# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=389

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 390

---

## [NEST 7 Against ES 8 Compatibility Mode Question](https://discuss.elastic.co/t/nest-7-against-es-8-compatibility-mode-question/345726)

<div class="topic-metadata">

**Author:** [@Sarah\_McQueary](https://discuss.elastic.co/u/Sarah_McQueary)\
**Replies:** 3\
**Last updated:** [October 26, 2023, 1:24pm UTC](https://discuss.elastic.co/t/nest-7-against-es-8-compatibility-mode-question/345726 "2023-10-26T13:24:16Z")

</div>

@stephenb Hello. We are in the process of upgrading ES to 8.x. Our code is still using NEST 7.x. We have been testing using NEST 7.x against ES 8.x and do not see any issues so far. We have tried with compatibly mode "t…

---

## [Java API Client Bulk Response Error Handling](https://discuss.elastic.co/t/java-api-client-bulk-response-error-handling/345794)

<div class="topic-metadata">

**Author:** [@ravneet21](https://discuss.elastic.co/u/ravneet21)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 1:20pm UTC](https://discuss.elastic.co/t/java-api-client-bulk-response-error-handling/345794 "2023-10-26T13:20:34Z")

</div>

Hi All, While migrating from Elastic HighLevelRestClient to bnew Java API Client, we are facing issues in handling error scenarios in BulkResponse. Earlier in HLRC, in BulkItemResponse, there was Failure type field, wh…

---

## [Logstash Service With Plugin that close after finish](https://discuss.elastic.co/t/logstash-service-with-plugin-that-close-after-finish/345820)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 1:13pm UTC](https://discuss.elastic.co/t/logstash-service-with-plugin-that-close-after-finish/345820 "2023-10-26T13:13:58Z")

</div>

Hi everyone, i have a quick question. I created a pipeline that after completition end by closing the prompt and my current configuration is logstash as a service in a linux server. What happens if i add the pipeline t…

---

## [Filebeat: not found matching indicies with pattern](https://discuss.elastic.co/t/filebeat-not-found-matching-indicies-with-pattern/345810)

<div class="topic-metadata">

**Author:** [@libertey](https://discuss.elastic.co/u/libertey)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 1:05pm UTC](https://discuss.elastic.co/t/filebeat-not-found-matching-indicies-with-pattern/345810 "2023-10-26T13:05:59Z")

</div>

Hey, im new to the complete elk stack now i tried to integrate it in one of our projects where only Elasticsearch was installed before. The Kibana installation worked great and was no problem. also the installation of l…

---

## [Runtime field component mapping with IF in script fails to parse due to compile error](https://discuss.elastic.co/t/runtime-field-component-mapping-with-if-in-script-fails-to-parse-due-to-compile-error/345816)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 12:51pm UTC](https://discuss.elastic.co/t/runtime-field-component-mapping-with-if-in-script-fails-to-parse-due-to-compile-error/345816 "2023-10-26T12:51:54Z")

</div>

I'm trying to create a mapping based on a value. However, whatever I try to save the component template, I'm shown the following error: :warning: Unable to create component template Failed to parse mapping: compile er…

---

## [Securityadmin.sh unable to find valid certification path to requested target error](https://discuss.elastic.co/t/securityadmin-sh-unable-to-find-valid-certification-path-to-requested-target-error/345809)

<div class="topic-metadata">

**Author:** [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 12:49pm UTC](https://discuss.elastic.co/t/securityadmin-sh-unable-to-find-valid-certification-path-to-requested-target-error/345809 "2023-10-26T12:49:58Z")

</div>

Hello,when i'm trying to execute securityadmin.sh with command ./securityadmin.sh -f /home/user/Documents/opensearch-2.8.0/config/opensearch-security/config.yml -icl -nhnv -cert /home/user/Documents/opensearch-2.8.0/con…

---

## [\[Kibana\] Visualize number of documents having a field inferior to the 99th percentile of this field](https://discuss.elastic.co/t/kibana-visualize-number-of-documents-having-a-field-inferior-to-the-99th-percentile-of-this-field/344485)

<div class="topic-metadata">

**Author:** [@JeromeLavadou](https://discuss.elastic.co/u/JeromeLavadou)\
**Replies:** 4\
**Last updated:** [October 26, 2023, 12:40pm UTC](https://discuss.elastic.co/t/kibana-visualize-number-of-documents-having-a-field-inferior-to-the-99th-percentile-of-this-field/344485 "2023-10-26T12:40:17Z")

</div>

Hello, Is there a way, in a Kibana visualization (Lens, TSVB...), to display on a chart (line, bar, etc.), for each time bucket, the number of documents having a field, let's says "response\_time", inferior to the 99th p…

---

## [Anonymize part of string](https://discuss.elastic.co/t/anonymize-part-of-string/345631)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 3\
**Last updated:** [October 26, 2023, 12:30pm UTC](https://discuss.elastic.co/t/anonymize-part-of-string/345631 "2023-10-26T12:30:56Z")

</div>

Hi, I have access logs which contains sensitive data \[2023-00-00T00:00:00.000\] ... "GET /example.com/foo/bar?password=SecretPassword&user=UserName" ... Is it possible to anonymize password value in that string?

---

## [Map azureAD roles or groups with elasticsearch roles](https://discuss.elastic.co/t/map-azuread-roles-or-groups-with-elasticsearch-roles/345763)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 12:30pm UTC](https://discuss.elastic.co/t/map-azuread-roles-or-groups-with-elasticsearch-roles/345763 "2023-10-26T12:30:14Z")

</div>

We deploy ES 8.8.1 with ECK on kubernetes. We connect it to azureAD, login works fine. I would like to map azureAD roles or groups with elasticsearch roles, I have no idea how to start. Our config is: xpack.security.…

---

## [Download csv report is intermittently failing if documents are more](https://discuss.elastic.co/t/download-csv-report-is-intermittently-failing-if-documents-are-more/345775)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 12:23pm UTC](https://discuss.elastic.co/t/download-csv-report-is-intermittently-failing-if-documents-are-more/345775 "2023-10-26T12:23:52Z")

</div>

Hi, download csv report is always failing if documents are more than 40k, and for around 30k documents it's getting success sometimes but sometimes it's failing. I am using Kibana 7.16.3 version single node cluster and…

---

## [Logstash stopped processing because of an error: (LoadError) failure to load file: java.io.FileNotFoundException: /usr/share/logstash/logstash-core/lib/logstash/build.rb (Permission denied)](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-loaderror-failure-to-load-file-java-io-filenotfoundexception-usr-share-logstash-logstash-core-lib-logstash-build-rb-permission-denied/345801)

<div class="topic-metadata">

**Author:** [@jrajasek](https://discuss.elastic.co/u/jrajasek)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 11:34am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-loaderror-failure-to-load-file-java-io-filenotfoundexception-usr-share-logstash-logstash-core-lib-logstash-build-rb-permission-denied/345801 "2023-10-26T11:34:38Z")

</div>

Building the custom docker image with these below commands. FROM docker.elastic.co/logstash/logstash:8.10.4 RUN rm -f /usr/share/logstash/pipeline/logstash.conf COPY pipeline/ /usr/share/logstash/pipeline/ COPY confi…

---

## [Show complete xml content on mousehover in Kibana 8.3.2 table view](https://discuss.elastic.co/t/show-complete-xml-content-on-mousehover-in-kibana-8-3-2-table-view/345619)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 3\
**Last updated:** [October 26, 2023, 10:07am UTC](https://discuss.elastic.co/t/show-complete-xml-content-on-mousehover-in-kibana-8-3-2-table-view/345619 "2023-10-26T10:07:10Z")

</div>

Hi, I added the fields from documents in Discover and save it. After that I visualized that saved table from library into dashboard. One of the field is having xml content but in table it's not showing complete content. …

---

## [Total number of shards](https://discuss.elastic.co/t/total-number-of-shards/345749)

<div class="topic-metadata">

**Author:** [@lemospt](https://discuss.elastic.co/u/lemospt)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 9:25am UTC](https://discuss.elastic.co/t/total-number-of-shards/345749 "2023-10-26T09:25:27Z")

</div>

Hi Guys, i have an elastic cluster with 5 nodes. This cluster is configured 1290 indices, all indices is configured to have 2 primary shards and 1 replica shard. For me the cluster should have 3\*1290=3870 shards but ac…

---

## [ML CPU, Memory, of Host/Processes](https://discuss.elastic.co/t/ml-cpu-memory-of-host-processes/345781)

<div class="topic-metadata">

**Author:** [@Nabeel\_Ahmed\_NAK](https://discuss.elastic.co/u/Nabeel_Ahmed_NAK)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 8:26am UTC](https://discuss.elastic.co/t/ml-cpu-memory-of-host-processes/345781 "2023-10-26T08:26:00Z")

</div>

Hi All Using Machine Learning Anomaly/data frame I want to find the root cause of high CPU and memory, concerning the host and processes. Moreover, if possible error logs and any APM are running, that data too. I need…

---

## [Trying to use sum\_bucket agg to summarize the last value per server into a total](https://discuss.elastic.co/t/trying-to-use-sum-bucket-agg-to-summarize-the-last-value-per-server-into-a-total/345729)

<div class="topic-metadata">

**Author:** [@mekberg](https://discuss.elastic.co/u/mekberg)\
**Replies:** 4\
**Last updated:** [October 26, 2023, 8:06am UTC](https://discuss.elastic.co/t/trying-to-use-sum-bucket-agg-to-summarize-the-last-value-per-server-into-a-total/345729 "2023-10-26T08:06:44Z")

</div>

I'm trying to create a search (ultimately a visualization) that will give me the total number of Controller nodes in a cluster. Each node reports metrics every 15 seconds, and each document will contain the value for tha…

---

## [I need to use the Suggester when I enable the DLS](https://discuss.elastic.co/t/i-need-to-use-the-suggester-when-i-enable-the-dls/345263)

<div class="topic-metadata">

**Author:** [@sjp.jamalian](https://discuss.elastic.co/u/sjp.jamalian)\
**Replies:** 4\
**Last updated:** [October 26, 2023, 6:34am UTC](https://discuss.elastic.co/t/i-need-to-use-the-suggester-when-i-enable-the-dls/345263 "2023-10-26T06:34:42Z")

</div>

Hello, When I enable the security and want to use the Suggester, I get this error: org.elasticsearch.ElasticsearchException: Elasticsearch exception \[type=security\_exception, reason=Suggest isn't supported if document …

---

## [How to compare value exactly from array of document with params in script plainess?](https://discuss.elastic.co/t/how-to-compare-value-exactly-from-array-of-document-with-params-in-script-plainess/345691)

<div class="topic-metadata">

**Author:** [@duyhunter1001](https://discuss.elastic.co/u/duyhunter1001)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 6:19am UTC](https://discuss.elastic.co/t/how-to-compare-value-exactly-from-array-of-document-with-params-in-script-plainess/345691 "2023-10-26T06:19:16Z")

</div>

Hi everyone, I have a index example above: PUT target\_index { "mappings": { "properties": { "targetoperator": { "type": "keyword" }, "targetvalue": { "type": "float" } } } } PUT t…

---

## [Get repository folder name for an index](https://discuss.elastic.co/t/get-repository-folder-name-for-an-index/345737)

<div class="topic-metadata">

**Author:** [@karan\_c](https://discuss.elastic.co/u/karan_c)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 6:15am UTC](https://discuss.elastic.co/t/get-repository-folder-name-for-an-index/345737 "2023-10-26T06:15:18Z")

</div>

Hi All, I'm creating day wise snapshots which contains multiple indices for different services (also day wise). I'm planning to move older snapshots from S3 Intelligent-Tiering to S3 Glacier Deep Archive storage class. …

---

## [Elastic agent - Logs for Hosts](https://discuss.elastic.co/t/elastic-agent-logs-for-hosts/345772)

<div class="topic-metadata">

**Author:** [@The\_BlueishSky](https://discuss.elastic.co/u/The_BlueishSky)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 5:58am UTC](https://discuss.elastic.co/t/elastic-agent-logs-for-hosts/345772 "2023-10-26T05:58:33Z")

</div>

We are in process of implementing ELK Agent and more focus for better SIEM detections. At the moment our config ships all the logs and we also don't want to tailor only security events. Is there a recommendation or exp…

---

## [Configuration Elastic Cluster 8.10.3 Certificates in roles master, coordinator anda data](https://discuss.elastic.co/t/configuration-elastic-cluster-8-10-3-certificates-in-roles-master-coordinator-anda-data/345750)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 4:05am UTC](https://discuss.elastic.co/t/configuration-elastic-cluster-8-10-3-certificates-in-roles-master-coordinator-anda-data/345750 "2023-10-26T04:05:04Z")

</div>

I have a question, how can I configure the certificates for an elastic cluster in version 8.10.3, it will contain master roles, coordinators, data and machine learning. Is it intended to have several roles on the nodes,…

---

## ["could not read the current timestamp"](https://discuss.elastic.co/t/could-not-read-the-current-timestamp/344608)

<div class="topic-metadata">

**Author:** [@arunv707](https://discuss.elastic.co/u/arunv707)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 3:59am UTC](https://discuss.elastic.co/t/could-not-read-the-current-timestamp/344608 "2023-10-26T03:59:25Z")

</div>

I get the following in application logs. Could someone please help? \[2023-09-19T17:07:52,876\]\[DEBUG\]\[o.e.a.s.TransportSearchAction\] \[O1onMaP\] \[xxxxxx\]\[0\], node\[a24qYwKTTUO6yFcWf8QRKg\], \[P\], s\[STARTED\], a\[id=50vjfxaPSuqA…

---

## [Fscrawler, error 415 when using REST API for upload PDF file](https://discuss.elastic.co/t/fscrawler-error-415-when-using-rest-api-for-upload-pdf-file/345760)

<div class="topic-metadata">

**Author:** [@Erik\_Bors](https://discuss.elastic.co/u/Erik_Bors)\
**Replies:** 4\
**Last updated:** [October 25, 2023, 9:25pm UTC](https://discuss.elastic.co/t/fscrawler-error-415-when-using-rest-api-for-upload-pdf-file/345760 "2023-10-25T21:25:59Z")

</div>

Trying to use the REST API service of the fscrawler. When using the POST MAN with PDF file, the app is answering with the 415 code - unsupported media type Content-Type header is correct with application/pdf. Using POS…

---

## [Deprecation info missing in the docs?](https://discuss.elastic.co/t/deprecation-info-missing-in-the-docs/345744)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 2\
**Last updated:** [October 25, 2023, 8:59pm UTC](https://discuss.elastic.co/t/deprecation-info-missing-in-the-docs/345744 "2023-10-25T20:59:16Z")

</div>

I saw the following deprecation warning today: \[ignore\_throttled\] parameter is deprecated because frozen indices have been deprecated. Consider cold or frozen tiers in place of frozen indices. So far so good, finding a…

---

## [Superuser access in each Space](https://discuss.elastic.co/t/superuser-access-in-each-space/345405)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 8\
**Last updated:** [October 25, 2023, 7:19pm UTC](https://discuss.elastic.co/t/superuser-access-in-each-space/345405 "2023-10-25T19:19:47Z")

</div>

How do you implement superuser access to every Space for any users that need that level of access? For example, in a deployment utilizing SAML for access a user has superuser privileges in one Space to manage everything…

---

## [Fleet integrations page failing to load](https://discuss.elastic.co/t/fleet-integrations-page-failing-to-load/345473)

<div class="topic-metadata">

**Author:** [@tdanno](https://discuss.elastic.co/u/tdanno)\
**Replies:** 4\
**Last updated:** [October 25, 2023, 7:19pm UTC](https://discuss.elastic.co/t/fleet-integrations-page-failing-to-load/345473 "2023-10-25T19:19:32Z")

</div>

On three separate clusters in three different parts of the world everything is functioning fine except the ability to fully load the integrations page- it seems like whatever it needs to do to reach out to the central re…

---

## [Discover does not show any data for indices with \_source disabled](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-indices-with-source-disabled/345652)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 11\
**Last updated:** [October 25, 2023, 5:32pm UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-indices-with-source-disabled/345652 "2023-10-25T17:32:38Z")

</div>

Hello, I disabled the \_source field on a couple of indices yesterday and today I noticed that I can not see anything from those indices on Discover. I can filter on values and fields, but everything is empty on Kibana …

---

## [Parse single array json (Elastic Agent)](https://discuss.elastic.co/t/parse-single-array-json-elastic-agent/345558)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 5\
**Last updated:** [October 25, 2023, 5:24pm UTC](https://discuss.elastic.co/t/parse-single-array-json-elastic-agent/345558 "2023-10-25T17:24:33Z")

</div>

I'm trying to parse parsedmarc json files. These log files contain a single array with multiple records. I've taken the json and am testing with a single record, and am struggling to find the right combination of filebea…

---

## [Redirecting postgresql tables to Elasticsearch](https://discuss.elastic.co/t/redirecting-postgresql-tables-to-elasticsearch/345458)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 5:21pm UTC](https://discuss.elastic.co/t/redirecting-postgresql-tables-to-elasticsearch/345458 "2023-10-25T17:21:22Z")

</div>

Hi, I am trying to redirect my postgresql tables to elasticsearch using JDBC and Logstash. I was able to do it but i came across a problem of ingesting the same data over and over again. I know i need to use tracking co…

---

## [Elastic Agent - listen on tcp/9200?](https://discuss.elastic.co/t/elastic-agent-listen-on-tcp-9200/345756)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 5:17pm UTC](https://discuss.elastic.co/t/elastic-agent-listen-on-tcp-9200/345756 "2023-10-25T17:17:54Z")

</div>

Parsedmarc can send to Elasticsearch using xpack, but rather than go through the pain of this I was hoping to use the Elastic Agent already installed on this server to do the shipping of the data. Is there an Elastic Ag…

---

## [Remove HTTP encondings](https://discuss.elastic.co/t/remove-http-encondings/345720)

<div class="topic-metadata">

**Author:** [@lemospt](https://discuss.elastic.co/u/lemospt)\
**Replies:** 3\
**Last updated:** [October 25, 2023, 5:03pm UTC](https://discuss.elastic.co/t/remove-http-encondings/345720 "2023-10-25T17:03:12Z")

</div>

Hi guys, i'm integrating log from proxy squid, there is a field called 'Original Received Request Header' that has data like below, User-Agent:%20git/2.30.2%0D%0AProxy-Connection:%20Keep-Alive%0D%0AHost:%20github.priva…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=388)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=390)
