# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=385

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 386

---

## [Unbalanced CPU load when enabling vector search](https://discuss.elastic.co/t/unbalanced-cpu-load-when-enabling-vector-search/346150)

<div class="topic-metadata">

**Author:** [@FlorianL](https://discuss.elastic.co/u/FlorianL)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 4:06pm UTC](https://discuss.elastic.co/t/unbalanced-cpu-load-when-enabling-vector-search/346150 "2023-10-31T16:06:07Z")

</div>

Hello everyone, I have been trying to work with vector search at scale, but I ends up into a very awkward unstable state of my cluster. I have browse this forum but did not find someone sharing a similar problem to mine…

---

## [Offline maps in kibana 8.8](https://discuss.elastic.co/t/offline-maps-in-kibana-8-8/346137)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 5\
**Last updated:** [October 31, 2023, 3:49pm UTC](https://discuss.elastic.co/t/offline-maps-in-kibana-8-8/346137 "2023-10-31T15:49:20Z")

</div>

Hello, I want to create a map in Kibana 8.8, but I am in an environment that does not have internet access. Is there a method to create maps offline in Kibana? Thank you

---

## [Define second pattern for the remaining logs](https://discuss.elastic.co/t/define-second-pattern-for-the-remaining-logs/346010)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 3:27pm UTC](https://discuss.elastic.co/t/define-second-pattern-for-the-remaining-logs/346010 "2023-10-31T15:27:00Z")

</div>

Hello, I have now set up a pipeline and defined a GROK pattern. It is working. However, the logs that do not match the pattern are not displayed. How could I define a simple second pattern to catch the remaining logs?

---

## [Logstash parse date format AM/PM](https://discuss.elastic.co/t/logstash-parse-date-format-am-pm/346115)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [October 31, 2023, 3:15pm UTC](https://discuss.elastic.co/t/logstash-parse-date-format-am-pm/346115 "2023-10-31T15:15:50Z")

</div>

Hello All, I need to parse below data and send it to elastic index.For some reason index gets created but data dont come in index. I am trying to parse multiple csv file with below data. Here date format field contain A…

---

## [message":"error fetching EC2 Identity Document: operation error ec2imds: GetInstance Identity Document, exceeded maximum number of attempts, 3, request send failed, Get \\"http://169.254.169.254/latest/dynamic/instance-identity/document\\": dial tcp 169.254](https://discuss.elastic.co/t/message-error-fetching-ec2-identity-document-operation-error-ec2imds-getinstance-identity-document-exceeded-maximum-number-of-attempts-3-request-send-failed-get-http-169-254-169-254-latest-dynamic-instance-identity-document-dial-tcp-169-254/346140)

<div class="topic-metadata">

**Author:** [@pedada](https://discuss.elastic.co/u/pedada)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 2:13pm UTC](https://discuss.elastic.co/t/message-error-fetching-ec2-identity-document-operation-error-ec2imds-getinstance-identity-document-exceeded-maximum-number-of-attempts-3-request-send-failed-get-http-169-254-169-254-latest-dynamic-instance-identity-document-dial-tcp-169-254/346140 "2023-10-31T14:13:12Z")

</div>

message":"error fetching EC2 Identity Document: operation error ec2imds: GetInstance Identity Document, exceeded maximum number of attempts, 3, request send failed, Get "http://169.254.169.254/latest/dynamic/instance-ide…

---

## [KIbana CSP error](https://discuss.elastic.co/t/kibana-csp-error/344888)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 1\
**Last updated:** [October 12, 2023, 4:14pm UTC](https://discuss.elastic.co/t/kibana-csp-error/344888 "2023-10-12T16:14:04Z")

</div>

"Hello Community, I'm facing an issue with my Elasticsearch cluster. It's up and running smoothly, but when I try to access Kibana on my browser, I see a message saying 'Kibana server not ready yet' in the console. I've…

---

## [Logstash - Parsing fields with duplicate names](https://discuss.elastic.co/t/logstash-parsing-fields-with-duplicate-names/346131)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 5\
**Last updated:** [October 31, 2023, 1:19pm UTC](https://discuss.elastic.co/t/logstash-parsing-fields-with-duplicate-names/346131 "2023-10-31T13:19:42Z")

</div>

If I receive a log in that looks like this, how do I deal with the fact that the subfields under "records" are identical? Is there a concept of \[records\]\[operationName\]\[0\] and \[1\], for example? { "records": \[ { …

---

## [How to create index pattern(data view) for all indices](https://discuss.elastic.co/t/how-to-create-index-pattern-data-view-for-all-indices/346134)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 2\
**Last updated:** [October 31, 2023, 1:11pm UTC](https://discuss.elastic.co/t/how-to-create-index-pattern-data-view-for-all-indices/346134 "2023-10-31T13:11:39Z")

</div>

Hi all, I'm using Kibana 8.6.2. I had added indices some time back and don't want to delete or modify them. I have about 70 indices with different names: eg: locations roles tasks stats tickets stats These were cre…

---

## [2 agents on a machine?](https://discuss.elastic.co/t/2-agents-on-a-machine/346114)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 12:36pm UTC](https://discuss.elastic.co/t/2-agents-on-a-machine/346114 "2023-10-31T12:36:41Z")

</div>

Hi All, I'm wondering if anyone has any experience of putting 2 elastic agents on a machine? We've got a client who is using elastic for monitoring, and we need to have the elastic agent on for security.. this is on Mi…

---

## [Elasticsearch cluster configuration for intensive write](https://discuss.elastic.co/t/elasticsearch-cluster-configuration-for-intensive-write/346107)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 5\
**Last updated:** [October 31, 2023, 11:31am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-configuration-for-intensive-write/346107 "2023-10-31T11:31:25Z")

</div>

Hi, I need to index ~1TB data per day. I have the required HW and want to know which cluster should I raise, means How many nodes, How many shards, etc. Is there any formula for that? Thanks.

---

## [Kibana is extremely slow (Loading graphs)](https://discuss.elastic.co/t/kibana-is-extremely-slow-loading-graphs/345694)

<div class="topic-metadata">

**Author:** [@Saili\_Bakalkar](https://discuss.elastic.co/u/Saili_Bakalkar)\
**Replies:** 3\
**Last updated:** [October 31, 2023, 11:18am UTC](https://discuss.elastic.co/t/kibana-is-extremely-slow-loading-graphs/345694 "2023-10-31T11:18:57Z")

</div>

Hello everyone, I'm encountering significant performance issues with my Kibana setup, and I'm seeking guidance to improve its responsiveness. I've attached images to provide insights into the current state of our cluste…

---

## [Kibana Join two dasets into one visualization](https://discuss.elastic.co/t/kibana-join-two-dasets-into-one-visualization/346124)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 11:15am UTC](https://discuss.elastic.co/t/kibana-join-two-dasets-into-one-visualization/346124 "2023-10-31T11:15:43Z")

</div>

Hi all, I have an index wit fields like this : Myindex: url: "/some/url1", service: "someservice1", uuid: "ccc-xxx-yyy-zzz1" url: "/some/url2", service: "someservice1", uuid: "ccc-xxx-yyy-zzz2" url: "…

---

## [Object mapping for \[protoPayload.response.status\] tried to parse field \[status\] as object, but found a concrete value (document\_parsing\_exception)](https://discuss.elastic.co/t/object-mapping-for-protopayload-response-status-tried-to-parse-field-status-as-object-but-found-a-concrete-value-document-parsing-exception/346117)

<div class="topic-metadata">

**Author:** [@narrayana\_swamy](https://discuss.elastic.co/u/narrayana_swamy)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 10:38am UTC](https://discuss.elastic.co/t/object-mapping-for-protopayload-response-status-tried-to-parse-field-status-as-object-but-found-a-concrete-value-document-parsing-exception/346117 "2023-10-31T10:38:55Z")

</div>

Hi, I am trying to load the data via GCP dataflow to elasticsearch, but i am getting the below error. i am not using any agents. i have installed the GCP integrations. "Error message from worker: java.io.IOException: Er…

---

## [Query on filebeat src rpm or how to get filebeat rpm with ASLR enabled](https://discuss.elastic.co/t/query-on-filebeat-src-rpm-or-how-to-get-filebeat-rpm-with-aslr-enabled/346101)

<div class="topic-metadata">

**Author:** [@vbali3](https://discuss.elastic.co/u/vbali3)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 9:00am UTC](https://discuss.elastic.co/t/query-on-filebeat-src-rpm-or-how-to-get-filebeat-rpm-with-aslr-enabled/346101 "2023-10-31T09:00:42Z")

</div>

Can we get filebeat src rpm or filebeat rpm with ASLR enabled?

---

## [How to join two stream data sources and find matches](https://discuss.elastic.co/t/how-to-join-two-stream-data-sources-and-find-matches/346097)

<div class="topic-metadata">

**Author:** [@fim01](https://discuss.elastic.co/u/fim01)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 8:22am UTC](https://discuss.elastic.co/t/how-to-join-two-stream-data-sources-and-find-matches/346097 "2023-10-31T08:22:08Z")

</div>

I'm asking for an idea or approach to solve the following business problem: Two stream data sources (A and B) continuously ingesting events into two separate indices (A and B) in Elasticsearch. Each of them has a unique…

---

## [How do i change the hyper reference of header logo in production mode?](https://discuss.elastic.co/t/how-do-i-change-the-hyper-reference-of-header-logo-in-production-mode/346094)

<div class="topic-metadata">

**Author:** [@didar2016](https://discuss.elastic.co/u/didar2016)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 7:28am UTC](https://discuss.elastic.co/t/how-do-i-change-the-hyper-reference-of-header-logo-in-production-mode/346094 "2023-10-31T07:28:43Z")

</div>

In dev mode it is possible to change the link but not in production mode. I don't find the header\_logo.tsx file in production mode.

---

## [Logs are missing kubernetes metadata when using filebeat \>= 8.9.0](https://discuss.elastic.co/t/logs-are-missing-kubernetes-metadata-when-using-filebeat-8-9-0/344693)

<div class="topic-metadata">

**Author:** [@gparks](https://discuss.elastic.co/u/gparks)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 6:07am UTC](https://discuss.elastic.co/t/logs-are-missing-kubernetes-metadata-when-using-filebeat-8-9-0/344693 "2023-10-31T06:07:41Z")

</div>

I'm running filebeat as a daemonset in kubernetes, it was previously on 8.8.2 but when upgraded to 8.9.0 logs from the first input stop including the kubernetes metadata but logs from the ingress-nginx input continue to …

---

## [Kibana cookies contain "--" characters in the SID which causes the user requests to get blocked in the azure WAF](https://discuss.elastic.co/t/kibana-cookies-contain-characters-in-the-sid-which-causes-the-user-requests-to-get-blocked-in-the-azure-waf/346087)

<div class="topic-metadata">

**Author:** [@sahadev\_d](https://discuss.elastic.co/u/sahadev_d)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 5:45am UTC](https://discuss.elastic.co/t/kibana-cookies-contain-characters-in-the-sid-which-causes-the-user-requests-to-get-blocked-in-the-azure-waf/346087 "2023-10-31T05:45:08Z")

</div>

Hi Community, We are facing issue while using kibana using with URL, Whenever the user log-in to kibana with the RBAs user creds the user gets 403 error from the kibana servers. As we debugged the issue we came to know…

---

## [ElasticSearch Fleet - Outdated Policy](https://discuss.elastic.co/t/elasticsearch-fleet-outdated-policy/346082)

<div class="topic-metadata">

**Author:** [@crypt0ace](https://discuss.elastic.co/u/crypt0ace)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 3:37am UTC](https://discuss.elastic.co/t/elasticsearch-fleet-outdated-policy/346082 "2023-10-31T03:37:25Z")

</div>

Hello! I just added a Windows integration in my home lab in the Elasticsearch and I got this error Then when i view the integrations I can see Windows got added but I can also see this "Outdated Policy" with my agen…

---

## [Elastic data large exception (Data too large, data for \[http\_request\])](https://discuss.elastic.co/t/elastic-data-large-exception-data-too-large-data-for-http-request/345907)

<div class="topic-metadata">

**Author:** [@Rajesh123](https://discuss.elastic.co/u/Rajesh123)\
**Replies:** 2\
**Last updated:** [October 31, 2023, 12:25am UTC](https://discuss.elastic.co/t/elastic-data-large-exception-data-too-large-data-for-http-request/345907 "2023-10-31T00:25:14Z")

</div>

Hello, Could you please help on below issue . we getting this issue on Elastic and kibana. \`1e9fa016\]\[trial #34\] null during Elasticsearch operation (ElasticsearchStatusException\[Elasticsearch exception \[type=circuit\_b…

---

## [Data too large for response \[parent\]](https://discuss.elastic.co/t/data-too-large-for-response-parent/346048)

<div class="topic-metadata">

**Author:** [@uhlirradek95](https://discuss.elastic.co/u/uhlirradek95)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 12:22am UTC](https://discuss.elastic.co/t/data-too-large-for-response-parent/346048 "2023-10-31T00:22:48Z")

</div>

Hi, could you please help me to understand following exception? Cluster configuration: 3 nodes each 6CPU, 32GB RAM, completely on SSD While making a search request, following exception occours: \[Invalid response ret…

---

## [TLS issue with Filebeat 8.10 an higher](https://discuss.elastic.co/t/tls-issue-with-filebeat-8-10-an-higher/345606)

<div class="topic-metadata">

**Author:** [@Somecallmesteve](https://discuss.elastic.co/u/Somecallmesteve)\
**Replies:** 20\
**Last updated:** [October 30, 2023, 9:54pm UTC](https://discuss.elastic.co/t/tls-issue-with-filebeat-8-10-an-higher/345606 "2023-10-30T21:54:40Z")

</div>

I started trying to upgrade some clients to Filebeat 8.10.3 and found that if I install 8.10.x I get the following error when connecting to a Logstash output using tsl : "...x509: cannot validate certificate for X.X.X.X…

---

## [Reference custom field in another custom field](https://discuss.elastic.co/t/reference-custom-field-in-another-custom-field/346066)

<div class="topic-metadata">

**Author:** [@patricio.devilla](https://discuss.elastic.co/u/patricio.devilla)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 7:13pm UTC](https://discuss.elastic.co/t/reference-custom-field-in-another-custom-field/346066 "2023-10-30T19:13:27Z")

</div>

Is it possible to reference a custom field in another field? Creating custom field custom\_1 Creating custom field custom\_2 emit(doc\['custom\_1'\].value) I get the following error No field found for \[custom\_1\] in ma…

---

## [Custom Logs integration upgrade fails with invalid\_index\_template\_exception](https://discuss.elastic.co/t/custom-logs-integration-upgrade-fails-with-invalid-index-template-exception/346056)

<div class="topic-metadata">

**Author:** [@jmartin](https://discuss.elastic.co/u/jmartin)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 3:53pm UTC](https://discuss.elastic.co/t/custom-logs-integration-upgrade-fails-with-invalid-index-template-exception/346056 "2023-10-30T15:53:07Z")

</div>

When trying to upgrade the custom logs integration, for fleet from version 2.0.0 to 2.3.0. Kibana gives the following error: invalid\_index\_template\_exception: index\_template \[logs-ERMP@custom\] invalid, cause \[Validati…

---

## [MySQL Connector cannot connect to Elasticsearch Docker Instance](https://discuss.elastic.co/t/mysql-connector-cannot-connect-to-elasticsearch-docker-instance/346043)

<div class="topic-metadata">

**Author:** [@James\_Cook1](https://discuss.elastic.co/u/James_Cook1)\
**Replies:** 1\
**Last updated:** [October 30, 2023, 3:38pm UTC](https://discuss.elastic.co/t/mysql-connector-cannot-connect-to-elasticsearch-docker-instance/346043 "2023-10-30T15:38:23Z")

</div>

Hello We are currently in the process of attempting to set up a locally running instance of Elasticsearch to connect to a MySQL database using Docker Containers but are unable to get this to work. We are following the …

---

## [Syslog severity and facility not set when upgrading version](https://discuss.elastic.co/t/syslog-severity-and-facility-not-set-when-upgrading-version/345695)

<div class="topic-metadata">

**Author:** [@Andrea\_De\_Pinto](https://discuss.elastic.co/u/Andrea_De_Pinto)\
**Replies:** 3\
**Last updated:** [October 30, 2023, 3:13pm UTC](https://discuss.elastic.co/t/syslog-severity-and-facility-not-set-when-upgrading-version/345695 "2023-10-30T15:13:31Z")

</div>

Hi, I did the migration from the version 6.8 to the 8.9 and I have a logstash pipeline that use the syslog to feed my elasticsearch. This is the configuration I have on the 6.8 : input { syslog { type =\> "sy…

---

## [How to handle unmapped fields](https://discuss.elastic.co/t/how-to-handle-unmapped-fields/345991)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 4\
**Last updated:** [October 30, 2023, 2:35pm UTC](https://discuss.elastic.co/t/how-to-handle-unmapped-fields/345991 "2023-10-30T14:35:14Z")

</div>

filter { grok { id =\> "name school grok filter" match =\> { 'message' =\> '^.\*name=\\'%{WORD:student.name}\\'.\*school=\\'%{WORD:student.school}\\''} } } For example, with WORD:student.name I would like to create a…

---

## [Extract Exception Class](https://discuss.elastic.co/t/extract-exception-class/346046)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 2:21pm UTC](https://discuss.elastic.co/t/extract-exception-class/346046 "2023-10-30T14:21:54Z")

</div>

Hello, what is the best way to extract the exception from the following log? I only need the exception class NullpointerException e.g. My attempt: %{TIMESTAMP\_ISO8601:log\_timestamp}.%{LOGLEVEL:log\_level}.\[%{GREEDYDATA:…

---

## [search profile breakdown](https://discuss.elastic.co/t/search-profile-breakdown/346041)

<div class="topic-metadata">

**Author:** [@getsolaris](https://discuss.elastic.co/u/getsolaris)\
**Replies:** 0\
**Last updated:** [October 30, 2023, 2:17pm UTC](https://discuss.elastic.co/t/search-profile-breakdown/346041 "2023-10-30T14:17:59Z")

</div>

hello, I'm using Elasticsearch's profile API to try and figure out what's taking so long. I currently have an index implemented with parent-child modeling. When I run a has\_child query, I am getting a high match in my…

---

## [How exlude particular index from ilm policy](https://discuss.elastic.co/t/how-exlude-particular-index-from-ilm-policy/345792)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 4\
**Last updated:** [October 30, 2023, 2:15pm UTC](https://discuss.elastic.co/t/how-exlude-particular-index-from-ilm-policy/345792 "2023-10-30T14:15:55Z")

</div>

Hi, OS : 22.04 linux ES version: 7.17.0 I have created ilm policy like delete all indexes after 45 days. I am using \* in policy. but I want to exclude particular index pattern which is not deleted or ilm policy is not…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=384)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=386)
