# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=348

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 349

---

## [Issue while running a pipeline](https://discuss.elastic.co/t/issue-while-running-a-pipeline/347650)

<div class="topic-metadata">

**Author:** [@Manasa4](https://discuss.elastic.co/u/Manasa4)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 10:34pm UTC](https://discuss.elastic.co/t/issue-while-running-a-pipeline/347650 "2023-12-18T22:34:50Z")

</div>

Hi Team, I'm trying to run elser and ner pipelines through the reindexing and I'm having the following error : pipeline with id \[elser\_pipeline\_peopleagg\] could not be loaded, caused by \[org.elasticsearch.Elasticsearch…

---

## [Enrich table size](https://discuss.elastic.co/t/enrich-table-size/349600)

<div class="topic-metadata">

**Author:** [@lkw](https://discuss.elastic.co/u/lkw)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 10:33pm UTC](https://discuss.elastic.co/t/enrich-table-size/349600 "2023-12-18T22:33:32Z")

</div>

I am ingesting time-series data and want to enrich it. But my enrich table could be quite large. Are there any rules of thumb regarding the size an index used for enrich in an ingress pipeline can be? Is 10k documents …

---

## [ES 8.8.2 high query latency](https://discuss.elastic.co/t/es-8-8-2-high-query-latency/349191)

<div class="topic-metadata">

**Author:** [@darshanypatel](https://discuss.elastic.co/u/darshanypatel)\
**Replies:** 3\
**Last updated:** [December 18, 2023, 10:19pm UTC](https://discuss.elastic.co/t/es-8-8-2-high-query-latency/349191 "2023-12-18T22:19:42Z")

</div>

I am encountering degraded query latency in v8. We are upgrading our cluster from 7.16.2 to 8.8.2 by standing up a new duplicate cluster with the new version and reindexing the data to it. The latency is 500ms to several…

---

## [Is it possible to add configuration options when using hints based autodiscover with heartbeat?](https://discuss.elastic.co/t/is-it-possible-to-add-configuration-options-when-using-hints-based-autodiscover-with-heartbeat/349478)

<div class="topic-metadata">

**Author:** [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Replies:** 2\
**Last updated:** [December 18, 2023, 10:01pm UTC](https://discuss.elastic.co/t/is-it-possible-to-add-configuration-options-when-using-hints-based-autodiscover-with-heartbeat/349478 "2023-12-18T22:01:40Z")

</div>

We are using heartbeat to monitor our k8s service and we are doing this with hints based auto discovery via annotations that we set on a service. I would like to have this service include the response body and I see tha…

---

## [Elasticsearch Query Multiple Must Nots](https://discuss.elastic.co/t/elasticsearch-query-multiple-must-nots/349570)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 7\
**Last updated:** [December 18, 2023, 7:28pm UTC](https://discuss.elastic.co/t/elasticsearch-query-multiple-must-nots/349570 "2023-12-18T19:28:37Z")

</div>

Is it possible to have 2 different must not query strings across two different fields I have this but it doesnt let me have 2 query strings GET winevents/\_search { "query": { "bool": { "must": \[ { …

---

## [Logstash not connecting to Elasticsearch - using Docker-Compose](https://discuss.elastic.co/t/logstash-not-connecting-to-elasticsearch-using-docker-compose/349461)

<div class="topic-metadata">

**Author:** [@zewcro](https://discuss.elastic.co/u/zewcro)\
**Replies:** 12\
**Last updated:** [December 18, 2023, 6:19pm UTC](https://discuss.elastic.co/t/logstash-not-connecting-to-elasticsearch-using-docker-compose/349461 "2023-12-18T18:19:57Z")

</div>

Hello, I'm trying to create indexes in elasticsearch from a postgresql database. So I set up docker compose: version: '3.8' services: postgres: image: postgres:latest volumes: - C:\\Users\\theor\\desktop…

---

## [OIDC without TLS](https://discuss.elastic.co/t/oidc-without-tls/349580)

<div class="topic-metadata">

**Author:** [@Jo\_han](https://discuss.elastic.co/u/Jo_han)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 4:39pm UTC](https://discuss.elastic.co/t/oidc-without-tls/349580 "2023-12-18T16:39:01Z")

</div>

Hello, I am deploying ECK in an on-premise Kubernetes cluster with Istio installed. We drew a security perimeter at our gateway. Meaning all the services are only reachable through the gateway, where TLS and authentica…

---

## [Massive performance degradation when terms filter has over 16 values?](https://discuss.elastic.co/t/massive-performance-degradation-when-terms-filter-has-over-16-values/349106)

<div class="topic-metadata">

**Author:** [@elastic\_dude](https://discuss.elastic.co/u/elastic_dude)\
**Replies:** 9\
**Last updated:** [December 18, 2023, 4:19pm UTC](https://discuss.elastic.co/t/massive-performance-degradation-when-terms-filter-has-over-16-values/349106 "2023-12-18T16:19:50Z")

</div>

Came across some odd behavior. We have a query that performs in the tens of milliseconds until we go over 16 values in our terms filter. When 17 or more are included the performance degrades by 15-20 multiples. Here is …

---

## [Index template - settings](https://discuss.elastic.co/t/index-template-settings/349568)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 2:56pm UTC](https://discuss.elastic.co/t/index-template-settings/349568 "2023-12-18T14:56:12Z")

</div>

Hi All, I set up ILM for a particular index pattern. After applying this when I check index settings I see the following output: GET abc-90010-2023.12.18/\_settings { "abc-90010-2023.12.18": { "settings": { …

---

## [Runtime script: access list of fields](https://discuss.elastic.co/t/runtime-script-access-list-of-fields/349561)

<div class="topic-metadata">

**Author:** [@dao](https://discuss.elastic.co/u/dao)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 2:44pm UTC](https://discuss.elastic.co/t/runtime-script-access-list-of-fields/349561 "2023-12-18T14:44:51Z")

</div>

hello, I try to create a field that is an array of strings. Each string is the name of a field example: I have docs like this: { a: 1, b:2, toto: 'processed', tata:'processed' } I want to create a field that will be…

---

## [Help needed for certificate configuration](https://discuss.elastic.co/t/help-needed-for-certificate-configuration/349194)

<div class="topic-metadata">

**Author:** [@litronics](https://discuss.elastic.co/u/litronics)\
**Replies:** 13\
**Last updated:** [December 18, 2023, 2:14pm UTC](https://discuss.elastic.co/t/help-needed-for-certificate-configuration/349194 "2023-12-18T14:14:11Z")

</div>

Elasticsearch drives me nuts when it comes to certificates and how they are used / configured. This is my current configuration: ## Cluster Settings cluster.name: "elk-tls-cluster" node.name: node-1 network.host: "0.0.…

---

## [Manually execute ILM policy](https://discuss.elastic.co/t/manually-execute-ilm-policy/349560)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 1:44pm UTC](https://discuss.elastic.co/t/manually-execute-ilm-policy/349560 "2023-12-18T13:44:59Z")

</div>

Hey there, is there a way to manually execute an ILMm policy? If I modify the mapping template for example, I would like to immediately create and use a new updated index, avoiding to wait for example date threshold or …

---

## [Elastic service stops unexpectedly](https://discuss.elastic.co/t/elastic-service-stops-unexpectedly/349555)

<div class="topic-metadata">

**Author:** [@mreddy9](https://discuss.elastic.co/u/mreddy9)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 12:35pm UTC](https://discuss.elastic.co/t/elastic-service-stops-unexpectedly/349555 "2023-12-18T12:35:51Z")

</div>

Hi all, Sometime Elasticsearch service stops unexpectedly in the weekend and there are no details in logs to identify the exact issue. Please suggest any solution if you already come across this issue in past. log deta…

---

## [Kibana discover show wrong result when filter by date type field](https://discuss.elastic.co/t/kibana-discover-show-wrong-result-when-filter-by-date-type-field/349316)

<div class="topic-metadata">

**Author:** [@bbhhhh](https://discuss.elastic.co/u/bbhhhh)\
**Replies:** 3\
**Last updated:** [December 18, 2023, 12:08pm UTC](https://discuss.elastic.co/t/kibana-discover-show-wrong-result-when-filter-by-date-type-field/349316 "2023-12-18T12:08:01Z")

</div>

I created an index template 'order-index-template' which defined a date type mapping: ... "index\_patterns": \[ "order-index" \], "mappings": { "properties": { "orderTime": { "type": "date" …

---

## [Logstash error Cpu.cfs\_period\_us cannot be found](https://discuss.elastic.co/t/logstash-error-cpu-cfs-period-us-cannot-be-found/349515)

<div class="topic-metadata">

**Author:** [@Lena\_Yoon](https://discuss.elastic.co/u/Lena_Yoon)\
**Replies:** 9\
**Last updated:** [December 18, 2023, 11:43am UTC](https://discuss.elastic.co/t/logstash-error-cpu-cfs-period-us-cannot-be-found/349515 "2023-12-18T11:43:11Z")

</div>

Hello, I have been working with Logstash this week but stuck with below error. The error occurs when retrieving data from Oracle DB using the JDBC input plugin, filtering it in the pipeline, and despite the index being…

---

## [Merge two buckets muli\_level inside buckets](https://discuss.elastic.co/t/merge-two-buckets-muli-level-inside-buckets/349547)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 10:14am UTC](https://discuss.elastic.co/t/merge-two-buckets-muli-level-inside-buckets/349547 "2023-12-18T10:14:55Z")

</div>

{ "aggregations" : { "alert\_types" : { "doc\_count\_error\_upper\_bound" : 0, "sum\_other\_doc\_count" : 0, "buckets" : \[ { "key" : "1", "doc\_count" : 3, "device\_ref…

---

## [One logstash instance per kubernetes cluster](https://discuss.elastic.co/t/one-logstash-instance-per-kubernetes-cluster/349546)

<div class="topic-metadata">

**Author:** [@codedoings](https://discuss.elastic.co/u/codedoings)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 10:11am UTC](https://discuss.elastic.co/t/one-logstash-instance-per-kubernetes-cluster/349546 "2023-12-18T10:11:01Z")

</div>

Hi, What would be the best approach for configuring logstash in an environment where: Elasticsearch and Kibana are running in their own kubernetes cluster (deployed with ECK). Elasticsearch and Kibana instance is shar…

---

## [Fleet server configurations for elk-apm setup in AKS cluster](https://discuss.elastic.co/t/fleet-server-configurations-for-elk-apm-setup-in-aks-cluster/349542)

<div class="topic-metadata">

**Author:** [@mahimakha](https://discuss.elastic.co/u/mahimakha)\
**Replies:** 2\
**Last updated:** [December 18, 2023, 9:49am UTC](https://discuss.elastic.co/t/fleet-server-configurations-for-elk-apm-setup-in-aks-cluster/349542 "2023-12-18T09:49:35Z")

</div>

Hi I am trying to configure the ELK-APM on AKS cluster. I have been following the documentation as per the given link Run Elastic Agent on Kubernetes managed by Fleet | Fleet and Elastic Agent Guide \[8.5\] | Elastic I a…

---

## [Upgrade from 7.17.14 to 8.11.3 failes](https://discuss.elastic.co/t/upgrade-from-7-17-14-to-8-11-3-failes/349538)

<div class="topic-metadata">

**Author:** [@Ingo\_Voland](https://discuss.elastic.co/u/Ingo_Voland)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 9:39am UTC](https://discuss.elastic.co/t/upgrade-from-7-17-14-to-8-11-3-failes/349538 "2023-12-18T09:39:22Z")

</div>

We have a 1 node elastic installation (7.17.14), upgrading to 8.11.3 failes wiith the error message Caused by: org.elasticsearch.gateway.CorruptStateException: Format version is not supported. Upgrading to \[8.11.3\] is o…

---

## [Filebeat registry file and log.json are not updated](https://discuss.elastic.co/t/filebeat-registry-file-and-log-json-are-not-updated/349535)

<div class="topic-metadata">

**Author:** [@sheldonyip](https://discuss.elastic.co/u/sheldonyip)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 7:39am UTC](https://discuss.elastic.co/t/filebeat-registry-file-and-log-json-are-not-updated/349535 "2023-12-18T07:39:20Z")

</div>

Pls help to find the root cause. The file beat was originally uploaded to ELK, but suddenly the registry and log.json did not update. Filebeat version is 7.17.7, and the OS is Red Hat Enterprise Linux release 8.8 (Ootp…

---

## [Elastic 8.11.3 on docker in OSX silicon has disk volume sizing issues](https://discuss.elastic.co/t/elastic-8-11-3-on-docker-in-osx-silicon-has-disk-volume-sizing-issues/349522)

<div class="topic-metadata">

**Author:** [@matthal](https://discuss.elastic.co/u/matthal)\
**Replies:** 6\
**Last updated:** [December 18, 2023, 3:09am UTC](https://discuss.elastic.co/t/elastic-8-11-3-on-docker-in-osx-silicon-has-disk-volume-sizing-issues/349522 "2023-12-18T03:09:07Z")

</div>

Trying to run elasticsearch locally for development using docker compose (Getting started with the Elastic Stack and Docker-Compose | Elastic Blog) I end up getting disk pressure issues, well a warning, but it ends up …

---

## [Date time with time multifield](https://discuss.elastic.co/t/date-time-with-time-multifield/349513)

<div class="topic-metadata">

**Author:** [@RRGTHWAR1](https://discuss.elastic.co/u/RRGTHWAR1)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 1:18am UTC](https://discuss.elastic.co/t/date-time-with-time-multifield/349513 "2023-12-18T01:18:58Z")

</div>

This has come up from time to time, but I haven’t seen any definitive answers. Is it possible to have a time-only multi-field in a date time field? For example, created\_date would be the full datetime, and created\_date.t…

---

## [Logstash error(no data ) while ingesting CSV data with ELK version 8.9.2](https://discuss.elastic.co/t/logstash-error-no-data-while-ingesting-csv-data-with-elk-version-8-9-2/349510)

<div class="topic-metadata">

**Author:** [@raemonx](https://discuss.elastic.co/u/raemonx)\
**Replies:** 2\
**Last updated:** [December 17, 2023, 10:08pm UTC](https://discuss.elastic.co/t/logstash-error-no-data-while-ingesting-csv-data-with-elk-version-8-9-2/349510 "2023-12-17T22:08:44Z")

</div>

I was facing an issue while ingesting an csv file called housing\_price\_data.csv using logstash. I was using ELK with docker. I was using ELK version 8.11 I did not want to add any security so there is no SSL, passwords o…

---

## [Circuit breaker in Elasticsearch](https://discuss.elastic.co/t/circuit-breaker-in-elasticsearch/349508)

<div class="topic-metadata">

**Author:** [@pksinghal](https://discuss.elastic.co/u/pksinghal)\
**Replies:** 9\
**Last updated:** [December 17, 2023, 5:01pm UTC](https://discuss.elastic.co/t/circuit-breaker-in-elasticsearch/349508 "2023-12-17T17:01:15Z")

</div>

we are running an Elasticsearch cluster with 3 nodes. sometimes a heavy agg query comes(run manually from Kibana dev tools) and one of the nodes becomes inaccessible. So full cluster becomes inaccessible as ES takes so…

---

## [Best data structure for sensor data](https://discuss.elastic.co/t/best-data-structure-for-sensor-data/349497)

<div class="topic-metadata">

**Author:** [@allatrue](https://discuss.elastic.co/u/allatrue)\
**Replies:** 1\
**Last updated:** [December 17, 2023, 5:10pm UTC](https://discuss.elastic.co/t/best-data-structure-for-sensor-data/349497 "2023-12-17T17:10:18Z")

</div>

Hello everyone, We are setting up a cluster for collecting of IoT/sensor data. And I'm not sure what is the best structure for this kind of data. The simplest way would be to use single index for all similar (numeric) d…

---

## [Cannot login to Elastic Cloud](https://discuss.elastic.co/t/cannot-login-to-elastic-cloud/349439)

<div class="topic-metadata">

**Author:** [@develop-finline](https://discuss.elastic.co/u/develop-finline)\
**Replies:** 4\
**Last updated:** [December 17, 2023, 3:50pm UTC](https://discuss.elastic.co/t/cannot-login-to-elastic-cloud/349439 "2023-12-17T15:50:09Z")

</div>

Hi team, I'm not able to reach out to any of my clusters, I'm not able to login to Elastic Cloud. Endpoints of clusters aren't available. I've tried to reset my elastic cloud account password but still cannot login a…

---

## [Registery blow ups](https://discuss.elastic.co/t/registery-blow-ups/349500)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 3\
**Last updated:** [December 17, 2023, 1:46pm UTC](https://discuss.elastic.co/t/registery-blow-ups/349500 "2023-12-17T13:46:15Z")

</div>

Hey, Running a filebeat on a NFS share which stores backup of json message files from our application's communication with external applications and wonder how to best avoid registery to blow up in size while also ensur…

---

## [Logstash ran as service won't read logs only when ran through the command line](https://discuss.elastic.co/t/logstash-ran-as-service-wont-read-logs-only-when-ran-through-the-command-line/349403)

<div class="topic-metadata">

**Author:** [@ELI\_MA](https://discuss.elastic.co/u/ELI_MA)\
**Replies:** 14\
**Last updated:** [December 17, 2023, 5:10am UTC](https://discuss.elastic.co/t/logstash-ran-as-service-wont-read-logs-only-when-ran-through-the-command-line/349403 "2023-12-17T05:10:27Z")

</div>

Hi, I’m running Logstash on SUSE Linux where I’ve installed the RPM package for compatibility. Currently, When I start logstash as a service sudo systemctl stop logstash.service and check service status it seems to be r…

---

## [Not able to search a specific log file in Kibana UI](https://discuss.elastic.co/t/not-able-to-search-a-specific-log-file-in-kibana-ui/347428)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 3\
**Last updated:** [December 17, 2023, 5:02am UTC](https://discuss.elastic.co/t/not-able-to-search-a-specific-log-file-in-kibana-ui/347428 "2023-12-17T05:02:03Z")

</div>

Hi, I am running the Elastic Stack on Red Hat Enterprise Linux release 8.8 (Ootpa) and the versions are as below. # rpm -qa | grep logstash logstash-8.11.0-1.x86\_64 # rpm -qa | grep elasticsearch elasticsearch-8.11.0-1…

---

## [Elasticsearch upgrade assistant](https://discuss.elastic.co/t/elasticsearch-upgrade-assistant/349447)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 2\
**Last updated:** [December 16, 2023, 11:26pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-assistant/349447 "2023-12-16T23:26:59Z")

</div>

Hi all, We are trying to upgrade our Elasticsearch cluster from 7.17 to 8.X and found that its recommended to use Upgrade assistant for this. But we do not use Kibana in our cluster. The ES is acting as a search backend…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=347)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=349)
