# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=331

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 332

---

## [How to export large set data and write to csv using elasticsearch](https://discuss.elastic.co/t/how-to-export-large-set-data-and-write-to-csv-using-elasticsearch/351152)

<div class="topic-metadata">

**Author:** [@Bikash\_Hutait](https://discuss.elastic.co/u/Bikash_Hutait)\
**Replies:** 0\
**Last updated:** [January 16, 2024, 10:34am UTC](https://discuss.elastic.co/t/how-to-export-large-set-data-and-write-to-csv-using-elasticsearch/351152 "2024-01-16T10:34:13Z")

</div>

We have an application allowing users to export records based on search/filter criteria. I am looking for a solution to implement the "export all" functionality to a CSV file. I conducted a test utilizing the \_scroll AP…

---

## [Register percolate query with java api client ElasticSearch 8](https://discuss.elastic.co/t/register-percolate-query-with-java-api-client-elasticsearch-8/351084)

<div class="topic-metadata">

**Author:** [@TSCH](https://discuss.elastic.co/u/TSCH)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 3:46pm UTC](https://discuss.elastic.co/t/register-percolate-query-with-java-api-client-elasticsearch-8/351084 "2024-01-15T15:46:13Z")

</div>

When trying to implement a similar usecase as the elasticsearch doicumentation for the percolate query with the java api client I ran into an issue and wonder if I'm doing things wrong, or there is something missing in t…

---

## [Java::JavaLang::IllegalStateException\` for \`PipelineAction::Create\<main\>](https://discuss.elastic.co/t/java-illegalstateexception-for-pipelineaction-create-main/351142)

<div class="topic-metadata">

**Author:** [@bp\_cs](https://discuss.elastic.co/u/bp_cs)\
**Replies:** 1\
**Last updated:** [January 16, 2024, 9:58am UTC](https://discuss.elastic.co/t/java-illegalstateexception-for-pipelineaction-create-main/351142 "2024-01-16T09:58:30Z")

</div>

Thread.exclusive is deprecated, use Thread::Mutex Sending Logstash logs to D:/code/logstash/logstash-7.4.2/logs which is now configured via log4j2.properties \[2024-01-16T16:51:36,256\]\[WARN \]\[logstash.config.source.multil…

---

## [Persistent queue configuration in Windows OS using File IO](https://discuss.elastic.co/t/persistent-queue-configuration-in-windows-os-using-file-io/351145)

<div class="topic-metadata">

**Author:** [@sudipta.s](https://discuss.elastic.co/u/sudipta.s)\
**Replies:** 0\
**Last updated:** [January 16, 2024, 9:56am UTC](https://discuss.elastic.co/t/persistent-queue-configuration-in-windows-os-using-file-io/351145 "2024-01-16T09:56:39Z")

</div>

Hello team, We are looking for some support on Persistent queue configuration in windows OS. We are using file IO and exposed some shared location with all write privilege. With guided configuration in elastic documenta…

---

## [Elasticsearch snapshot is failing due to access denied exception](https://discuss.elastic.co/t/elasticsearch-snapshot-is-failing-due-to-access-denied-exception/350474)

<div class="topic-metadata">

**Author:** [@tykarthick](https://discuss.elastic.co/u/tykarthick)\
**Replies:** 15\
**Last updated:** [January 16, 2024, 9:28am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-is-failing-due-to-access-denied-exception/350474 "2024-01-16T09:28:25Z")

</div>

Hi Team, Greetings ! A POC is under progress for the Elasticsearch snapshot and restoration and this POC is on the Azure VM's Linux environment. The version of Elasticsearch is 8.6.2 with three node cluster setup. The…

---

## [Single node elasticsearch installation with podman and IPv6](https://discuss.elastic.co/t/single-node-elasticsearch-installation-with-podman-and-ipv6/351086)

<div class="topic-metadata">

**Author:** [@hitchalon](https://discuss.elastic.co/u/hitchalon)\
**Replies:** 2\
**Last updated:** [January 16, 2024, 8:40am UTC](https://discuss.elastic.co/t/single-node-elasticsearch-installation-with-podman-and-ipv6/351086 "2024-01-16T08:40:02Z")

</div>

Hi all, I am trying to install Elasticsearch by using podman on a IPv6 only host (RHEL 9.3, podman 4.6.3). Here is my run commands for elasticsearch and kibana podman run --name es01 --net elastic-v6 -p \[1000:1400:240…

---

## [Is it possible that with the help of SYSLOG we can push the present log events as well as the past history of events?](https://discuss.elastic.co/t/is-it-possible-that-with-the-help-of-syslog-we-can-push-the-present-log-events-as-well-as-the-past-history-of-events/351123)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 0\
**Last updated:** [January 16, 2024, 6:58am UTC](https://discuss.elastic.co/t/is-it-possible-that-with-the-help-of-syslog-we-can-push-the-present-log-events-as-well-as-the-past-history-of-events/351123 "2024-01-16T06:58:28Z")

</div>

Any specific configuration required for that??

---

## [Filebeat CEL Input Type - FIle Options](https://discuss.elastic.co/t/filebeat-cel-input-type-file-options/350812)

<div class="topic-metadata">

**Author:** [@bigdaddy0918](https://discuss.elastic.co/u/bigdaddy0918)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 7:40pm UTC](https://discuss.elastic.co/t/filebeat-cel-input-type-file-options/350812 "2024-01-15T19:40:12Z")

</div>

I'm using a CEL type input in Filebeat. Currently the filebeat.yml file points at a specific directory/file. What is the syntax to wildcard a portion of the file? (i.e. for the parameter resource.url: file:///home/di…

---

## [Get error when config "value\_serializer" and "key\_serializer" in output part](https://discuss.elastic.co/t/get-error-when-config-value-serializer-and-key-serializer-in-output-part/351062)

<div class="topic-metadata">

**Author:** [@Pengcheng\_Fu](https://discuss.elastic.co/u/Pengcheng_Fu)\
**Replies:** 1\
**Last updated:** [January 15, 2024, 7:34pm UTC](https://discuss.elastic.co/t/get-error-when-config-value-serializer-and-key-serializer-in-output-part/351062 "2024-01-15T19:34:19Z")

</div>

I am testing transfer data between mutile kafka cluster my configuration is below: input { kafka { bootstrap\_servers =\> "10.62.169.206:9092,10.62.220.44:9092,10.62.220.150:9092" topics =\> \["prod-sk…

---

## [Does single node Elasticsearch supports ILM ploicy](https://discuss.elastic.co/t/does-single-node-elasticsearch-supports-ilm-ploicy/350124)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 41\
**Last updated:** [January 15, 2024, 6:46pm UTC](https://discuss.elastic.co/t/does-single-node-elasticsearch-supports-ilm-ploicy/350124 "2024-01-15T18:46:05Z")

</div>

Hello, I have applied the ILM policy because the disk space usage was seen very high. But I don't see any changes in the disk space after implementing the ILM policy for filebeat. shards disk.indices disk.used disk.to…

---

## [Kubernetes deployed Elastic Agent is looped in beat restart](https://discuss.elastic.co/t/kubernetes-deployed-elastic-agent-is-looped-in-beat-restart/351054)

<div class="topic-metadata">

**Author:** [@Alphayeeeet](https://discuss.elastic.co/u/Alphayeeeet)\
**Replies:** 1\
**Last updated:** [January 15, 2024, 5:16pm UTC](https://discuss.elastic.co/t/kubernetes-deployed-elastic-agent-is-looped-in-beat-restart/351054 "2024-01-15T17:16:10Z")

</div>

As according to GitHub, I opened the post in the wrong category. That's why I am reposting: Kubernetes deployed Elastic Agent is looped in beat restart

---

## [Saved Objects link disappeared except the default space](https://discuss.elastic.co/t/saved-objects-link-disappeared-except-the-default-space/350992)

<div class="topic-metadata">

**Author:** [@Zakwan\_hajjar](https://discuss.elastic.co/u/Zakwan_hajjar)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 4:39pm UTC](https://discuss.elastic.co/t/saved-objects-link-disappeared-except-the-default-space/350992 "2024-01-15T16:39:56Z")

</div>

I'm using the latest stable version 8.11.4 and I have a strange case in Kibana that I don't have an option for "Saved Objects". This problem exists in all spaces except the default space. I am logged in as root user so I…

---

## [Question about Kibana connectors](https://discuss.elastic.co/t/question-about-kibana-connectors/351081)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 1\
**Last updated:** [January 15, 2024, 4:23pm UTC](https://discuss.elastic.co/t/question-about-kibana-connectors/351081 "2024-01-15T16:23:05Z")

</div>

Hello, I was wandering, the kibana email connetor, is assume that's different from xpack.notification.email namespace in \`elasticsearch.yml. So from a watcher I can only use the xpack one? KR Henk

---

## [How to save a time range in kibana?](https://discuss.elastic.co/t/how-to-save-a-time-range-in-kibana/351065)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 3\
**Last updated:** [January 15, 2024, 4:12pm UTC](https://discuss.elastic.co/t/how-to-save-a-time-range-in-kibana/351065 "2024-01-15T16:12:28Z")

</div>

I've seen in some kibana instances that instead of selecting the preconfigured range (1 day, 7 days, etc) you can store a custom timerange with a name. Any idea how to do it?

---

## [Providing Socket tineout exception not working in elastic java api](https://discuss.elastic.co/t/providing-socket-tineout-exception-not-working-in-elastic-java-api/350923)

<div class="topic-metadata">

**Author:** [@Divy\_Garg](https://discuss.elastic.co/u/Divy_Garg)\
**Replies:** 7\
**Last updated:** [January 15, 2024, 3:56pm UTC](https://discuss.elastic.co/t/providing-socket-tineout-exception-not-working-in-elastic-java-api/350923 "2024-01-15T15:56:29Z")

</div>

Hi I am using below libraries to connect to elasticsearch from java implementation group: 'co.elastic.clients', name: 'elasticsearch-java', version: '8.11.4' implementation group: 'org.elasticsearch.client', name: 'el…

---

## [/bin/tini: error while loading shared libraries: libc.so.6: cannot open shared object file: No such file or directory](https://discuss.elastic.co/t/bin-tini-error-while-loading-shared-libraries-libc-so-6-cannot-open-shared-object-file-no-such-file-or-directory/351077)

<div class="topic-metadata">

**Author:** [@Abdeljalil\_El\_Yousso](https://discuss.elastic.co/u/Abdeljalil_El_Yousso)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 2:44pm UTC](https://discuss.elastic.co/t/bin-tini-error-while-loading-shared-libraries-libc-so-6-cannot-open-shared-object-file-no-such-file-or-directory/351077 "2024-01-15T14:44:26Z")

</div>

how to resolve the following error if anybody encoutred it while running elasticserach 8.10.4 on docker in debian terminal /bin/tini: error while loading shared libraries: libc.so.6: cannot open shared object file: No s…

---

## [Ensuring Document Ordering in Bulk Ingestion](https://discuss.elastic.co/t/ensuring-document-ordering-in-bulk-ingestion/350972)

<div class="topic-metadata">

**Author:** [@Ivelin\_Yanev](https://discuss.elastic.co/u/Ivelin_Yanev)\
**Replies:** 11\
**Last updated:** [January 15, 2024, 2:41pm UTC](https://discuss.elastic.co/t/ensuring-document-ordering-in-bulk-ingestion/350972 "2024-01-15T14:41:04Z")

</div>

Hi everyone, I'm currently working on implementing bulk operations for documents. In my scenario, I receive PubSub messages and generate corresponding Elasticsearch documents using the data from these PubSub messages. I…

---

## [Query with must and should with ANd and OR Logic in Elasticsearch](https://discuss.elastic.co/t/query-with-must-and-should-with-and-and-or-logic-in-elasticsearch/351068)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 12:35pm UTC](https://discuss.elastic.co/t/query-with-must-and-should-with-and-and-or-logic-in-elasticsearch/351068 "2024-01-15T12:35:38Z")

</div>

Hi, I want my search work like all the search terms searched with AND results first and then with OR results. example, Search term - borosil infrastructure the result should come like - borosil infrastructure boro…

---

## [ILM is deleting after rollover](https://discuss.elastic.co/t/ilm-is-deleting-after-rollover/350525)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 4\
**Last updated:** [January 15, 2024, 11:48am UTC](https://discuss.elastic.co/t/ilm-is-deleting-after-rollover/350525 "2024-01-15T11:48:35Z")

</div>

Hi, I have set rollover after 10gb and delete after 7 days. PUT \_ilm/policy/policy1 { "policy": { "phases": { "hot": { "actions": { "rollover": { "max\_primary\_shard\_size": "10g…

---

## [Only one of the Elasticsearch Warm node is getting most of the data while shifting the data from Hot to Warm as per the ILM Policy](https://discuss.elastic.co/t/only-one-of-the-elasticsearch-warm-node-is-getting-most-of-the-data-while-shifting-the-data-from-hot-to-warm-as-per-the-ilm-policy/351064)

<div class="topic-metadata">

**Author:** [@KunwarAkanksha](https://discuss.elastic.co/u/KunwarAkanksha)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 10:47am UTC](https://discuss.elastic.co/t/only-one-of-the-elasticsearch-warm-node-is-getting-most-of-the-data-while-shifting-the-data-from-hot-to-warm-as-per-the-ilm-policy/351064 "2024-01-15T10:47:22Z")

</div>

I have Multinode Cord, Master, Hot and Warm Elasticsearch Cluster, with 5 primary and 2 replica shards , but according to ILM when the Load is shifting from hot to warm, only one of the warm node is getting most of the d…

---

## [Error when recovering snapshot](https://discuss.elastic.co/t/error-when-recovering-snapshot/350640)

<div class="topic-metadata">

**Author:** [@Epic555](https://discuss.elastic.co/u/Epic555)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 10:27am UTC](https://discuss.elastic.co/t/error-when-recovering-snapshot/350640 "2024-01-15T10:27:44Z")

</div>

I created a snapshot with curl from 1 cluster. When I try to recover a snapshot with curl on another cluster, 2nd Cluster cannot allocate all indices. Cluster 1 has 2 nodes, cluster 2 has 1 node. I have a file "snap-hb19…

---

## [Kibana not starting & Cluster Status Yellow](https://discuss.elastic.co/t/kibana-not-starting-cluster-status-yellow/351052)

<div class="topic-metadata">

**Author:** [@aguskhohar](https://discuss.elastic.co/u/aguskhohar)\
**Replies:** 3\
**Last updated:** [January 15, 2024, 10:27am UTC](https://discuss.elastic.co/t/kibana-not-starting-cluster-status-yellow/351052 "2024-01-15T10:27:18Z")

</div>

Hi guys, Could you help me, why my kibana not starting, and im check the cluster status Yellow? Collect in elastic Log : \[2024-01-14T22:53:17,827\]\[INFO \]\[o.e.i.m.MapperService \] \[Desktop\] \[.kibana-observability-ai-…

---

## [Get\_custom\_fields of vsphere.yml of metricbeat?](https://discuss.elastic.co/t/get-custom-fields-of-vsphere-yml-of-metricbeat/350809)

<div class="topic-metadata">

**Author:** [@morry48](https://discuss.elastic.co/u/morry48)\
**Replies:** 3\
**Last updated:** [January 15, 2024, 9:03am UTC](https://discuss.elastic.co/t/get-custom-fields-of-vsphere-yml-of-metricbeat/350809 "2024-01-15T09:03:11Z")

</div>

Does anyone know how to edit the area of "get\_custom\_fields" in the vsphere.yml(vsphere module) of metricbeat? I'm currently using version 7.7.0 and am wondering about how to configure the "get\_custom\_fields" to filter …

---

## [Error connecting to package registry : reason: self-signed certificate in certificate chain](https://discuss.elastic.co/t/error-connecting-to-package-registry-reason-self-signed-certificate-in-certificate-chain/351057)

<div class="topic-metadata">

**Author:** [@Gabin\_17](https://discuss.elastic.co/u/Gabin_17)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 8:40am UTC](https://discuss.elastic.co/t/error-connecting-to-package-registry-reason-self-signed-certificate-in-certificate-chain/351057 "2024-01-15T08:40:52Z")

</div>

Hello everyone ! I have this issue when i start Kibana. I saw different solution on linux but not on windows and I work on windows Failed to fetch latest version of synthetics from registry: Error connecting to package…

---

## [I'm facing .elasticsearch.bootstrap.StartupException: java.lang.IllegalArgumentException: you cannot specify a keystore and key file](https://discuss.elastic.co/t/im-facing-elasticsearch-bootstrap-startupexception-java-lang-illegalargumentexception-you-cannot-specify-a-keystore-and-key-file/350942)

<div class="topic-metadata">

**Author:** [@bshiwanand](https://discuss.elastic.co/u/bshiwanand)\
**Replies:** 4\
**Last updated:** [January 15, 2024, 8:15am UTC](https://discuss.elastic.co/t/im-facing-elasticsearch-bootstrap-startupexception-java-lang-illegalargumentexception-you-cannot-specify-a-keystore-and-key-file/350942 "2024-01-15T08:15:22Z")

</div>

I'm trying to enable xpack security enable so that internal and external communication will happen on https instead of http so please guide me how I do that, and guide me how to resolve below error. Error: {"type": "de…

---

## [Using one device to send metricbeat data from multiple devices](https://discuss.elastic.co/t/using-one-device-to-send-metricbeat-data-from-multiple-devices/350383)

<div class="topic-metadata">

**Author:** [@Lasse\_Fisker](https://discuss.elastic.co/u/Lasse_Fisker)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 8:08am UTC](https://discuss.elastic.co/t/using-one-device-to-send-metricbeat-data-from-multiple-devices/350383 "2024-01-15T08:08:42Z")

</div>

Hi I have a use case, in which I want to use one instance of metricbeat to send its own data + metricbeat data from a different instance. The scenario is as follows: Device A Has internet access Has ethernet connect…

---

## [HowTo reconfigure an ElasticAgent with an invalid Fleet-URL](https://discuss.elastic.co/t/howto-reconfigure-an-elasticagent-with-an-invalid-fleet-url/350600)

<div class="topic-metadata">

**Author:** [@m3sos](https://discuss.elastic.co/u/m3sos)\
**Replies:** 4\
**Last updated:** [January 15, 2024, 7:23am UTC](https://discuss.elastic.co/t/howto-reconfigure-an-elasticagent-with-an-invalid-fleet-url/350600 "2024-01-15T07:23:03Z")

</div>

My elastic agents are running in a kubernetes cluster (daemon set). For debugging purposes I configured a fleet server url pointing to a wiremock instance (pod only) running temporarily in the cluster too. After debuggi…

---

## [Configure elastic search query to alert when the average of Total time taken exceeds a threshold](https://discuss.elastic.co/t/configure-elastic-search-query-to-alert-when-the-average-of-total-time-taken-exceeds-a-threshold/350274)

<div class="topic-metadata">

**Author:** [@Vanya](https://discuss.elastic.co/u/Vanya)\
**Replies:** 2\
**Last updated:** [January 15, 2024, 6:02am UTC](https://discuss.elastic.co/t/configure-elastic-search-query-to-alert-when-the-average-of-total-time-taken-exceeds-a-threshold/350274 "2024-01-15T06:02:47Z")

</div>

Hi All, I am trying to write a search query for Kibana rules for it to alert when the average of the total time taken exceeds a certain thereshold. Have tried using aggegators, filters and also scripts but on testing th…

---

## [Index pattern has no field but the other index pattern is working properly, i can't also connect to mapping using curl](https://discuss.elastic.co/t/index-pattern-has-no-field-but-the-other-index-pattern-is-working-properly-i-cant-also-connect-to-mapping-using-curl/350540)

<div class="topic-metadata">

**Author:** [@Epangilinangt](https://discuss.elastic.co/u/Epangilinangt)\
**Replies:** 3\
**Last updated:** [January 15, 2024, 3:15am UTC](https://discuss.elastic.co/t/index-pattern-has-no-field-but-the-other-index-pattern-is-working-properly-i-cant-also-connect-to-mapping-using-curl/350540 "2024-01-15T03:15:18Z")

</div>

Index pattern has no field but the other index pattern is working properly, i can't also connect to mapping using curl

---

## [How to aggregate non-nested fields in a nested aggregation?](https://discuss.elastic.co/t/how-to-aggregate-non-nested-fields-in-a-nested-aggregation/351044)

<div class="topic-metadata">

**Author:** [@Chanseok](https://discuss.elastic.co/u/Chanseok)\
**Replies:** 0\
**Last updated:** [January 15, 2024, 1:33am UTC](https://discuss.elastic.co/t/how-to-aggregate-non-nested-fields-in-a-nested-aggregation/351044 "2024-01-15T01:33:05Z")

</div>

The prices.adult field in "lowest\_price" is non-nested fields in a nest. The current "lowest\_price" value is null. How can I get that value? // Aggregation code "aggs": { "destination": { "nested": { …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=330)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=332)
