# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=359

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 360

---

## [Anomaly Job scroll\_size parameter behaviour](https://discuss.elastic.co/t/anomaly-job-scroll-size-parameter-behaviour/348533)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 2:07pm UTC](https://discuss.elastic.co/t/anomaly-job-scroll-size-parameter-behaviour/348533 "2023-12-04T14:07:04Z")

</div>

Hello everyone, a quick question regarding the scroll\_size parameter of a datafeed in an anomaly job. Is the scroll\_size just limiting the number of results per query returned, but every document is processed (thus a r…

---

## [Nested inner\_hits more than 100 results](https://discuss.elastic.co/t/nested-inner-hits-more-than-100-results/348562)

<div class="topic-metadata">

**Author:** [@Vinicius\_Junges](https://discuss.elastic.co/u/Vinicius_Junges)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 1:41pm UTC](https://discuss.elastic.co/t/nested-inner-hits-more-than-100-results/348562 "2023-12-04T13:41:52Z")

</div>

Hey guys. I don't know if I'm in the right place, is my first time here. I'm doing a nested query with inner\_hits, but the elasticsearch configuration is limited to 100 by default. Is there any way to get more than 100 r…

---

## [Alert changes in documents](https://discuss.elastic.co/t/alert-changes-in-documents/348561)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 1:37pm UTC](https://discuss.elastic.co/t/alert-changes-in-documents/348561 "2023-12-04T13:37:47Z")

</div>

Hello, I'm trying to implement an alert system in Elasticsearch. I'll describe the key elements of the problem and my solution attempts until now. Scenario We are ingesting information into an Elasticsearch index usin…

---

## [Filebeat not starting](https://discuss.elastic.co/t/filebeat-not-starting/348486)

<div class="topic-metadata">

**Author:** [@tagba](https://discuss.elastic.co/u/tagba)\
**Replies:** 7\
**Last updated:** [December 4, 2023, 1:35pm UTC](https://discuss.elastic.co/t/filebeat-not-starting/348486 "2023-12-04T13:35:15Z")

</div>

I have installed elk version 7.3.2 on an ubuntu machine running on a VM, but the filebeat is not starting. Below is the error message. × filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsea…

---

## [Kibana 8.11.1 - ClamAV Infected file -\> security\_detection\_engine-8.11.1.zip](https://discuss.elastic.co/t/kibana-8-11-1-clamav-infected-file-security-detection-engine-8-11-1-zip/347939)

<div class="topic-metadata">

**Author:** [@RafaelE](https://discuss.elastic.co/u/RafaelE)\
**Replies:** 3\
**Last updated:** [December 4, 2023, 12:49pm UTC](https://discuss.elastic.co/t/kibana-8-11-1-clamav-infected-file-security-detection-engine-8-11-1-zip/347939 "2023-12-04T12:49:12Z")

</div>

Hello everyone, I'm creating this topic to report a situation where the antivirus ClamAV have identified a possible infected file on your Debian package ClamAV report /usr/share/kibana/node\_modules/@kbn/fleet-plugin/t…

---

## [Node.js Application Fail to Connect Elasticsearch](https://discuss.elastic.co/t/node-js-application-fail-to-connect-elasticsearch/348223)

<div class="topic-metadata">

**Author:** [@Burak\_Karatay](https://discuss.elastic.co/u/Burak_Karatay)\
**Replies:** 5\
**Last updated:** [December 4, 2023, 11:50am UTC](https://discuss.elastic.co/t/node-js-application-fail-to-connect-elasticsearch/348223 "2023-12-04T11:50:27Z")

</div>

I have very simple Node.js Application to connect my local Elasticsearch engine, when I try to use Kibana, I can connect after provide user and email but when I try to send ping from my Node.js app It gives following err…

---

## [Fleet UI in Kibana not working after update to 8.11.1](https://discuss.elastic.co/t/fleet-ui-in-kibana-not-working-after-update-to-8-11-1/348478)

<div class="topic-metadata">

**Author:** [@yash1311](https://discuss.elastic.co/u/yash1311)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 10:56am UTC](https://discuss.elastic.co/t/fleet-ui-in-kibana-not-working-after-update-to-8-11-1/348478 "2023-12-04T10:56:14Z")

</div>

When I access Fleet on Kibana post upgrade, I get the message "Unable to initialize Fleet: Invalid licence to set per policy output, you need platinum licence". My default output was elasticsearch, I'm not able to figur…

---

## [NGramTokenFilter: Unknown field 'token\_chars'](https://discuss.elastic.co/t/ngramtokenfilter-unknown-field-token-chars/348532)

<div class="topic-metadata">

**Author:** [@Rohit\_Gaur](https://discuss.elastic.co/u/Rohit_Gaur)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 8:43am UTC](https://discuss.elastic.co/t/ngramtokenfilter-unknown-field-token-chars/348532 "2023-12-04T08:43:53Z")

</div>

I am upgrading my Elasticsearch to 8.9 while creating documents using Elasticsearch client I faced the following error co.elastic.clients.json.JsonpMappingException: Error deserializing co.elastic.clients.elasticsearch.…

---

## [Logstash log repeated acquisition](https://discuss.elastic.co/t/logstash-log-repeated-acquisition/347821)

<div class="topic-metadata">

**Author:** [@kubo\_Smith](https://discuss.elastic.co/u/kubo_Smith)\
**Replies:** 14\
**Last updated:** [December 4, 2023, 7:34am UTC](https://discuss.elastic.co/t/logstash-log-repeated-acquisition/347821 "2023-12-04T07:34:16Z")

</div>

My log is like this: \[23/Nov/2023:14:12:37 +0800\] | gateway | \[http\] | 195.161.250.29 | POST /gateway/xxx HTTP/1.1 | 9090 | 200 | 182 | sss67jhsd | 0 | gateway | - | - | - | - | Java/1.8.0\_362 Logstash(version: 7.4.2)…

---

## [Does the functionality of converting documents into vector data in Elasticsearch require payment? How is it paid for in the self-managed type?](https://discuss.elastic.co/t/does-the-functionality-of-converting-documents-into-vector-data-in-elasticsearch-require-payment-how-is-it-paid-for-in-the-self-managed-type/348523)

<div class="topic-metadata">

**Author:** [@katherineadams](https://discuss.elastic.co/u/katherineadams)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 6:56am UTC](https://discuss.elastic.co/t/does-the-functionality-of-converting-documents-into-vector-data-in-elasticsearch-require-payment-how-is-it-paid-for-in-the-self-managed-type/348523 "2023-12-04T06:56:32Z")

</div>

Does the functionality of converting documents into vector data in Elasticsearch require payment? How is it paid for in the self-managed type?

---

## [Extracting time from @timestamp field using Runtime](https://discuss.elastic.co/t/extracting-time-from-timestamp-field-using-runtime/348468)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 13\
**Last updated:** [December 4, 2023, 6:47am UTC](https://discuss.elastic.co/t/extracting-time-from-timestamp-field-using-runtime/348468 "2023-12-04T06:47:56Z")

</div>

I understand Scripted Fields have been deprecated since 7.13. The replacement is now Runtime. I have a @timestamp field How can I extract out the time component into a new field @timeofday - such that when I filter …

---

## [Logstash CPU Problem](https://discuss.elastic.co/t/logstash-cpu-problem/348239)

<div class="topic-metadata">

**Author:** [@marcowiskhy](https://discuss.elastic.co/u/marcowiskhy)\
**Replies:** 13\
**Last updated:** [December 4, 2023, 3:37am UTC](https://discuss.elastic.co/t/logstash-cpu-problem/348239 "2023-12-04T03:37:54Z")

</div>

Hey guys, I am ingesting firewall logs through logstash via tcp input and am dealing with an issue. Event logs (e.g. vpn) and UTM arrive normally, but when I enable traffic logs (which jumps from 20 eps to 3k eps) logst…

---

## [WARN and ERROR logs are not reflecting in Elasticsearch](https://discuss.elastic.co/t/warn-and-error-logs-are-not-reflecting-in-elasticsearch/348505)

<div class="topic-metadata">

**Author:** [@ErGeek](https://discuss.elastic.co/u/ErGeek)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 3:37am UTC](https://discuss.elastic.co/t/warn-and-error-logs-are-not-reflecting-in-elasticsearch/348505 "2023-12-04T03:37:21Z")

</div>

Hi All, When we are sending logs from Kafka to Elasticsearch, the logs belonging to log-levels "WARN" and "ERRORS" are not reflecting in the Discover page. But the "INFO" and "FATAL" loglevels are reflecting as expected…

---

## [Setting en variable for filebeat in ebextension](https://discuss.elastic.co/t/setting-en-variable-for-filebeat-in-ebextension/348465)

<div class="topic-metadata">

**Author:** [@apsh](https://discuss.elastic.co/u/apsh)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 12:13am UTC](https://discuss.elastic.co/t/setting-en-variable-for-filebeat-in-ebextension/348465 "2023-12-04T00:13:58Z")

</div>

I've been encountering an issue with my Filebeat setup on AWS Elastic Beanstalk. I'm trying to dynamically set the environment name in my Filebeat configuration using an environment variable ($ENVIRONMENT). However, it s…

---

## [API key owner](https://discuss.elastic.co/t/api-key-owner/348167)

<div class="topic-metadata">

**Author:** [@mcosta](https://discuss.elastic.co/u/mcosta)\
**Replies:** 8\
**Last updated:** [December 3, 2023, 11:59pm UTC](https://discuss.elastic.co/t/api-key-owner/348167 "2023-12-03T23:59:14Z")

</div>

Hi all, Using Elastic Cloud V8.10.2 I need to create several API keys to be used on logstash. When API key is created on Kibana -\> Security -\> API Keys, it ends with the owner being my user. When API key is created o…

---

## [Big data on the one server without cluster](https://discuss.elastic.co/t/big-data-on-the-one-server-without-cluster/348512)

<div class="topic-metadata">

**Author:** [@habajol675](https://discuss.elastic.co/u/habajol675)\
**Replies:** 1\
**Last updated:** [December 3, 2023, 11:18pm UTC](https://discuss.elastic.co/t/big-data-on-the-one-server-without-cluster/348512 "2023-12-03T23:18:50Z")

</div>

Hello everyone, I am currently studying the work of elastic and plan to transfer the search to elastic. I'm calculating how much space my database will take up and realized that I need several disks. My database will wei…

---

## [Persistent CertificateException error on running any of the elasticsearch tools in docker](https://discuss.elastic.co/t/persistent-certificateexception-error-on-running-any-of-the-elasticsearch-tools-in-docker/348492)

<div class="topic-metadata">

**Author:** [@bere\_test](https://discuss.elastic.co/u/bere_test)\
**Replies:** 5\
**Last updated:** [December 3, 2023, 8:46pm UTC](https://discuss.elastic.co/t/persistent-certificateexception-error-on-running-any-of-the-elasticsearch-tools-in-docker/348492 "2023-12-03T20:46:17Z")

</div>

I have set up an Elasticsearch and Kibana stack with the docker-compose.yml file obtained from here - https://github.com/elastic/elasticsearch/blob/main/docs/reference/setup/install/docker/docker-compose.yml. I can run k…

---

## [Elasticsearch CPU 100% GC](https://discuss.elastic.co/t/elasticsearch-cpu-100-gc/348466)

<div class="topic-metadata">

**Author:** [@marcowiskhy](https://discuss.elastic.co/u/marcowiskhy)\
**Replies:** 5\
**Last updated:** [December 3, 2023, 7:56pm UTC](https://discuss.elastic.co/t/elasticsearch-cpu-100-gc/348466 "2023-12-03T19:56:23Z")

</div>

Hey guys, On the last day I decided to perform some operations in Elasticsearch. I had some indexes that were generated daily by Logstash, until I decided to use ILM to automatically manage and generate rollbacks. After…

---

## [Filebeat configuration : multiline.\* (working) vs parsers (not working)](https://discuss.elastic.co/t/filebeat-configuration-multiline-working-vs-parsers-not-working/348508)

<div class="topic-metadata">

**Author:** [@jadam\_fr](https://discuss.elastic.co/u/jadam_fr)\
**Replies:** 2\
**Last updated:** [December 3, 2023, 8:21pm UTC](https://discuss.elastic.co/t/filebeat-configuration-multiline-working-vs-parsers-not-working/348508 "2023-12-03T20:21:12Z")

</div>

Hi, I'm a bit stumped trying to determine why this config using old-style multine.\* conf values works : filebeat.inputs: - type: stdin id: multi-line-log-ex close\_eof: true enabled: true multiline.pattern : '…

---

## [Are we about to violate the Elastic License 2.0？](https://discuss.elastic.co/t/are-we-about-to-violate-the-elastic-license-2-0/348488)

<div class="topic-metadata">

**Author:** [@Chengbo\_He](https://discuss.elastic.co/u/Chengbo_He)\
**Replies:** 2\
**Last updated:** [December 3, 2023, 2:37pm UTC](https://discuss.elastic.co/t/are-we-about-to-violate-the-elastic-license-2-0/348488 "2023-12-03T14:37:05Z")

</div>

Our team plans to develop a product that is similar to a security situational awareness platform, and we will sell this product to customers as a commodity. However, customers cannot directly interact with Elasticsearch.…

---

## [Not able to connect power BI ODBC to Elastic search](https://discuss.elastic.co/t/not-able-to-connect-power-bi-odbc-to-elastic-search/348170)

<div class="topic-metadata">

**Author:** [@cbeprem](https://discuss.elastic.co/u/cbeprem)\
**Replies:** 2\
**Last updated:** [December 3, 2023, 8:45am UTC](https://discuss.elastic.co/t/not-able-to-connect-power-bi-odbc-to-elastic-search/348170 "2023-12-03T08:45:59Z")

</div>

Hi Team, I have a Elastic cluster running on 7.17.6, but i am trying to connect Power Bi desktop to elastic through ODBC client , but it throwing the below error, also enclosed is the image. Kindly suggest me how …

---

## [Not able to filter from timestamp](https://discuss.elastic.co/t/not-able-to-filter-from-timestamp/346692)

<div class="topic-metadata">

**Author:** [@shivakrishnaadduri](https://discuss.elastic.co/u/shivakrishnaadduri)\
**Replies:** 2\
**Last updated:** [December 2, 2023, 9:46pm UTC](https://discuss.elastic.co/t/not-able-to-filter-from-timestamp/346692 "2023-12-02T21:46:44Z")

</div>

I am trying to filter last 10 or some x minutes of data based on values in timestamp Here is my timestamp data : "timestamp": "2023-11-08 14:28:06", and mapping info "timestamp": { "type": "date",…

---

## [Logstash pipeline StackOverflowError when using large conf file](https://discuss.elastic.co/t/logstash-pipeline-stackoverflowerror-when-using-large-conf-file/348471)

<div class="topic-metadata">

**Author:** [@blardy](https://discuss.elastic.co/u/blardy)\
**Replies:** 5\
**Last updated:** [December 2, 2023, 5:08pm UTC](https://discuss.elastic.co/t/logstash-pipeline-stackoverflowerror-when-using-large-conf-file/348471 "2023-12-02T17:08:10Z")

</div>

Hey there, Is there a limitation for logstash regarding the size of the configuration file ? I am having StackOverflowError error when logstash starts when using a large conf file (like 400kb) . Below an excerpt of th…

---

## [Issues related to address location search in Elasticsearch](https://discuss.elastic.co/t/issues-related-to-address-location-search-in-elasticsearch/348469)

<div class="topic-metadata">

**Author:** [@fangyan](https://discuss.elastic.co/u/fangyan)\
**Replies:** 0\
**Last updated:** [December 2, 2023, 8:01am UTC](https://discuss.elastic.co/t/issues-related-to-address-location-search-in-elasticsearch/348469 "2023-12-02T08:01:50Z")

</div>

There is now a demand list for paginated queries. Within a 10 kilometer radius, the search is based on sales volume and LBS rules, while outside the 10 kilometer radius, the search is based on ratings and LBS rules. I no…

---

## [\[logstash.licensechecker.licensereader\] Unable to retrieve Elasticsearch cluster info. {:message=\>"No Available connections", :exception=\>LogStash::Outputs::ElasticSearch::HttpClient::Pool::NoConnectionAvailableError}](https://discuss.elastic.co/t/logstash-licensechecker-licensereader-unable-to-retrieve-elasticsearch-cluster-info-message-no-available-connections-exception-logstash-noconnectionavailableerror/348421)

<div class="topic-metadata">

**Author:** [@Abdeljalil\_El\_Yousso](https://discuss.elastic.co/u/Abdeljalil_El_Yousso)\
**Replies:** 1\
**Last updated:** [December 2, 2023, 5:37am UTC](https://discuss.elastic.co/t/logstash-licensechecker-licensereader-unable-to-retrieve-elasticsearch-cluster-info-message-no-available-connections-exception-logstash-noconnectionavailableerror/348421 "2023-12-02T05:37:47Z")

</div>

Hey , im using elasticsearch 8.10 on docker , on a debian server , i cannot connect my logstash instance running also on dokcer , on a debian environement . i receive 3 error message WARN \]\[logstash.licensechecker.lice…

---

## [Email alert for exception](https://discuss.elastic.co/t/email-alert-for-exception/348077)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 5\
**Last updated:** [December 2, 2023, 3:48am UTC](https://discuss.elastic.co/t/email-alert-for-exception/348077 "2023-12-02T03:48:38Z")

</div>

Hi, I am running the Elastic Stack on Red Hat Enterprise Linux release 8.8 (Ootpa) and the versions are as below. # rpm -qa | grep logstash logstash-8.11.0-1.x86\_64 # rpm -qa | grep elasticsearch elasticsearch-8.11.0-1…

---

## [Exiting: error connecting to Kibana: fail to get the Kibana version: fail to parse kibana version (): passed version is not semver:](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-fail-to-parse-kibana-version-passed-version-is-not-semver/347263)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 3\
**Last updated:** [December 2, 2023, 12:08am UTC](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-fail-to-parse-kibana-version-passed-version-is-not-semver/347263 "2023-12-02T00:08:27Z")

</div>

Hello, I'm trying to follow: yet running into following error: Exiting: error connecting to Kibana: fail to get the Kibana version: fail to parse kibana version (): passed version is not semver: alexus@mbp kalei …

---

## [How to programmatically trigger dashboard refresh from a plugin](https://discuss.elastic.co/t/how-to-programmatically-trigger-dashboard-refresh-from-a-plugin/347947)

<div class="topic-metadata">

**Author:** [@Sanskar\_Panchal](https://discuss.elastic.co/u/Sanskar_Panchal)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 9:54pm UTC](https://discuss.elastic.co/t/how-to-programmatically-trigger-dashboard-refresh-from-a-plugin/347947 "2023-12-01T21:54:19Z")

</div>

Hi, I am building a plugin which adds a custom panel action for visualizations. I want to trigger dashboard refresh from with the code. I have access to data and dashboard plugin inside plugin , but I didn't find any f…

---

## [Split Chart Displays all possible values](https://discuss.elastic.co/t/split-chart-displays-all-possible-values/348083)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 9:58pm UTC](https://discuss.elastic.co/t/split-chart-displays-all-possible-values/348083 "2023-12-01T21:58:05Z")

</div>

Hi, I have two side by side visualizations that are the exact same, just with different filters. They both "Split chart" on the same field, which has a cardinality of 30. There are generally more records in the left…

---

## [Getting 502 bad gateway for a particular query](https://discuss.elastic.co/t/getting-502-bad-gateway-for-a-particular-query/348052)

<div class="topic-metadata">

**Author:** [@Nishant\_Garg](https://discuss.elastic.co/u/Nishant_Garg)\
**Replies:** 1\
**Last updated:** [December 1, 2023, 9:51pm UTC](https://discuss.elastic.co/t/getting-502-bad-gateway-for-a-particular-query/348052 "2023-12-01T21:51:22Z")

</div>

GET \*/\_search { "size": 10000, "query": { "bool": { "should": \[ {"match": {"imei": "value"}}, {"match": {"imei1": "value"}}, {"match": {"IMEI": "value"}} \] } } } this sa…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=358)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=360)
