# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=375

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 376

---

## [ES 7.8.1 crashing, insufficient memory... why?!](https://discuss.elastic.co/t/es-7-8-1-crashing-insufficient-memory-why/347050)

<div class="topic-metadata">

**Author:** [@jsamhall](https://discuss.elastic.co/u/jsamhall)\
**Replies:** 4\
**Last updated:** [November 14, 2023, 8:48am UTC](https://discuss.elastic.co/t/es-7-8-1-crashing-insufficient-memory-why/347050 "2023-11-14T08:48:12Z")

</div>

Hello, I am new to being a sysadmin for ES and in this case, it is backing a Magento2 installation running on Ubuntu 18.04 LTS Problem: Occasionally, and I'm not sure why, ES performance begins to degrade and then cra…

---

## [Field and Value missmatch Paolo Alto OS11 paring Logstash \> Elastic \> Kibana](https://discuss.elastic.co/t/field-and-value-missmatch-paolo-alto-os11-paring-logstash-elastic-kibana/346969)

<div class="topic-metadata">

**Author:** [@Trung\_Nguyen](https://discuss.elastic.co/u/Trung_Nguyen)\
**Replies:** 5\
**Last updated:** [November 14, 2023, 8:30am UTC](https://discuss.elastic.co/t/field-and-value-missmatch-paolo-alto-os11-paring-logstash-elastic-kibana/346969 "2023-11-14T08:30:59Z")

</div>

Hi, i'm a new logstash and trying to parsing log from my firewall PAN\_OS 11 but the field and value dose not match, such as field "NAT Destination IP" get value from the "Rule Name" Thanks a lot for any hlep Trung

---

## [Logstash and since db permission](https://discuss.elastic.co/t/logstash-and-since-db-permission/346934)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 2\
**Last updated:** [November 14, 2023, 7:15am UTC](https://discuss.elastic.co/t/logstash-and-since-db-permission/346934 "2023-11-14T07:15:56Z")

</div>

Logstash runs as a container.logstash version 8.11.0 Logstash input looks like the below input { file { path =\> "/common/logs/parser-server-tasks-application/app.log" start\_position =\> "beginning" sincedb…

---

## [Explore data in Discover in Bar chart is disabled](https://discuss.elastic.co/t/explore-data-in-discover-in-bar-chart-is-disabled/346862)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 3\
**Last updated:** [November 14, 2023, 7:07am UTC](https://discuss.elastic.co/t/explore-data-in-discover-in-bar-chart-is-disabled/346862 "2023-11-14T07:07:10Z")

</div>

Hi Team, we are trying to get the Explore data in discover option in Bar charts. Scenario: Here we have three Bar vertical layers individually in lens visualization then we are not getting the option (in Settings---\>Mo…

---

## [Is Logstash Free use?](https://discuss.elastic.co/t/is-logstash-free-use/347078)

<div class="topic-metadata">

**Author:** [@inbeom\_cho](https://discuss.elastic.co/u/inbeom_cho)\
**Replies:** 1\
**Last updated:** [November 14, 2023, 6:10am UTC](https://discuss.elastic.co/t/is-logstash-free-use/347078 "2023-11-14T06:10:55Z")

</div>

Hi forum, when i use only logstash 8.8 version, that is free? Or If i want free, must use logstash oss?

---

## [Reindex Api "didn't store \_source" error](https://discuss.elastic.co/t/reindex-api-didnt-store-source-error/347043)

<div class="topic-metadata">

**Author:** [@Hakan\_Kara](https://discuss.elastic.co/u/Hakan_Kara)\
**Replies:** 4\
**Last updated:** [November 14, 2023, 5:48am UTC](https://discuss.elastic.co/t/reindex-api-didnt-store-source-error/347043 "2023-11-14T05:48:46Z")

</div>

Hello, we are getting following error while using reindex api. Could we ignore these kind of errors with reindex api ? Or could we destroy the following doc with given id ? { "type" : "illegal\_argument\_exception", …

---

## [Elastic Agent RUM - Cryptography](https://discuss.elastic.co/t/elastic-agent-rum-cryptography/345568)

<div class="topic-metadata">

**Author:** [@Gelinski](https://discuss.elastic.co/u/Gelinski)\
**Replies:** 4\
**Last updated:** [November 14, 2023, 3:36am UTC](https://discuss.elastic.co/t/elastic-agent-rum-cryptography/345568 "2023-11-14T03:36:15Z")

</div>

Hello folks, What is the algorithm used to encrypt data between Elastic Agent RUM and APM server? Thanks, Matheus

---

## [Elasticsearch Kibana](https://discuss.elastic.co/t/elasticsearch-kibana/346944)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 5\
**Last updated:** [November 14, 2023, 3:31am UTC](https://discuss.elastic.co/t/elasticsearch-kibana/346944 "2023-11-14T03:31:34Z")

</div>

Hi Team, I was deployed Elasticsearch cluster with one master node one data node on docker with version of 8.8.1 When i am trying to add that into Kibana I am getting an error. \[2023-11-13T04:55:05.704+00:00\]\[WARN \]\[sav…

---

## [Logstash Kafka input handling extended JSON format](https://discuss.elastic.co/t/logstash-kafka-input-handling-extended-json-format/347068)

<div class="topic-metadata">

**Author:** [@ys\_goh](https://discuss.elastic.co/u/ys_goh)\
**Replies:** 1\
**Last updated:** [November 14, 2023, 1:49am UTC](https://discuss.elastic.co/t/logstash-kafka-input-handling-extended-json-format/347068 "2023-11-14T01:49:54Z")

</div>

Hello all, I am trying to get data from MongoDB to OpenSearch, and this is our pipeline: MongoDB ==\> Kafka source connector ==\> Kafka topic ==\> Logstash ==\> OpenSearch Problem is, when MongoDB data get written into the…

---

## [Logstash: SNMP Poll Input - skipping "error: no such.."](https://discuss.elastic.co/t/logstash-snmp-poll-input-skipping-error-no-such/347051)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 10:59pm UTC](https://discuss.elastic.co/t/logstash-snmp-poll-input-skipping-error-no-such/347051 "2023-11-13T22:59:49Z")

</div>

Hello, I am using SNMP poll input for logstash. Using SNMP V3, I have a wide range of network devices to monitor which means many oids that are specific by vendor. I want to know if there is a way to skip oids in whic…

---

## [Failure on document\_parsing\_exception - dot\_product similarity on dense\_vector index field](https://discuss.elastic.co/t/failure-on-document-parsing-exception-dot-product-similarity-on-dense-vector-index-field/346718)

<div class="topic-metadata">

**Author:** [@ORipalta](https://discuss.elastic.co/u/ORipalta)\
**Replies:** 5\
**Last updated:** [November 13, 2023, 9:58pm UTC](https://discuss.elastic.co/t/failure-on-document-parsing-exception-dot-product-similarity-on-dense-vector-index-field/346718 "2023-11-13T21:58:00Z")

</div>

I'm trying to use dot-plot similarity on Elasticsearch. But after creating the index, the data/rows fail to load due to document\_parsing\_exception. The error message that is being returned is failed to parse: The \[dot\_p…

---

## [Can't delete or recover .kibana\_security\_session\_1 index](https://discuss.elastic.co/t/cant-delete-or-recover-kibana-security-session-1-index/347035)

<div class="topic-metadata">

**Author:** [@RRGTHWAR](https://discuss.elastic.co/u/RRGTHWAR)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 9:26pm UTC](https://discuss.elastic.co/t/cant-delete-or-recover-kibana-security-session-1-index/347035 "2023-11-13T21:26:44Z")

</div>

My storage team badly botched an upgrade, and as a result the .kibana\_security\_session\_1 index in my ECK cluster was corrupted. I don't have any backups of it to restore, and I can't delete it because the superuser privi…

---

## [QueryPhaseCollector invokes lucene score() twice on every doc when min\_score is used](https://discuss.elastic.co/t/queryphasecollector-invokes-lucene-score-twice-on-every-doc-when-min-score-is-used/347062)

<div class="topic-metadata">

**Author:** [@Mike\_McMahon](https://discuss.elastic.co/u/Mike_McMahon)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 8:56pm UTC](https://discuss.elastic.co/t/queryphasecollector-invokes-lucene-score-twice-on-every-doc-when-min-score-is-used/347062 "2023-11-13T20:56:42Z")

</div>

Elastic 8.10 introduced a major change QueryPhaseCollector (see https://github.com/elastic/elasticsearch/pull/97410) in how lucene queries are executed. I have observed that now, when using min\_score, each document gets …

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/346809)

<div class="topic-metadata">

**Author:** [@maycoonferreira](https://discuss.elastic.co/u/maycoonferreira)\
**Replies:** 17\
**Last updated:** [November 13, 2023, 6:54pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/346809 "2023-11-13T18:54:52Z")

</div>

Kibana server is not ready yet

---

## [Elasticsearch 8.10.2 synonyms not working when synonyms\_path is used](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working-when-synonyms-path-is-used/346745)

<div class="topic-metadata">

**Author:** [@smritibhandari91](https://discuss.elastic.co/u/smritibhandari91)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 6:35pm UTC](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working-when-synonyms-path-is-used/346745 "2023-11-13T18:35:24Z")

</div>

We successfully deployed Elasticsearch 8.10.2 using the ECK operator. However, we encountered an issue when trying to access the synonyms\_path during the index creation process. Error: The problem is that the index crea…

---

## [No .PEM generated when using --pem mode in elasticsearch-certutil](https://discuss.elastic.co/t/no-pem-generated-when-using-pem-mode-in-elasticsearch-certutil/347046)

<div class="topic-metadata">

**Author:** [@carel0x53](https://discuss.elastic.co/u/carel0x53)\
**Replies:** 3\
**Last updated:** [November 13, 2023, 5:37pm UTC](https://discuss.elastic.co/t/no-pem-generated-when-using-pem-mode-in-elasticsearch-certutil/347046 "2023-11-13T17:37:08Z")

</div>

I'm trying to generate a PEM certificate for elasticsearch using elasticsearch-certutil by introducing the following line bin/elasticsearch-certutil ca --pem Then, the program asks me to set a name for the resulting .z…

---

## [Kibana 8.11.0 Failed To Start (Exit Code 1)](https://discuss.elastic.co/t/kibana-8-11-0-failed-to-start-exit-code-1/346893)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 53\
**Last updated:** [November 13, 2023, 4:53pm UTC](https://discuss.elastic.co/t/kibana-8-11-0-failed-to-start-exit-code-1/346893 "2023-11-13T16:53:10Z")

</div>

I am running a ELK Stack in a local hosted Docker Container that comprises of sub containers of Elasticsearch, Kibana and Logstash service. Setup / config wise, I followed Ali Younges youtube video closely to setup. …

---

## [Can I make a read only dashboard for display purposes?](https://discuss.elastic.co/t/can-i-make-a-read-only-dashboard-for-display-purposes/346781)

<div class="topic-metadata">

**Author:** [@ivahbo](https://discuss.elastic.co/u/ivahbo)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 4:28pm UTC](https://discuss.elastic.co/t/can-i-make-a-read-only-dashboard-for-display-purposes/346781 "2023-11-13T16:28:10Z")

</div>

I want a dashboard I can give out as a URL that only exposes the components of the dashboard (pretty charts) and no other menus.

---

## [Logstash does not execute certain queries correctly](https://discuss.elastic.co/t/logstash-does-not-execute-certain-queries-correctly/346800)

<div class="topic-metadata">

**Author:** [@Stefan\_Sabolowitsch](https://discuss.elastic.co/u/Stefan_Sabolowitsch)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 4:20pm UTC](https://discuss.elastic.co/t/logstash-does-not-execute-certain-queries-correctly/346800 "2023-11-13T16:20:49Z")

</div>

Hi there i do not understand the behavior of logstash. Although the field is\_read exists, a successful query is still performed and an e-mail is sent. input { elasticsearch { hosts =\> "https://elasti…

---

## [How to migrate my information from one cluster to another?](https://discuss.elastic.co/t/how-to-migrate-my-information-from-one-cluster-to-another/347027)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 3:52pm UTC](https://discuss.elastic.co/t/how-to-migrate-my-information-from-one-cluster-to-another/347027 "2023-11-13T15:52:58Z")

</div>

How to migrate information from a version 7.17 cluster to a version 8.10 cluster manually without using the cloud.

---

## [What is better, update or install from the beginning?](https://discuss.elastic.co/t/what-is-better-update-or-install-from-the-beginning/346820)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 3:26pm UTC](https://discuss.elastic.co/t/what-is-better-update-or-install-from-the-beginning/346820 "2023-11-13T15:26:18Z")

</div>

Hello, good day, I have an elasticsearch cluster with version 7.17. I would like to know what is most convenient? upgrade the cluster to version 8.10 or perform a new installation with version 8.10 and only migrate the d…

---

## [Elastic Integration with Sentinel one deep visibility data](https://discuss.elastic.co/t/elastic-integration-with-sentinel-one-deep-visibility-data/346301)

<div class="topic-metadata">

**Author:** [@ksrawat88](https://discuss.elastic.co/u/ksrawat88)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 3:05pm UTC](https://discuss.elastic.co/t/elastic-integration-with-sentinel-one-deep-visibility-data/346301 "2023-11-13T15:05:12Z")

</div>

Anyone has integrated Sentinel one deep visibility data with ELK stack.? or atlease able to search on sentinel one deep visibilty data from Kibana. ? We are looking in this option and right now we have open source ELK s…

---

## [Why is .transform-notifications in my snaphot?](https://discuss.elastic.co/t/why-is-transform-notifications-in-my-snaphot/347028)

<div class="topic-metadata">

**Author:** [@Alain\_Bod](https://discuss.elastic.co/u/Alain_Bod)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/why-is-transform-notifications-in-my-snaphot/347028 "2023-11-13T15:02:43Z")

</div>

Hi, I've created a snaphot policy with indices "index1, index2". But I get ".transform-notifications" as well in my snapshot. Why is that? ES version 8.11.0

---

## [Stats aggregation: as\_string fields missing when searching in multiple indices](https://discuss.elastic.co/t/stats-aggregation-as-string-fields-missing-when-searching-in-multiple-indices/347016)

<div class="topic-metadata">

**Author:** [@msh](https://discuss.elastic.co/u/msh)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 1:23pm UTC](https://discuss.elastic.co/t/stats-aggregation-as-string-fields-missing-when-searching-in-multiple-indices/347016 "2023-11-13T13:23:19Z")

</div>

Hi, here are steps to reproduce: Fresh installation of ES v 8.11 Create an index "items" with a document containing a date: curl --location --request PUT 'localhost:9200/items/\_doc/1' \\ --header 'Content-Type: applic…

---

## [Show only Data in the kibana table if any of the column's has more than one value](https://discuss.elastic.co/t/show-only-data-in-the-kibana-table-if-any-of-the-columns-has-more-than-one-value/346867)

<div class="topic-metadata">

**Author:** [@Rajesh\_Cherukuri](https://discuss.elastic.co/u/Rajesh_Cherukuri)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 1:46pm UTC](https://discuss.elastic.co/t/show-only-data-in-the-kibana-table-if-any-of-the-columns-has-more-than-one-value/346867 "2023-11-13T13:46:09Z")

</div>

hi here is the kibana table visualization where multiple values are available only for few columns i want to show only columns that has multiple values but not the columns that has single value

---

## [LDAP user authentication](https://discuss.elastic.co/t/ldap-user-authentication/347000)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 12:58pm UTC](https://discuss.elastic.co/t/ldap-user-authentication/347000 "2023-11-13T12:58:31Z")

</div>

Hello, I want to configure LDAP. Should the configuration be done at the Kibana level or the Elasticsearch level? And for the flow openings, should I create openings between LDAP and Kibana or LDAP and Elasticsearch? T…

---

## [How should I configure memory swapping?](https://discuss.elastic.co/t/how-should-i-configure-memory-swapping/347010)

<div class="topic-metadata">

**Author:** [@elasticsearchman](https://discuss.elastic.co/u/elasticsearchman)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 12:24pm UTC](https://discuss.elastic.co/t/how-should-i-configure-memory-swapping/347010 "2023-11-13T12:24:47Z")

</div>

Hello, I want to build Elasticsearch and Kibana using Podman on RHEL 8.5. It is my understanding that disabling memory swapping is a best practice in Elasticsearch. I am planning to implement the following settings bas…

---

## [Cisco Meraki webhooks integration fails when using shared secrets](https://discuss.elastic.co/t/cisco-meraki-webhooks-integration-fails-when-using-shared-secrets/347007)

<div class="topic-metadata">

**Author:** [@brynjar](https://discuss.elastic.co/u/brynjar)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 11:59am UTC](https://discuss.elastic.co/t/cisco-meraki-webhooks-integration-fails-when-using-shared-secrets/347007 "2023-11-13T11:59:53Z")

</div>

Hello, I've been testing the Cisco Meraki webhooks integration lately, and while it works just fine without specifying a shared secret, it stops working immediately once any text is entered in secret\_value as described …

---

## [The state of the new Java Client (ES 8)](https://discuss.elastic.co/t/the-state-of-the-new-java-client-es-8/346689)

<div class="topic-metadata">

**Author:** [@rand0m86](https://discuss.elastic.co/u/rand0m86)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 11:58am UTC](https://discuss.elastic.co/t/the-state-of-the-new-java-client-es-8/346689 "2023-11-13T11:58:41Z")

</div>

Hi there, I just want to hear back from ES maintainers on the current state of the new Elasticsearch Java Client. We did quite some effort migrating our app from ES 6.8 to 8.x in terms of switching to this new client, …

---

## [TSDS Best Compression On ILM Rollover?](https://discuss.elastic.co/t/tsds-best-compression-on-ilm-rollover/346886)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 11:36am UTC](https://discuss.elastic.co/t/tsds-best-compression-on-ilm-rollover/346886 "2023-11-13T11:36:29Z")

</div>

Hi All, I recently saw this issue; Don't set index.codec: 'best\_compression' for TSDB data streams · Issue #160288 · elastic/kibana (github.com), and I was kind of curious. What is the guidance for compression as part o…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=374)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=376)
