# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=411

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 412

---

## [BucketSelectorPipelineAggregationBuilder missing from elasticsearch 8.9.2](https://discuss.elastic.co/t/bucketselectorpipelineaggregationbuilder-missing-from-elasticsearch-8-9-2/344067)

<div class="topic-metadata">

**Author:** [@rishavgu](https://discuss.elastic.co/u/rishavgu)\
**Replies:** 3\
**Last updated:** [September 28, 2023, 4:30pm UTC](https://discuss.elastic.co/t/bucketselectorpipelineaggregationbuilder-missing-from-elasticsearch-8-9-2/344067 "2023-09-28T16:30:16Z")

</div>

We are upgrading our Elasticsearch from 8.5.3 to 8.9.2 and our migration is failing with following error: Cannot resolve symbol 'BucketSelectorPipelineAggregationBuilder' Seems like in 8.9.2 this class file has been rem…

---

## [Error when creating a index template for a Time Serie](https://discuss.elastic.co/t/error-when-creating-a-index-template-for-a-time-serie/344002)

<div class="topic-metadata">

**Author:** [@Mubolio](https://discuss.elastic.co/u/Mubolio)\
**Replies:** 8\
**Last updated:** [September 28, 2023, 4:06pm UTC](https://discuss.elastic.co/t/error-when-creating-a-index-template-for-a-time-serie/344002 "2023-09-28T16:06:33Z")

</div>

Hello, I'm trying to use a timeserie datastream, for that I try to create an index template, note that the bellow example it is almost the same as the one in the documentation: PUT \_index\_template/my-weather-sensor-i…

---

## [Logstash never picked up any logs. I mean it never parse any logs except 2 log lines for the entire day](https://discuss.elastic.co/t/logstash-never-picked-up-any-logs-i-mean-it-never-parse-any-logs-except-2-log-lines-for-the-entire-day/344063)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 9\
**Last updated:** [September 28, 2023, 3:55pm UTC](https://discuss.elastic.co/t/logstash-never-picked-up-any-logs-i-mean-it-never-parse-any-logs-except-2-log-lines-for-the-entire-day/344063 "2023-09-28T15:55:40Z")

</div>

I have using logstash 8.10.0 for windows and linux downloaded from elastic.co downloads. I could hardly see 2 events ingested by logstash. logstash-plain.log does not have any error after pipeline\_running. configura…

---

## [How do I have to migrate the usage of org.elasticsearch.\* multiSearchResponse to co.elastic.\* MsearchResponse?](https://discuss.elastic.co/t/how-do-i-have-to-migrate-the-usage-of-org-elasticsearch-multisearchresponse-to-co-elastic-msearchresponse/344081)

<div class="topic-metadata">

**Author:** [@du-it](https://discuss.elastic.co/u/du-it)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 3:52pm UTC](https://discuss.elastic.co/t/how-do-i-have-to-migrate-the-usage-of-org-elasticsearch-multisearchresponse-to-co-elastic-msearchresponse/344081 "2023-09-28T15:52:16Z")

</div>

I am migrating from org.elasticsearch.\* to co.elastic.\* classes using elasticsearch-java dependency 8.10.2. It's really not obvious which co.elastic.\* classes are the org.elasticsearvh.\* equivalent when replacing the R…

---

## [Received response for a request that has timed out and "failed to retrieve stats for node"](https://discuss.elastic.co/t/received-response-for-a-request-that-has-timed-out-and-failed-to-retrieve-stats-for-node/343963)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 7\
**Last updated:** [September 28, 2023, 3:01pm UTC](https://discuss.elastic.co/t/received-response-for-a-request-that-has-timed-out-and-failed-to-retrieve-stats-for-node/343963 "2023-09-28T15:01:22Z")

</div>

Hi.. I have a 5 node cluster where we are receiving data around 400 GB per day. Disk in the cluster is at 70% mark on all the nodes. We have observed slowness in running simple queries like \_cat/indices also. When we c…

---

## [Logstash OSS distribution containing EULA](https://discuss.elastic.co/t/logstash-oss-distribution-containing-eula/341230)

<div class="topic-metadata">

**Author:** [@MkGitRepo](https://discuss.elastic.co/u/MkGitRepo)\
**Replies:** 4\
**Last updated:** [September 28, 2023, 1:07pm UTC](https://discuss.elastic.co/t/logstash-oss-distribution-containing-eula/341230 "2023-09-28T13:07:20Z")

</div>

Hi, I was checking the license for logstash-oss and found a notice.txt file containing licenses of few dependencies. One among them is the END USER LICENSE AGREEMENT RED HAT UNIVERSAL BASE IMAGE which is a notice adde…

---

## [Mapper\_parsing\_exception", "reason"=\>"object mapping for \[host\] tried to parse field \[host\] as object, but found a concrete value"}}}}](https://discuss.elastic.co/t/mapper-parsing-exception-reason-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value/344000)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 3\
**Last updated:** [September 28, 2023, 12:27pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-reason-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value/344000 "2023-09-28T12:27:48Z")

</div>

Please suggest me if there is a work around. \[2023-09-27T14:56:22,072\]\[INFO \]\[logstash.javapipeline \]\[main\] Pipeline started {"pipeline.id"=\>"main"}\[2023-09-27T14:56:22,094\]\[INFO \]\[logstash.agent \] Pipeline…

---

## [How catch "user.name" parameter from winlog with logstash](https://discuss.elastic.co/t/how-catch-user-name-parameter-from-winlog-with-logstash/343971)

<div class="topic-metadata">

**Author:** [@DVD\_MNC](https://discuss.elastic.co/u/DVD_MNC)\
**Replies:** 5\
**Last updated:** [September 28, 2023, 12:02pm UTC](https://discuss.elastic.co/t/how-catch-user-name-parameter-from-winlog-with-logstash/343971 "2023-09-28T12:02:54Z")

</div>

Hello, i write the following row in pipeline in the filter section: mutate { add\_field =\> {"parameter" =\> "{\[user\]\[name\]}" } } it do not work. the parameter field is fill with "{\[user\]\[name\]}" as text and original va…

---

## [Exiting: resource ‘metricbeat-7.17.12’ exists, but it is not an alias](https://discuss.elastic.co/t/exiting-resource-metricbeat-7-17-12-exists-but-it-is-not-an-alias/344059)

<div class="topic-metadata">

**Author:** [@lliadan](https://discuss.elastic.co/u/lliadan)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 11:48am UTC](https://discuss.elastic.co/t/exiting-resource-metricbeat-7-17-12-exists-but-it-is-not-an-alias/344059 "2023-09-28T11:48:13Z")

</div>

hello, i'm installing ELK in my company and i have some issues. My elk server is ready and i try to appare 4 linux with filebeat . I copy past the same folder for my 4 machines. 2 of them work but i have this error on…

---

## [PutIndexTemplateRequest](https://discuss.elastic.co/t/putindextemplaterequest/343994)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 2\
**Last updated:** [September 28, 2023, 11:42am UTC](https://discuss.elastic.co/t/putindextemplaterequest/343994 "2023-09-28T11:42:40Z")

</div>

Is there a replacement for the create method below in the new Java API? Thanks. PutIndexTemplateRequest request = new PutIndexTemplateRequest(TEMPLATE\_NAME); request.create(false); // Required to allow…

---

## [Total\_shards\_per\_node on an index pattern instead of an simple index](https://discuss.elastic.co/t/total-shards-per-node-on-an-index-pattern-instead-of-an-simple-index/343869)

<div class="topic-metadata">

**Author:** [@Guillaume\_Soustrade](https://discuss.elastic.co/u/Guillaume_Soustrade)\
**Replies:** 2\
**Last updated:** [September 28, 2023, 11:05am UTC](https://discuss.elastic.co/t/total-shards-per-node-on-an-index-pattern-instead-of-an-simple-index/343869 "2023-09-28T11:05:38Z")

</div>

Hello, I'm looking for a way to limit the number of shards per nodes on a group of index. Is it possible, may be by using index patterns ? My situation is : I have a set of 14 indexes with 12 shards for each We have …

---

## [Cannot create repository on a MinIO instance](https://discuss.elastic.co/t/cannot-create-repository-on-a-minio-instance/344055)

<div class="topic-metadata">

**Author:** [@astingengo](https://discuss.elastic.co/u/astingengo)\
**Replies:** 1\
**Last updated:** [September 28, 2023, 10:48am UTC](https://discuss.elastic.co/t/cannot-create-repository-on-a-minio-instance/344055 "2023-09-28T10:48:09Z")

</div>

ES version: 7.17.13 What I did: I installed s3-repository I created the generic keystore for access key and secret key and mounted as secret with secureSettings.secretName Installed on Kubernetes cluster \[so all chang…

---

## [Filebeat sends 20 days old logs](https://discuss.elastic.co/t/filebeat-sends-20-days-old-logs/344049)

<div class="topic-metadata">

**Author:** [@Hamunaptroid](https://discuss.elastic.co/u/Hamunaptroid)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 9:06am UTC](https://discuss.elastic.co/t/filebeat-sends-20-days-old-logs/344049 "2023-09-28T09:06:58Z")

</div>

Hello, I had approximately 12 hours of downtime on one server (RHEL8) but after it was online again, filebeat started to send logs from the time of downtime. Now, I can see logs in Kibana that have timestamp of the day …

---

## [Is RHEL9 supported on Elasticsearch 7.10.x or lower version](https://discuss.elastic.co/t/is-rhel9-supported-on-elasticsearch-7-10-x-or-lower-version/344031)

<div class="topic-metadata">

**Author:** [@ajay.bansal123](https://discuss.elastic.co/u/ajay.bansal123)\
**Replies:** 4\
**Last updated:** [September 28, 2023, 8:47am UTC](https://discuss.elastic.co/t/is-rhel9-supported-on-elasticsearch-7-10-x-or-lower-version/344031 "2023-09-28T08:47:56Z")

</div>

Hi Folks, Does Elasticsearch 7.10.x OR lower version supports RHEL 9.x OR Rocky Linux 9.x I did not find this info on support-matrix page BR, ajay

---

## [Retention policy characteristics](https://discuss.elastic.co/t/retention-policy-characteristics/343879)

<div class="topic-metadata">

**Author:** [@Tostis](https://discuss.elastic.co/u/Tostis)\
**Replies:** 6\
**Last updated:** [September 28, 2023, 8:23am UTC](https://discuss.elastic.co/t/retention-policy-characteristics/343879 "2023-09-28T08:23:30Z")

</div>

Hello, I am pretty new to Elasticsearch, but got some questions about retention policies. If I am implementing a retention policy for example to delete old data from a index if it is older then 5 days. How is this hand…

---

## [Sending Spring Boot logs directly to Elasticsearch](https://discuss.elastic.co/t/sending-spring-boot-logs-directly-to-elasticsearch/344045)

<div class="topic-metadata">

**Author:** [@tusharSuvarna](https://discuss.elastic.co/u/tusharSuvarna)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 8:12am UTC](https://discuss.elastic.co/t/sending-spring-boot-logs-directly-to-elasticsearch/344045 "2023-09-28T08:12:30Z")

</div>

Hi, I am running a spring boot application as a docker container. I want to send the logs of the application directly to Elasticsearch server without using Filebeats, Logstash or APM. Basically everything that is writt…

---

## [Suggestion in terms of RAM for 3 master nodes and 3 coordinating nodes with 9 data nodes](https://discuss.elastic.co/t/suggestion-in-terms-of-ram-for-3-master-nodes-and-3-coordinating-nodes-with-9-data-nodes/344040)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 7:28am UTC](https://discuss.elastic.co/t/suggestion-in-terms-of-ram-for-3-master-nodes-and-3-coordinating-nodes-with-9-data-nodes/344040 "2023-09-28T07:28:40Z")

</div>

Hello, Give me pls an optimal suggestion in terms of RAM for 3 master nodes and 3 coordinating nodes with 9 data nodes each having 64GB. I m using Elastic version 8.8.1

---

## [High CPU usage periodically](https://discuss.elastic.co/t/high-cpu-usage-periodically/343250)

<div class="topic-metadata">

**Author:** [@xCeLfr](https://discuss.elastic.co/u/xCeLfr)\
**Replies:** 8\
**Last updated:** [September 28, 2023, 7:47am UTC](https://discuss.elastic.co/t/high-cpu-usage-periodically/343250 "2023-09-28T07:47:33Z")

</div>

Hi, there are many topics about CPU load but I can't find an answer. Our standalone Elasticsearch 7.12.0 node runs on a 16 GB RAM Linux server. Every 10 minutes or so elasticsearch consumes 100% CPU and queries are ver…

---

## [How to show two value percentages on one gauge?](https://discuss.elastic.co/t/how-to-show-two-value-percentages-on-one-gauge/343844)

<div class="topic-metadata">

**Author:** [@andrewarnier](https://discuss.elastic.co/u/andrewarnier)\
**Replies:** 3\
**Last updated:** [September 28, 2023, 7:24am UTC](https://discuss.elastic.co/t/how-to-show-two-value-percentages-on-one-gauge/343844 "2023-09-28T07:24:33Z")

</div>

hi all , I have a column in data which two values are Human and Bot, how i can calculate percentage and show in one gauge. for example 7 documents are Human and total documents are 1000 from 1/1 to 2/15 ,then Human …

---

## [Old Index is not deleted as per ILM](https://discuss.elastic.co/t/old-index-is-not-deleted-as-per-ilm/344036)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 6:59am UTC](https://discuss.elastic.co/t/old-index-is-not-deleted-as-per-ilm/344036 "2023-09-28T06:59:57Z")

</div>

Hello, I have created an ILM for my .monitoring-es-7-\* indices PUT \_ilm/policy/Elasticsearch\_monitoring\_test\_policy { "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": { …

---

## [Kuberentes metadata are missing on the pod logs](https://discuss.elastic.co/t/kuberentes-metadata-are-missing-on-the-pod-logs/344035)

<div class="topic-metadata">

**Author:** [@Raoudha\_Lagha](https://discuss.elastic.co/u/Raoudha_Lagha)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 6:54am UTC](https://discuss.elastic.co/t/kuberentes-metadata-are-missing-on-the-pod-logs/344035 "2023-09-28T06:54:43Z")

</div>

Hello Could you please help us with this issue: we found out that some of our pod logs are missing Kubernetes metadata. We are running on Kubernetes version 1.24 and using Karpetener to provision the nodes, The Filebe…

---

## [What is the best aproach to add self-sign certificate to Elasticsearch Kubernetes](https://discuss.elastic.co/t/what-is-the-best-aproach-to-add-self-sign-certificate-to-elasticsearch-kubernetes/343760)

<div class="topic-metadata">

**Author:** [@astingengo](https://discuss.elastic.co/u/astingengo)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 12:59pm UTC](https://discuss.elastic.co/t/what-is-the-best-aproach-to-add-self-sign-certificate-to-elasticsearch-kubernetes/343760 "2023-09-25T12:59:32Z")

</div>

I deployed Elasticsearch in Kubernetes and I'm trying to backup it to an S3 Instance that has a self sign certificate. What would be the best approach to do so \[having Elasticsearch in Kubernetes\]? I tried to import th…

---

## [Logstash not pushing logs to loki](https://discuss.elastic.co/t/logstash-not-pushing-logs-to-loki/344007)

<div class="topic-metadata">

**Author:** [@sheldor](https://discuss.elastic.co/u/sheldor)\
**Replies:** 2\
**Last updated:** [September 28, 2023, 6:45am UTC](https://discuss.elastic.co/t/logstash-not-pushing-logs-to-loki/344007 "2023-09-28T06:45:00Z")

</div>

Below is my logstash config input { file { ecs\_compatibility =\> disabled path =\> \[ "/a/logs/project\_apps/\*\*/\*.log" \] start\_position =\> beginning exclude =\> \[ …

---

## [MetricBeats to Scrap Metrics From Confluent For Kubernetes ( CFK ) PODS](https://discuss.elastic.co/t/metricbeats-to-scrap-metrics-from-confluent-for-kubernetes-cfk-pods/344021)

<div class="topic-metadata">

**Author:** [@vinay.bommarati](https://discuss.elastic.co/u/vinay.bommarati)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 3:28am UTC](https://discuss.elastic.co/t/metricbeats-to-scrap-metrics-from-confluent-for-kubernetes-cfk-pods/344021 "2023-09-28T03:28:37Z")

</div>

Hi All , We have central elastic and have Confluent Kafka deployed onto OpenShift cluster ( CFK). Understand from Confluent Docs that , all CFK pods are exposing metrics with promethus exporter. So I am planning to use…

---

## [Error The given configuration is invalid. Reason: Unable to configure plugins](https://discuss.elastic.co/t/error-the-given-configuration-is-invalid-reason-unable-to-configure-plugins/344018)

<div class="topic-metadata">

**Author:** [@HectorCy10](https://discuss.elastic.co/u/HectorCy10)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 10:32pm UTC](https://discuss.elastic.co/t/error-the-given-configuration-is-invalid-reason-unable-to-configure-plugins/344018 "2023-09-27T22:32:18Z")

</div>

Hi everyone, i have the next error but i can not find any topic to solve this issue

---

## [Parse rabbitmq json log](https://discuss.elastic.co/t/parse-rabbitmq-json-log/344009)

<div class="topic-metadata">

**Author:** [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Replies:** 5\
**Last updated:** [September 27, 2023, 9:32pm UTC](https://discuss.elastic.co/t/parse-rabbitmq-json-log/344009 "2023-09-27T21:32:20Z")

</div>

Hi, got json log message from rabbit as {"timestamp":"2022-12-21 03:14:59.977922+02:00","level":"error","msg":"Error on AMQP connection \<0.32551.1583\>: enotconn (socket is not connected)","domain":"rabbitmq.connection",…

---

## [HIGH PRIORITY -\> how to add subaggregtion in terms aggregation for spring-data-elasticsearch 5.1](https://discuss.elastic.co/t/high-priority-how-to-add-subaggregtion-in-terms-aggregation-for-spring-data-elasticsearch-5-1/344015)

<div class="topic-metadata">

**Author:** [@Abhinav\_Tyagi](https://discuss.elastic.co/u/Abhinav_Tyagi)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 9:14pm UTC](https://discuss.elastic.co/t/high-priority-how-to-add-subaggregtion-in-terms-aggregation-for-spring-data-elasticsearch-5-1/344015 "2023-09-27T21:14:36Z")

</div>

i am rewriting my older verison elasticsearch implementations. I latest spring-data-elasticsearch 5.1, queryBuilders got removed due to whic i am not able to use/ add "AggregationBuilders" inside my native query. Can a…

---

## [What is the default source of the @timestamp field in Filebeat?](https://discuss.elastic.co/t/what-is-the-default-source-of-the-timestamp-field-in-filebeat/343640)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 3\
**Last updated:** [September 27, 2023, 8:59pm UTC](https://discuss.elastic.co/t/what-is-the-default-source-of-the-timestamp-field-in-filebeat/343640 "2023-09-27T20:59:01Z")

</div>

I'm ingesting Syslog input with Filebeat, and I'd like to use the timestamp processor to adjust the timezone of the logs (my source is sending them in local time and Kibana is expecting UTC). According to the documentati…

---

## [Multiple input log, reading the same files](https://discuss.elastic.co/t/multiple-input-log-reading-the-same-files/344013)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 8:45pm UTC](https://discuss.elastic.co/t/multiple-input-log-reading-the-same-files/344013 "2023-09-27T20:45:17Z")

</div>

Hi, it is posible to use multiple inputs on the same files, but with different filters? The configuration below works but only if I run filebeat with: ./filebeat.exe -c filebeat.yml not when I run it as a service UPDA…

---

## [Field \[field\] not present as part of path \[field.query\]](https://discuss.elastic.co/t/field-field-not-present-as-part-of-path-field-query/344008)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 6:45pm UTC](https://discuss.elastic.co/t/field-field-not-present-as-part-of-path-field-query/344008 "2023-09-27T18:45:20Z")

</div>

I'm creating a pipeline with a gsub processor and I keep getting this error when testing the pipeline on a document. I had to add a unique delimiter before ingesting to deal with a whitespace issue. I'm now trying to rep…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=410)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=412)
