# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=248

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 249

---

## [Unable to create an enrollment token. Elasticsearch node HTTP layer SSL configuration is not configured with a keystore](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token-elasticsearch-node-http-layer-ssl-configuration-is-not-configured-with-a-keystore/350527)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 1\
**Last updated:** [January 7, 2024, 2:41pm UTC](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token-elasticsearch-node-http-layer-ssl-configuration-is-not-configured-with-a-keystore/350527 "2024-01-07T14:41:13Z")

</div>

Hi Team, I am upgrading elasticsearch from 7.17.0 to 8.11 on ubuntu 22.04 I have completed elasticsearch installation and x-pack while I am creating token for cluster it is showing below error Error: Unable to create …

---

## [Drill down o kibana table based on field's value](https://discuss.elastic.co/t/drill-down-o-kibana-table-based-on-fields-value/349643)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 2\
**Last updated:** [January 7, 2024, 10:21am UTC](https://discuss.elastic.co/t/drill-down-o-kibana-table-based-on-fields-value/349643 "2024-01-07T10:21:35Z")

</div>

I have a data table in my dashboard and the table is split based on a field whose values are names of different cities and table will show the count of different cities. Is it possible to drill down based on the city's n…

---

## [Custom UDP logs are only listening on ipv6](https://discuss.elastic.co/t/custom-udp-logs-are-only-listening-on-ipv6/350497)

<div class="topic-metadata">

**Author:** [@phirestalker](https://discuss.elastic.co/u/phirestalker)\
**Replies:** 7\
**Last updated:** [January 7, 2024, 7:06am UTC](https://discuss.elastic.co/t/custom-udp-logs-are-only-listening-on-ipv6/350497 "2024-01-07T07:06:00Z")

</div>

I set up some custom UDP port integrations. I noticed that a lot of logs were not coming in, so I did netstat on the host. It turns out that it is only listening on ipv6. How can I set it to listen on both or only ipv4?

---

## [Can you modify web scraper extraction rules for reserved field name: body\_content?](https://discuss.elastic.co/t/can-you-modify-web-scraper-extraction-rules-for-reserved-field-name-body-content/350513)

<div class="topic-metadata">

**Author:** [@mmaccou](https://discuss.elastic.co/u/mmaccou)\
**Replies:** 0\
**Last updated:** [January 6, 2024, 4:21pm UTC](https://discuss.elastic.co/t/can-you-modify-web-scraper-extraction-rules-for-reserved-field-name-body-content/350513 "2024-01-06T16:21:27Z")

</div>

By default, body\_content grabs content that's irrelevant for my use case. Instead of creating a new field with custom extraction rules, I'd rather edit the rules for body\_content to avoid creating unused fields in my doc…

---

## [The s3 input for creating the index does not work with preffix and csv files](https://discuss.elastic.co/t/the-s3-input-for-creating-the-index-does-not-work-with-preffix-and-csv-files/350496)

<div class="topic-metadata">

**Author:** [@Marcos\_Daniel\_Santos](https://discuss.elastic.co/u/Marcos_Daniel_Santos)\
**Replies:** 3\
**Last updated:** [January 6, 2024, 12:33pm UTC](https://discuss.elastic.co/t/the-s3-input-for-creating-the-index-does-not-work-with-preffix-and-csv-files/350496 "2024-01-06T12:33:04Z")

</div>

Hi everyone, I have a bucekt s3 with 2 csv files, one that is a securityhub repot and the other a guardduty report, both AWS services and security. I'm using the preffix to get my object, using the logstash -f file.conf…

---

## [Help understanding boolean should query results](https://discuss.elastic.co/t/help-understanding-boolean-should-query-results/350495)

<div class="topic-metadata">

**Author:** [@allan.silverstein](https://discuss.elastic.co/u/allan.silverstein)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 10:46pm UTC](https://discuss.elastic.co/t/help-understanding-boolean-should-query-results/350495 "2024-01-05T22:46:45Z")

</div>

Hello, I'm not understanding why the following query does not show any documents hits for the "support\_files.bgp\_evpn\_routes" field. It does show hits for the first match\_phrase (name a). As a troubleshooting test, I c…

---

## [Kibana Maps Service Custom Icons in the Layer Style Section](https://discuss.elastic.co/t/kibana-maps-service-custom-icons-in-the-layer-style-section/205304)

<div class="topic-metadata">

**Author:** [@14kporter](https://discuss.elastic.co/u/14kporter)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 8:37pm UTC](https://discuss.elastic.co/t/kibana-maps-service-custom-icons-in-the-layer-style-section/205304 "2024-01-05T20:37:37Z")

</div>

Currently I am using Kibana Map Service and plotting Geopoints. I want to change the icons of the points to something that is not one of the pre-selected Maiki icons and import another icon in the SVG format. Is this …

---

## [Filebeat not getting logs from kubernetes pods](https://discuss.elastic.co/t/filebeat-not-getting-logs-from-kubernetes-pods/350403)

<div class="topic-metadata">

**Author:** [@gustavo\_luigi\_cev](https://discuss.elastic.co/u/gustavo_luigi_cev)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 7:58pm UTC](https://discuss.elastic.co/t/filebeat-not-getting-logs-from-kubernetes-pods/350403 "2024-01-05T19:58:17Z")

</div>

Hi! I'm trying to use Filebeat on my aws eks to get my containers logs. filebeat-configmap.yaml apiVersion: v1 kind: ConfigMap metadata: name: filebeat-config namespace: elk data: filebeat.yml: |- logging.le…

---

## [Percolating returns more results that i expect](https://discuss.elastic.co/t/percolating-returns-more-results-that-i-expect/350481)

<div class="topic-metadata">

**Author:** [@oli.girling](https://discuss.elastic.co/u/oli.girling)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 6:56pm UTC](https://discuss.elastic.co/t/percolating-returns-more-results-that-i-expect/350481 "2024-01-05T18:56:42Z")

</div>

Smashing my head against the wall with this, wondering if anyone can point anything out thats obvious. Using ES 5.6 (I know its out of date, im in the process of upgrading) I have an advert in ES GET /gb/classified/15…

---

## [Elastic agent uninstall](https://discuss.elastic.co/t/elastic-agent-uninstall/349659)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 9\
**Last updated:** [January 5, 2024, 5:53pm UTC](https://discuss.elastic.co/t/elastic-agent-uninstall/349659 "2024-01-05T17:53:32Z")

</div>

Hello, it seeemed to be simple but, im trying to uninstall elastic agent, but unfortunately no luck root@elk:/opt/elastic-agent-8.11.2-linux-x86\_64# elastic-agent uninstall Error: can only be uninstalled by executing …

---

## [Metric Threshold - Email Alert Body](https://discuss.elastic.co/t/metric-threshold-email-alert-body/350478)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 4:50pm UTC](https://discuss.elastic.co/t/metric-threshold-email-alert-body/350478 "2024-01-05T16:50:21Z")

</div>

Hello, I am using a simple alert to capture CPU usage. Using Email Action, the alert is working as expected but I want to see if I can edit the body to include the same data but more cleaned up. This is expected and d…

---

## [How i put a response into a kibana URL](https://discuss.elastic.co/t/how-i-put-a-response-into-a-kibana-url/350410)

<div class="topic-metadata">

**Author:** [@Natanael\_Rodrigues](https://discuss.elastic.co/u/Natanael_Rodrigues)\
**Replies:** 3\
**Last updated:** [January 5, 2024, 3:25pm UTC](https://discuss.elastic.co/t/how-i-put-a-response-into-a-kibana-url/350410 "2024-01-05T15:25:06Z")

</div>

Hello all, I have a script that will execute at a Unix serve curl -X POST "htt..xxxxx/xxxxx\*/\_search?pretty=" -H 'authorization: Basic xxxxxxxx' -H 'content-type: application/json' -d '{ "aggs": { "2": { …

---

## [How to delete huge number of documents from Index? What can be better option?](https://discuss.elastic.co/t/how-to-delete-huge-number-of-documents-from-index-what-can-be-better-option/350469)

<div class="topic-metadata">

**Author:** [@msabnis79](https://discuss.elastic.co/u/msabnis79)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 2:31pm UTC](https://discuss.elastic.co/t/how-to-delete-huge-number-of-documents-from-index-what-can-be-better-option/350469 "2024-01-05T14:31:48Z")

</div>

For example, we are having 2 billion documents in an index in ES and want to delete 1 billion documents based on some data from Oracle database? So i have to copy data from Oracle 1 billion records and based on Primary …

---

## [Kibana Discover browser title (looks) not set 1st time](https://discuss.elastic.co/t/kibana-discover-browser-title-looks-not-set-1st-time/350458)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 1:48pm UTC](https://discuss.elastic.co/t/kibana-discover-browser-title-looks-not-set-1st-time/350458 "2024-01-05T13:48:53Z")

</div>

Hello, I noticed Kibana puts name of Discover search in browser title. This is very useful feature, but I see it is "unreliable". When I save search for first time, it sets title to "Discover: Errors". When I load sa…

---

## [Sharding and index settings](https://discuss.elastic.co/t/sharding-and-index-settings/350457)

<div class="topic-metadata">

**Author:** [@Mertozturkk](https://discuss.elastic.co/u/Mertozturkk)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 12:31pm UTC](https://discuss.elastic.co/t/sharding-and-index-settings/350457 "2024-01-05T12:31:39Z")

</div>

The 3 Node Elasticsearch we have set up currently has a 6TB index set into 16 P and 1 R shards and is slow to respond to queries. If we want to create an index from scratch that will reach a similar volume in the new ver…

---

## [Data analysis with Kibana - How to get v8 Lab environment (current is still v7)](https://discuss.elastic.co/t/data-analysis-with-kibana-how-to-get-v8-lab-environment-current-is-still-v7/350449)

<div class="topic-metadata">

**Author:** [@AdW](https://discuss.elastic.co/u/AdW)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 11:53am UTC](https://discuss.elastic.co/t/data-analysis-with-kibana-how-to-get-v8-lab-environment-current-is-still-v7/350449 "2024-01-05T11:53:30Z")

</div>

Hello, Some time ago I started the Data analysis with Kibana course which runs the v7.15.1 Lab environment. Recently the exam got moved to v8 and I think my course updated, but my Lab environment is still at v7.15.1. M…

---

## [Csp error for custom kibana login page](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701)

<div class="topic-metadata">

**Author:** [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Replies:** 9\
**Last updated:** [January 5, 2024, 11:42am UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701 "2024-01-05T11:42:28Z")

</div>

heeyy i am using a custom plugin for my kibana that changes the login page to give a custom look but i am getting an errror relating to csp

---

## [Visualize customerId mapped to customer name in e.g. Kibana table](https://discuss.elastic.co/t/visualize-customerid-mapped-to-customer-name-in-e-g-kibana-table/350390)

<div class="topic-metadata">

**Author:** [@rickardo](https://discuss.elastic.co/u/rickardo)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 9:43am UTC](https://discuss.elastic.co/t/visualize-customerid-mapped-to-customer-name-in-e-g-kibana-table/350390 "2024-01-05T09:43:30Z")

</div>

We have reports entries like below and Visualize statistics from "reports" in a Kibana table. But to show customerId=1 makes no sense so want to show them by their name that are defined in another Index in this case. L…

---

## [LDAP Configuration - ELK 8.8.1](https://discuss.elastic.co/t/ldap-configuration-elk-8-8-1/350444)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 9:42am UTC](https://discuss.elastic.co/t/ldap-configuration-elk-8-8-1/350444 "2024-01-05T09:42:50Z")

</div>

I'm currently configuring the LDAP on my coordinator & Kibana nodes (8.8.1) Here are the steps I've taken: Tested the connection with the LDAP server on my coordinator, and it's successful. Configured my elasticsearc…

---

## [Logstash tcp input plugin connection reset error](https://discuss.elastic.co/t/logstash-tcp-input-plugin-connection-reset-error/350441)

<div class="topic-metadata">

**Author:** [@fmelk65](https://discuss.elastic.co/u/fmelk65)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 9:10am UTC](https://discuss.elastic.co/t/logstash-tcp-input-plugin-connection-reset-error/350441 "2024-01-05T09:10:16Z")

</div>

Hello, I have 25 Kubernetes clusters forward their logs to logstash VM (k8s fluentd ---\> logstash). I'm getting a lot of connection reset errors. It's been discussed here before, can @true64gurus specifically help? \[…

---

## [What is the meaning of brackets in an index name?](https://discuss.elastic.co/t/what-is-the-meaning-of-brackets-in-an-index-name/350376)

<div class="topic-metadata">

**Author:** [@mbby](https://discuss.elastic.co/u/mbby)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 7:24am UTC](https://discuss.elastic.co/t/what-is-the-meaning-of-brackets-in-an-index-name/350376 "2024-01-05T07:24:22Z")

</div>

We are using heartbeat and I saw a data view like this: (synthetics-data-view),heartbeat-8,heartbeat-7\*,synthetics-\* Why is synthetics-data-view written in brackets?

---

## [Watermark sonarqube](https://discuss.elastic.co/t/watermark-sonarqube/350406)

<div class="topic-metadata">

**Author:** [@walterh91](https://discuss.elastic.co/u/walterh91)\
**Replies:** 3\
**Last updated:** [January 5, 2024, 7:17am UTC](https://discuss.elastic.co/t/watermark-sonarqube/350406 "2024-01-05T07:17:18Z")

</div>

Hello how are you? Currently, I am using two versions of SonarQube: Development environment: Community Edition Version 9.1 (build 47736) Production environment: Developer Edition Version 9.9.1 (build 69595) In both c…

---

## [Error-Failed version compatibility check with elasticsearch: tls: failed to verify certificate: x509: certificate signed by unknown authority](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711)

<div class="topic-metadata">

**Author:** [@Austin1](https://discuss.elastic.co/u/Austin1)\
**Replies:** 6\
**Last updated:** [January 5, 2024, 5:26am UTC](https://discuss.elastic.co/t/error-failed-version-compatibility-check-with-elasticsearch-tls-failed-to-verify-certificate-x509-certificate-signed-by-unknown-authority/349711 "2024-01-05T05:26:41Z")

</div>

Hi all , Please help me with setting up elastic agent container! I got below error when I used podman run command followed: Error-Failed version compatibility check with elasticsearch: tls: failed to verify certificat…

---

## [Error Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate](https://discuss.elastic.co/t/error-unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/350389)

<div class="topic-metadata">

**Author:** [@kray](https://discuss.elastic.co/u/kray)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 4:32am UTC](https://discuss.elastic.co/t/error-unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/350389 "2024-01-05T04:32:47Z")

</div>

please help, when I open the wazuh web the following error and I checked the kibana log, there is the following error {"type":"log","@timestamp":"2024-01-04T20:11:27+07:00","tags":\["error","elasticsearch-service"\],"p…

---

## [Are there any plans to increase the 800kb push limit?](https://discuss.elastic.co/t/are-there-any-plans-to-increase-the-800kb-push-limit/350314)

<div class="topic-metadata">

**Author:** [@joel.parker](https://discuss.elastic.co/u/joel.parker)\
**Replies:** 6\
**Last updated:** [January 5, 2024, 1:04am UTC](https://discuss.elastic.co/t/are-there-any-plans-to-increase-the-800kb-push-limit/350314 "2024-01-05T01:04:41Z")

</div>

I want to run a set of tests that will check the contents of PDF files using the pdf-parse node module. However, when I import it to use in my monitors I can't push it up to elastic as I get the following error: Error: …

---

## [Changing the log-in text](https://discuss.elastic.co/t/changing-the-log-in-text/350363)

<div class="topic-metadata">

**Author:** [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 6:27pm UTC](https://discuss.elastic.co/t/changing-the-log-in-text/350363 "2024-01-04T18:27:49Z")

</div>

Hey there, I am trying to change the login text to "Welcome to Elastic." I tried changing the source code in the \\kibana-7.17.0-windowsx86\_64\\xpack\\plugins\\security\\target\\public\\security.chunk.5.js file, but it won't wo…

---

## [Backup/Restore Indexes](https://discuss.elastic.co/t/backup-restore-indexes/350411)

<div class="topic-metadata">

**Author:** [@marcowiskhy](https://discuss.elastic.co/u/marcowiskhy)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 8:31pm UTC](https://discuss.elastic.co/t/backup-restore-indexes/350411 "2024-01-04T20:31:25Z")

</div>

Hey guys, I have an Elasticsearch node in production and am experiencing issues regarding disk storage. At the moment I cannot increase computational resources or add other nodes because I depend on collaboration with a…

---

## [Can't log in other than from the local host](https://discuss.elastic.co/t/cant-log-in-other-than-from-the-local-host/349883)

<div class="topic-metadata">

**Author:** [@rcfa](https://discuss.elastic.co/u/rcfa)\
**Replies:** 3\
**Last updated:** [January 4, 2024, 7:51pm UTC](https://discuss.elastic.co/t/cant-log-in-other-than-from-the-local-host/349883 "2024-01-04T19:51:08Z")

</div>

I'm a newby, so excuse if I ask a dummy question, but I got to start somewhere, and being able to log in is, well, prerequisite... So on my server, let's call it 10.0.0.1 I have installed the Elasticsearch and kibana pa…

---

## [savedVisualization / embeddable in canvas broken after upgrading to version 8.9.2 due to saved Objects Id](https://discuss.elastic.co/t/savedvisualization-embeddable-in-canvas-broken-after-upgrading-to-version-8-9-2-due-to-saved-objects-id/349652)

<div class="topic-metadata">

**Author:** [@preetish\_P](https://discuss.elastic.co/u/preetish_P)\
**Replies:** 4\
**Last updated:** [January 4, 2024, 6:32pm UTC](https://discuss.elastic.co/t/savedvisualization-embeddable-in-canvas-broken-after-upgrading-to-version-8-9-2-due-to-saved-objects-id/349652 "2024-01-04T18:32:53Z")

</div>

Hi folks, We are looking to upgrade elk stack from 7.17.2 to 8.9.2. One of the first observations we made in Canvas is that savedVisualization is broken. We have Canvas dashboards having upto 9 kibana visualisation impo…

---

## [\[Elasticsearch user settings and extensions\] Increase http.max\_initial\_line\_length](https://discuss.elastic.co/t/elasticsearch-user-settings-and-extensions-increase-http-max-initial-line-length/350387)

<div class="topic-metadata">

**Author:** [@Xavier\_Huberdeau](https://discuss.elastic.co/u/Xavier_Huberdeau)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 4:53pm UTC](https://discuss.elastic.co/t/elasticsearch-user-settings-and-extensions-increase-http-max-initial-line-length/350387 "2024-01-04T16:53:46Z")

</div>

Hello, I'm trying to change the elasticsearch settings yml configuration from elastic.co When I put http.max\_initial\_line\_length: 32kb, it says: Your changes cannot be applied Elasticsearch - 'http.max\_initial\_li…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=247)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=249)
