# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=340

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 341

---

## [Elasticsearch: What's the best way to store big-data cost effective](https://discuss.elastic.co/t/elasticsearch-whats-the-best-way-to-store-big-data-cost-effective/350289)

<div class="topic-metadata">

**Author:** [@basiltitus](https://discuss.elastic.co/u/basiltitus)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 9:26am UTC](https://discuss.elastic.co/t/elasticsearch-whats-the-best-way-to-store-big-data-cost-effective/350289 "2024-01-03T09:26:06Z")

</div>

We are using Basic Elasticsearch v7.4 on a single node with nearly 2TB of data. We planning to increase our retention however we are constrained by it's storage capacity. While adding disks and using multiple data path i…

---

## [Retrieve inner\_hits when searching multiple kNN fields in same nested document](https://discuss.elastic.co/t/retrieve-inner-hits-when-searching-multiple-knn-fields-in-same-nested-document/350024)

<div class="topic-metadata">

**Author:** [@Jasper\_Simon](https://discuss.elastic.co/u/Jasper_Simon)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 8:20am UTC](https://discuss.elastic.co/t/retrieve-inner-hits-when-searching-multiple-knn-fields-in-same-nested-document/350024 "2024-01-03T08:20:42Z")

</div>

I've got this use case (examples here are simplified to the essentials) where I want to do a knn search on multiple vectors of the same nested document inside a larger document, and be able to distinguish which of the ne…

---

## [I want restore my details in the managed repository like client, bucket , base path how to get old details](https://discuss.elastic.co/t/i-want-restore-my-details-in-the-managed-repository-like-client-bucket-base-path-how-to-get-old-details/350281)

<div class="topic-metadata">

**Author:** [@Gopi\_Tellakula](https://discuss.elastic.co/u/Gopi_Tellakula)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 7:53am UTC](https://discuss.elastic.co/t/i-want-restore-my-details-in-the-managed-repository-like-client-bucket-base-path-how-to-get-old-details/350281 "2024-01-03T07:53:15Z")

</div>

i want restore my details in managed repository like client, bucket , base path how to get old details, i ran some code in dev tools to create another repository it changed this managed repository details also. i need t…

---

## [Low footprint way of importing Windows Service Data](https://discuss.elastic.co/t/low-footprint-way-of-importing-windows-service-data/350282)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 7:56am UTC](https://discuss.elastic.co/t/low-footprint-way-of-importing-windows-service-data/350282 "2024-01-03T07:56:40Z")

</div>

Hello All, We are looking to import windows server service status (on or off etc) data into our ELK stack from client servers which currently have filebeat installed. Is there a way of doing this without installing met…

---

## [Identify the reasons of not active indexes](https://discuss.elastic.co/t/identify-the-reasons-of-not-active-indexes/350268)

<div class="topic-metadata">

**Author:** [@Clyo\_Michel\_Mayela\_R](https://discuss.elastic.co/u/Clyo_Michel_Mayela_R)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 1:20am UTC](https://discuss.elastic.co/t/identify-the-reasons-of-not-active-indexes/350268 "2024-01-03T01:20:34Z")

</div>

Getting this error message "ElasticsearchException: not all primary shards of \[.geoip\_databases\] index are active" how to found the root case that is causing this problem?

---

## [Parent Circuit Breaking Exception](https://discuss.elastic.co/t/parent-circuit-breaking-exception/350165)

<div class="topic-metadata">

**Author:** [@Brad\_Baker](https://discuss.elastic.co/u/Brad_Baker)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 10:01pm UTC](https://discuss.elastic.co/t/parent-circuit-breaking-exception/350165 "2024-01-02T22:01:10Z")

</div>

We setup some monitoring to watch for parent circuit breaker trips in Elasticsearch and its going off like crazy. What I am trying to figure out is how to determine what is causing it. From what I have read and understan…

---

## [Date parsing logstash](https://discuss.elastic.co/t/date-parsing-logstash/350064)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 4\
**Last updated:** [January 2, 2024, 9:14pm UTC](https://discuss.elastic.co/t/date-parsing-logstash/350064 "2024-01-02T21:14:04Z")

</div>

Hello Dears, i am trying to use syslog timestamp as @timestamp in Elasticsearch, i tried to use date filter and it gives me \_dateparsefailure in the logs when i browse them on kibana. filter Plugin snippet. filter{ …

---

## [Unable to do anything properly with ES](https://discuss.elastic.co/t/unable-to-do-anything-properly-with-es/350244)

<div class="topic-metadata">

**Author:** [@hich\_testone](https://discuss.elastic.co/u/hich_testone)\
**Replies:** 18\
**Last updated:** [January 2, 2024, 9:13pm UTC](https://discuss.elastic.co/t/unable-to-do-anything-properly-with-es/350244 "2024-01-02T21:13:19Z")

</div>

Dear All, I followed exactly the guide here to install ES :slight\_smile: But when I run : sudo /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s node I keep getting this error : ERROR: Failed to …

---

## [HighVolume Hosts are dropping data](https://discuss.elastic.co/t/highvolume-hosts-are-dropping-data/349582)

<div class="topic-metadata">

**Author:** [@JJ007](https://discuss.elastic.co/u/JJ007)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 8:37pm UTC](https://discuss.elastic.co/t/highvolume-hosts-are-dropping-data/349582 "2024-01-02T20:37:15Z")

</div>

Hi, We have certain high volume hosts that are sending data to EventHub via winlogbeat. These hosts are dropping some data and I dont see any indication of this in logs. I see certain outputs.events.failed but dont see…

---

## [Updating Indexed Entities](https://discuss.elastic.co/t/updating-indexed-entities/348287)

<div class="topic-metadata">

**Author:** [@Muhammad\_namjas](https://discuss.elastic.co/u/Muhammad_namjas)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 8:14pm UTC](https://discuss.elastic.co/t/updating-indexed-entities/348287 "2024-01-02T20:14:56Z")

</div>

I created a new entity connected to Hibernate Elastic Search and indexed it. Upon retrieving the indexed data, I noticed that updating the entity using the student ID resulted in deleting the existing data and re-inserti…

---

## [Elasticsearch query](https://discuss.elastic.co/t/elasticsearch-query/350260)

<div class="topic-metadata">

**Author:** [@Bibhudutta\_Mohanty](https://discuss.elastic.co/u/Bibhudutta_Mohanty)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 7:13pm UTC](https://discuss.elastic.co/t/elasticsearch-query/350260 "2024-01-02T19:13:54Z")

</div>

I have a field called @editors in my index . It has multiple values like , i would like only show the last editor name in last\_editors field . I want to write a query where i can only fetch the the last editor name in e…

---

## [Logstash-plugin command for preparing offline pack is not working on 8.11.3](https://discuss.elastic.co/t/logstash-plugin-command-for-preparing-offline-pack-is-not-working-on-8-11-3/349302)

<div class="topic-metadata">

**Author:** [@ebiibe82](https://discuss.elastic.co/u/ebiibe82)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 5:56pm UTC](https://discuss.elastic.co/t/logstash-plugin-command-for-preparing-offline-pack-is-not-working-on-8-11-3/349302 "2024-01-02T17:56:10Z")

</div>

Hello All, I am new to Elastic Stack. I have installed Logstash 8.11.3 using deb package on Ubuntu 22.04 Server. On top of it, I have installed logstash-output-syslog plugin. Till this point, it works fine. After this, …

---

## [ElasticSearch Nested Search Analyzer not working](https://discuss.elastic.co/t/elasticsearch-nested-search-analyzer-not-working/350256)

<div class="topic-metadata">

**Author:** [@pasupathi-raja](https://discuss.elastic.co/u/pasupathi-raja)\
**Replies:** 2\
**Last updated:** [January 2, 2024, 4:57pm UTC](https://discuss.elastic.co/t/elasticsearch-nested-search-analyzer-not-working/350256 "2024-01-02T16:57:25Z")

</div>

Index Creation I'm creating index with nested property and assigning analyzers to it both index and search time as follows. PUT /test\_index\_pasu { "settings": { "analysis": { "analyzer": { "keyword\_…

---

## [Kibana Vega visualizations don't honor courier:ignoreFilterIfFieldNotInIndex settings](https://discuss.elastic.co/t/kibana-vega-visualizations-dont-honor-courier-ignorefilteriffieldnotinindex-settings/348962)

<div class="topic-metadata">

**Author:** [@Prakash\_Gupta](https://discuss.elastic.co/u/Prakash_Gupta)\
**Replies:** 2\
**Last updated:** [January 2, 2024, 4:13pm UTC](https://discuss.elastic.co/t/kibana-vega-visualizations-dont-honor-courier-ignorefilteriffieldnotinindex-settings/348962 "2024-01-02T16:13:34Z")

</div>

I have a dashboard where I have multiple metrics visualizations from different indices including lenses and vega. If I apply a filter on the dashboard, I just wanted the visualizations which are having the field should o…

---

## [Agent Enrollment: failed to fix permissions](https://discuss.elastic.co/t/agent-enrollment-failed-to-fix-permissions/350254)

<div class="topic-metadata">

**Author:** [@DefensiveDepth](https://discuss.elastic.co/u/DefensiveDepth)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 4:00pm UTC](https://discuss.elastic.co/t/agent-enrollment-failed-to-fix-permissions/350254 "2024-01-02T16:00:43Z")

</div>

Cannot consistently replicate this issue, but it does pop up every so often. Deploying 8.10.4 Fleet-connected Agent to Oracle Linux 9: "Error: failed to fix permissions: chmod /opt/Elastic/Agent/data/elastic-agent-a92c…

---

## [Elasticsearch cluster resiliency and availability](https://discuss.elastic.co/t/elasticsearch-cluster-resiliency-and-availability/350033)

<div class="topic-metadata">

**Author:** [@artechkey](https://discuss.elastic.co/u/artechkey)\
**Replies:** 12\
**Last updated:** [January 2, 2024, 3:56pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-resiliency-and-availability/350033 "2024-01-02T15:56:48Z")

</div>

Hi, We are currently running ES on a 4 node cluster where 2 nodes are in DC 1 & 2 in DC 2. We have a third node in DC 1 with master-voting-only role. The n/w latency b/w DC 1 & DC 2 is negligible. DC 1 - 2 nodes (all r…

---

## [Index not found in Logs](https://discuss.elastic.co/t/index-not-found-in-logs/349828)

<div class="topic-metadata">

**Author:** [@anoman](https://discuss.elastic.co/u/anoman)\
**Replies:** 2\
**Last updated:** [January 2, 2024, 3:27pm UTC](https://discuss.elastic.co/t/index-not-found-in-logs/349828 "2024-01-02T15:27:28Z")

</div>

I have installed Microsoft Defender Endpoint integration to collect logs. The agent was installed properly and the other configuration. But If I go to Elastic Search -\> Discover and try to create a new data view, I can'…

---

## [Kibana not accessible via Kubernetes Ingress](https://discuss.elastic.co/t/kibana-not-accessible-via-kubernetes-ingress/349162)

<div class="topic-metadata">

**Author:** [@patrick-94](https://discuss.elastic.co/u/patrick-94)\
**Replies:** 4\
**Last updated:** [January 2, 2024, 3:18pm UTC](https://discuss.elastic.co/t/kibana-not-accessible-via-kubernetes-ingress/349162 "2024-01-02T15:18:04Z")

</div>

Hey, i have the following Problem which I copy and paste it from Github, anyone here who can help me out with this? This is the Original Post to Github: Kibana not accessible via Ingress · Issue #172630 · elastic/kiban…

---

## [Visualization Lens bar display limit](https://discuss.elastic.co/t/visualization-lens-bar-display-limit/350212)

<div class="topic-metadata">

**Author:** [@Liam619](https://discuss.elastic.co/u/Liam619)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 3:17pm UTC](https://discuss.elastic.co/t/visualization-lens-bar-display-limit/350212 "2024-01-02T15:17:52Z")

</div>

Hi everyone and happy new year. I have a question regarding Visual Lens -\> Bar Chart. I'm trying to display more bars in my chart, during my testing stage, it found that the number of bar charts that can display with a…

---

## [Potential memory leak using tcp input?](https://discuss.elastic.co/t/potential-memory-leak-using-tcp-input/349968)

<div class="topic-metadata">

**Author:** [@udp\_issues\_are\_one](https://discuss.elastic.co/u/udp_issues_are_one)\
**Replies:** 14\
**Last updated:** [January 2, 2024, 3:15pm UTC](https://discuss.elastic.co/t/potential-memory-leak-using-tcp-input/349968 "2024-01-02T15:15:08Z")

</div>

Hello, we are using logstash to collect sflow. We use fluentd at the ingest point, which forwards flows to logstash to do some processing and push to the elastic cloud. These both reside on the same box and largely wor…

---

## [Error: Limit of total fields \[1000\] has been exceeded but index limit is higher](https://discuss.elastic.co/t/error-limit-of-total-fields-1000-has-been-exceeded-but-index-limit-is-higher/350103)

<div class="topic-metadata">

**Author:** [@MColeman](https://discuss.elastic.co/u/MColeman)\
**Replies:** 7\
**Last updated:** [January 2, 2024, 3:00pm UTC](https://discuss.elastic.co/t/error-limit-of-total-fields-1000-has-been-exceeded-but-index-limit-is-higher/350103 "2024-01-02T15:00:37Z")

</div>

I'm re-indexing some data from our old cluster into a new one. I pre-created my index (logstash-2023.10.02) and changed the total field mappings to 4000, the same as the old index on the old host. If I look at the new i…

---

## [Elasticsearch performance testing](https://discuss.elastic.co/t/elasticsearch-performance-testing/350228)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 2:55pm UTC](https://discuss.elastic.co/t/elasticsearch-performance-testing/350228 "2024-01-02T14:55:29Z")

</div>

Hi all, We are trying to come up with performance tests, stress tests etc to calculate throughput and identify bottlenecks in our elasticsearch cluster. We are using elasticsearch exporter to export metrics from the clu…

---

## [How list index and size using python](https://discuss.elastic.co/t/how-list-index-and-size-using-python/350235)

<div class="topic-metadata">

**Author:** [@pratik\_jain163](https://discuss.elastic.co/u/pratik_jain163)\
**Replies:** 2\
**Last updated:** [January 2, 2024, 2:35pm UTC](https://discuss.elastic.co/t/how-list-index-and-size-using-python/350235 "2024-01-02T14:35:19Z")

</div>

i tried to write one Python code for get ES index and size but it gave me a huge json output and I was not able to find an exact result. how we can do this. es.indices.stats(index=index)

---

## [Null pointer exception | co.elastic.clients.elasticsearch.\_types.InlineScript](https://discuss.elastic.co/t/null-pointer-exception-co-elastic-clients-elasticsearch-types-inlinescript/350122)

<div class="topic-metadata">

**Author:** [@ravneet21](https://discuss.elastic.co/u/ravneet21)\
**Replies:** 0\
**Last updated:** [December 29, 2023, 10:15am UTC](https://discuss.elastic.co/t/null-pointer-exception-co-elastic-clients-elasticsearch-types-inlinescript/350122 "2023-12-29T10:15:47Z")

</div>

After migration from Rest High Level Client 7.17.1 to Elastic Java API client 8.6.2, I am getting nullpointer exception in InlineScript creation if any key's value is passed as null. Earlier with HLRC, the null values we…

---

## [Elasticagent - filebeat is still increasing memory](https://discuss.elastic.co/t/elasticagent-filebeat-is-still-increasing-memory/350211)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 2:07pm UTC](https://discuss.elastic.co/t/elasticagent-filebeat-is-still-increasing-memory/350211 "2024-01-02T14:07:33Z")

</div>

Hello, we are using ELK 8.11 and we have figured out that after installing elastic agent on windows and linux machines, they are 2 processes filebeat that are still increasing/allocation RAM more and more RAM. Even it …

---

## [How to add ssl certificate config parameters for AWS RDS MySQL connection for metricbeat](https://discuss.elastic.co/t/how-to-add-ssl-certificate-config-parameters-for-aws-rds-mysql-connection-for-metricbeat/350080)

<div class="topic-metadata">

**Author:** [@Chandrashekar](https://discuss.elastic.co/u/Chandrashekar)\
**Replies:** 2\
**Last updated:** [January 2, 2024, 1:57pm UTC](https://discuss.elastic.co/t/how-to-add-ssl-certificate-config-parameters-for-aws-rds-mysql-connection-for-metricbeat/350080 "2024-01-02T13:57:46Z")

</div>

Hi I am trying to configure the AWS RDS metric using metricbeat mysql module. I have enabled the require\_secure\_transport ON for aws rds parametergroup Below is the mysql.yml (/etc/metricbeat/modules.d/mysql.yml) mo…

---

## [Two Logstash nodes. Same config. Persistent queue filling only in one of them](https://discuss.elastic.co/t/two-logstash-nodes-same-config-persistent-queue-filling-only-in-one-of-them/350229)

<div class="topic-metadata">

**Author:** [@nahiko](https://discuss.elastic.co/u/nahiko)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 1:34pm UTC](https://discuss.elastic.co/t/two-logstash-nodes-same-config-persistent-queue-filling-only-in-one-of-them/350229 "2024-01-02T13:34:31Z")

</div>

Hello! I have a 3 node Elasticsearch cluster, 2 Logstash nodes and about 100 filebeats sending data to Logstash. Every piece is 7.17 Both Logstash nodes have the exact same configuration. There is a 16 GB persistent q…

---

## [Logstash inconsistency while reading csv data](https://discuss.elastic.co/t/logstash-inconsistency-while-reading-csv-data/348881)

<div class="topic-metadata">

**Author:** [@iko](https://discuss.elastic.co/u/iko)\
**Replies:** 8\
**Last updated:** [January 2, 2024, 1:15pm UTC](https://discuss.elastic.co/t/logstash-inconsistency-while-reading-csv-data/348881 "2024-01-02T13:15:05Z")

</div>

Hello, We are using Logstash for parsing csv data and load them into Postgresql and then after making proper transformation we move that data to Elasticsearch by using same Logstash . We don't have any problem about tra…

---

## [Kibana 审计功能](https://discuss.elastic.co/t/kibana/350219)

<div class="topic-metadata">

**Author:** [@wq1357226](https://discuss.elastic.co/u/wq1357226)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 10:04am UTC](https://discuss.elastic.co/t/kibana/350219 "2024-01-02T10:04:37Z")

</div>

kibana7.11.2咋样开启审计日志功能，记录在目标日志中或者展示到控制台上，根据官网文档添加配置重启，无报错，也无日志输出

---

## [Filebeat not deleting disk queue segment files](https://discuss.elastic.co/t/filebeat-not-deleting-disk-queue-segment-files/349094)

<div class="topic-metadata">

**Author:** [@vis20953](https://discuss.elastic.co/u/vis20953)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 10:04am UTC](https://discuss.elastic.co/t/filebeat-not-deleting-disk-queue-segment-files/349094 "2024-01-02T10:04:18Z")

</div>

Hi friends, We are experiencing an issue where the Filebeat service does not delete the segment files in the disk queue, resulting in the service not sending log entries to Logstash when the max\_size has been reached: …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=339)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=341)
