# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=394

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 395

---

## [Elasticsearch is returning less than the top K matches for a vector search](https://discuss.elastic.co/t/elasticsearch-is-returning-less-than-the-top-k-matches-for-a-vector-search/345207)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 3\
**Last updated:** [October 19, 2023, 8:19pm UTC](https://discuss.elastic.co/t/elasticsearch-is-returning-less-than-the-top-k-matches-for-a-vector-search/345207 "2023-10-19T20:19:40Z")

</div>

I have a problem where elasticsearch doesn't return k matches for a knn search. It used to work before so I think something has changed between version 8.8.3 to 8.10.3. Perhaps a minimum score? I could not find it in the…

---

## [Elasticsearch process ended by code 137](https://discuss.elastic.co/t/elasticsearch-process-ended-by-code-137/345399)

<div class="topic-metadata">

**Author:** [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Replies:** 7\
**Last updated:** [October 19, 2023, 7:09pm UTC](https://discuss.elastic.co/t/elasticsearch-process-ended-by-code-137/345399 "2023-10-19T19:09:10Z")

</div>

Hi, When checking the error message for the termination of the Elasticsearch process, it was indicating that the process was terminated due to error 137, when consulting I saw that it indicates excessive memory consumpt…

---

## [Cluster to ingest 7TB of data daily](https://discuss.elastic.co/t/cluster-to-ingest-7tb-of-data-daily/345412)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 1\
**Last updated:** [October 19, 2023, 6:41pm UTC](https://discuss.elastic.co/t/cluster-to-ingest-7tb-of-data-daily/345412 "2023-10-19T18:41:19Z")

</div>

The task at hand is to build a cluster that can ingest 7 terabytes daily, and Hold the data for 7 days in Hot phase, and 83 days in Cold phase, What is the best recommendation in a huge elasticsearch cluster? How many…

---

## [Elastic agent offline after upgrade from Fleet](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973)

<div class="topic-metadata">

**Author:** [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Replies:** 15\
**Last updated:** [October 19, 2023, 6:22pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade-from-fleet/344973 "2023-10-19T18:22:20Z")

</div>

Hi, Because of the last vulnerabilities from this week affecting Elastic Suite, I've made an upgrade from 8.8.0 to 8.10.3 of all my Elastic Agent from Fleet. Now all the agents are Offline (and displaying the version a…

---

## [Unable to Start ES Cluster using docker-compose on M1 Mac](https://discuss.elastic.co/t/unable-to-start-es-cluster-using-docker-compose-on-m1-mac/345406)

<div class="topic-metadata">

**Author:** [@lance.zukel](https://discuss.elastic.co/u/lance.zukel)\
**Replies:** 1\
**Last updated:** [October 19, 2023, 4:59pm UTC](https://discuss.elastic.co/t/unable-to-start-es-cluster-using-docker-compose-on-m1-mac/345406 "2023-10-19T16:59:03Z")

</div>

Need to set up a 3 node cluster using docker on my M1 Mac, using docker desktop/docker-compose. I am getting the following error: 2023-10-19 10:33:05 ERROR: \[1\] bootstrap checks failed. You must address the points desc…

---

## [Elastic agent not grokking after migrating from filebeat](https://discuss.elastic.co/t/elastic-agent-not-grokking-after-migrating-from-filebeat/345407)

<div class="topic-metadata">

**Author:** [@Cara410](https://discuss.elastic.co/u/Cara410)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 4:48pm UTC](https://discuss.elastic.co/t/elastic-agent-not-grokking-after-migrating-from-filebeat/345407 "2023-10-19T16:48:14Z")

</div>

Hello, I had a fully functional GROK written for filebeat and we recently just moved to using Elastic Agent. Now the GROK isn't functioning the same. It seems to take the first few lines of the GROK and execute them but…

---

## [Elastic Agent - Multiple inputs/output through Fleet](https://discuss.elastic.co/t/elastic-agent-multiple-inputs-output-through-fleet/345336)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 2\
**Last updated:** [October 19, 2023, 2:58pm UTC](https://discuss.elastic.co/t/elastic-agent-multiple-inputs-output-through-fleet/345336 "2023-10-19T14:58:52Z")

</div>

Hello, here's our current setup: Multiple filebeats on a single VM (hundreds of VMs - Linux & windows based) Each filebeat scrapes from a unique path, sends to unique output (logstash endpoints) Metricbeat on ea…

---

## [Elastic agent does not send all of kubernetes container logs](https://discuss.elastic.co/t/elastic-agent-does-not-send-all-of-kubernetes-container-logs/345400)

<div class="topic-metadata">

**Author:** [@enural](https://discuss.elastic.co/u/enural)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 2:21pm UTC](https://discuss.elastic.co/t/elastic-agent-does-not-send-all-of-kubernetes-container-logs/345400 "2023-10-19T14:21:42Z")

</div>

Hello, We are using Microsoft Azure Platform. We created a azure virtual machine and install the elastic-stack on this machine following offical documents, and add the fleet server to this virtual machine. We followed …

---

## [Daily incoming data size calculation](https://discuss.elastic.co/t/daily-incoming-data-size-calculation/345105)

<div class="topic-metadata">

**Author:** [@nonameo](https://discuss.elastic.co/u/nonameo)\
**Replies:** 3\
**Last updated:** [October 19, 2023, 2:09pm UTC](https://discuss.elastic.co/t/daily-incoming-data-size-calculation/345105 "2023-10-19T14:09:14Z")

</div>

Hi everyone, I need to know the daily incoming data size in GB. How can I calculate it? Could you please help with that?

---

## [Dissect - Pipeline in Logstash](https://discuss.elastic.co/t/dissect-pipeline-in-logstash/345315)

<div class="topic-metadata">

**Author:** [@lucasyuki](https://discuss.elastic.co/u/lucasyuki)\
**Replies:** 3\
**Last updated:** [October 19, 2023, 2:06pm UTC](https://discuss.elastic.co/t/dissect-pipeline-in-logstash/345315 "2023-10-19T14:06:26Z")

</div>

Hi team , im trying to dissect the message log I'm trying to parse the "Message" column, I tested it in Elastic cloud and the command in the ingest pipelines tab was working My config in logstash conf.d input { syslo…

---

## [How to write code in json input in kiban deshboard graph? please share with example](https://discuss.elastic.co/t/how-to-write-code-in-json-input-in-kiban-deshboard-graph-please-share-with-example/345392)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 1:05pm UTC](https://discuss.elastic.co/t/how-to-write-code-in-json-input-in-kiban-deshboard-graph-please-share-with-example/345392 "2023-10-19T13:05:01Z")

</div>

how to write code in json input in kiban deshboard graph? please share with example.

---

## [In pie chart kibana is this possible to set customize colour?](https://discuss.elastic.co/t/in-pie-chart-kibana-is-this-possible-to-set-customize-colour/344917)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 2\
**Last updated:** [October 19, 2023, 1:01pm UTC](https://discuss.elastic.co/t/in-pie-chart-kibana-is-this-possible-to-set-customize-colour/344917 "2023-10-19T13:01:46Z")

</div>

In pie chart kibana, is this possible to set customize colour ?

---

## [Huge packets sent from filebeat to ES](https://discuss.elastic.co/t/huge-packets-sent-from-filebeat-to-es/345343)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 1\
**Last updated:** [October 19, 2023, 11:49am UTC](https://discuss.elastic.co/t/huge-packets-sent-from-filebeat-to-es/345343 "2023-10-19T11:49:02Z")

</div>

Hi all, I'm using the netflow module on filebeat v8.8.0 to send netflow traffic to ES. The incoming netflow packets are all about 5KB to 6KB. When I did a tcpdump on the interface that is sending the netflow data to ES,…

---

## [System/socket dataset setup failed: guess\_struct\_creds](https://discuss.elastic.co/t/system-socket-dataset-setup-failed-guess-struct-creds/344175)

<div class="topic-metadata">

**Author:** [@0xdeadbeer](https://discuss.elastic.co/u/0xdeadbeer)\
**Replies:** 2\
**Last updated:** [October 19, 2023, 11:46am UTC](https://discuss.elastic.co/t/system-socket-dataset-setup-failed-guess-struct-creds/344175 "2023-10-19T11:46:06Z")

</div>

Auditbeat runs flawlessly without the socket module. However, whenever I turn it on the following error shows up: {"log.level":"info","@timestamp":"2023-09-30T20:01:20.511+0200","log.origin":{"file.name":"instance/beat.…

---

## [How to use {{#context.hits}} alert with an INDEX action?](https://discuss.elastic.co/t/how-to-use-context-hits-alert-with-an-index-action/345378)

<div class="topic-metadata">

**Author:** [@jamesarbrown](https://discuss.elastic.co/u/jamesarbrown)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 10:37am UTC](https://discuss.elastic.co/t/how-to-use-context-hits-alert-with-an-index-action/345378 "2023-10-19T10:37:09Z")

</div>

Hi, I would like to pass the context.hits information to the index alert connector i have created. The connector all works, but anything re the context.hits and I get an empty result. This is one of the many itteratio…

---

## [How to read logs from different docker container using logstash](https://discuss.elastic.co/t/how-to-read-logs-from-different-docker-container-using-logstash/345250)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 2\
**Last updated:** [October 19, 2023, 10:34am UTC](https://discuss.elastic.co/t/how-to-read-logs-from-different-docker-container-using-logstash/345250 "2023-10-19T10:34:27Z")

</div>

I have multiple docker containers in host. For example :- tomcat process docker container, elasticsearch process docker container, postgresql process docker container. And Logstash are running in seperate docker cont…

---

## [Scripted field to sum a value of the field](https://discuss.elastic.co/t/scripted-field-to-sum-a-value-of-the-field/345364)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 3\
**Last updated:** [October 19, 2023, 10:07am UTC](https://discuss.elastic.co/t/scripted-field-to-sum-a-value-of-the-field/345364 "2023-10-19T10:07:22Z")

</div>

Hi there, please look at my screenshot below. there are 4 data in the same timestamp and what I want to do is to sum the value of http\_status field so it will be 39 + 2 + 2 + 2 = 45 is it possible to do that using a …

---

## [Sql module, pb with DB password characters](https://discuss.elastic.co/t/sql-module-pb-with-db-password-characters/345375)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 10:02am UTC](https://discuss.elastic.co/t/sql-module-pb-with-db-password-characters/345375 "2023-10-19T10:02:27Z")

</div>

Hello, I use Elastic 7.17 with metricbeat and the sql module. The DB connection fails with this line in the log: error opening connection: testing connection: parse "sqlserver://elk:J6": invalid port ":J6" after host …

---

## [Wrong format for duration in milliseconds](https://discuss.elastic.co/t/wrong-format-for-duration-in-milliseconds/344414)

<div class="topic-metadata">

**Author:** [@desna](https://discuss.elastic.co/u/desna)\
**Replies:** 1\
**Last updated:** [October 19, 2023, 9:48am UTC](https://discuss.elastic.co/t/wrong-format-for-duration-in-milliseconds/344414 "2023-10-19T09:48:08Z")

</div>

I have a property that represents duration in milliseconds (type Long), for example 1204172350 is 1,99 weeks (or 13,94 days). From Kibana index patterns I've configured my field with a format duration, input format: mill…

---

## [Elasticsearch REST API Commands](https://discuss.elastic.co/t/elasticsearch-rest-api-commands/345168)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 4\
**Last updated:** [October 19, 2023, 9:24am UTC](https://discuss.elastic.co/t/elasticsearch-rest-api-commands/345168 "2023-10-19T09:24:24Z")

</div>

Hi Team, I need a help for understanding the O/P of REST API commands while running through Dev Console in Kibana Dashboard. While doing search of an item, apart from result the O/P shows so many other details. Is th…

---

## [Filebeat cat not erich with metadata after 5 min when using add\_kubernetes\_metadata](https://discuss.elastic.co/t/filebeat-cat-not-erich-with-metadata-after-5-min-when-using-add-kubernetes-metadata/345369)

<div class="topic-metadata">

**Author:** [@aisuhua](https://discuss.elastic.co/u/aisuhua)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 8:54am UTC](https://discuss.elastic.co/t/filebeat-cat-not-erich-with-metadata-after-5-min-when-using-add-kubernetes-metadata/345369 "2023-10-19T08:54:59Z")

</div>

When no log was written within 5 minutes，filebeat cat not erich with kubenetes metadata. After I had change logger.level to debug，the debug file like below: kubernetes: Querying for pod failed with error: pods \\"worke…

---

## [Elasticsearch Next 7.x - ScriptQuery Id and Params Properties alternative to get Stored Script using its ID](https://discuss.elastic.co/t/elasticsearch-next-7-x-scriptquery-id-and-params-properties-alternative-to-get-stored-script-using-its-id/345351)

<div class="topic-metadata">

**Author:** [@Juan07](https://discuss.elastic.co/u/Juan07)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 3:59am UTC](https://discuss.elastic.co/t/elasticsearch-next-7-x-scriptquery-id-and-params-properties-alternative-to-get-stored-script-using-its-id/345351 "2023-10-19T03:59:47Z")

</div>

We have updated to Nest 7 from Nest 6. We are getting compiler error with exception ScriptQuery does not contain a definition for Id and Params. Here, we are trying to get a stored script using its ID. But seems these p…

---

## [Logstash fetching data from multiple MySQL databases](https://discuss.elastic.co/t/logstash-fetching-data-from-multiple-mysql-databases/345350)

<div class="topic-metadata">

**Author:** [@mfrob](https://discuss.elastic.co/u/mfrob)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 3:48am UTC](https://discuss.elastic.co/t/logstash-fetching-data-from-multiple-mysql-databases/345350 "2023-10-19T03:48:20Z")

</div>

Hi there, I think this community is really great and helpful, especially for someone like me who is really new to the ELK stack, barely a week in. So Ive been tasked to use elasticsearch for a new company project. In or…

---

## [Elasticsearch Subscription for CCR](https://discuss.elastic.co/t/elasticsearch-subscription-for-ccr/345348)

<div class="topic-metadata">

**Author:** [@Leonadius](https://discuss.elastic.co/u/Leonadius)\
**Replies:** 2\
**Last updated:** [October 19, 2023, 3:43am UTC](https://discuss.elastic.co/t/elasticsearch-subscription-for-ccr/345348 "2023-10-19T03:43:50Z")

</div>

Good day team, I want to ask about the subscriptions for CCR features. Currently we have 2 ELK clusters on DC and DRC, and we planning to replicate some of the indices from DC to DRC (one way). Both of the clusters have…

---

## [Elastic Agent not matching @timestamp](https://discuss.elastic.co/t/elastic-agent-not-matching-timestamp/345334)

<div class="topic-metadata">

**Author:** [@Cara410](https://discuss.elastic.co/u/Cara410)\
**Replies:** 0\
**Last updated:** [October 18, 2023, 9:19pm UTC](https://discuss.elastic.co/t/elastic-agent-not-matching-timestamp/345334 "2023-10-18T21:19:28Z")

</div>

Hello, I migrated to Elastic Agent from Filebeat and I am having trouble getting the log timestamp to match the @timestamp. My configuration goes from Elastic Agent -\> Logstash -\> elasticsearch. I have this in my elasti…

---

## [High Level Rest Client and SyncedFlushRequest](https://discuss.elastic.co/t/high-level-rest-client-and-syncedflushrequest/345330)

<div class="topic-metadata">

**Author:** [@Vlado](https://discuss.elastic.co/u/Vlado)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 9:18pm UTC](https://discuss.elastic.co/t/high-level-rest-client-and-syncedflushrequest/345330 "2023-10-18T21:18:19Z")

</div>

Hi folks, adding some signal here that I've run into the same issue as the below two RestHighLevelClient and SyncedFlushRequest. That is SyncedFlushRequest throws a java.lang.NoClassDefFoundError: org/elasticsearch/a…

---

## [ElasticAgent not creating new index](https://discuss.elastic.co/t/elasticagent-not-creating-new-index/345326)

<div class="topic-metadata">

**Author:** [@Cara410](https://discuss.elastic.co/u/Cara410)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 9:09pm UTC](https://discuss.elastic.co/t/elasticagent-not-creating-new-index/345326 "2023-10-18T21:09:35Z")

</div>

Hello, I just migrated from using Filebeat to using Elastic Agent. I am using the custom logs integration to ingest some custom logs I have been able to get the logs into the generic default logs in Discover and have th…

---

## [REST API Connector to ingext REST API JSON Response in elastic Cloud Index](https://discuss.elastic.co/t/rest-api-connector-to-ingext-rest-api-json-response-in-elastic-cloud-index/345329)

<div class="topic-metadata">

**Author:** [@gupashis1978](https://discuss.elastic.co/u/gupashis1978)\
**Replies:** 0\
**Last updated:** [October 18, 2023, 9:05pm UTC](https://discuss.elastic.co/t/rest-api-connector-to-ingext-rest-api-json-response-in-elastic-cloud-index/345329 "2023-10-18T21:05:34Z")

</div>

Using Elastic Cloud 8.9. Requirement is to index the JSON Data ( response) of REST API GET call. Not able to find any in built managed connector for this scenario. Looking for a connector where I can enter REST API Endpo…

---

## [Retrieving sorted results using a point-in-time search with slicing](https://discuss.elastic.co/t/retrieving-sorted-results-using-a-point-in-time-search-with-slicing/345328)

<div class="topic-metadata">

**Author:** [@valasatava](https://discuss.elastic.co/u/valasatava)\
**Replies:** 0\
**Last updated:** [October 18, 2023, 8:58pm UTC](https://discuss.elastic.co/t/retrieving-sorted-results-using-a-point-in-time-search-with-slicing/345328 "2023-10-18T20:58:16Z")

</div>

Hi everyone, I'm running into issues with retrieving results using Paginate search results | Elasticsearch Guide \[8.10\] | Elastic and preserving the sorted order across the whole data set. I need to pull lots of docume…

---

## [Busqueda con error en Discoverc](https://discuss.elastic.co/t/busqueda-con-error-en-discoverc/345314)

<div class="topic-metadata">

**Author:** [@volivares](https://discuss.elastic.co/u/volivares)\
**Replies:** 3\
**Last updated:** [October 18, 2023, 8:34pm UTC](https://discuss.elastic.co/t/busqueda-con-error-en-discoverc/345314 "2023-10-18T20:34:08Z")

</div>

Hola Estoy queriendo realizar una búsqueda de una frase dentro de un conjunto de palabras en el "message" y me devuelve el siguiente error: Response: { "took": 1963, "timed\_out": false, "\_shards": { "tota…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=393)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=395)
