# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=453

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 454

---

## [Logstash from multiple beats server](https://discuss.elastic.co/t/logstash-from-multiple-beats-server/323491)

<div class="topic-metadata">

**Author:** [@hasan.idriss](https://discuss.elastic.co/u/hasan.idriss)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 12:08pm UTC](https://discuss.elastic.co/t/logstash-from-multiple-beats-server/323491 "2023-01-19T12:08:45Z")

</div>

hello every one, i am using logstash to receive data from multiple server using winlogbeats over the port 5044 I want to create an index for each server based on the server name can some one provide me with the logsta…

---

## [Dev Tools Console can't retrieve data - Error Bad Gateway 502](https://discuss.elastic.co/t/dev-tools-console-cant-retrieve-data-error-bad-gateway-502/323500)

<div class="topic-metadata">

**Author:** [@Kamil\_BdBelfort](https://discuss.elastic.co/u/Kamil_BdBelfort)\
**Replies:** 3\
**Last updated:** [January 19, 2023, 11:51am UTC](https://discuss.elastic.co/t/dev-tools-console-cant-retrieve-data-error-bad-gateway-502/323500 "2023-01-19T11:51:09Z")

</div>

Hi there, Can anyone explain me please why do I get this error when I am running elasticsearch on localhost? See screenshot: Thanks a lot, Kamil

---

## [elasticsearch.AuthorizationException: AuthorizationException(403, 'security\_exception', 'action \[cluster:monitor/main\] is unauthorized for user\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*this action is grante d by the cluster privileges \[monitor,manage,all\]')](https://discuss.elastic.co/t/elasticsearch-authorizationexception-authorizationexception-403-security-exception-action-cluster-monitor-main-is-unauthorized-for-user-this-action-is-grante-d-by-the-cluster-privileges-monitor-manage-all/323499)

<div class="topic-metadata">

**Author:** [@savitaSUtar](https://discuss.elastic.co/u/savitaSUtar)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 11:42am UTC](https://discuss.elastic.co/t/elasticsearch-authorizationexception-authorizationexception-403-security-exception-action-cluster-monitor-main-is-unauthorized-for-user-this-action-is-grante-d-by-the-cluster-privileges-monitor-manage-all/323499 "2023-01-19T11:42:54Z")

</div>

I am writting a Elastic search connection code from python like : es = Elasticsearch("url", basic\_auth=("Username", "password")) print(es.info()) but getting error as : elasticsearch.AuthorizationException: Authorizat…

---

## [Disable SSO forsome ECE Deployments](https://discuss.elastic.co/t/disable-sso-forsome-ece-deployments/323503)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 11:32am UTC](https://discuss.elastic.co/t/disable-sso-forsome-ece-deployments/323503 "2023-01-19T11:32:02Z")

</div>

Hello, I have noticed that system deployments are not doing the SSO. Is there a way to also disable this for a user created deployments? Or I want a deployment in ECE to ask me for my credentials, is this possible? K…

---

## [How to visualize max aggregation inside terms aggregation in Kibana?](https://discuss.elastic.co/t/how-to-visualize-max-aggregation-inside-terms-aggregation-in-kibana/323406)

<div class="topic-metadata">

**Author:** [@cr\_168328](https://discuss.elastic.co/u/cr_168328)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 11:25am UTC](https://discuss.elastic.co/t/how-to-visualize-max-aggregation-inside-terms-aggregation-in-kibana/323406 "2023-01-19T11:25:57Z")

</div>

I have an index exams which contains data related to students who passed some exams. A student can attempt an exam multiple times. Hence there may be more than one document in the index for a particular student and exam…

---

## [org.elasticsearch.action.UnavailableShardsException: \[ . async—searchl \[01 primary shard is not active Timeout: \[1m](https://discuss.elastic.co/t/org-elasticsearch-action-unavailableshardsexception-async-searchl-01-primary-shard-is-not-active-timeout-1m/323466)

<div class="topic-metadata">

**Author:** [@forabraham1](https://discuss.elastic.co/u/forabraham1)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 11:17am UTC](https://discuss.elastic.co/t/org-elasticsearch-action-unavailableshardsexception-async-searchl-01-primary-shard-is-not-active-timeout-1m/323466 "2023-01-19T11:17:19Z")

</div>

After upgrading ES from 7.9 to 7.17 ES is throwing this exception "org.elasticsearch.action.UnavailableShardsException: \[ . async—searchl \[01 primary shard is not active Timeout: \[1m". Due to which Kibana isn't returnin…

---

## [Error occurrences per 1000 requests - Multiple queries on a single graph](https://discuss.elastic.co/t/error-occurrences-per-1000-requests-multiple-queries-on-a-single-graph/323421)

<div class="topic-metadata">

**Author:** [@Nefeli\_Tavoulari](https://discuss.elastic.co/u/Nefeli_Tavoulari)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 11:05am UTC](https://discuss.elastic.co/t/error-occurrences-per-1000-requests-multiple-queries-on-a-single-graph/323421 "2023-01-19T11:05:20Z")

</div>

Is it possible displaying the frequency of a specific error per 1000 operations on a visualization on Kibana, without Kibana Lens? Using filters I can get the count of errors and the count of operations and display them …

---

## [Would turning off swap require extra configuration](https://discuss.elastic.co/t/would-turning-off-swap-require-extra-configuration/323342)

<div class="topic-metadata">

**Author:** [@hasancansaral](https://discuss.elastic.co/u/hasancansaral)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 10:46am UTC](https://discuss.elastic.co/t/would-turning-off-swap-require-extra-configuration/323342 "2023-01-19T10:46:43Z")

</div>

I have a 3 node cluster, all master eligible and all having 4 cores, 16gb memory. I have 2 read/write indexes with none of them above 1 GB/1 million documents. Each index is 1 primary shard and 2 replicas. I've recently…

---

## [No data is generated Observability](https://discuss.elastic.co/t/no-data-is-generated-observability/323288)

<div class="topic-metadata">

**Author:** [@den2](https://discuss.elastic.co/u/den2)\
**Replies:** 6\
**Last updated:** [January 19, 2023, 10:24am UTC](https://discuss.elastic.co/t/no-data-is-generated-observability/323288 "2023-01-19T10:24:23Z")

</div>

Hello! I can’t create data, it constantly throws me to the start page, I need help

---

## [Failed to save to index due to maximum shard overlimit](https://discuss.elastic.co/t/failed-to-save-to-index-due-to-maximum-shard-overlimit/323424)

<div class="topic-metadata">

**Author:** [@aagirre92](https://discuss.elastic.co/u/aagirre92)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 10:13am UTC](https://discuss.elastic.co/t/failed-to-save-to-index-due-to-maximum-shard-overlimit/323424 "2023-01-19T10:13:29Z")

</div>

Hello, I am running a web application (in my own windows server machine) called Automation Anywhere A360. This web application uses a local Elasticsearch instance to handle its Audit Logs. Cluster health endpoint shows…

---

## [Unassigned Shards when New Index was created: Cluster Yellow](https://discuss.elastic.co/t/unassigned-shards-when-new-index-was-created-cluster-yellow/323483)

<div class="topic-metadata">

**Author:** [@rpraveenverma](https://discuss.elastic.co/u/rpraveenverma)\
**Replies:** 3\
**Last updated:** [January 19, 2023, 9:32am UTC](https://discuss.elastic.co/t/unassigned-shards-when-new-index-was-created-cluster-yellow/323483 "2023-01-19T09:32:54Z")

</div>

New Index Creation led to Unassigned Shards and Yellow Cluster State. Context : It happened when relocation for one node was already in progress. Checked explanation for its state. It says : Relocation Throttled , rea…

---

## [Kibana bar chart legend set constant color](https://discuss.elastic.co/t/kibana-bar-chart-legend-set-constant-color/322288)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 7\
**Last updated:** [January 19, 2023, 8:34am UTC](https://discuss.elastic.co/t/kibana-bar-chart-legend-set-constant-color/322288 "2023-01-19T08:34:13Z")

</div>

Hello, I've a simple requirement where in I need to set constant color for bar and legends. ex: Error:Always red, Success:Always greeen,Initialize:Always yellow...etc The current behaviour of kibana dosen't fullfill …

---

## [Using premade dashboard with Logstash](https://discuss.elastic.co/t/using-premade-dashboard-with-logstash/323315)

<div class="topic-metadata">

**Author:** [@TonisSaarjoe](https://discuss.elastic.co/u/TonisSaarjoe)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 7:48am UTC](https://discuss.elastic.co/t/using-premade-dashboard-with-logstash/323315 "2023-01-19T07:48:23Z")

</div>

Hello there, Some what new to ELK. So I have 3 different machines Monitoring, Logstash and Beats Monitoring - hosts Kibana and Elasticsearch. secure machine allows only Logstash Logstash - hosts only Logstash. Beats…

---

## [Scaling of cardinality sub-aggregation](https://discuss.elastic.co/t/scaling-of-cardinality-sub-aggregation/320264)

<div class="topic-metadata">

**Author:** [@astrodi](https://discuss.elastic.co/u/astrodi)\
**Replies:** 16\
**Last updated:** [January 19, 2023, 7:20am UTC](https://discuss.elastic.co/t/scaling-of-cardinality-sub-aggregation/320264 "2023-01-19T07:20:55Z")

</div>

Hello there, as continuation of this discussion thread, what other options are there in Elasticsearch to scale aggregation? I have experimented with: adding client nodes (didn't help for big result-set) playing wit…

---

## [Logstash stops elasticsearch](https://discuss.elastic.co/t/logstash-stops-elasticsearch/323017)

<div class="topic-metadata">

**Author:** [@bas\_kos](https://discuss.elastic.co/u/bas_kos)\
**Replies:** 27\
**Last updated:** [January 19, 2023, 7:17am UTC](https://discuss.elastic.co/t/logstash-stops-elasticsearch/323017 "2023-01-19T07:17:45Z")

</div>

After starting logstash, elasticsearch stops. If logstash is not running, then elasticsearch and kibana work and I go to the kibana web interface. I tried to cleanly remove logstash and install with default settings, I…

---

## [Logstash JSON parser error](https://discuss.elastic.co/t/logstash-json-parser-error/323356)

<div class="topic-metadata">

**Author:** [@Ramesh\_Perumal](https://discuss.elastic.co/u/Ramesh_Perumal)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 7:01am UTC](https://discuss.elastic.co/t/logstash-json-parser-error/323356 "2023-01-19T07:01:29Z")

</div>

Hi, We are getting json parser warning message as below: \[2023-01-08T13:21:12,936\]\[WARN \]\[logstash.filters.json \] Error parsing json {:source=\>"slmPart", :raw=\>"{"action":UPDATE,"information":"Signing CSR for root …

---

## [Data flows through nodes](https://discuss.elastic.co/t/data-flows-through-nodes/323078)

<div class="topic-metadata">

**Author:** [@yinbucheng](https://discuss.elastic.co/u/yinbucheng)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 6:19am UTC](https://discuss.elastic.co/t/data-flows-through-nodes/323078 "2023-01-19T06:19:14Z")

</div>

The elastic cluster node I built has a separate data role master role coordinate role ingest role. I also configured the ingest pipeline, which nodes I will pass through when I insert data. The exposed cluster link is …

---

## [Elastic search and kibana configuration](https://discuss.elastic.co/t/elastic-search-and-kibana-configuration/323091)

<div class="topic-metadata">

**Author:** [@keerthana7](https://discuss.elastic.co/u/keerthana7)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 5:58am UTC](https://discuss.elastic.co/t/elastic-search-and-kibana-configuration/323091 "2023-01-19T05:58:48Z")

</div>

I couldn't configure elastic. Can anyone tell me what is the problem here and how to solve it?

---

## [How to build QueryBuilder to search for the map of entry's in ElasticSearch index](https://discuss.elastic.co/t/how-to-build-querybuilder-to-search-for-the-map-of-entrys-in-elasticsearch-index/323469)

<div class="topic-metadata">

**Author:** [@SandhyaRani](https://discuss.elastic.co/u/SandhyaRani)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 4:40am UTC](https://discuss.elastic.co/t/how-to-build-querybuilder-to-search-for-the-map-of-entrys-in-elasticsearch-index/323469 "2023-01-19T04:40:10Z")

</div>

I would need queryBuilder to search the index with entire map of values and return documents only if all map values matched in ES index. I could do for set of values like below val sampleSet = setOf("foo", "bar") val …

---

## [Problem with element BY.ID for autologin to kibana using python selenium webdriver](https://discuss.elastic.co/t/problem-with-element-by-id-for-autologin-to-kibana-using-python-selenium-webdriver/322355)

<div class="topic-metadata">

**Author:** [@Reka\_Novana](https://discuss.elastic.co/u/Reka_Novana)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 3:43am UTC](https://discuss.elastic.co/t/problem-with-element-by-id-for-autologin-to-kibana-using-python-selenium-webdriver/322355 "2023-01-19T03:43:14Z")

</div>

I want to make an auto screenshot script using selenium python but I can't find element id of the username and password that I found is only random element id for username and password. Could you please inform me if I ca…

---

## [Advanced JSON input](https://discuss.elastic.co/t/advanced-json-input/322366)

<div class="topic-metadata">

**Author:** [@imsudo](https://discuss.elastic.co/u/imsudo)\
**Replies:** 5\
**Last updated:** [January 19, 2023, 2:08am UTC](https://discuss.elastic.co/t/advanced-json-input/322366 "2023-01-19T02:08:05Z")

</div>

I have a data table with data, Metrics, aggregation as count. ( as it shows all the log count) see attached image(if avl) i wish to get only the count of 5xx errors (500-599) in downstreamStatus data field using advanc…

---

## [K8S GKE Deployment - Connect to Internal DNS](https://discuss.elastic.co/t/k8s-gke-deployment-connect-to-internal-dns/323463)

<div class="topic-metadata">

**Author:** [@Jennifer\_Klemisch](https://discuss.elastic.co/u/Jennifer_Klemisch)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 1:41am UTC](https://discuss.elastic.co/t/k8s-gke-deployment-connect-to-internal-dns/323463 "2023-01-19T01:41:25Z")

</div>

I have a Terraform created GKE. Then I use Yaml files to install ES (8.6.0) and Kibana. As part of my terraform IAAS I reserve 2 IPs, and 2 "google\_dns\_record\_set" (es\_dns and kb\_dns) which sit on our company shared VP…

---

## [Pb with format during a CSV import](https://discuss.elastic.co/t/pb-with-format-during-a-csv-import/323267)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 1:33am UTC](https://discuss.elastic.co/t/pb-with-format-during-a-csv-import/323267 "2023-01-19T01:33:58Z")

</div>

Hi all, Sorry in advance for my bad english and my poor knowledge on ELK. I need to import regularly a csv file like this : data\_id iso event\_id\_cnty event\_id\_no\_cnty event\_date year time\_precision event\_type sub\_…

---

## [Elasticsearch high cpu usage](https://discuss.elastic.co/t/elasticsearch-high-cpu-usage/323079)

<div class="topic-metadata">

**Author:** [@yeziblo](https://discuss.elastic.co/u/yeziblo)\
**Replies:** 2\
**Last updated:** [January 18, 2023, 11:29pm UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-usage/323079 "2023-01-18T23:29:07Z")

</div>

Hi everyone. My Es cluster had high cpu usage at 3:30 am today, below is grafana monitoring: And the kibana monitoring: I don't have a clue, because in my nginx log files, I didn't see any request rise signif…

---

## [Are there any cron jobs I can perform daily to keep my cluster healthy?](https://discuss.elastic.co/t/are-there-any-cron-jobs-i-can-perform-daily-to-keep-my-cluster-healthy/323150)

<div class="topic-metadata">

**Author:** [@SemperFi](https://discuss.elastic.co/u/SemperFi)\
**Replies:** 3\
**Last updated:** [January 18, 2023, 11:16pm UTC](https://discuss.elastic.co/t/are-there-any-cron-jobs-i-can-perform-daily-to-keep-my-cluster-healthy/323150 "2023-01-18T23:16:18Z")

</div>

I've got a very basic Elasticsearch cluster set up on my server to support search for a Xenforo forum. My technical knowledge is good enough to be dangerous. Lately Elasticsearch is crashing about once a week and I'm w…

---

## [.alerts-security.alerts-default\* indice removed suddenly](https://discuss.elastic.co/t/alerts-security-alerts-default-indice-removed-suddenly/323434)

<div class="topic-metadata">

**Author:** [@raghiboon](https://discuss.elastic.co/u/raghiboon)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 10:03pm UTC](https://discuss.elastic.co/t/alerts-security-alerts-default-indice-removed-suddenly/323434 "2023-01-18T22:03:56Z")

</div>

Hi everybody. i just removed .alerts-security.alerts-default-0000 suddenly after i was working with rules and made my dashboards. is there a way to recreate it? because it gives me this error: Bulk indexing of signals…

---

## [Multipipeline configuration](https://discuss.elastic.co/t/multipipeline-configuration/323272)

<div class="topic-metadata">

**Author:** [@SaM9](https://discuss.elastic.co/u/SaM9)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 9:55pm UTC](https://discuss.elastic.co/t/multipipeline-configuration/323272 "2023-01-18T21:55:31Z")

</div>

How can I create a pipeline configuration in Logstash for two different logs that I'm receiving from syslog, the syslog auditd log and the web server log, and separate them to get different outputs? I have tried using an…

---

## [Limitations for Managed Logstash pipelines](https://discuss.elastic.co/t/limitations-for-managed-logstash-pipelines/323450)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 0\
**Last updated:** [January 18, 2023, 7:29pm UTC](https://discuss.elastic.co/t/limitations-for-managed-logstash-pipelines/323450 "2023-01-18T19:29:04Z")

</div>

Hello, I want to start using the managed pipelines in the Kibana GUI. From the documentation it is not really clear what the limitations are. As an example if you want to include a Ruby script I presume this script must…

---

## [Has anyone see/solved this kibana error?](https://discuss.elastic.co/t/has-anyone-see-solved-this-kibana-error/323325)

<div class="topic-metadata">

**Author:** [@mwitmer](https://discuss.elastic.co/u/mwitmer)\
**Replies:** 8\
**Last updated:** [January 18, 2023, 6:17pm UTC](https://discuss.elastic.co/t/has-anyone-see-solved-this-kibana-error/323325 "2023-01-18T18:17:34Z")

</div>

{"type":"log","@timestamp":"2023-01-17T13:02:00Z","tags":\["error","elasticsearch","data"\],"pid":818,"message":"\[ResponseError\]: Response Error"} Getting A LOT of these errors and the dashboards are not updating.

---

## [Unable to move the reports from Ansible to logstash](https://discuss.elastic.co/t/unable-to-move-the-reports-from-ansible-to-logstash/322977)

<div class="topic-metadata">

**Author:** [@janaka8](https://discuss.elastic.co/u/janaka8)\
**Replies:** 1\
**Last updated:** [January 18, 2023, 6:03pm UTC](https://discuss.elastic.co/t/unable-to-move-the-reports-from-ansible-to-logstash/322977 "2023-01-18T18:03:46Z")

</div>

Team, We have a ansible setup in our environment and even are using a Kibana Dashboard for resporting purpose. We are getting below attached error while pushing the reports from ansible logs to kibana dashboard. { "co…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=452)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=454)
