# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=352

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 353

---

## [Fielddata is disabled on \[host.name\] in \[metricbeat-8.10.3\]](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 8\
**Last updated:** [December 12, 2023, 9:03pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261 "2023-12-12T21:03:10Z")

</div>

Hello good morning! I am ingesting data from metricbeat to elasticsearch and loading the dashboards of version metricbeat 8.10.3 with the command "./metricbeat setup --dashboard" but when viewing the dashboards it shows…

---

## [Date\_histogram: Unknown time-zone ID: Europe/Kyiv](https://discuss.elastic.co/t/date-histogram-unknown-time-zone-id-europe-kyiv/349188)

<div class="topic-metadata">

**Author:** [@Inbal](https://discuss.elastic.co/u/Inbal)\
**Replies:** 9\
**Last updated:** [December 12, 2023, 8:15pm UTC](https://discuss.elastic.co/t/date-histogram-unknown-time-zone-id-europe-kyiv/349188 "2023-12-12T20:15:57Z")

</div>

Hey, I have a es search with aggregations which contains date\_histogram with time\_zone parameter. When I'm choosing "Europe/Kyiv" as time\_zone I'm getting the following error reason: "Unknown time-zone ID: Europe/Kyiv"…

---

## [Need help about starting logstash-8.11.2](https://discuss.elastic.co/t/need-help-about-starting-logstash-8-11-2/349125)

<div class="topic-metadata">

**Author:** [@AlexLWei](https://discuss.elastic.co/u/AlexLWei)\
**Replies:** 13\
**Last updated:** [December 12, 2023, 8:12pm UTC](https://discuss.elastic.co/t/need-help-about-starting-logstash-8-11-2/349125 "2023-12-12T20:12:08Z")

</div>

I installed Logstash by downloading and unzipping the zip file from the official website and it occurs an error about JDK , Using bundled JDK: /opt/logstash-8.11.2/jdk Unrecognized VM option 'UseConcMarkSweepGC' Erro…

---

## [Elasticsearch first time run hangs adding index template](https://discuss.elastic.co/t/elasticsearch-first-time-run-hangs-adding-index-template/349169)

<div class="topic-metadata">

**Author:** [@MColeman](https://discuss.elastic.co/u/MColeman)\
**Replies:** 15\
**Last updated:** [December 12, 2023, 7:49pm UTC](https://discuss.elastic.co/t/elasticsearch-first-time-run-hangs-adding-index-template/349169 "2023-12-12T19:49:47Z")

</div>

Hi, Using the unzip install method. Unzip, run elasticsearch.bat and it seems to be hanging at \[o.e.c.m.MetadataIndexTemplateService\] adding index template \[logs\] for index patterns \[logs--\] for hours. I was expecting t…

---

## [Can I include Environment Variables in config.yml for Elastic Serverless Forwarder?](https://discuss.elastic.co/t/can-i-include-environment-variables-in-config-yml-for-elastic-serverless-forwarder/349187)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 6:36pm UTC](https://discuss.elastic.co/t/can-i-include-environment-variables-in-config-yml-for-elastic-serverless-forwarder/349187 "2023-12-12T18:36:08Z")

</div>

Please forgive me if this is tagged wrong, it was the closest I could find to "Elastic Stack-\>Elastic Serverless Forwarder," which is what I want. I have what should be a fairly easy question. With both beats and Elast…

---

## [Subqueries in Kibana Discover screen](https://discuss.elastic.co/t/subqueries-in-kibana-discover-screen/348931)

<div class="topic-metadata">

**Author:** [@ton1uwu](https://discuss.elastic.co/u/ton1uwu)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 6:24pm UTC](https://discuss.elastic.co/t/subqueries-in-kibana-discover-screen/348931 "2023-12-12T18:24:27Z")

</div>

I need to query data based on some other record timestamp, I have a log with requests and responses from a service, but i don't really have a way to know which response is for which request besides the endpoint and the t…

---

## [MatchAllQuery is slow once segment size exceeds 1](https://discuss.elastic.co/t/matchallquery-is-slow-once-segment-size-exceeds-1/349095)

<div class="topic-metadata">

**Author:** [@jwSmith1](https://discuss.elastic.co/u/jwSmith1)\
**Replies:** 5\
**Last updated:** [December 12, 2023, 6:04pm UTC](https://discuss.elastic.co/t/matchallquery-is-slow-once-segment-size-exceeds-1/349095 "2023-12-12T18:04:14Z")

</div>

Hi, I'm managing an extra-small index and had some issues with the latency. The index has ~4000 documents (25mb in total) 1 shard low index and search traffic I need to periodically fetch all of the documents from th…

---

## [Cannot read properties of undefined (reading 'split')](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-split/349034)

<div class="topic-metadata">

**Author:** [@Huzefa](https://discuss.elastic.co/u/Huzefa)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 11:16am UTC](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-split/349034 "2023-12-11T11:16:17Z")

</div>

I am currently encountering an issue in Kibana related to "Cannot read properties of undefined (reading 'split')" when attempting to upgrade agent policies or view agent policies. The occurrence of this error was noted a…

---

## [Create visualization for sum of system.cpu.cores per host](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595)

<div class="topic-metadata">

**Author:** [@lpowers](https://discuss.elastic.co/u/lpowers)\
**Replies:** 7\
**Last updated:** [December 12, 2023, 5:23pm UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595 "2023-12-12T17:23:46Z")

</div>

I'm trying to create a visualization for the total cores for each host and then sum them all up to get a count for each of our clusters. Is it possible?

---

## [Winlogbeat cannot sent a spécific event windows (level information) to kibana for provider .net runtime](https://discuss.elastic.co/t/winlogbeat-cannot-sent-a-specific-event-windows-level-information-to-kibana-for-provider-net-runtime/348922)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 4:11pm UTC](https://discuss.elastic.co/t/winlogbeat-cannot-sent-a-specific-event-windows-level-information-to-kibana-for-provider-net-runtime/348922 "2023-12-08T16:11:00Z")

</div>

Hello Team, I noticed that we cannot sent all windows evenement with below description about "information level" with winlogbeat to kibana : " The description of event ID 0 in the .NET Runtime source cannot be found.…

---

## [How to create a geoDistance sort search in java with elasticsearch 8.11.0](https://discuss.elastic.co/t/how-to-create-a-geodistance-sort-search-in-java-with-elasticsearch-8-11-0/348983)

<div class="topic-metadata">

**Author:** [@jasin](https://discuss.elastic.co/u/jasin)\
**Replies:** 6\
**Last updated:** [December 12, 2023, 4:40pm UTC](https://discuss.elastic.co/t/how-to-create-a-geodistance-sort-search-in-java-with-elasticsearch-8-11-0/348983 "2023-12-12T16:40:49Z")

</div>

here is my code but the sort doesn't work and throw an error SearchResponse\<HotelDoc\> response = client.search(s -\> s .index("hotel") .query(q -\> q …

---

## [Implement my own Hybrid Search](https://discuss.elastic.co/t/implement-my-own-hybrid-search/349100)

<div class="topic-metadata">

**Author:** [@r1ckC139](https://discuss.elastic.co/u/r1ckC139)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 4:20pm UTC](https://discuss.elastic.co/t/implement-my-own-hybrid-search/349100 "2023-12-12T16:20:36Z")

</div>

Hi team, I've developed a hybrid search algorithm. Initially, I perform a BM25 search, obtaining the top k results (id, score). Subsequently, a k-nearest neighbors (KNN) search is executed, yielding another set of top k…

---

## [F5 load balancer SSL\_ERROR\_SYSCALL, errno 104 with Elasticsearch cluster](https://discuss.elastic.co/t/f5-load-balancer-ssl-error-syscall-errno-104-with-elasticsearch-cluster/349120)

<div class="topic-metadata">

**Author:** [@miksonx](https://discuss.elastic.co/u/miksonx)\
**Replies:** 4\
**Last updated:** [December 12, 2023, 4:14pm UTC](https://discuss.elastic.co/t/f5-load-balancer-ssl-error-syscall-errno-104-with-elasticsearch-cluster/349120 "2023-12-12T16:14:11Z")

</div>

We have configured F5 LB in front of Elasticsearch nodes cluster with re-encrypt of SSL traffic to the nodes. Nodes have SSL enabled on http. Direct communication to nodes i.e. API (curl) or sending data over https on po…

---

## [Palo Alto Next-Gen Firewall compatibility with Global Protect VPN Client](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084)

<div class="topic-metadata">

**Author:** [@CodeMonky](https://discuss.elastic.co/u/CodeMonky)\
**Replies:** 5\
**Last updated:** [December 12, 2023, 2:52pm UTC](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084 "2023-12-12T14:52:15Z")

</div>

Good day all! I'm looking for confirmation on the features of the Palo Alto Next-Gen Firewall integration with elastic. On the overview page of the integration, it details support of the Global Protect type of message. …

---

## [License Platinum Subscription 64 GB only for node?](https://discuss.elastic.co/t/license-platinum-subscription-64-gb-only-for-node/348422)

<div class="topic-metadata">

**Author:** [@Rossella\_Palmisano](https://discuss.elastic.co/u/Rossella_Palmisano)\
**Replies:** 7\
**Last updated:** [December 12, 2023, 2:28pm UTC](https://discuss.elastic.co/t/license-platinum-subscription-64-gb-only-for-node/348422 "2023-12-12T14:28:09Z")

</div>

For the calculation of elastic platinum licenses should only nodes count or should I also consider the GB RAM per node? Which nodes need to be licensed? I have both master nodes and worker nodes.

---

## [Is Vega performance good on large dataset?](https://discuss.elastic.co/t/is-vega-performance-good-on-large-dataset/348713)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 6\
**Last updated:** [December 12, 2023, 2:15pm UTC](https://discuss.elastic.co/t/is-vega-performance-good-on-large-dataset/348713 "2023-12-12T14:15:37Z")

</div>

I am working on a large timeseries dataset, around 120000 document approx. I want to know how the performance is of Vega on such large database. Does it take a lot of time to load to show charts and graphs. Or it works a…

---

## [Possible bug with sorting dynamically mapped fields](https://discuss.elastic.co/t/possible-bug-with-sorting-dynamically-mapped-fields/349149)

<div class="topic-metadata">

**Author:** [@Evgeni\_Dzhelyov](https://discuss.elastic.co/u/Evgeni_Dzhelyov)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 1:05pm UTC](https://discuss.elastic.co/t/possible-bug-with-sorting-dynamically-mapped-fields/349149 "2023-12-12T13:05:01Z")

</div>

We ingest a lot of custom logs in Elasticsearch. For the application logs we use a custom schema with dynamic mappings, but when sorting for some of the fields we hit a strange bug: Sort by a dext.duration#double field…

---

## [Save index-template in helm chart](https://discuss.elastic.co/t/save-index-template-in-helm-chart/349038)

<div class="topic-metadata">

**Author:** [@nkarthik](https://discuss.elastic.co/u/nkarthik)\
**Replies:** 2\
**Last updated:** [December 12, 2023, 1:02pm UTC](https://discuss.elastic.co/t/save-index-template-in-helm-chart/349038 "2023-12-12T13:02:05Z")

</div>

Hi, I am using the 7.17 elastic stack. I know that we can create the index template in the kibana UI. But is there a way to create index-template as a YAML of any Kubernetes resource, so that every time kibana gets deplo…

---

## [Can not create a document has mutlipolygon having hole](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/349133)

<div class="topic-metadata">

**Author:** [@Sai\_Suvam\_Patnaik](https://discuss.elastic.co/u/Sai_Suvam_Patnaik)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:47am UTC](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/349133 "2023-12-12T11:47:05Z")

</div>

Hi all , can anyone help me I am facing a following issue . Summary Can not create a document has multipolygon having hole. This is the screenshot of the shp file in qgis: Expected behavior The document is succe…

---

## [AWS lambda end of support for Go1.x runtime](https://discuss.elastic.co/t/aws-lambda-end-of-support-for-go1-x-runtime/349047)

<div class="topic-metadata">

**Author:** [@rsingh1](https://discuss.elastic.co/u/rsingh1)\
**Replies:** 3\
**Last updated:** [December 12, 2023, 11:37am UTC](https://discuss.elastic.co/t/aws-lambda-end-of-support-for-go1-x-runtime/349047 "2023-12-12T11:37:21Z")

</div>

Hi, My use case is to continue using the functionbeat itself, but since the go1.x runtime will not be supported in AWS lambda, can I create a new build with the gov2 version? On that, Will it be too much of effort doi…

---

## [Create a rule for stopped log alert](https://discuss.elastic.co/t/create-a-rule-for-stopped-log-alert/349009)

<div class="topic-metadata">

**Author:** [@Bhavani90](https://discuss.elastic.co/u/Bhavani90)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:21am UTC](https://discuss.elastic.co/t/create-a-rule-for-stopped-log-alert/349009 "2023-12-12T11:21:29Z")

</div>

Hi, I'm trying to set up an alert for when my application logs haven't been updated in 1 hour. Could you please share the relevant query?

---

## [Does Cross Cluster Search Performance varies with number of clusters](https://discuss.elastic.co/t/does-cross-cluster-search-performance-varies-with-number-of-clusters/348954)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 3\
**Last updated:** [December 12, 2023, 11:19am UTC](https://discuss.elastic.co/t/does-cross-cluster-search-performance-varies-with-number-of-clusters/348954 "2023-12-12T11:19:08Z")

</div>

Hi Team, I have a query. We have around 5000 Nodes in our setup. If I distribute the Nodes across 30 different Clusters will the cross cluster search performance be significantly be faster as compared to if I have nod…

---

## [Field not found message](https://discuss.elastic.co/t/field-not-found-message/349040)

<div class="topic-metadata">

**Author:** [@vils](https://discuss.elastic.co/u/vils)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:17am UTC](https://discuss.elastic.co/t/field-not-found-message/349040 "2023-12-12T11:17:36Z")

</div>

Hi all, I received an error message for a metric, saying the field wasn't found. The field not being found is fine since it does not apply to all my users, but is there a way to remove the error message. Instead having …

---

## [Exact replacement of LIKE with MATCH() / QUERY() in SQL query](https://discuss.elastic.co/t/exact-replacement-of-like-with-match-query-in-sql-query/349134)

<div class="topic-metadata">

**Author:** [@Grzegorz\_Kolakowski](https://discuss.elastic.co/u/Grzegorz_Kolakowski)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:13am UTC](https://discuss.elastic.co/t/exact-replacement-of-like-with-match-query-in-sql-query/349134 "2023-12-12T11:13:21Z")

</div>

Hi! The documentation suggests to use MATCH()/QUERY() instead of LIKE for performance reasons. I am wondering if it is possible to translate expression from LIKE filter to either MATCH or QUERY in order to achieve exact…

---

## [Elastic Map Service : Unable to find EMS tile configuration for id:road\_map : Kibana 7.17.0](https://discuss.elastic.co/t/elastic-map-service-unable-to-find-ems-tile-configuration-for-id-road-map-kibana-7-17-0/349122)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 4\
**Last updated:** [December 12, 2023, 9:59am UTC](https://discuss.elastic.co/t/elastic-map-service-unable-to-find-ems-tile-configuration-for-id-road-map-kibana-7-17-0/349122 "2023-12-12T09:59:05Z")

</div>

We have done on premise Kibana deployment at client location on Windows Server VM. VM does not have public internet access. We are getting below error while loading map. Unable to load layer Unable to find EMS tile con…

---

## [Elastic's Tenable Vulnerability Management Integration - Re-injesting Lost Data](https://discuss.elastic.co/t/elastics-tenable-vulnerability-management-integration-re-injesting-lost-data/349131)

<div class="topic-metadata">

**Author:** [@longansoju](https://discuss.elastic.co/u/longansoju)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 9:55am UTC](https://discuss.elastic.co/t/elastics-tenable-vulnerability-management-integration-re-injesting-lost-data/349131 "2023-12-12T09:55:42Z")

</div>

TDLR: is there a way to force elastic to injest all existing data for the past month from my tenable source? For those that prefer an in-depth explaination: I was tasked with coming out with a Tenable Dashboard that sh…

---

## [Allow multi-line breaking using \\n in Discover Datatable](https://discuss.elastic.co/t/allow-multi-line-breaking-using-n-in-discover-datatable/348975)

<div class="topic-metadata">

**Author:** [@Saar\_Tamir](https://discuss.elastic.co/u/Saar_Tamir)\
**Replies:** 3\
**Last updated:** [December 12, 2023, 8:29am UTC](https://discuss.elastic.co/t/allow-multi-line-breaking-using-n-in-discover-datatable/348975 "2023-12-12T08:29:34Z")

</div>

Hello, I'm sending strings with \\n so I can see logs in multi-line formatting, but all I see is the literal '\\n'. For example: I found this previous issue and PR: and I see that it added on 8.4.0 but only for Lens…

---

## [Elasticsearch throws error 503 Server Unavailable](https://discuss.elastic.co/t/elasticsearch-throws-error-503-server-unavailable/348896)

<div class="topic-metadata">

**Author:** [@Kalidastate](https://discuss.elastic.co/u/Kalidastate)\
**Replies:** 7\
**Last updated:** [December 12, 2023, 8:13am UTC](https://discuss.elastic.co/t/elasticsearch-throws-error-503-server-unavailable/348896 "2023-12-12T08:13:24Z")

</div>

I am facing one issue with the Elasticsearch in the production environment. Elasticsearch stops responding to the API calls and it needs to be restarted. Logs collected from Elasticsearch are as follows When the issue…

---

## [Suggestion on elastic cluster requirement](https://discuss.elastic.co/t/suggestion-on-elastic-cluster-requirement/349109)

<div class="topic-metadata">

**Author:** [@Ishaque\_Mohammed](https://discuss.elastic.co/u/Ishaque_Mohammed)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 6:25am UTC](https://discuss.elastic.co/t/suggestion-on-elastic-cluster-requirement/349109 "2023-12-12T06:25:07Z")

</div>

I have GKE clusters in that I am getting total 50MB logs /second to elastic and for this I have setup a 6 node elastic cluster with 4core and 16GB RAM configuration still I am facing issue when a surge occurs however my…

---

## [Kibana visualization bar chart not as expected](https://discuss.elastic.co/t/kibana-visualization-bar-chart-not-as-expected/349099)

<div class="topic-metadata">

**Author:** [@Liam619](https://discuss.elastic.co/u/Liam619)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 4:05am UTC](https://discuss.elastic.co/t/kibana-visualization-bar-chart-not-as-expected/349099 "2023-12-12T04:05:31Z")

</div>

Hi, I'm new to Kibana / Elastic service and trying to create a bar chart. I have 2 fields that store the number of storage capacity. What I'm trying to achieve here is that I wanted to display the bar separately. But s…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=351)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=353)
