# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=406

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 407

---

## [Elasticsearch jvm memory outbursts above settings causing oom-kill](https://discuss.elastic.co/t/elasticsearch-jvm-memory-outbursts-above-settings-causing-oom-kill/344490)

<div class="topic-metadata">

**Author:** [@Guillaume\_Soustrade](https://discuss.elastic.co/u/Guillaume_Soustrade)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 1:49pm UTC](https://discuss.elastic.co/t/elasticsearch-jvm-memory-outbursts-above-settings-causing-oom-kill/344490 "2023-10-05T13:49:55Z")

</div>

Dear Elasticsearch connoisseurs, We have a repeating issue in our clusters of nodes suddenly exiting due to the java process being oom-killed. Let's take the example of this falling node : 94.3 Go of RAM 8 CPUs SWAP …

---

## [Elastic-Agent takes up too much disk space](https://discuss.elastic.co/t/elastic-agent-takes-up-too-much-disk-space/344429)

<div class="topic-metadata">

**Author:** [@swtrux](https://discuss.elastic.co/u/swtrux)\
**Replies:** 3\
**Last updated:** [October 5, 2023, 1:32pm UTC](https://discuss.elastic.co/t/elastic-agent-takes-up-too-much-disk-space/344429 "2023-10-05T13:32:50Z")

</div>

The size of elastic-agent continues to increase with every version: 8.8 1.7G 8.7 1.4G 8.6 1.2G 8.5 415M 1.7GB for this package size is way too big. We are looking at moving to elastic-agent but can't have over 2000 …

---

## [Getting error after adding filebeat](https://discuss.elastic.co/t/getting-error-after-adding-filebeat/344481)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 12:56pm UTC](https://discuss.elastic.co/t/getting-error-after-adding-filebeat/344481 "2023-10-05T12:56:24Z")

</div>

Dear Team, We are getting error as below after adding new log files through filebeat ,we have increased our heap size up to 30 g ,and total memory is 62 gb present now on server , \[ERROR\]\[o.e.x.c.a.AsyncTaskIndexServic…

---

## [Does Elastic accept combined JSON with flatten keys](https://discuss.elastic.co/t/does-elastic-accept-combined-json-with-flatten-keys/344373)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 12:06pm UTC](https://discuss.elastic.co/t/does-elastic-accept-combined-json-with-flatten-keys/344373 "2023-10-04T12:06:17Z")

</div>

Hi, is it possible to send to ES messages in combined JSON format { "a": { "b": { "c.d.e.f": "value" } } } or it ends with error like can't merge a non object mapping with an object mapping?

---

## [Best practice for TDocument class reference to pass to Java's ElasticsearchClient methods?](https://discuss.elastic.co/t/best-practice-for-tdocument-class-reference-to-pass-to-javas-elasticsearchclient-methods/344473)

<div class="topic-metadata">

**Author:** [@ilgrosso](https://discuss.elastic.co/u/ilgrosso)\
**Replies:** 2\
**Last updated:** [October 5, 2023, 12:14pm UTC](https://discuss.elastic.co/t/best-practice-for-tdocument-class-reference-to-pass-to-javas-elasticsearchclient-methods/344473 "2023-10-05T12:14:45Z")

</div>

Hi, I am using the latest Java REST API client and wondering what Class\<TDocument\> reference I should be passing to the search() method in case of no object domain model is being used. At present I am using a bare Map.…

---

## [How do we write painless script for scripted fields](https://discuss.elastic.co/t/how-do-we-write-painless-script-for-scripted-fields/344467)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 11:49am UTC](https://discuss.elastic.co/t/how-do-we-write-painless-script-for-scripted-fields/344467 "2023-10-05T11:49:06Z")

</div>

Hi Team, am trying to write painless script for the below scenario.. i have department numbers like 1100,1200,1300... so, instead of department numbers am expecting short name as IND, USA, UK....by using scripted fiel…

---

## [How to change an index mapping in Elastic search](https://discuss.elastic.co/t/how-to-change-an-index-mapping-in-elastic-search/344456)

<div class="topic-metadata">

**Author:** [@Francesco66](https://discuss.elastic.co/u/Francesco66)\
**Replies:** 4\
**Last updated:** [October 5, 2023, 11:47am UTC](https://discuss.elastic.co/t/how-to-change-an-index-mapping-in-elastic-search/344456 "2023-10-05T11:47:11Z")

</div>

Hello, I am ingesting the following document into Elasticsearch via Logstash: \[xxxx@yyyy ~\]# curl -k http://my\_es\_hostname:9200/cdp-zos-syslog-console-plex75-20231005/\_search?pretty { "took" : 564, "timed\_out" : fal…

---

## [Filebeat 7.17.6 automatically populates event.module and service.type fields?](https://discuss.elastic.co/t/filebeat-7-17-6-automatically-populates-event-module-and-service-type-fields/344474)

<div class="topic-metadata">

**Author:** [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 11:34am UTC](https://discuss.elastic.co/t/filebeat-7-17-6-automatically-populates-event-module-and-service-type-fields/344474 "2023-10-05T11:34:33Z")

</div>

Hi, I'm facing weird behaviour of Filebeat for which I couldn't find any explanation in the docs. So we write application logs into files in ECS format using Elastic.CommonSchema.Serilog package. All log entries have po…

---

## [Optimal way to handle log with multiple format?](https://discuss.elastic.co/t/optimal-way-to-handle-log-with-multiple-format/344470)

<div class="topic-metadata">

**Author:** [@Tanin\_Imanothai](https://discuss.elastic.co/u/Tanin_Imanothai)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 10:33am UTC](https://discuss.elastic.co/t/optimal-way-to-handle-log-with-multiple-format/344470 "2023-10-05T10:33:57Z")

</div>

I try to parse this dataset: https://github.com/logpai/loghub/tree/master/Android using logstash. I have tried using grok filter but some parts of the log contains multiple templates. example of log: 03-17 16:13:38.81…

---

## [503 error from Kibana while running Filebeat setup](https://discuss.elastic.co/t/503-error-from-kibana-while-running-filebeat-setup/344435)

<div class="topic-metadata">

**Author:** [@nspeaks](https://discuss.elastic.co/u/nspeaks)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 9:54am UTC](https://discuss.elastic.co/t/503-error-from-kibana-while-running-filebeat-setup/344435 "2023-10-05T09:54:52Z")

</div>

I am trying to run the command filebeat setup -e and this is the error I get {"log.level":"info","@timestamp":"2023-10-05T02:55:42.666Z","log.origin":{"file.name":"instance/beat.go","file.line":783},"message":"Home pa…

---

## [View SAML Users](https://discuss.elastic.co/t/view-saml-users/344462)

<div class="topic-metadata">

**Author:** [@lehu](https://discuss.elastic.co/u/lehu)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 9:20am UTC](https://discuss.elastic.co/t/view-saml-users/344462 "2023-10-05T09:20:13Z")

</div>

Hi, does anybody know why I can't see users that login with SAML even though I am an admin? It is necessary to view all users to change their roles otherwise all SAML users have the same role, which I dont want... Any su…

---

## [Watcher filter Latency\_info](https://discuss.elastic.co/t/watcher-filter-latency-info/344458)

<div class="topic-metadata">

**Author:** [@Aitor\_MtzAm](https://discuss.elastic.co/u/Aitor_MtzAm)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 8:52am UTC](https://discuss.elastic.co/t/watcher-filter-latency-info/344458 "2023-10-05T08:52:34Z")

</div>

I need the watcher to differentiate between 2 values of the same field: Within the latency\_info field in the task "Integration" I need to differentiate whether the result field is "-" or "200". "latency\_info": \[ { "t…

---

## [Salesforce input logstash - add filter](https://discuss.elastic.co/t/salesforce-input-logstash-add-filter/344217)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 4\
**Last updated:** [October 5, 2023, 8:17am UTC](https://discuss.elastic.co/t/salesforce-input-logstash-add-filter/344217 "2023-10-05T08:17:50Z")

</div>

I have a input configuration like that and i wonder if is possible to filter document like with a query or something like that. salesforce{ use\_test\_sandbox =\> true client\_id =\> '' client…

---

## [Error with net/smtp in Logstash (Docker)](https://discuss.elastic.co/t/error-with-net-smtp-in-logstash-docker/344312)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 2\
**Last updated:** [October 5, 2023, 8:08am UTC](https://discuss.elastic.co/t/error-with-net-smtp-in-logstash-docker/344312 "2023-10-05T08:08:47Z")

</div>

Hi everyone, im having some issue with docker and logstash. I have the following error: 2023-10-03 14:46:24 warning: thread "\[main\]-pipeline-manager" terminated with exception (report\_on\_exception is true): 2023-10-03 …

---

## [Why does cluster.routing.allocation.exclude.\_ip only work as a transient, not persistent setting?](https://discuss.elastic.co/t/why-does-cluster-routing-allocation-exclude-ip-only-work-as-a-transient-not-persistent-setting/344419)

<div class="topic-metadata">

**Author:** [@Jamshid](https://discuss.elastic.co/u/Jamshid)\
**Replies:** 3\
**Last updated:** [October 5, 2023, 7:12am UTC](https://discuss.elastic.co/t/why-does-cluster-routing-allocation-exclude-ip-only-work-as-a-transient-not-persistent-setting/344419 "2023-10-05T07:12:47Z")

</div>

Just a sanity check... trying to remove a node by setting cluster.routing.allocation.exclude.\_ip does not seem to have any effect if it's a persistent setting. Tested with elasticesarch 7.17.13 on a 3-node cluster. When …

---

## [Lot of delay in logs parsing at kibana GUI](https://discuss.elastic.co/t/lot-of-delay-in-logs-parsing-at-kibana-gui/344449)

<div class="topic-metadata">

**Author:** [@syedsyed](https://discuss.elastic.co/u/syedsyed)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 7:01am UTC](https://discuss.elastic.co/t/lot-of-delay-in-logs-parsing-at-kibana-gui/344449 "2023-10-05T07:01:33Z")

</div>

I have Elasticsearch and kibana installed and i have integrated the fleet server into it, enrolled the elastic agent with sonicwall integration into it, but i am facing lot of delay of about one and half day, mostly the …

---

## [Max items on runtime fields](https://discuss.elastic.co/t/max-items-on-runtime-fields/344307)

<div class="topic-metadata">

**Author:** [@lipig](https://discuss.elastic.co/u/lipig)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 6:16am UTC](https://discuss.elastic.co/t/max-items-on-runtime-fields/344307 "2023-10-05T06:16:31Z")

</div>

Hi Elastic people, A curiosity... I emit more than 100 values ​​in the runtime fields, and I saw in the forum that 100 was the maximum. I saw this thread from 2021 and wanted to ask if there have been any updates. Th…

---

## [Elastic system indices migration issue while upgrade](https://discuss.elastic.co/t/elastic-system-indices-migration-issue-while-upgrade/344434)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 6:10am UTC](https://discuss.elastic.co/t/elastic-system-indices-migration-issue-while-upgrade/344434 "2023-10-05T06:10:48Z")

</div>

Hi, I am upgrading elastic from 6.8 to 7.17.0 and then 8.x.x. From version 6.8 to 7.17 migration was fine but while preparing to migrate from version 7.17 to 8.x.x upgrade assistant is not able to migrate this one(Task…

---

## [Filebeat cisco ios Parsing delimeter error](https://discuss.elastic.co/t/filebeat-cisco-ios-parsing-delimeter-error/344432)

<div class="topic-metadata">

**Author:** [@lee.clemens](https://discuss.elastic.co/u/lee.clemens)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 10:00pm UTC](https://discuss.elastic.co/t/filebeat-cisco-ios-parsing-delimeter-error/344432 "2023-10-04T22:00:10Z")

</div>

Hello, I'm seeing this runtime error being logged parsing deny logs from IOS: GoError: could not find beginning delimiter: list in remaining: F0/0: fman\_fp\_image: list ACL\_Inbound denied udp 127.0.0.1(51052) -\> 127.0.…

---

## [Master node in ECK with differente IP between pod and elasticsearch](https://discuss.elastic.co/t/master-node-in-eck-with-differente-ip-between-pod-and-elasticsearch/344431)

<div class="topic-metadata">

**Author:** [@dudds22](https://discuss.elastic.co/u/dudds22)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 8:34pm UTC](https://discuss.elastic.co/t/master-node-in-eck-with-differente-ip-between-pod-and-elasticsearch/344431 "2023-10-04T20:34:06Z")

</div>

Hi, Today we faced a strange situation and really want to share with you in order to try to obtain more infos about what can be happened. Context: We have a elasticsearch cluster and we need to send slowlogs to Datado…

---

## [Slef-host elasticsearch with azure ad sso SAML](https://discuss.elastic.co/t/slef-host-elasticsearch-with-azure-ad-sso-saml/344423)

<div class="topic-metadata">

**Author:** [@Yue\_CHEN](https://discuss.elastic.co/u/Yue_CHEN)\
**Replies:** 3\
**Last updated:** [October 4, 2023, 9:09pm UTC](https://discuss.elastic.co/t/slef-host-elasticsearch-with-azure-ad-sso-saml/344423 "2023-10-04T21:09:38Z")

</div>

Hello, Recently created a self-host Elasticsearch and Kibana version 8.10 in Azure VM. Both working fine now. Like to get Azure AD SSO enable when user open kibana. But did not see a good document for how to set it up.…

---

## [Elastic query takes over 1 minute due to time spent in "HighlightPhase"](https://discuss.elastic.co/t/elastic-query-takes-over-1-minute-due-to-time-spent-in-highlightphase/344344)

<div class="topic-metadata">

**Author:** [@David\_Avant](https://discuss.elastic.co/u/David_Avant)\
**Replies:** 5\
**Last updated:** [October 4, 2023, 7:26pm UTC](https://discuss.elastic.co/t/elastic-query-takes-over-1-minute-due-to-time-spent-in-highlightphase/344344 "2023-10-04T19:26:59Z")

</div>

Some elastic queries are slow, taking more than a minute to execute. The query input is simple: just a single, numeric account identifier (i.e. "123456789"). The query takes 68 seconds to execute and returns 6 hits. T…

---

## [File not found when attempting to index](https://discuss.elastic.co/t/file-not-found-when-attempting-to-index/344353)

<div class="topic-metadata">

**Author:** [@Ahriss](https://discuss.elastic.co/u/Ahriss)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 7:23pm UTC](https://discuss.elastic.co/t/file-not-found-when-attempting-to-index/344353 "2023-10-04T19:23:12Z")

</div>

Hello. I'm building a simple elasticsearch/PHP application, and I got a very weird error. I can search on it just fine, though I need to build pagination for it still, but when I attempt to index something, I simply get …

---

## [Filebeat auth.oauth2 error appeared on Google workspace config](https://discuss.elastic.co/t/filebeat-auth-oauth2-error-appeared-on-google-workspace-config/344421)

<div class="topic-metadata">

**Author:** [@Umor](https://discuss.elastic.co/u/Umor)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 6:25pm UTC](https://discuss.elastic.co/t/filebeat-auth-oauth2-error-appeared-on-google-workspace-config/344421 "2023-10-04T18:25:50Z")

</div>

Greetings, I am using the Google Workspace module, and while running Filebeat the Google logs show and after a couple of minutes this error appeared {"log.level":"error","@timestamp":"2023-10-04T23:21:34.745+0500","log…

---

## [Send syslog to Filebeat server](https://discuss.elastic.co/t/send-syslog-to-filebeat-server/343987)

<div class="topic-metadata">

**Author:** [@msylvestre](https://discuss.elastic.co/u/msylvestre)\
**Replies:** 27\
**Last updated:** [October 4, 2023, 7:06pm UTC](https://discuss.elastic.co/t/send-syslog-to-filebeat-server/343987 "2023-10-04T19:06:22Z")

</div>

Greetings, I'm trying to send my Cisco Switches logs to my Filebeat server but for some reason it's not working. I can see that the Filebeat receives the logs, but it doesn't ship them to elastic afterwards. I tried usi…

---

## [ERROR: Skipping security auto configuration because it appears that the node is not starting up for the first time. The node might already be part of a cluster and this auto setup utility is designed to configure Security for new clusters only., with exit](https://discuss.elastic.co/t/error-skipping-security-auto-configuration-because-it-appears-that-the-node-is-not-starting-up-for-the-first-time-the-node-might-already-be-part-of-a-cluster-and-this-auto-setup-utility-is-designed-to-configure-security-for-new-clusters-only-with-exit/344422)

<div class="topic-metadata">

**Author:** [@nav\_11](https://discuss.elastic.co/u/nav_11)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 6:29pm UTC](https://discuss.elastic.co/t/error-skipping-security-auto-configuration-because-it-appears-that-the-node-is-not-starting-up-for-the-first-time-the-node-might-already-be-part-of-a-cluster-and-this-auto-setup-utility-is-designed-to-configure-security-for-new-clusters-only-with-exit/344422 "2023-10-04T18:29:24Z")

</div>

Getting below error while adding the node. I am following the MACOS setup guide below. Command: bin/elasticsearch --enrollment-token ERROR: Skipping security auto configuration because it appears that the node is no…

---

## [Import Objects API for Rules/Connectors](https://discuss.elastic.co/t/import-objects-api-for-rules-connectors/344409)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 5:38pm UTC](https://discuss.elastic.co/t/import-objects-api-for-rules-connectors/344409 "2023-10-04T17:38:36Z")

</div>

Hello, Elastic! I'm currently using a curl command to push an Alert Rule. Currently the rule gets created but is created in a 'disabled' state (see warnings.message): { "successCount": 1, "success": true, "warnin…

---

## [Getting index rate](https://discuss.elastic.co/t/getting-index-rate/344381)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 3:56pm UTC](https://discuss.elastic.co/t/getting-index-rate/344381 "2023-10-04T15:56:49Z")

</div>

Hi, I am looking a way to monitor index rate not through Kibana. Is there any RestAPI command that provide the current index rate? Is there alternative way? Thanks...

---

## [ECK Filebeat processor add\_kubernetes\_metadata does not add fields with kube metadata](https://discuss.elastic.co/t/eck-filebeat-processor-add-kubernetes-metadata-does-not-add-fields-with-kube-metadata/344322)

<div class="topic-metadata">

**Author:** [@AlekseyD](https://discuss.elastic.co/u/AlekseyD)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 3:30pm UTC](https://discuss.elastic.co/t/eck-filebeat-processor-add-kubernetes-metadata-does-not-add-fields-with-kube-metadata/344322 "2023-10-04T15:30:30Z")

</div>

Kubernetes: 1.24.3 Kibana: 8.10.2 Elastic: 8.10.2 Filebeat: 8.10.2 Fresh install via ECK 2.9.0 The processor "add\_kubernetesmetadata" does not add kubernetes metadata fields to elasticsearch, the filebeat log does n…

---

## [Issue in restoring an Elastic Snapshot](https://discuss.elastic.co/t/issue-in-restoring-an-elastic-snapshot/343329)

<div class="topic-metadata">

**Author:** [@girolamo](https://discuss.elastic.co/u/girolamo)\
**Replies:** 7\
**Last updated:** [October 4, 2023, 3:08pm UTC](https://discuss.elastic.co/t/issue-in-restoring-an-elastic-snapshot/343329 "2023-10-04T15:08:18Z")

</div>

Hello there, I'm having issues restoring an elasticsearch snapshot. I've tried: POST \_snapshot/snapshot\_repo/snap-EIHidJXeQWuHpnGfzR04Uw/\_restore { "indices": "target\_indicies" } but I've got: { "error" : { "ro…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=405)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=407)
