# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=383

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 384

---

## [Elasticsearch vm.max\_map\_count error in docker image on MacOS 14](https://discuss.elastic.co/t/elasticsearch-vm-max-map-count-error-in-docker-image-on-macos-14/346285)

<div class="topic-metadata">

**Author:** [@timofeyp](https://discuss.elastic.co/u/timofeyp)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 3:54pm UTC](https://discuss.elastic.co/t/elasticsearch-vm-max-map-count-error-in-docker-image-on-macos-14/346285 "2023-11-02T15:54:29Z")

</div>

Hello! I have the "vm.max\_map\_count \[65530\] is too low, increase to at least \[262144\]" error while elastic container starting on Docker 4.25, MacOS 14 and ARM core. Here is my container props: image: elasticsearch…

---

## [Elastic Architecture review](https://discuss.elastic.co/t/elastic-architecture-review/345987)

<div class="topic-metadata">

**Author:** [@ksrawat88](https://discuss.elastic.co/u/ksrawat88)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 3:24pm UTC](https://discuss.elastic.co/t/elastic-architecture-review/345987 "2023-11-02T15:24:03Z")

</div>

We are planning to deploy elastic stack for logging and monitoring as SIEM, we want to start from open source version (community version) and if we see value we would upgrade to enterprise version with full security feat…

---

## [How can you know that a logstash input query has finished](https://discuss.elastic.co/t/how-can-you-know-that-a-logstash-input-query-has-finished/346173)

<div class="topic-metadata">

**Author:** [@dimitris\_sb](https://discuss.elastic.co/u/dimitris_sb)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 3:22pm UTC](https://discuss.elastic.co/t/how-can-you-know-that-a-logstash-input-query-has-finished/346173 "2023-11-02T15:22:31Z")

</div>

Hi All, If you deploy a logstash pipeline using the input plugin with a query, how could you know that ingesting data has been completed to decommission it? Thank you in advance for your insight

---

## [Elasticsearch 8.10.2 synonyms not working](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working/346303)

<div class="topic-metadata">

**Author:** [@smritibhandari91](https://discuss.elastic.co/u/smritibhandari91)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 3:16pm UTC](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working/346303 "2023-11-02T15:16:53Z")

</div>

We have deployed Elasticsearch 8.10.2 via ECK. The deployment is successful, however, we are facing below two issues: Index creation failing with IOException while reading synonyms\_path\_path. Synonym path has been succ…

---

## [Data not updating on kibana](https://discuss.elastic.co/t/data-not-updating-on-kibana/346297)

<div class="topic-metadata">

**Author:** [@IJ\_Oma](https://discuss.elastic.co/u/IJ_Oma)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 2:55pm UTC](https://discuss.elastic.co/t/data-not-updating-on-kibana/346297 "2023-11-02T14:55:22Z")

</div>

Hello all, Data stopped flowing from the database jbdc through logstash to kibana across all indices. Is anyone else having same issue? For about more than a week now, data updates on kibana via logstash has been very s…

---

## [What is logstash instance?](https://discuss.elastic.co/t/what-is-logstash-instance/345357)

<div class="topic-metadata">

**Author:** [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)\
**Replies:** 10\
**Last updated:** [November 2, 2023, 2:50pm UTC](https://discuss.elastic.co/t/what-is-logstash-instance/345357 "2023-11-02T14:50:49Z")

</div>

I want to know what a logstash instance is? Is it a self-generated .conf file? Which command should I use to check which instances are running?

---

## [Multiline pattern for covering all inconsistencies](https://discuss.elastic.co/t/multiline-pattern-for-covering-all-inconsistencies/346162)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 6\
**Last updated:** [November 2, 2023, 2:46pm UTC](https://discuss.elastic.co/t/multiline-pattern-for-covering-all-inconsistencies/346162 "2023-11-02T14:46:00Z")

</div>

Hello All, The application log generates messages which include various lines (not the same number every time). It also contains messages in XML form and various other kind. Is there a way I could define a multiline.p…

---

## [Data view in Kibana with the latest timestamp version of a datastream](https://discuss.elastic.co/t/data-view-in-kibana-with-the-latest-timestamp-version-of-a-datastream/345177)

<div class="topic-metadata">

**Author:** [@Mubolio](https://discuss.elastic.co/u/Mubolio)\
**Replies:** 11\
**Last updated:** [November 2, 2023, 1:34pm UTC](https://discuss.elastic.co/t/data-view-in-kibana-with-the-latest-timestamp-version-of-a-datastream/345177 "2023-11-02T13:34:41Z")

</div>

Hello, I have a datastream that it is often being updated, for some graphs I use the full data stream for visualizations, for example, doing histograms with the @timestamp field. But for other cases I would like to do g…

---

## [Undefined method \`accept' for nil:NilClass](https://discuss.elastic.co/t/undefined-method-accept-for-nil-nilclass/346226)

<div class="topic-metadata">

**Author:** [@jsamuel](https://discuss.elastic.co/u/jsamuel)\
**Replies:** 4\
**Last updated:** [November 2, 2023, 1:23pm UTC](https://discuss.elastic.co/t/undefined-method-accept-for-nil-nilclass/346226 "2023-11-02T13:23:53Z")

</div>

At present, we are operating several instances of Elasticsearch, encompassing both 5.x and 6.x versions, and are in the process of assessing the viability of OpenSearch. However, it is imperative to maintain the current …

---

## [Ingest and Conditional Routing](https://discuss.elastic.co/t/ingest-and-conditional-routing/346231)

<div class="topic-metadata">

**Author:** [@Cal](https://discuss.elastic.co/u/Cal)\
**Replies:** 6\
**Last updated:** [November 2, 2023, 1:00pm UTC](https://discuss.elastic.co/t/ingest-and-conditional-routing/346231 "2023-11-02T13:00:40Z")

</div>

I believe this is a Logstash issue, but please correct me if I am wrong. Currently, I have a Kibana instance set up with a lengthy EQL filter to search a description field for keywords. I want to do the filtering as pa…

---

## [Can we get filebeat src rpm or filebeat rpm with ASLR enabled?](https://discuss.elastic.co/t/can-we-get-filebeat-src-rpm-or-filebeat-rpm-with-aslr-enabled/346166)

<div class="topic-metadata">

**Author:** [@vbali3](https://discuss.elastic.co/u/vbali3)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 12:56pm UTC](https://discuss.elastic.co/t/can-we-get-filebeat-src-rpm-or-filebeat-rpm-with-aslr-enabled/346166 "2023-11-02T12:56:12Z")

</div>

If source rpm is not available, please provide us with the steps to build filebeat rpm and source rpm or a valid spec file maybe. We want to build for RHEL8/ALMA8 with ASLR enabled.

---

## [Configuring both TLS 1.2 and TLS 1.3 in Logstash 8.8](https://discuss.elastic.co/t/configuring-both-tls-1-2-and-tls-1-3-in-logstash-8-8/346280)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 12:37pm UTC](https://discuss.elastic.co/t/configuring-both-tls-1-2-and-tls-1-3-in-logstash-8-8/346280 "2023-11-02T12:37:10Z")

</div>

In my Logstash8.8 syslog configuration file, I want to configure two TLS versions: TLS 1.2 and TLS 1.3, but it doesn't work. Can you provide the correct way to configure it? Should I create two separate inputs? tcp { i…

---

## [Not able show field in table visualization](https://discuss.elastic.co/t/not-able-show-field-in-table-visualization/346288)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 12:24pm UTC](https://discuss.elastic.co/t/not-able-show-field-in-table-visualization/346288 "2023-11-02T12:24:01Z")

</div>

I have created a dashboard for endpoints which show how many parameters in particular endpoints. I have made two indexes and I have created a data view using that two index according to camma separated index-pattern. the…

---

## [Random access pagination with search\_after on Elasticsearch](https://discuss.elastic.co/t/random-access-pagination-with-search-after-on-elasticsearch/346203)

<div class="topic-metadata">

**Author:** [@cerenimo](https://discuss.elastic.co/u/cerenimo)\
**Replies:** 6\
**Last updated:** [November 2, 2023, 11:51am UTC](https://discuss.elastic.co/t/random-access-pagination-with-search-after-on-elasticsearch/346203 "2023-11-02T11:51:18Z")

</div>

There are more than 10 thousand documents in my index, but I cannot access all documents with search. I may also have performance problems with the scroll API. I found a method on how to overcome this with search\_after i…

---

## [How to modify index creation time on restored indices?](https://discuss.elastic.co/t/how-to-modify-index-creation-time-on-restored-indices/346284)

<div class="topic-metadata">

**Author:** [@Kavinkumar\_C](https://discuss.elastic.co/u/Kavinkumar_C)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 11:43am UTC](https://discuss.elastic.co/t/how-to-modify-index-creation-time-on-restored-indices/346284 "2023-11-02T11:43:54Z")

</div>

We have an ILM policy that deletes data after 7 days of index creation. We also take snapshots of the indices and store them for upto 30 days. Whenever we restore a backup, the ILM policy is executed, and the restored in…

---

## [Deleted Restore files from S3 AWS](https://discuss.elastic.co/t/deleted-restore-files-from-s3-aws/345921)

<div class="topic-metadata">

**Author:** [@Pete1](https://discuss.elastic.co/u/Pete1)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 10:57am UTC](https://discuss.elastic.co/t/deleted-restore-files-from-s3-aws/345921 "2023-11-02T10:57:10Z")

</div>

Hello, i am using S3 as a backup storage for my Elasticsearch. The problem is that i deleted all my files except the indices folder from S3. Is there any way to recover the indices ?

---

## [Compare values across two indicies](https://discuss.elastic.co/t/compare-values-across-two-indicies/346279)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 10:31am UTC](https://discuss.elastic.co/t/compare-values-across-two-indicies/346279 "2023-11-02T10:31:21Z")

</div>

Hi, i want to compare two fields in two indexes in elasticsearch and return a hit if they match. For example: Index1: -hostname: "computer" Index2: -host\_name: "computer" If hostname value equals to host\_name value, I…

---

## [Kibana lens based Area chart and Normal Area chart (Aggregation based) dosent follow opacity color correctly?](https://discuss.elastic.co/t/kibana-lens-based-area-chart-and-normal-area-chart-aggregation-based-dosent-follow-opacity-color-correctly/346276)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 10:30am UTC](https://discuss.elastic.co/t/kibana-lens-based-area-chart-and-normal-area-chart-aggregation-based-dosent-follow-opacity-color-correctly/346276 "2023-11-02T10:30:24Z")

</div>

Hello All, I tried making area chart using Lens based AREA CHART and also along with Normal Area chart. The reason to choose NORMAL Area chart over lens based is because I want to below which I am unable to do in lens…

---

## [Filebeat Error](https://discuss.elastic.co/t/filebeat-error/346093)

<div class="topic-metadata">

**Author:** [@Phyo\_WaThone\_Win](https://discuss.elastic.co/u/Phyo_WaThone_Win)\
**Replies:** 3\
**Last updated:** [November 2, 2023, 9:54am UTC](https://discuss.elastic.co/t/filebeat-error/346093 "2023-11-02T09:54:22Z")

</div>

Hello team, When I setup the auditbeat, I face some issues in my elk server. Here is error information: x509: certificate signed by unknown authority. Could you please help for this issues? Thanks,

---

## [Kibana Default Index pattern is changing automatically after being set for Multiple times](https://discuss.elastic.co/t/kibana-default-index-pattern-is-changing-automatically-after-being-set-for-multiple-times/346274)

<div class="topic-metadata">

**Author:** [@Vijay\_Varma](https://discuss.elastic.co/u/Vijay_Varma)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 9:46am UTC](https://discuss.elastic.co/t/kibana-default-index-pattern-is-changing-automatically-after-being-set-for-multiple-times/346274 "2023-11-02T09:46:20Z")

</div>

Initially observed there Duplicate index patterns are present in Kibana and it is due to the import of objects which are using different IDs for same Index pattern name. So we changed the Index pattern ID to an unique ID…

---

## [CSV Export from a lens - No date is shown in the CSV document](https://discuss.elastic.co/t/csv-export-from-a-lens-no-date-is-shown-in-the-csv-document/346192)

<div class="topic-metadata">

**Author:** [@deepack86](https://discuss.elastic.co/u/deepack86)\
**Replies:** 2\
**Last updated:** [November 2, 2023, 9:36am UTC](https://discuss.elastic.co/t/csv-export-from-a-lens-no-date-is-shown-in-the-csv-document/346192 "2023-11-02T09:36:39Z")

</div>

Hi! I have some problem with the CSV export from a lends trend. If i choose the Minimum Interval under 1 hour, in my export is only shown the time and not the Date + time. If the Minimun Intervall is above one ho…

---

## [Is it possible to accelerating aggregations by using SIMD instructions?](https://discuss.elastic.co/t/is-it-possible-to-accelerating-aggregations-by-using-simd-instructions/346271)

<div class="topic-metadata">

**Author:** [@huajun\_qi](https://discuss.elastic.co/u/huajun_qi)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 9:26am UTC](https://discuss.elastic.co/t/is-it-possible-to-accelerating-aggregations-by-using-simd-instructions/346271 "2023-11-02T09:26:23Z")

</div>

Is it possible to accelerating elasticsearch's aggregations by using SIMD instructions? OLAP databases like ClickHouse, TiDB, StarRocks use this way to achieve great performance.

---

## [Ingest: transforming multiple values in an array](https://discuss.elastic.co/t/ingest-transforming-multiple-values-in-an-array/346147)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 2\
**Last updated:** [November 2, 2023, 8:35am UTC](https://discuss.elastic.co/t/ingest-transforming-multiple-values-in-an-array/346147 "2023-11-02T08:35:42Z")

</div>

Hey, I'm looking for a way to transform { "related": { "user": \[ "user1@domain", "user2@anotherdomain" \] } } into { "related": { "user": \[ "user1@domain", "user1", "use…

---

## [Write bulk is stick for a long time](https://discuss.elastic.co/t/write-bulk-is-stick-for-a-long-time/346265)

<div class="topic-metadata">

**Author:** [@bxl](https://discuss.elastic.co/u/bxl)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 7:08am UTC](https://discuss.elastic.co/t/write-bulk-is-stick-for-a-long-time/346265 "2023-11-02T07:08:47Z")

</div>

elasticsearch version: 7.16.2 os: rhel 7.9 es node load very high, write task execution 1-2 hours, help me, thanks hot\_threads 100.0% \[cpu=11.1%, other=88.9%\] (500ms out of 500ms) cpu usage by thread 'elasticsearch\[i…

---

## [How can I inspect elastic-agent document submissions?](https://discuss.elastic.co/t/how-can-i-inspect-elastic-agent-document-submissions/346259)

<div class="topic-metadata">

**Author:** [@skestle](https://discuss.elastic.co/u/skestle)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 3:54am UTC](https://discuss.elastic.co/t/how-can-i-inspect-elastic-agent-document-submissions/346259 "2023-11-02T03:54:12Z")

</div>

I have an elastic ingestion problem where the elastic agent successfully publishes documents, but they don't show up at all in Elasticsearch. What's more insulting is that the agent logs say that 9 events have been publi…

---

## [Aborting enrolling to cluster. Could not communicate with the node on any of the addresses from the enrolment token](https://discuss.elastic.co/t/aborting-enrolling-to-cluster-could-not-communicate-with-the-node-on-any-of-the-addresses-from-the-enrolment-token/346174)

<div class="topic-metadata">

**Author:** [@Vyshak\_Sekhar](https://discuss.elastic.co/u/Vyshak_Sekhar)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 3:47am UTC](https://discuss.elastic.co/t/aborting-enrolling-to-cluster-could-not-communicate-with-the-node-on-any-of-the-addresses-from-the-enrolment-token/346174 "2023-11-02T03:47:16Z")

</div>

I am trying to install a 2 node Elasticsearch cluster , i installed and my Elasticsearch that node is running fine and while im trying to connect the next node to the using enrollment token im getting this borting enroll…

---

## [Kibana 8.8.2 is not able to connect to elastic](https://discuss.elastic.co/t/kibana-8-8-2-is-not-able-to-connect-to-elastic/346257)

<div class="topic-metadata">

**Author:** [@juhigupta](https://discuss.elastic.co/u/juhigupta)\
**Replies:** 0\
**Last updated:** [November 2, 2023, 3:17am UTC](https://discuss.elastic.co/t/kibana-8-8-2-is-not-able-to-connect-to-elastic/346257 "2023-11-02T03:17:44Z")

</div>

I m trying to move from 7.17.9 to kibana 8.8.2 but kibana is rejecting to connect with elastic with cert not configured error. Those certificates are working in 7.17.9 but kibana 8.8.2 doesn't recognise. Any suggestions…

---

## [Date Range Search based on Oldest Document](https://discuss.elastic.co/t/date-range-search-based-on-oldest-document/346255)

<div class="topic-metadata">

**Author:** [@samjsem](https://discuss.elastic.co/u/samjsem)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 3:03am UTC](https://discuss.elastic.co/t/date-range-search-based-on-oldest-document/346255 "2023-11-02T03:03:48Z")

</div>

Hi team, I am writing to ask: What is the best way to construct a query to satisfy the following requirement: Date range specification in the filter clause of a boolean query so that gte is based on the oldest document …

---

## [Disable SNI in the TLS session to when connecting to Logstash](https://discuss.elastic.co/t/disable-sni-in-the-tls-session-to-when-connecting-to-logstash/346252)

<div class="topic-metadata">

**Author:** [@jefffriedman](https://discuss.elastic.co/u/jefffriedman)\
**Replies:** 1\
**Last updated:** [November 2, 2023, 2:41am UTC](https://discuss.elastic.co/t/disable-sni-in-the-tls-session-to-when-connecting-to-logstash/346252 "2023-11-02T02:41:54Z")

</div>

When using Logstash 8.3.x on Linux we can connect via SSL from a server with an IPv6 address. When using Logstash 8.4.0 and higher, we get an error trying to establish a connection. By enabling duebggng in the JVM by ad…

---

## [No netflow data in elasticsearch for mikrotik router (fleet agent)](https://discuss.elastic.co/t/no-netflow-data-in-elasticsearch-for-mikrotik-router-fleet-agent/346171)

<div class="topic-metadata">

**Author:** [@skestle](https://discuss.elastic.co/u/skestle)\
**Replies:** 2\
**Last updated:** [November 2, 2023, 2:12am UTC](https://discuss.elastic.co/t/no-netflow-data-in-elasticsearch-for-mikrotik-router-fleet-agent/346171 "2023-11-02T02:12:00Z")

</div>

I cannot get my mikrotik router Traffic Flow data to appear in elasticstack with my fleet elastic-agent. Wireshark shows that the data is coming in (and fails when elastic-agent is restarting). sudo softflowd -v 5 -D -…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=382)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=384)
