastic.co/t/need-proper-example-and-resource-for-xml-filter-plugin/323087 "2023-01-16T12:25:38Z")

</div>

I want to parse unstructured xml log data.I am not getting any proper resource for reference.The xml filter plugin documentation is not that able to sort my problem. I am new to the ELK please help me out of this....

---

## [Filebeat's add\_docker\_metadata stop working after container restart](https://discuss.elastic.co/t/filebeats-add-docker-metadata-stop-working-after-container-restart/322358)

<div class="topic-metadata">

**Author:** [@kowy](https://discuss.elastic.co/u/kowy)\
**Replies:** 1\
**Last updated:** [January 16, 2023, 12:22pm UTC](https://discuss.elastic.co/t/filebeats-add-docker-metadata-stop-working-after-container-restart/322358 "2023-01-16T12:22:00Z")

</div>

We use filebeat from Graylog to collect logs from services run in docker-compose. Filebeat is not started as a linux service, but executed as this command: sudo /usr/share/filebeat/bin/filebeat --path.home /usr/share/f…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=664)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=666)
