# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=249

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 250

---

## [\[Elasticsearch user settings and extensions\] Increase http.max\_initial\_line\_length](https://discuss.elastic.co/t/elasticsearch-user-settings-and-extensions-increase-http-max-initial-line-length/350387)

<div class="topic-metadata">

**Author:** [@Xavier\_Huberdeau](https://discuss.elastic.co/u/Xavier_Huberdeau)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 4:53pm UTC](https://discuss.elastic.co/t/elasticsearch-user-settings-and-extensions-increase-http-max-initial-line-length/350387 "2024-01-04T16:53:46Z")

</div>

Hello, I'm trying to change the elasticsearch settings yml configuration from elastic.co When I put http.max\_initial\_line\_length: 32kb, it says: Your changes cannot be applied Elasticsearch - 'http.max\_initial\_li…

---

## [Kindly suggest hardware sizing](https://discuss.elastic.co/t/kindly-suggest-hardware-sizing/350348)

<div class="topic-metadata">

**Author:** [@sakda.pk](https://discuss.elastic.co/u/sakda.pk)\
**Replies:** 0\
**Last updated:** [January 4, 2024, 4:12am UTC](https://discuss.elastic.co/t/kindly-suggest-hardware-sizing/350348 "2024-01-04T04:12:28Z")

</div>

I have size of data is 850 GB per day and must keep data in 91 days. Total size about 77 TB. pleased help to suggest. - quantity node - quantity shade of index per day Additional Question - how maximum space of n…

---

## [Missing packetbeat.yml file /etc/packetbeat](https://discuss.elastic.co/t/missing-packetbeat-yml-file-etc-packetbeat/350340)

<div class="topic-metadata">

**Author:** [@ACodingfreak](https://discuss.elastic.co/u/ACodingfreak)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 2:38pm UTC](https://discuss.elastic.co/t/missing-packetbeat-yml-file-etc-packetbeat/350340 "2024-01-04T14:38:52Z")

</div>

Hi All, I am trying to install packetbeat in my ubuntu 22.04 machine following the instructions shared in As shown in below logs, /etc/packetbeat is empty and I dont see the default template of packetbeat.yml file. A…

---

## [Using location data to show a route taken](https://discuss.elastic.co/t/using-location-data-to-show-a-route-taken/350263)

<div class="topic-metadata">

**Author:** [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Replies:** 2\
**Last updated:** [January 4, 2024, 1:38pm UTC](https://discuss.elastic.co/t/using-location-data-to-show-a-route-taken/350263 "2024-01-04T13:38:40Z")

</div>

Hi I have time based data for the location of an item, that I'd like to visualise as a sort of "route map", i.e. a sequnece of lines joining the various location points as traversed in time series order. Maybe I'm miss…

---

## [Geo.location as object and not as geo\_point](https://discuss.elastic.co/t/geo-location-as-object-and-not-as-geo-point/349230)

<div class="topic-metadata">

**Author:** [@helldunkel](https://discuss.elastic.co/u/helldunkel)\
**Replies:** 3\
**Last updated:** [January 4, 2024, 11:48am UTC](https://discuss.elastic.co/t/geo-location-as-object-and-not-as-geo-point/349230 "2024-01-04T11:48:44Z")

</div>

Hi, I created a component template for a custon sensor. everything works, has the right datatypes. Only destination.geo.location is set to object and not to geo\_point: "destination": { "type": "object", …

---

## [Multiple Kibanas on 1 cluster](https://discuss.elastic.co/t/multiple-kibanas-on-1-cluster/350372)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 10:32am UTC](https://discuss.elastic.co/t/multiple-kibanas-on-1-cluster/350372 "2024-01-04T10:32:47Z")

</div>

Hi, Is it possible\\alowed to run multiple Kibana instances connected to same cluster? Will it create internal index (.monitoring, etc) per instance? Thanks...

---

## [Alternatives to kibana](https://discuss.elastic.co/t/alternatives-to-kibana/350360)

<div class="topic-metadata">

**Author:** [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Replies:** 2\
**Last updated:** [January 4, 2024, 9:53am UTC](https://discuss.elastic.co/t/alternatives-to-kibana/350360 "2024-01-04T09:53:18Z")

</div>

Hey i was wondering if i could connect my elasticsearch and logstash with some other vizualisation tool like powerbi or tablue for free . I tried to do so but it seems i have to buy the platinum version to download the e…

---

## [I want to know details about how we reduced the heap usage per shard](https://discuss.elastic.co/t/i-want-to-know-details-about-how-we-reduced-the-heap-usage-per-shard/350346)

<div class="topic-metadata">

**Author:** [@emmning](https://discuss.elastic.co/u/emmning)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 9:28am UTC](https://discuss.elastic.co/t/i-want-to-know-details-about-how-we-reduced-the-heap-usage-per-shard/350346 "2024-01-04T09:28:15Z")

</div>

Through this blog I see that starting from 8.3, we have significantly reduced Usage of each shard of the heap. I would like to know more details about how we can reduce the heap usage per shard. Anyone knows a PR or blog…

---

## [Siem integrated ml jobs and multi tenancy](https://discuss.elastic.co/t/siem-integrated-ml-jobs-and-multi-tenancy/350315)

<div class="topic-metadata">

**Author:** [@Crazyworlds](https://discuss.elastic.co/u/Crazyworlds)\
**Replies:** 2\
**Last updated:** [January 4, 2024, 8:31am UTC](https://discuss.elastic.co/t/siem-integrated-ml-jobs-and-multi-tenancy/350315 "2024-01-04T08:31:48Z")

</div>

Hi to everyone, We use the ECS field 'organization.name" and "data\_stream.namespace" to distinguish the organization name, and it work well with SIEM alert rules excluding those based on machine learning. On this king…

---

## [Embedding kibana using iframe](https://discuss.elastic.co/t/embedding-kibana-using-iframe/350042)

<div class="topic-metadata">

**Author:** [@Atul87](https://discuss.elastic.co/u/Atul87)\
**Replies:** 3\
**Last updated:** [January 4, 2024, 8:28am UTC](https://discuss.elastic.co/t/embedding-kibana-using-iframe/350042 "2024-01-04T08:28:10Z")

</div>

Hi team, I am trying to embed kibana url using iframe, but its not working for me. I am using kibana version 7.17.13, I want to embed overall kibana, with all its functionality not just any one dashbord of it. Authenti…

---

## [Logstash metrics using modules in Metricbeat](https://discuss.elastic.co/t/logstash-metrics-using-modules-in-metricbeat/350279)

<div class="topic-metadata">

**Author:** [@maadhav](https://discuss.elastic.co/u/maadhav)\
**Replies:** 4\
**Last updated:** [January 4, 2024, 5:41am UTC](https://discuss.elastic.co/t/logstash-metrics-using-modules-in-metricbeat/350279 "2024-01-04T05:41:29Z")

</div>

Hi Team There are 2 modules in Metricbeat to collect Logstash metrics logstash logstash-xpack Which module should be used ? Regards

---

## [Is dfs\_query\_then\_fetch automatically disabled on single shard?](https://discuss.elastic.co/t/is-dfs-query-then-fetch-automatically-disabled-on-single-shard/350351)

<div class="topic-metadata">

**Author:** [@Yukha\_Dharmeswara](https://discuss.elastic.co/u/Yukha_Dharmeswara)\
**Replies:** 0\
**Last updated:** [January 4, 2024, 5:17am UTC](https://discuss.elastic.co/t/is-dfs-query-then-fetch-automatically-disabled-on-single-shard/350351 "2024-01-04T05:17:34Z")

</div>

When we specify search\_type=dfs\_query\_then\_fetch in querystring, does Elasticsearch automatically disable dfs\_query\_then\_fetch when there's only 1 shard in single node mode? Or do i have to use query\_then\_fetch to trigge…

---

## [Stack Monitoring Access Denied](https://discuss.elastic.co/t/stack-monitoring-access-denied/350313)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 9:32pm UTC](https://discuss.elastic.co/t/stack-monitoring-access-denied/350313 "2024-01-03T21:32:48Z")

</div>

When I try to view Stack Monitoring, I receive an error message. I get the same message with the default elastic admin user as well as my provisioned unique admin user account I use. I only have one cluster, so I'm not…

---

## [Share a dashboard in read-only mode](https://discuss.elastic.co/t/share-a-dashboard-in-read-only-mode/350326)

<div class="topic-metadata">

**Author:** [@gnatola](https://discuss.elastic.co/u/gnatola)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 7:58pm UTC](https://discuss.elastic.co/t/share-a-dashboard-in-read-only-mode/350326 "2024-01-03T19:58:40Z")

</div>

Hello, using Kibana 8.11. Created a dashboard that I would like to share in read-only mode. I would like to be the only person who can edit the dashboard. What is the best way to accomplish this? Thanks.

---

## [ES SQL custom mappings](https://discuss.elastic.co/t/es-sql-custom-mappings/349980)

<div class="topic-metadata">

**Author:** [@ES\_SQL\_HELP](https://discuss.elastic.co/u/ES_SQL_HELP)\
**Replies:** 6\
**Last updated:** [January 3, 2024, 5:08pm UTC](https://discuss.elastic.co/t/es-sql-custom-mappings/349980 "2024-01-03T17:08:54Z")

</div>

Hello, I'm wondering if it's possible to use ES SQL on custom field mappings for types e.g. long, integer, doubles.

---

## [How to read GZIP and encoding with UTF-8 logs from kafka topic through logstash pipeline](https://discuss.elastic.co/t/how-to-read-gzip-and-encoding-with-utf-8-logs-from-kafka-topic-through-logstash-pipeline/349775)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 5\
**Last updated:** [January 3, 2024, 4:53pm UTC](https://discuss.elastic.co/t/how-to-read-gzip-and-encoding-with-utf-8-logs-from-kafka-topic-through-logstash-pipeline/349775 "2024-01-03T16:53:39Z")

</div>

Hi All, Application team doing "GZIP and encoding with UTF-8" and sending their logs to kafka topics. Now i want to read those logs through logstash pipeline. Could you please guide me on this? Thanks

---

## [Inconsistencies between platforms](https://discuss.elastic.co/t/inconsistencies-between-platforms/350261)

<div class="topic-metadata">

**Author:** [@nml1988](https://discuss.elastic.co/u/nml1988)\
**Replies:** 11\
**Last updated:** [January 3, 2024, 3:35pm UTC](https://discuss.elastic.co/t/inconsistencies-between-platforms/350261 "2024-01-03T15:35:06Z")

</div>

Hello! I need help with a problem I'm having between 2 versions of ELK. These versions correspond to two different platforms that consume data from the same source. The first image corresponds to an ELK stack 7.9, where…

---

## [Add filed to Elastic Agentedit](https://discuss.elastic.co/t/add-filed-to-elastic-agentedit/350139)

<div class="topic-metadata">

**Author:** [@Crazyworlds](https://discuss.elastic.co/u/Crazyworlds)\
**Replies:** 2\
**Last updated:** [January 3, 2024, 2:03pm UTC](https://discuss.elastic.co/t/add-filed-to-elastic-agentedit/350139 "2024-01-03T14:03:05Z")

</div>

I notice that Elastic Agent does not populate the ecs filed organization.name and for this, following the documentation I try to create a pipiline as this: POST /\_ingest/pipeline/\_simulate { "pipeline" : { "processo…

---

## [Production configuration question](https://discuss.elastic.co/t/production-configuration-question/350302)

<div class="topic-metadata">

**Author:** [@Aleksandar\_Aleksand1](https://discuss.elastic.co/u/Aleksandar_Aleksand1)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 1:07pm UTC](https://discuss.elastic.co/t/production-configuration-question/350302 "2024-01-03T13:07:42Z")

</div>

Hi all, I am preparing the following elasticsearch cluster architecture: Total 6 Nodes: 1 Node with roles: master and remote\_cluster\_client 3 Nodes with roles: data, data\_hot, data\_content and ingest 1 Node with role…

---

## [Integration of elastic and logstash with other vizualization](https://discuss.elastic.co/t/integration-of-elastic-and-logstash-with-other-vizualization/350292)

<div class="topic-metadata">

**Author:** [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 12:50pm UTC](https://discuss.elastic.co/t/integration-of-elastic-and-logstash-with-other-vizualization/350292 "2024-01-03T12:50:41Z")

</div>

Hey there i am working on a project that requires me to integrate ELK stack with other vizualiation tools fo free , however i am running into the issue of downloading the ODBC driver as it is showing that i would need a …

---

## [Help for Tracking Exception Rule Hits in Elastic Security](https://discuss.elastic.co/t/help-for-tracking-exception-rule-hits-in-elastic-security/350298)

<div class="topic-metadata">

**Author:** [@anak1n](https://discuss.elastic.co/u/anak1n)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 11:22am UTC](https://discuss.elastic.co/t/help-for-tracking-exception-rule-hits-in-elastic-security/350298 "2024-01-03T11:22:43Z")

</div>

Hello Elastic Security Community, I'm currently working with Elastic Security and have implemented several exception rules to fine-tune my alert system. However, I've encountered a challenge: I need to measure the effec…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/350280)

<div class="topic-metadata">

**Author:** [@MD\_Rezaul\_Karim](https://discuss.elastic.co/u/MD_Rezaul_Karim)\
**Replies:** 10\
**Last updated:** [January 3, 2024, 11:11am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/350280 "2024-01-03T11:11:08Z")

</div>

Hi, I am getting following error. anyone pls. help me .. Jan 03 13:21:50 siem kibana\[10792\]: FATAL Error: Unable to complete saved object migrations for the \[.kibana\_task\_manager\] index. Please check the health of you…

---

## [Kibana 7.17.6 \> 8 Kibana\_system 403 unauthorized?](https://discuss.elastic.co/t/kibana-7-17-6-8-kibana-system-403-unauthorized/350288)

<div class="topic-metadata">

**Author:** [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 11:10am UTC](https://discuss.elastic.co/t/kibana-7-17-6-8-kibana-system-403-unauthorized/350288 "2024-01-03T11:10:32Z")

</div>

Hi everyone ! i've been upgrading my cluster recently everything went well until i got kibana HTTP 403 Errors with both kibana\_system and elastic users. Am i supposed to create a user with \[manage\] \[manage\_all\] perms i…

---

## [How to read base64 encoded logs from kafka through logstash pipeline](https://discuss.elastic.co/t/how-to-read-base64-encoded-logs-from-kafka-through-logstash-pipeline/349688)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 9\
**Last updated:** [January 3, 2024, 9:28am UTC](https://discuss.elastic.co/t/how-to-read-base64-encoded-logs-from-kafka-through-logstash-pipeline/349688 "2024-01-03T09:28:30Z")

</div>

Hello all, I am working on something I have never worked on before and I really do not know where to go from here and I am hoping someone might have some direction for me to attempt trying to get this parsed to Elastics…

---

## [Elasticsearch: What's the best way to store big-data cost effective](https://discuss.elastic.co/t/elasticsearch-whats-the-best-way-to-store-big-data-cost-effective/350289)

<div class="topic-metadata">

**Author:** [@basiltitus](https://discuss.elastic.co/u/basiltitus)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 9:26am UTC](https://discuss.elastic.co/t/elasticsearch-whats-the-best-way-to-store-big-data-cost-effective/350289 "2024-01-03T09:26:06Z")

</div>

We are using Basic Elasticsearch v7.4 on a single node with nearly 2TB of data. We planning to increase our retention however we are constrained by it's storage capacity. While adding disks and using multiple data path i…

---

## [I want restore my details in the managed repository like client, bucket , base path how to get old details](https://discuss.elastic.co/t/i-want-restore-my-details-in-the-managed-repository-like-client-bucket-base-path-how-to-get-old-details/350281)

<div class="topic-metadata">

**Author:** [@Gopi\_Tellakula](https://discuss.elastic.co/u/Gopi_Tellakula)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 7:53am UTC](https://discuss.elastic.co/t/i-want-restore-my-details-in-the-managed-repository-like-client-bucket-base-path-how-to-get-old-details/350281 "2024-01-03T07:53:15Z")

</div>

i want restore my details in managed repository like client, bucket , base path how to get old details, i ran some code in dev tools to create another repository it changed this managed repository details also. i need t…

---

## [Low footprint way of importing Windows Service Data](https://discuss.elastic.co/t/low-footprint-way-of-importing-windows-service-data/350282)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 7:56am UTC](https://discuss.elastic.co/t/low-footprint-way-of-importing-windows-service-data/350282 "2024-01-03T07:56:40Z")

</div>

Hello All, We are looking to import windows server service status (on or off etc) data into our ELK stack from client servers which currently have filebeat installed. Is there a way of doing this without installing met…

---

## [Parent Circuit Breaking Exception](https://discuss.elastic.co/t/parent-circuit-breaking-exception/350165)

<div class="topic-metadata">

**Author:** [@Brad\_Baker](https://discuss.elastic.co/u/Brad_Baker)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 10:01pm UTC](https://discuss.elastic.co/t/parent-circuit-breaking-exception/350165 "2024-01-02T22:01:10Z")

</div>

We setup some monitoring to watch for parent circuit breaker trips in Elasticsearch and its going off like crazy. What I am trying to figure out is how to determine what is causing it. From what I have read and understan…

---

## [Date parsing logstash](https://discuss.elastic.co/t/date-parsing-logstash/350064)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 4\
**Last updated:** [January 2, 2024, 9:14pm UTC](https://discuss.elastic.co/t/date-parsing-logstash/350064 "2024-01-02T21:14:04Z")

</div>

Hello Dears, i am trying to use syslog timestamp as @timestamp in Elasticsearch, i tried to use date filter and it gives me \_dateparsefailure in the logs when i browse them on kibana. filter Plugin snippet. filter{ …

---

## [Updating Indexed Entities](https://discuss.elastic.co/t/updating-indexed-entities/348287)

<div class="topic-metadata">

**Author:** [@Muhammad\_namjas](https://discuss.elastic.co/u/Muhammad_namjas)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 8:14pm UTC](https://discuss.elastic.co/t/updating-indexed-entities/348287 "2024-01-02T20:14:56Z")

</div>

I created a new entity connected to Hibernate Elastic Search and indexed it. Upon retrieving the indexed data, I noticed that updating the entity using the student ID resulted in deleting the existing data and re-inserti…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=248)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=250)
