# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=341

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 342

---

## [Kibana v8(beat)和V7主题版本的区别](https://discuss.elastic.co/t/kibana-v8-beat-v7/350217)

<div class="topic-metadata">

**Author:** [@wq1357226](https://discuss.elastic.co/u/wq1357226)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 10:01am UTC](https://discuss.elastic.co/t/kibana-v8-beat-v7/350217 "2024-01-02T10:01:19Z")

</div>

kibana7.11.2提供V8（beat）和V7两种版本选择，有什么区别呢

---

## [Certificate pinning in Elasticsearch](https://discuss.elastic.co/t/certificate-pinning-in-elasticsearch/350214)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 9:55am UTC](https://discuss.elastic.co/t/certificate-pinning-in-elasticsearch/350214 "2024-01-02T09:55:54Z")

</div>

Hi, We are using Elasticsearch 7.17.0 and using azure storage blobs for snapshots. We recently received a general notification from azure about certificate pinning. I believe we do not have any such configuration tha…

---

## [Logstash upgrade issue - 8.11.3 version](https://discuss.elastic.co/t/logstash-upgrade-issue-8-11-3-version/350132)

<div class="topic-metadata">

**Author:** [@siva0030](https://discuss.elastic.co/u/siva0030)\
**Replies:** 7\
**Last updated:** [January 2, 2024, 9:23am UTC](https://discuss.elastic.co/t/logstash-upgrade-issue-8-11-3-version/350132 "2024-01-02T09:23:40Z")

</div>

Hello Team, Good evening! Today I have upgraded the Logstash from version 8.10.4 to 8.11.3 version. After the upgrade the Logstash is keep restarting and throwing below errors. This type of FATAL error is coming for a…

---

## [Esrally creat index error,class\_cast\_exception](https://discuss.elastic.co/t/esrally-creat-index-error-class-cast-exception/350215)

<div class="topic-metadata">

**Author:** [@zhouxuanxuan](https://discuss.elastic.co/u/zhouxuanxuan)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 9:19am UTC](https://discuss.elastic.co/t/esrally-creat-index-error-class-cast-exception/350215 "2024-01-02T09:19:44Z")

</div>

\[ERROR\] Cannot race. Error in load generator \[0\] Cannot run task \[create-index\]: Request returned an error. Error type: transport, Description: class\_cast\_exception ({'error': {'root\_cause': \[{'type': 'class\_cast\_except…

---

## [Encountered a retryable error (will retry with exponential backoff) {:code=\>413}](https://discuss.elastic.co/t/encountered-a-retryable-error-will-retry-with-exponential-backoff-code-413/349802)

<div class="topic-metadata">

**Author:** [@sathishkumarD](https://discuss.elastic.co/u/sathishkumarD)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 9:02am UTC](https://discuss.elastic.co/t/encountered-a-retryable-error-will-retry-with-exponential-backoff-code-413/349802 "2024-01-02T09:02:25Z")

</div>

Elastic search and Logstash version: 8.5.1 Getting below error from logstash when trying to transfer files to elasticsearch. Could someone help me to fix the issue. \[ERROR\]\[logstash.outputs.elasticsearch\]\[main\]\[532e27b…

---

## [Elasticsearch 7.16 shard recovery slow](https://discuss.elastic.co/t/elasticsearch-7-16-shard-recovery-slow/349952)

<div class="topic-metadata">

**Author:** [@wangxiangyu](https://discuss.elastic.co/u/wangxiangyu)\
**Replies:** 6\
**Last updated:** [January 2, 2024, 8:51am UTC](https://discuss.elastic.co/t/elasticsearch-7-16-shard-recovery-slow/349952 "2024-01-02T08:51:47Z")

</div>

hi, The elasticsearch cluster has 6 hot node and 4 cold node. One cold node is removed caused by hardware failure. So lots of missing replica shards( about 20TB) began to recover. But I found the recovery process was v…

---

## [.NET 8 - ElasticsearchClientException: The client is unable to verify that the server is Elasticsearch due to an unsuccessful product check call](https://discuss.elastic.co/t/net-8-elasticsearchclientexception-the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/350208)

<div class="topic-metadata">

**Author:** [@Urbancsik\_Gergely](https://discuss.elastic.co/u/Urbancsik_Gergely)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 8:34am UTC](https://discuss.elastic.co/t/net-8-elasticsearchclientexception-the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/350208 "2024-01-02T08:34:37Z")

</div>

Hello. We upgrade our application to .net 8, and and we also upgrade the latest NEST library: version: \<PackageReference Include="NEST" Version="7.17.5" /\> \<PackageReference Include="NEST.JsonNetSerializer" Version="7.…

---

## [Kibana\_error](https://discuss.elastic.co/t/kibana-error/349585)

<div class="topic-metadata">

**Author:** [@sossoulokoariel](https://discuss.elastic.co/u/sossoulokoariel)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 8:30am UTC](https://discuss.elastic.co/t/kibana-error/349585 "2024-01-02T08:30:48Z")

</div>

Hi community, hope you're well. I'm in the process of implementing the ELK stack as part of my dissertation project. For a few weeks I haven't logged in, but today I logged in, but the web interface puts Kibana is not re…

---

## [Fail Setup Logstash](https://discuss.elastic.co/t/fail-setup-logstash/350203)

<div class="topic-metadata">

**Author:** [@Septianingrum.17](https://discuss.elastic.co/u/Septianingrum.17)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 8:23am UTC](https://discuss.elastic.co/t/fail-setup-logstash/350203 "2024-01-02T08:23:05Z")

</div>

Hi, I tried setting up logstash in my environment, previously I had 3 elasticsearch nodes and 1 kibana. I followed the steps" based on the URL: https://www.elastic.co/blog/configuring-ssl-tls-and-https-to-secure-elasti…

---

## [Ignore\_inactive does not work in filebeat with filestream config type](https://discuss.elastic.co/t/ignore-inactive-does-not-work-in-filebeat-with-filestream-config-type/349111)

<div class="topic-metadata">

**Author:** [@josepcorrea](https://discuss.elastic.co/u/josepcorrea)\
**Replies:** 7\
**Last updated:** [January 2, 2024, 8:15am UTC](https://discuss.elastic.co/t/ignore-inactive-does-not-work-in-filebeat-with-filestream-config-type/349111 "2024-01-02T08:15:05Z")

</div>

When I use the filestream type instead of the log type, filebeat always reads the entire log file from the beginning. - type: filestream id: test\_id enable: true paths: - "/usr/share/filebeat/inputs.d/\*.log" …

---

## [Failed to Fetching the Redis Info and keyspace logs to Kibana](https://discuss.elastic.co/t/failed-to-fetching-the-redis-info-and-keyspace-logs-to-kibana/350201)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 8:10am UTC](https://discuss.elastic.co/t/failed-to-fetching-the-redis-info-and-keyspace-logs-to-kibana/350201 "2024-01-02T08:10:10Z")

</div>

So my task was to install the metricbeat and enable the redis module to pick the INFO and Keyspace values. By providing that I was facing lot of issues mostly on TCP related. I have tried multiple ways to mitigate this b…

---

## [Kibana8.4.3 & nginx，nginx returns 502 bad gateway](https://discuss.elastic.co/t/kibana8-4-3-nginx-nginx-returns-502-bad-gateway/350197)

<div class="topic-metadata">

**Author:** [@gaygayGuys](https://discuss.elastic.co/u/gaygayGuys)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 7:29am UTC](https://discuss.elastic.co/t/kibana8-4-3-nginx-nginx-returns-502-bad-gateway/350197 "2024-01-02T07:29:19Z")

</div>

hello everyone ! i need help !!!! when i use nginx to proxy kibana ,i find a tricky problem. at the beginning ,everything is ok. but several minutes later, 502 bad gateway is starting to appear! i hava no idea to solve…

---

## [Little help understanding a document query issue](https://discuss.elastic.co/t/little-help-understanding-a-document-query-issue/350198)

<div class="topic-metadata">

**Author:** [@Oscar\_Llerena](https://discuss.elastic.co/u/Oscar_Llerena)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 7:29am UTC](https://discuss.elastic.co/t/little-help-understanding-a-document-query-issue/350198 "2024-01-02T07:29:47Z")

</div>

Hi everyone, happy new year! Can somebody please help me understanding the following issue? I have Elasticsearch (Elastic Defend) & Kibana in one server and Fleet in other separated. The monitoring agents are in a virt…

---

## [Where if anywhere does ES documentation explain about metadata, specifically index creation datetimes?](https://discuss.elastic.co/t/where-if-anywhere-does-es-documentation-explain-about-metadata-specifically-index-creation-datetimes/350185)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 4\
**Last updated:** [January 1, 2024, 10:57pm UTC](https://discuss.elastic.co/t/where-if-anywhere-does-es-documentation-explain-about-metadata-specifically-index-creation-datetimes/350185 "2024-01-01T22:57:57Z")

</div>

This in an application context, not "human consumption". With a bit of searching I finally found this answer. The up-to-date (v. 8.11) documentation for this appears to be here, "cat indices API". But there it says "ca…

---

## [Invalid version of beats protocol: 69](https://discuss.elastic.co/t/invalid-version-of-beats-protocol-69/349830)

<div class="topic-metadata">

**Author:** [@e-ferrari](https://discuss.elastic.co/u/e-ferrari)\
**Replies:** 10\
**Last updated:** [January 1, 2024, 10:28pm UTC](https://discuss.elastic.co/t/invalid-version-of-beats-protocol-69/349830 "2024-01-01T22:28:56Z")

</div>

Hello, I'm completely new to ELK. I'm reading the doc and try to execute this: But i got an error from logstash: \[2023-12-21T23:21:37,978\]\[WARN \]\[io.netty.channel.DefaultChannelPipeline\]\[main\]\[c6b88577022f3da3a78380…

---

## [Date Column has some rows with NULL - strict\_date\_optional\_time causes Exception](https://discuss.elastic.co/t/date-column-has-some-rows-with-null-strict-date-optional-time-causes-exception/350164)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 23\
**Last updated:** [January 1, 2024, 5:11pm UTC](https://discuss.elastic.co/t/date-column-has-some-rows-with-null-strict-date-optional-time-causes-exception/350164 "2024-01-01T17:11:46Z")

</div>

All this time, I use \[strict\_date\_optional\_time||yyyy-MM-dd HH:mm:ss.SSS||yyyy-MM-dd HH:mm:ss.SS||yyyy-MM-dd HH:mm:ss||yyyy-MM-dd HH:mm:ss.S\] To parse in columns with dates. Now, I have a csv file whose columns have ro…

---

## [Does Elasticsearch clients try to request to the node that has the primary shard of a specific doc?](https://discuss.elastic.co/t/does-elasticsearch-clients-try-to-request-to-the-node-that-has-the-primary-shard-of-a-specific-doc/350181)

<div class="topic-metadata">

**Author:** [@AmirrezaRiahi](https://discuss.elastic.co/u/AmirrezaRiahi)\
**Replies:** 3\
**Last updated:** [January 1, 2024, 3:49pm UTC](https://discuss.elastic.co/t/does-elasticsearch-clients-try-to-request-to-the-node-that-has-the-primary-shard-of-a-specific-doc/350181 "2024-01-01T15:49:50Z")

</div>

From my understanding, nodes only can perform write operations on documents if they own their primary shard. Therefore if we have 2 nodes A, B and A owns the primary shard of the doc D, if the client asks node B to modif…

---

## [Attempt to create Lens visualization produces an error "Cannot read properties of undefined (reading 'localeCompare')"](https://discuss.elastic.co/t/attempt-to-create-lens-visualization-produces-an-error-cannot-read-properties-of-undefined-reading-localecompare/350010)

<div class="topic-metadata">

**Author:** [@Nicole\_Hirshler](https://discuss.elastic.co/u/Nicole_Hirshler)\
**Replies:** 4\
**Last updated:** [January 1, 2024, 12:29pm UTC](https://discuss.elastic.co/t/attempt-to-create-lens-visualization-produces-an-error-cannot-read-properties-of-undefined-reading-localecompare/350010 "2024-01-01T12:29:42Z")

</div>

Since the upgrade to 7.17.12 ELK, I cannot create Lens visualization. I searched the internet and found some post saying that it can be related to the security. ELK is configured in my setup with two users: elastic and s…

---

## [Conditional formatting for data and colors according to input field available for dashboard users](https://discuss.elastic.co/t/conditional-formatting-for-data-and-colors-according-to-input-field-available-for-dashboard-users/350177)

<div class="topic-metadata">

**Author:** [@Magdy](https://discuss.elastic.co/u/Magdy)\
**Replies:** 0\
**Last updated:** [January 1, 2024, 7:17am UTC](https://discuss.elastic.co/t/conditional-formatting-for-data-and-colors-according-to-input-field-available-for-dashboard-users/350177 "2024-01-01T07:17:38Z")

</div>

Create text input on the screen and compare it with the value in the tree map to change the background of cells accordingly.

---

## [Why data is inserting in index in delete phase, why not new index ... are we missing any configuration?](https://discuss.elastic.co/t/why-data-is-inserting-in-index-in-delete-phase-why-not-new-index-are-we-missing-any-configuration/350054)

<div class="topic-metadata">

**Author:** [@Shahzaib\_Khan](https://discuss.elastic.co/u/Shahzaib_Khan)\
**Replies:** 3\
**Last updated:** [January 1, 2024, 7:06am UTC](https://discuss.elastic.co/t/why-data-is-inserting-in-index-in-delete-phase-why-not-new-index-are-we-missing-any-configuration/350054 "2024-01-01T07:06:07Z")

</div>

I am facing an issue with Elasticsearch where, even after the rollover phase is successfully completed and a new index is created, data continues to be inserted into the old rollover index instead of the newly created in…

---

## [Elasticserach installation on linux preferences](https://discuss.elastic.co/t/elasticserach-installation-on-linux-preferences/350169)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 0\
**Last updated:** [January 1, 2024, 5:45am UTC](https://discuss.elastic.co/t/elasticserach-installation-on-linux-preferences/350169 "2024-01-01T05:45:39Z")

</div>

in order to install the latest (8.11.1) elasticsearch cluster in a production environment (oracle linux based), which method of installation is better? rpm or zip/tar.gz? in each method which user can we use ? root or …

---

## [How to read filebeat keystore?](https://discuss.elastic.co/t/how-to-read-filebeat-keystore/350153)

<div class="topic-metadata">

**Author:** [@Aparna\_R](https://discuss.elastic.co/u/Aparna_R)\
**Replies:** 3\
**Last updated:** [January 1, 2024, 5:40am UTC](https://discuss.elastic.co/t/how-to-read-filebeat-keystore/350153 "2024-01-01T05:40:13Z")

</div>

Hi, I am using Powershell Desired State Configuration (DSC) to manage filebeat on my VM. In the DSC script, I need to be able to compare the secure strings used in Filebeat configuration through keystore with the source…

---

## [How to compare the value of field with the input value from the screen to take an action?](https://discuss.elastic.co/t/how-to-compare-the-value-of-field-with-the-input-value-from-the-screen-to-take-an-action/350168)

<div class="topic-metadata">

**Author:** [@adnan-ali](https://discuss.elastic.co/u/adnan-ali)\
**Replies:** 0\
**Last updated:** [January 1, 2024, 5:37am UTC](https://discuss.elastic.co/t/how-to-compare-the-value-of-field-with-the-input-value-from-the-screen-to-take-an-action/350168 "2024-01-01T05:37:32Z")

</div>

in the tree map value ,we need to change the background color of tree map cell depend on the input value from the screen to comparing with value on tree map EX: tree map value is 1000 . input value from screen is 1200…

---

## [Unable to convert \[0.0\] to long](https://discuss.elastic.co/t/unable-to-convert-0-0-to-long/350031)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 9\
**Last updated:** [January 1, 2024, 4:30am UTC](https://discuss.elastic.co/t/unable-to-convert-0-0-to-long/350031 "2024-01-01T04:30:11Z")

</div>

Been a while. Things have been smooth sailing for my other data, until this set here. I am not sure why I get this error when ingesting it. \[2023-12-27T16:46:33,099\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\]\[5612df4…

---

## [Filebeat.yml not recognized environment variable](https://discuss.elastic.co/t/filebeat-yml-not-recognized-environment-variable/350087)

<div class="topic-metadata">

**Author:** [@Alejandro\_Avila\_Pere](https://discuss.elastic.co/u/Alejandro_Avila_Pere)\
**Replies:** 1\
**Last updated:** [December 31, 2023, 6:52pm UTC](https://discuss.elastic.co/t/filebeat-yml-not-recognized-environment-variable/350087 "2023-12-31T18:52:09Z")

</div>

Hello everyone, I am trying to obtain the logs generated by the console in a container that has a backend with the ECS format from the @elastic/ecs-winston-format library, with a filebeat service. However, it does not re…

---

## [ when downgrading version 8.11 to a lower version. my datanodes did restore on version downgrade but starting elastic search the data on the new nodes was not found. Is there any way to restore this data?](https://discuss.elastic.co/t/when-downgrading-version-8-11-to-a-lower-version-my-datanodes-did-restore-on-version-downgrade-but-starting-elastic-search-the-data-on-the-new-nodes-was-not-found-is-there-any-way-to-restore-this-data/350114)

<div class="topic-metadata">

**Author:** [@Cody-Test](https://discuss.elastic.co/u/Cody-Test)\
**Replies:** 3\
**Last updated:** [December 31, 2023, 4:48pm UTC](https://discuss.elastic.co/t/when-downgrading-version-8-11-to-a-lower-version-my-datanodes-did-restore-on-version-downgrade-but-starting-elastic-search-the-data-on-the-new-nodes-was-not-found-is-there-any-way-to-restore-this-data/350114 "2023-12-31T16:48:33Z")

</div>

Hello friend, currently my lab tests elasticsearch when downgrading version 8.11 to a lower version. my datanodes did restore on version downgrade but starting Elasticsearch the data on the new nodes was not found. Is th…

---

## [ERROR: Failed to determine the health of the cluster. , with exit code 69](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster-with-exit-code-69/350150)

<div class="topic-metadata">

**Author:** [@zeynepyz](https://discuss.elastic.co/u/zeynepyz)\
**Replies:** 5\
**Last updated:** [December 31, 2023, 3:18pm UTC](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster-with-exit-code-69/350150 "2023-12-31T15:18:35Z")

</div>

In /usr/share/elasticsearch/bin file i run "sudo ./elasticsearch-create-enrollment-token --scope kibana" command and i get this output: 03:26:10.736 \[main\] WARN org.elasticsearch.common.ssl.DiagnosticTrustManager - fai…

---

## [Logstash configuration with multiple http\_poller did'nt ran for some indices](https://discuss.elastic.co/t/logstash-configuration-with-multiple-http-poller-didnt-ran-for-some-indices/350151)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [December 31, 2023, 8:02am UTC](https://discuss.elastic.co/t/logstash-configuration-with-multiple-http-poller-didnt-ran-for-some-indices/350151 "2023-12-31T08:02:11Z")

</div>

Hello, I have a logstash configuration with multiple http\_poller input plugins. say input { http\_poller { id =\> "s1-input" urls =\> { sector\_api =\> { method =\> "POST" url =\> "url1" headers =\>…

---

## [No data passed from Filebeat](https://discuss.elastic.co/t/no-data-passed-from-filebeat/350137)

<div class="topic-metadata">

**Author:** [@OAuthority](https://discuss.elastic.co/u/OAuthority)\
**Replies:** 4\
**Last updated:** [December 29, 2023, 10:46pm UTC](https://discuss.elastic.co/t/no-data-passed-from-filebeat/350137 "2023-12-29T22:46:32Z")

</div>

I'm pretty new to this software, but trying to set up Kibana, Elasticsearch, Filebeat, and Logstash. The set up I'm trying to achieve is as such. Kibana, ES, Logstash are all on one server, for this sake, we'll say 1.1.…

---

## [BM25 score when do search in multi field](https://discuss.elastic.co/t/bm25-score-when-do-search-in-multi-field/350146)

<div class="topic-metadata">

**Author:** [@r1ckC139](https://discuss.elastic.co/u/r1ckC139)\
**Replies:** 1\
**Last updated:** [December 30, 2023, 2:14pm UTC](https://discuss.elastic.co/t/bm25-score-when-do-search-in-multi-field/350146 "2023-12-30T14:14:26Z")

</div>

es\_query = { "bool": { "must": \[ {"match": {"title": title\_text}}, {"match": {"year": year\_text}} \] } } when i do search 2 field match, how elasticsearch combine score of 2 match?

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=340)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=342)
