# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=361

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 362

---

## [How to limit the dataset size of elastic/security ESRally track](https://discuss.elastic.co/t/how-to-limit-the-dataset-size-of-elastic-security-esrally-track/348281)

<div class="topic-metadata">

**Author:** [@VidR](https://discuss.elastic.co/u/VidR)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 1:01am UTC](https://discuss.elastic.co/t/how-to-limit-the-dataset-size-of-elastic-security-esrally-track/348281 "2023-11-30T01:01:05Z")

</div>

I am running esrally elastic/security track on ESRally version 2.7.0. By default, it downloads the following datasets, with total size of 128GB. but I only need ~30-50GB input dataset size. rally@benchmark-bqfd7:~/.ral…

---

## [Overwriting supplied index micro-%{appName}%{+YYYY.MM.dd} with rollover alias vehicle-service](https://discuss.elastic.co/t/overwriting-supplied-index-micro-appname-yyyy-mm-dd-with-rollover-alias-vehicle-service/348354)

<div class="topic-metadata">

**Author:** [@Gaurav\_Sharma3](https://discuss.elastic.co/u/Gaurav_Sharma3)\
**Replies:** 4\
**Last updated:** [December 1, 2023, 4:05am UTC](https://discuss.elastic.co/t/overwriting-supplied-index-micro-appname-yyyy-mm-dd-with-rollover-alias-vehicle-service/348354 "2023-12-01T04:05:04Z")

</div>

input { tcp { port =\> 5000 codec =\> json } } output { if \[appName\] =="user-service"{ elasticsearch { hosts =\> \["http://localhost:9200"\] index =\> "micro-%{appName}%{+YYYY.MM.dd}" # Use date-based index names i…

---

## [Problema de thread\_pool.write.queue\_size](https://discuss.elastic.co/t/problema-de-thread-pool-write-queue-size/348387)

<div class="topic-metadata">

**Author:** [@Kelvin\_A\_Escobar\_Mor](https://discuss.elastic.co/u/Kelvin_A_Escobar_Mor)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 3:41am UTC](https://discuss.elastic.co/t/problema-de-thread-pool-write-queue-size/348387 "2023-12-01T03:41:27Z")

</div>

Tengo problema con encolamiento en mis cluster esperimento problema de rendimeiento y en ocaciones mi cluster se cae por carga quisera saber cual es una buena alternativa para abordar temas de thread\_pool.write.queue\_siz…

---

## [When I try to mount some file to a docker elasticsearchcontainer, it always has some errors like no such file or directory](https://discuss.elastic.co/t/when-i-try-to-mount-some-file-to-a-docker-elasticsearchcontainer-it-always-has-some-errors-like-no-such-file-or-directory/348383)

<div class="topic-metadata">

**Author:** [@nmc10](https://discuss.elastic.co/u/nmc10)\
**Replies:** 2\
**Last updated:** [December 1, 2023, 3:39am UTC](https://discuss.elastic.co/t/when-i-try-to-mount-some-file-to-a-docker-elasticsearchcontainer-it-always-has-some-errors-like-no-such-file-or-directory/348383 "2023-12-01T03:39:14Z")

</div>

You can see these image to understand what I mean. I even run a test container and use ls command to check if the file existed but although it exist in the container, it still shows the error that it missed when I starte…

---

## [Auto email when get alerts on elastic](https://discuss.elastic.co/t/auto-email-when-get-alerts-on-elastic/348385)

<div class="topic-metadata">

**Author:** [@wang4321](https://discuss.elastic.co/u/wang4321)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 3:38am UTC](https://discuss.elastic.co/t/auto-email-when-get-alerts-on-elastic/348385 "2023-12-01T03:38:01Z")

</div>

Hi! Can I know about auto emailing when I get alerts on elastic

---

## [How can I get a client ip of search request in ielasticsearch?](https://discuss.elastic.co/t/how-can-i-get-a-client-ip-of-search-request-in-ielasticsearch/348284)

<div class="topic-metadata">

**Author:** [@yunpeng.jiangyp](https://discuss.elastic.co/u/yunpeng.jiangyp)\
**Replies:** 3\
**Last updated:** [December 1, 2023, 2:44am UTC](https://discuss.elastic.co/t/how-can-i-get-a-client-ip-of-search-request-in-ielasticsearch/348284 "2023-12-01T02:44:12Z")

</div>

Hi guys: I found a slow search request , but i didn't know the search request's client ip . Can I get a client ip of search request in elasticsearch?

---

## [Un acknowledged events in PQ](https://discuss.elastic.co/t/un-acknowledged-events-in-pq/348379)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 2:29am UTC](https://discuss.elastic.co/t/un-acknowledged-events-in-pq/348379 "2023-12-01T02:29:01Z")

</div>

Hi Team, Is there any way to check the ununacknowledged events from the Persistent Queue method. Unfortunately we are not able to use the metric queue\_persisted\_growth\_events to find the ununacknowledged. Regards Kan…

---

## [Log.original field lost with upgrade 8.6.1 from 1.5.3](https://discuss.elastic.co/t/log-original-field-lost-with-upgrade-8-6-1-from-1-5-3/348363)

<div class="topic-metadata">

**Author:** [@ridvandev](https://discuss.elastic.co/u/ridvandev)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 11:25pm UTC](https://discuss.elastic.co/t/log-original-field-lost-with-upgrade-8-6-1-from-1-5-3/348363 "2023-11-30T23:25:06Z")

</div>

We used to use the log.original field a lot for our searches in Kibana, but since the upgrade of Elastic.CommonSchema.Nlog package, I can't seem to find this field anymore. Also, it looks like the log template we depend …

---

## [MongoDB Output plugin 3.1.7 error](https://discuss.elastic.co/t/mongodb-output-plugin-3-1-7-error/348372)

<div class="topic-metadata">

**Author:** [@Daniela\_Juliana\_Sanc](https://discuss.elastic.co/u/Daniela_Juliana_Sanc)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 11:18pm UTC](https://discuss.elastic.co/t/mongodb-output-plugin-3-1-7-error/348372 "2023-11-30T23:18:46Z")

</div>

Hi, I am not able to connect to MongoDB Compass Version 7.0.3 with below error.Using plugin version 3.1.7. \[WARN \]\[logstash.outputs.mongodb \]\[main\] MONGODB | Failed to handshake with localhost:27017: ArgumentError: wro…

---

## [Elastic Controls show error - Not Found](https://discuss.elastic.co/t/elastic-controls-show-error-not-found/347746)

<div class="topic-metadata">

**Author:** [@rj6578](https://discuss.elastic.co/u/rj6578)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 8:56pm UTC](https://discuss.elastic.co/t/elastic-controls-show-error-not-found/347746 "2023-11-30T20:56:06Z")

</div>

This is probably a basic question and something I am doing wrong. I am trying to create some Controls to filter my search. However, the Controls only seems to show data when its set to Filter Type "Number", "string, IP"…

---

## [Logstash CA error](https://discuss.elastic.co/t/logstash-ca-error/348369)

<div class="topic-metadata">

**Author:** [@Marcus\_Berglund](https://discuss.elastic.co/u/Marcus_Berglund)\
**Replies:** 2\
**Last updated:** [November 30, 2023, 8:55pm UTC](https://discuss.elastic.co/t/logstash-ca-error/348369 "2023-11-30T20:55:49Z")

</div>

Hi, I have been sitting with this issue all day! :slight\_smile: and I get the below error (on windows) \[2023-11-30T21:42:08,979\]\[ERROR\]\[logstash.outputs.elasticsearch\] Invalid setting for elasticsearch output plugin: …

---

## [Kibana degraded after upgrade](https://discuss.elastic.co/t/kibana-degraded-after-upgrade/348160)

<div class="topic-metadata">

**Author:** [@rudyfaile](https://discuss.elastic.co/u/rudyfaile)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 8:53pm UTC](https://discuss.elastic.co/t/kibana-degraded-after-upgrade/348160 "2023-11-30T20:53:35Z")

</div>

Hi, I upgraded my ELK stack running on self-hosted kubernetes. My Elasticsearch cluster is green, but my kibana instance is spewing error logs like: │ kibana \[2023-11-28T15:24:58.959+00:00\]\[ERROR\]\[plugins.taskManager\] …

---

## [NodeEnvironment.assertEnvIsLocked threw java.io.IOException: The device is not ready](https://discuss.elastic.co/t/nodeenvironment-assertenvislocked-threw-java-io-ioexception-the-device-is-not-ready/348089)

<div class="topic-metadata">

**Author:** [@blademan](https://discuss.elastic.co/u/blademan)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 8:46pm UTC](https://discuss.elastic.co/t/nodeenvironment-assertenvislocked-threw-java-io-ioexception-the-device-is-not-ready/348089 "2023-11-30T20:46:15Z")

</div>

ES is deployed on an Azure VMSS (Windows VMs). It's throwing java.io.IOException "The device is not ready" on some VMs when creating shards, while working well on some other VMs at the same time. Here is what the except…

---

## [Filebeat Context Error](https://discuss.elastic.co/t/filebeat-context-error/348366)

<div class="topic-metadata">

**Author:** [@bigdaddy0918](https://discuss.elastic.co/u/bigdaddy0918)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 8:41pm UTC](https://discuss.elastic.co/t/filebeat-context-error/348366 "2023-11-30T20:41:57Z")

</div>

I was able to push a new CEL input to Filebeat v8.7.1 via puppet. When we launch filebeat v.8.7.1 I see this message pop up in the log: {"log.level":"info","@timestamp":"2023-11-30T19:59:28.167Z","log.logger":"input.ce…

---

## [Watcher Http Input - PKIX path building failed](https://discuss.elastic.co/t/watcher-http-input-pkix-path-building-failed/348279)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 14\
**Last updated:** [November 30, 2023, 7:52pm UTC](https://discuss.elastic.co/t/watcher-http-input-pkix-path-building-failed/348279 "2023-11-30T19:52:34Z")

</div>

Hi, I create a watcher to monitoring de HEALTH of the Cluster. I did get this error on the watcher response: I also check my kibana configuration and I have TLS config : I dont know why this error happend!

---

## [Can not create a document has mutlipolygon having hole](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/348177)

<div class="topic-metadata">

**Author:** [@Sai\_Suvam\_Patnaik](https://discuss.elastic.co/u/Sai_Suvam_Patnaik)\
**Replies:** 2\
**Last updated:** [November 30, 2023, 6:31pm UTC](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/348177 "2023-11-30T18:31:07Z")

</div>

Hi, can anyone help me I am facing a following. Summary Can not create a document has mutlipolygon having hole. I do not know why responses reason is correct or this is bug? I have visualize the multipolygon, using …

---

## [Mapping in the new .NET client V8](https://discuss.elastic.co/t/mapping-in-the-new-net-client-v8/348357)

<div class="topic-metadata">

**Author:** [@MountainMoon](https://discuss.elastic.co/u/MountainMoon)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 6:29pm UTC](https://discuss.elastic.co/t/mapping-in-the-new-net-client-v8/348357 "2023-11-30T18:29:34Z")

</div>

I'm trying to write a mapping function using V8 client library. But there is not much i can configure. For example in the NEST V7, i can specify analyzer, multifields to a certain field via fluent mapping: ''' .Text(tt…

---

## [Logstash HTTP\_POLLER issue - PKIX path bulding failed](https://discuss.elastic.co/t/logstash-http-poller-issue-pkix-path-bulding-failed/348356)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 6:09pm UTC](https://discuss.elastic.co/t/logstash-http-poller-issue-pkix-path-bulding-failed/348356 "2023-11-30T18:09:48Z")

</div>

hi, I got this error when I try to extract information of Elasticsearch form logstash: cfg config on logstash Do you know what could be my error?

---

## [\[Kibana\] High and inconsistent RAM usage after upgrade to 8.11.1](https://discuss.elastic.co/t/kibana-high-and-inconsistent-ram-usage-after-upgrade-to-8-11-1/347825)

<div class="topic-metadata">

**Author:** [@byildiz](https://discuss.elastic.co/u/byildiz)\
**Replies:** 2\
**Last updated:** [November 30, 2023, 4:32pm UTC](https://discuss.elastic.co/t/kibana-high-and-inconsistent-ram-usage-after-upgrade-to-8-11-1/347825 "2023-11-30T16:32:22Z")

</div>

Hi guys, we have updated our Elastic Stack to the current latest version 8.11.1. But we have observed a higher RAM usage and data lacks related to the kibana instance, therefore we didn't continue to update our prod sta…

---

## [Failed to CompressedXContent on RestHighLevelClient 7.13](https://discuss.elastic.co/t/failed-to-compressedxcontent-on-resthighlevelclient-7-13/348345)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 4:30pm UTC](https://discuss.elastic.co/t/failed-to-compressedxcontent-on-resthighlevelclient-7-13/348345 "2023-11-30T16:30:20Z")

</div>

Hi, I am getting the following exception when creatin new CompressedXContent for Template instance ElasticsearchParseException\[Failed to parse content to map\]; nested: JsonParseException\[Unexpected character ('p' (code…

---

## [How to use snapshot repo url](https://discuss.elastic.co/t/how-to-use-snapshot-repo-url/348274)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 4:19pm UTC](https://discuss.elastic.co/t/how-to-use-snapshot-repo-url/348274 "2023-11-30T16:19:03Z")

</div>

Hi, We are creating a parallel cluster and we need to migrate all the data. I saw the option where we can take the snapshot on existing cluster and create a repo url which can be used by another cluster and we can resto…

---

## [How can fill logstash output in filebeat.yml file](https://discuss.elastic.co/t/how-can-fill-logstash-output-in-filebeat-yml-file/346556)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 4:05pm UTC](https://discuss.elastic.co/t/how-can-fill-logstash-output-in-filebeat-yml-file/346556 "2023-11-30T16:05:07Z")

</div>

This my elasticsearch output part in filebeat.yml file but I want to send logs to logstash # ---------------------------- Elasticsearch Output ---------------------------- output.elasticsearch: # Array of hosts to con…

---

## [Filebeat ignoring closing bracket {](https://discuss.elastic.co/t/filebeat-ignoring-closing-bracket/348312)

<div class="topic-metadata">

**Author:** [@Venkata\_Raja](https://discuss.elastic.co/u/Venkata_Raja)\
**Replies:** 9\
**Last updated:** [November 30, 2023, 3:06pm UTC](https://discuss.elastic.co/t/filebeat-ignoring-closing-bracket/348312 "2023-11-30T15:06:19Z")

</div>

Hi Team,, I have a multiline JSON message in a file , I used custom log integration to parse it with below multiline config. multiline: match: after negate: true pattern: '^{' I was getting all the data except last…

---

## [Trouble Finding Most Efficient Way to Optimize My Elastic Stack](https://discuss.elastic.co/t/trouble-finding-most-efficient-way-to-optimize-my-elastic-stack/348342)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 0\
**Last updated:** [November 30, 2023, 3:36pm UTC](https://discuss.elastic.co/t/trouble-finding-most-efficient-way-to-optimize-my-elastic-stack/348342 "2023-11-30T15:36:47Z")

</div>

Hello, I've been trying to play around with my settings to try to optimize my Elastic Stack. My main goal, right now, is to have my searches load faster. For example, when I load my dashboards, it takes 30 seconds to 1+…

---

## [Create a Kibana Rule](https://discuss.elastic.co/t/create-a-kibana-rule/348333)

<div class="topic-metadata">

**Author:** [@Claudia\_Tavares](https://discuss.elastic.co/u/Claudia_Tavares)\
**Replies:** 2\
**Last updated:** [November 30, 2023, 3:05pm UTC](https://discuss.elastic.co/t/create-a-kibana-rule/348333 "2023-11-30T15:05:54Z")

</div>

Kibana: version 7.17.3 I am trying to create a Rule in Kibana Alerts and Insights, but I'm having some difficults. To contextualize: 1- I want to calculate the total of documents in last 5 minutes 2- Calculate the nu…

---

## [ML Anomaly Job with exclude\_frequent option](https://discuss.elastic.co/t/ml-anomaly-job-with-exclude-frequent-option/348047)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 2:53pm UTC](https://discuss.elastic.co/t/ml-anomaly-job-with-exclude-frequent-option/348047 "2023-11-30T14:53:51Z")

</div>

Hello everyone, i was reading through the docs and became curious Say i create two detectors. One detector is high\_sum(a) over b The other detector is high\_sum(a) by c. Now, if i define exclude\_frequent = over for …

---

## [Elasticsearch Query](https://discuss.elastic.co/t/elasticsearch-query/347768)

<div class="topic-metadata">

**Author:** [@Brian-cf1](https://discuss.elastic.co/u/Brian-cf1)\
**Replies:** 3\
**Last updated:** [November 30, 2023, 2:41pm UTC](https://discuss.elastic.co/t/elasticsearch-query/347768 "2023-11-30T14:41:57Z")

</div>

How do i exclude multiple keywords from a field ? I need the following logic but its not letting me include 2 wild cards "must\_not": \[ { "wildcard": { "error.message": { "value": …

---

## [Customizing Elastic Map Service Basemaps](https://discuss.elastic.co/t/customizing-elastic-map-service-basemaps/348276)

<div class="topic-metadata">

**Author:** [@m.hanna](https://discuss.elastic.co/u/m.hanna)\
**Replies:** 5\
**Last updated:** [November 30, 2023, 2:29pm UTC](https://discuss.elastic.co/t/customizing-elastic-map-service-basemaps/348276 "2023-11-30T14:29:55Z")

</div>

I am testing using Elastic Map Service on a disconnected network. I am able to get the server installed and running, but the basemaps are quite busy and not that nice to look at. I was able to clean up the basemaps by m…

---

## [Filebeat reads logs from various locations?](https://discuss.elastic.co/t/filebeat-reads-logs-from-various-locations/348332)

<div class="topic-metadata">

**Author:** [@Satsan](https://discuss.elastic.co/u/Satsan)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 2:16pm UTC](https://discuss.elastic.co/t/filebeat-reads-logs-from-various-locations/348332 "2023-11-30T14:16:27Z")

</div>

Filebeat reads logs from various locations in same yml file and sends them to the ELK (Elasticsearch, Logstash, and Kibana) stack for processing and analysis? For instance: -log.file.path: /etc/home/usr/logs -log.fil…

---

## [Unexpected Behavior of Kibana Query for Filtering Logs with Specific Keywords](https://discuss.elastic.co/t/unexpected-behavior-of-kibana-query-for-filtering-logs-with-specific-keywords/348055)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 1\
**Last updated:** [November 30, 2023, 2:04pm UTC](https://discuss.elastic.co/t/unexpected-behavior-of-kibana-query-for-filtering-logs-with-specific-keywords/348055 "2023-11-30T14:04:30Z")

</div>

I'm using a Kibana query (log\_message:(Started\* OR Disabled\*)) to filter logs that start with the keywords "Started" or "Disabled". However, I've noticed that this query also returns log lines containing these keywords i…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=360)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=362)
