# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=494

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 495

---

## [Logstash not stopping if elasticsearch down - although persistent pipeline queue is enabled](https://discuss.elastic.co/t/logstash-not-stopping-if-elasticsearch-down-although-persistent-pipeline-queue-is-enabled/318403)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 1\
**Last updated:** [November 21, 2022, 9:32am UTC](https://discuss.elastic.co/t/logstash-not-stopping-if-elasticsearch-down-although-persistent-pipeline-queue-is-enabled/318403 "2022-11-21T09:32:12Z")

</div>

Hi, I am using multi-pipelining in logstash. I encountered issues before when I want to stop logstash and elasticsearch is unavailable. Thought the issue was the following: logstash has read events from redis and pro…

---

## [Master-Slave architecture Log Collection and Mapping](https://discuss.elastic.co/t/master-slave-architecture-log-collection-and-mapping/319410)

<div class="topic-metadata">

**Author:** [@Poongkuyil\_Muse](https://discuss.elastic.co/u/Poongkuyil_Muse)\
**Replies:** 0\
**Last updated:** [November 21, 2022, 9:28am UTC](https://discuss.elastic.co/t/master-slave-architecture-log-collection-and-mapping/319410 "2022-11-21T09:28:55Z")

</div>

I am able to retrieve apache web logs from one system and visualize them in kibana. However, we have more than one system that work as master-slave. My Scenario: If there are 3 systems A,B,C A - Master (IP1: 192.165.…

---

## [Check if index pattern exists using curl](https://discuss.elastic.co/t/check-if-index-pattern-exists-using-curl/319408)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [November 21, 2022, 9:24am UTC](https://discuss.elastic.co/t/check-if-index-pattern-exists-using-curl/319408 "2022-11-21T09:24:56Z")

</div>

Hi i am using ansible to create index patterns and data views in elk. Before creating a data view for a index pattern i would want to check if index pattern exists. Currently using this command curl -I -XHEAD --write-o…

---

## [Failed to ingest Data to an Index](https://discuss.elastic.co/t/failed-to-ingest-data-to-an-index/319405)

<div class="topic-metadata">

**Author:** [@Jecks\_Speed](https://discuss.elastic.co/u/Jecks_Speed)\
**Replies:** 0\
**Last updated:** [November 21, 2022, 8:58am UTC](https://discuss.elastic.co/t/failed-to-ingest-data-to-an-index/319405 "2022-11-21T08:58:53Z")

</div>

Hi everyone, Good day! I am newbie to ELK. currently i am working a return data of an API. upon checking my target body it has the return data from API call, However after processing these data using mutate and some if…

---

## [Cloudflare Logpush Elasticsearch](https://discuss.elastic.co/t/cloudflare-logpush-elasticsearch/319393)

<div class="topic-metadata">

**Author:** [@tomikoooo](https://discuss.elastic.co/u/tomikoooo)\
**Replies:** 1\
**Last updated:** [November 21, 2022, 7:18am UTC](https://discuss.elastic.co/t/cloudflare-logpush-elasticsearch/319393 "2022-11-21T07:18:59Z")

</div>

Im trying to connect elasticsearch to cloudflare via logpush. I have no choice to use ssl since cloudflare does not accept http. Whenever I tried to use the SSL configuration it does not start. I tried running netstat -…

---

## [Elasticsearch m1 macbook arm64 xpack.ml](https://discuss.elastic.co/t/elasticsearch-m1-macbook-arm64-xpack-ml/319387)

<div class="topic-metadata">

**Author:** [@zzdntjd](https://discuss.elastic.co/u/zzdntjd)\
**Replies:** 1\
**Last updated:** [November 21, 2022, 6:59am UTC](https://discuss.elastic.co/t/elasticsearch-m1-macbook-arm64-xpack-ml/319387 "2022-11-21T06:59:51Z")

</div>

hello! os : (apple silicon m1 macbook) mac os ventura elasticsearch version : 7.10.1 problem i start elasticsearch on m1 macbook air. suddenly, error to log on term. error is need to (xpack.ml.enabled: false) setti…

---

## [Reports Generation on Kibana](https://discuss.elastic.co/t/reports-generation-on-kibana/317319)

<div class="topic-metadata">

**Author:** [@tifty](https://discuss.elastic.co/u/tifty)\
**Replies:** 4\
**Last updated:** [October 25, 2022, 2:12pm UTC](https://discuss.elastic.co/t/reports-generation-on-kibana/317319 "2022-10-25T14:12:45Z")

</div>

Is it possible to generate .PNG or .PDF reports directly from the free version of Kibana? Or can I use any 3rd party tool that embeds with Kibana? Thanks

---

## [Sort data per date in kibana discover](https://discuss.elastic.co/t/sort-data-per-date-in-kibana-discover/318918)

<div class="topic-metadata">

**Author:** [@2019240081](https://discuss.elastic.co/u/2019240081)\
**Replies:** 4\
**Last updated:** [November 21, 2022, 6:49am UTC](https://discuss.elastic.co/t/sort-data-per-date-in-kibana-discover/318918 "2022-11-21T06:49:24Z")

</div>

I want to filter log dadta per date in kibana discover and this is the only way I've discovered so far How can I filter data per date more easily ?

---

## [Cluster with all system indices in RED status](https://discuss.elastic.co/t/cluster-with-all-system-indices-in-red-status/319285)

<div class="topic-metadata">

**Author:** [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Replies:** 2\
**Last updated:** [November 21, 2022, 6:26am UTC](https://discuss.elastic.co/t/cluster-with-all-system-indices-in-red-status/319285 "2022-11-21T06:26:14Z")

</div>

Hello, I have a cluster where i lost some nodes that are storing primaries & replicas of all system indices. index shard prirep state .reporting-2022-09-18 0 p UNASSIGNED .reporting-2022-09-18 0 r UNASSIGNED …

---

## [Kibana : Not able to generate large reports](https://discuss.elastic.co/t/kibana-not-able-to-generate-large-reports/318145)

<div class="topic-metadata">

**Author:** [@shobhit](https://discuss.elastic.co/u/shobhit)\
**Replies:** 4\
**Last updated:** [November 21, 2022, 5:52am UTC](https://discuss.elastic.co/t/kibana-not-able-to-generate-large-reports/318145 "2022-11-21T05:52:16Z")

</div>

Hi, I am using ELK Version 7.17.2 . We are trying to generate reports for more then a million rows CSV. Getting below error. Error Error: Max attempts reached (3). Queue timeout reached. ###kibana.yml \*server.host…

---

## [Trying to connect to elasticsearch using jenkins logstash plugin](https://discuss.elastic.co/t/trying-to-connect-to-elasticsearch-using-jenkins-logstash-plugin/319264)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [November 21, 2022, 5:35am UTC](https://discuss.elastic.co/t/trying-to-connect-to-elasticsearch-using-jenkins-logstash-plugin/319264 "2022-11-21T05:35:39Z")

</div>

Hi I've installed logstash plugin on jenkins. and elk stack 8.5.1 with authentication. I can access elasticsearch only using https with -k flag. How can i configure logstash to access elasticsaearch. when i enter onl…

---

## [Elasticsearch cluster migration from 7.12 to 8.5](https://discuss.elastic.co/t/elasticsearch-cluster-migration-from-7-12-to-8-5/319271)

<div class="topic-metadata">

**Author:** [@satendra1987](https://discuss.elastic.co/u/satendra1987)\
**Replies:** 10\
**Last updated:** [November 21, 2022, 5:02am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-migration-from-7-12-to-8-5/319271 "2022-11-21T05:02:30Z")

</div>

Hi, we are running an 1 node elasticsearch cluster on 7.12. we want to setup a 3 node cluster on 8.5. can someone let me know how to migrate the existing indexes to new cluster. Thanks Satendra

---

## [Kibana - important size of sdtout file](https://discuss.elastic.co/t/kibana-important-size-of-sdtout-file/319166)

<div class="topic-metadata">

**Author:** [@Stef072](https://discuss.elastic.co/u/Stef072)\
**Replies:** 1\
**Last updated:** [November 21, 2022, 2:11am UTC](https://discuss.elastic.co/t/kibana-important-size-of-sdtout-file/319166 "2022-11-21T02:11:08Z")

</div>

Hi there, The stdout file we have in /var/log/kibana seems to increase without end reaching todayy 2.1Gb. Is there a strategy to manage this file to control hard disk occupation ? Thanks

---

## [{"statusCode":503,"error":"Service Unavailable","message":"License is not available."}](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/319150)

<div class="topic-metadata">

**Author:** [@auser](https://discuss.elastic.co/u/auser)\
**Replies:** 6\
**Last updated:** [November 21, 2022, 2:04am UTC](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/319150 "2022-11-21T02:04:09Z")

</div>

I recently configured https for kibana running in three different environments. One of them works fine while the other two have issue as mentioned below - 1 - {"statusCode":503,"error":"Service Unavailable","message":"L…

---

## [Failed to determine the health of the cluster](https://discuss.elastic.co/t/failed-to-determine-the-health-of-the-cluster/318818)

<div class="topic-metadata">

**Author:** [@richardvk](https://discuss.elastic.co/u/richardvk)\
**Replies:** 1\
**Last updated:** [November 20, 2022, 11:33pm UTC](https://discuss.elastic.co/t/failed-to-determine-the-health-of-the-cluster/318818 "2022-11-20T23:33:16Z")

</div>

Im trying to enable clustering as per: I get this when creating a token: root@elk-1 ~ # /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s node ERROR: Failed to determine the health of the cluster…

---

## [Error creating a new index : validation failed maximum shards open](https://discuss.elastic.co/t/error-creating-a-new-index-validation-failed-maximum-shards-open/318564)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 3\
**Last updated:** [November 20, 2022, 5:32pm UTC](https://discuss.elastic.co/t/error-creating-a-new-index-validation-failed-maximum-shards-open/318564 "2022-11-20T17:32:39Z")

</div>

Hi, I need to create a new index and get the following error: Could you please help? command: POST /myindex1213/\_doc error message: validatiion failed 1: this action would add \[2\] total shards, but this cluster cur…

---

## [Where can I see my Certificate Fingerprint?](https://discuss.elastic.co/t/where-can-i-see-my-certificate-fingerprint/319335)

<div class="topic-metadata">

**Author:** [@asd11](https://discuss.elastic.co/u/asd11)\
**Replies:** 6\
**Last updated:** [November 20, 2022, 3:50pm UTC](https://discuss.elastic.co/t/where-can-i-see-my-certificate-fingerprint/319335 "2022-11-20T15:50:20Z")

</div>

The documentation says: the CA fingerprint logged by the server at initial startup. However I can't find it. Is it in security -\> CA certificates? If yes, than I can download that file, but how can I get the fingerpr…

---

## [Filebeat on ECK cannot create an index due to user privilage problemes](https://discuss.elastic.co/t/filebeat-on-eck-cannot-create-an-index-due-to-user-privilage-problemes/319364)

<div class="topic-metadata">

**Author:** [@khaled\_belgacem](https://discuss.elastic.co/u/khaled_belgacem)\
**Replies:** 0\
**Last updated:** [November 20, 2022, 11:50am UTC](https://discuss.elastic.co/t/filebeat-on-eck-cannot-create-an-index-due-to-user-privilage-problemes/319364 "2022-11-20T11:50:44Z")

</div>

Hello Everyone, On my way discovering ECK I'm running a filebeat instance on my ECK cluster so I can read from a file "ip.txt" and index it to a specific index in elasticsearch named "vpndetect", I keep getting an error…

---

## [iframeCode Single Metric Viewer](https://discuss.elastic.co/t/iframecode-single-metric-viewer/317354)

<div class="topic-metadata">

**Author:** [@Ismael\_Alvarez](https://discuss.elastic.co/u/Ismael_Alvarez)\
**Replies:** 0\
**Last updated:** [October 24, 2022, 11:21pm UTC](https://discuss.elastic.co/t/iframecode-single-metric-viewer/317354 "2022-10-24T23:21:14Z")

</div>

hey there! I need to share Single Metric Viewer as embed code Snapshot, attached example. Best regards

---

## [How can I increase number of values of visualize](https://discuss.elastic.co/t/how-can-i-increase-number-of-values-of-visualize/319289)

<div class="topic-metadata">

**Author:** [@yts85205107](https://discuss.elastic.co/u/yts85205107)\
**Replies:** 4\
**Last updated:** [November 20, 2022, 6:49am UTC](https://discuss.elastic.co/t/how-can-i-increase-number-of-values-of-visualize/319289 "2022-11-20T06:49:08Z")

</div>

Hi, I want to increase number of values of visualize, but I can't found the setting to increase. now, the number of values is 1000, I want to increase to 3000, how can I increase? Thanks.

---

## [How to get size of each event/record in logstash /elasticsearch](https://discuss.elastic.co/t/how-to-get-size-of-each-event-record-in-logstash-elasticsearch/319235)

<div class="topic-metadata">

**Author:** [@priti](https://discuss.elastic.co/u/priti)\
**Replies:** 1\
**Last updated:** [November 20, 2022, 5:57am UTC](https://discuss.elastic.co/t/how-to-get-size-of-each-event-record-in-logstash-elasticsearch/319235 "2022-11-20T05:57:28Z")

</div>

How to get size of each event/record in logstash /elasticsearch. Based on that size i am trying to calculate size of each application in that index.

---

## [Kibana installation error](https://discuss.elastic.co/t/kibana-installation-error/318913)

<div class="topic-metadata">

**Author:** [@Vivek\_Arumugam](https://discuss.elastic.co/u/Vivek_Arumugam)\
**Replies:** 16\
**Last updated:** [November 19, 2022, 4:28pm UTC](https://discuss.elastic.co/t/kibana-installation-error/318913 "2022-11-19T16:28:49Z")

</div>

Hi All, I have installed Elasticsearch "8.5.0". I keep getting the following problem when attempting to install Kibana.

---

## [Logstash split the child json to the parent layer](https://discuss.elastic.co/t/logstash-split-the-child-json-to-the-parent-layer/319339)

<div class="topic-metadata">

**Author:** [@lnsane](https://discuss.elastic.co/u/lnsane)\
**Replies:** 1\
**Last updated:** [November 19, 2022, 3:32pm UTC](https://discuss.elastic.co/t/logstash-split-the-child-json-to-the-parent-layer/319339 "2022-11-19T15:32:14Z")

</div>

this is json { "@timestamp" =\> 2022-11-19T06:19:08.249Z, "database" =\> "12", "data": { "a": 1, "b": 2 } } how resolve to { "@timestamp" =\> 2022-11-19T06:19:08.249Z, "database" =\> "12…

---

## [Sort products by ids stored in product\_cat index](https://discuss.elastic.co/t/sort-products-by-ids-stored-in-product-cat-index/318772)

<div class="topic-metadata">

**Author:** [@kiko](https://discuss.elastic.co/u/kiko)\
**Replies:** 5\
**Last updated:** [November 19, 2022, 1:49pm UTC](https://discuss.elastic.co/t/sort-products-by-ids-stored-in-product-cat-index/318772 "2022-11-19T13:49:29Z")

</div>

I have a products index which I now need to sort using ordered list of IDs stored in each product category document (in product\_categories index), like so: // product index { id:1, name: "coco" }, { id:2, name: "hazel" …

---

## [ECK - Kibana zone awareness not working](https://discuss.elastic.co/t/eck-kibana-zone-awareness-not-working/319332)

<div class="topic-metadata">

**Author:** [@marone](https://discuss.elastic.co/u/marone)\
**Replies:** 6\
**Last updated:** [November 19, 2022, 1:41pm UTC](https://discuss.elastic.co/t/eck-kibana-zone-awareness-not-working/319332 "2022-11-19T13:41:08Z")

</div>

Hello, I'm trying to configure Kibana to be zone awareness. I tried the following configuration but Kibana instances run in the same zones: apiVersion: kibana.k8s.elastic.co/v1 kind: Kibana metadata: name: kibana …

---

## [Java access denied when starting elasticsearch](https://discuss.elastic.co/t/java-access-denied-when-starting-elasticsearch/319333)

<div class="topic-metadata">

**Author:** [@johnny1891](https://discuss.elastic.co/u/johnny1891)\
**Replies:** 2\
**Last updated:** [November 19, 2022, 11:08am UTC](https://discuss.elastic.co/t/java-access-denied-when-starting-elasticsearch/319333 "2022-11-19T11:08:49Z")

</div>

Hi, I'm following this tutorial to install ELK stack How to install Elastic SIEM and Elastic EDR - On The Hunt but after adding certificates, I try to restart the service but I get this: I downloaded elastic today o…

---

## [Elasticsearch Fails to Start Java Lang Illegal State Exception: No match found](https://discuss.elastic.co/t/elasticsearch-fails-to-start-java-lang-illegal-state-exception-no-match-found/319239)

<div class="topic-metadata">

**Author:** [@D3epDiv3r](https://discuss.elastic.co/u/D3epDiv3r)\
**Replies:** 7\
**Last updated:** [November 19, 2022, 1:00am UTC](https://discuss.elastic.co/t/elasticsearch-fails-to-start-java-lang-illegal-state-exception-no-match-found/319239 "2022-11-19T01:00:32Z")

</div>

Hello folks, I have been trying to get Elastic Stack to run for at least 2 days now, I have been given a project in school that requires me to use Elasticsearch 5.2.0 specifically (Logstash 5.2.0, and Kibana 5.2.0) I hav…

---

## [Filtering aggregation results based on nested objects in ElasticSearch](https://discuss.elastic.co/t/filtering-aggregation-results-based-on-nested-objects-in-elasticsearch/319313)

<div class="topic-metadata">

**Author:** [@kornikopic](https://discuss.elastic.co/u/kornikopic)\
**Replies:** 0\
**Last updated:** [November 18, 2022, 3:11pm UTC](https://discuss.elastic.co/t/filtering-aggregation-results-based-on-nested-objects-in-elasticsearch/319313 "2022-11-18T15:11:59Z")

</div>

In my database, I have 2 tables such as: +------------+ +-------------+ | Project | | Deliverable | +------------+ +-------------+ | id +----------+ project\_id | | |1 …

---

## [Roadmap for the Elastic Stack Subscription model](https://discuss.elastic.co/t/roadmap-for-the-elastic-stack-subscription-model/319302)

<div class="topic-metadata">

**Author:** [@hanna](https://discuss.elastic.co/u/hanna)\
**Replies:** 1\
**Last updated:** [November 18, 2022, 9:23pm UTC](https://discuss.elastic.co/t/roadmap-for-the-elastic-stack-subscription-model/319302 "2022-11-18T21:23:21Z")

</div>

what are the plans in the future regarding the Elastic Stack subscriptions? Can I be sure that the features of the basic subscription will remain available free of charge in the future? I would like to avoid unexpected c…

---

## [Threatintel module filebeat](https://discuss.elastic.co/t/threatintel-module-filebeat/317858)

<div class="topic-metadata">

**Author:** [@emmanuel\_stevens\_LED](https://discuss.elastic.co/u/emmanuel_stevens_LED)\
**Replies:** 6\
**Last updated:** [November 18, 2022, 4:25pm UTC](https://discuss.elastic.co/t/threatintel-module-filebeat/317858 "2022-11-18T16:25:07Z")

</div>

Hello, I activate the theatintel module for filebeat but still doesn t get any datas i have this in my logs ''' Nov 1 03:00:02 hostname filebeat\[560069\]: {"log.level":"info","@timestamp":"2022-11-01T03:00:02.308Z"…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=493)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=495)
