# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=419

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 420

---

## [Semantic search on more than 10k documents](https://discuss.elastic.co/t/semantic-search-on-more-than-10k-documents/343362)

<div class="topic-metadata">

**Author:** [@Denis\_Stefan](https://discuss.elastic.co/u/Denis_Stefan)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 7:44am UTC](https://discuss.elastic.co/t/semantic-search-on-more-than-10k-documents/343362 "2023-09-20T07:44:47Z")

</div>

Hello. I am currently developing a semantic search solution and I have to work with more than 10k documents (more than the maximum number of candidates which is 10k for the kNN algorithm). I am trying to find a solution…

---

## [Sending output to different indices depending on conditions](https://discuss.elastic.co/t/sending-output-to-different-indices-depending-on-conditions/343423)

<div class="topic-metadata">

**Author:** [@DetlefG](https://discuss.elastic.co/u/DetlefG)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 7:31am UTC](https://discuss.elastic.co/t/sending-output-to-different-indices-depending-on-conditions/343423 "2023-09-20T07:31:17Z")

</div>

Hi, I try to write logs via filebeat to different indices depending on a field in the logs. But I'm not sure, how the rule setting when is working. Is it correct, that if the first when condition is fullfilled the seco…

---

## [Hardware compability for elasticsearch](https://discuss.elastic.co/t/hardware-compability-for-elasticsearch/343405)

<div class="topic-metadata">

**Author:** [@Cino](https://discuss.elastic.co/u/Cino)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 7:24am UTC](https://discuss.elastic.co/t/hardware-compability-for-elasticsearch/343405 "2023-09-20T07:24:07Z")

</div>

hello team, I have a basic question about hardware compability or dependency with search engine. My hardware consists of NVMe direct attached disks( for better performance). Could we use such alternate raid options like…

---

## [ELK Pricing help for onprem cluster](https://discuss.elastic.co/t/elk-pricing-help-for-onprem-cluster/343322)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 5:14am UTC](https://discuss.elastic.co/t/elk-pricing-help-for-onprem-cluster/343322 "2023-09-20T05:14:22Z")

</div>

Hi team, Can you please help us to understand pricing for ELK onprem 4 node cluster with 128 GB of ram for each node and 12 TB harddisk or each node Please share for platinum and enterprise pricing comparision

---

## [What is the max throughput of the stdout?](https://discuss.elastic.co/t/what-is-the-max-throughput-of-the-stdout/343416)

<div class="topic-metadata">

**Author:** [@Daniel9](https://discuss.elastic.co/u/Daniel9)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 5:00am UTC](https://discuss.elastic.co/t/what-is-the-max-throughput-of-the-stdout/343416 "2023-09-20T05:00:14Z")

</div>

Here is my out output configration below: output { stdout { codec =\> json\_lines } } Here is my verification result: |Logs/s(In)|Logs/s (out)|Bytes/log (out)|Queue increase size (m)| |1500|200|580|700m| |780|200|5…

---

## [ELK stack - Kibana fails time to time giving the same error ( Elasticsearch failed Search rejected due to missing shards \[)\[.kibana\_task\_manager\_7.17.7\_001\]\[0\]\])](https://discuss.elastic.co/t/elk-stack-kibana-fails-time-to-time-giving-the-same-error-elasticsearch-failed-search-rejected-due-to-missing-shards-kibana-task-manager-7-17-7-001-0/343414)

<div class="topic-metadata">

**Author:** [@Senith\_Dilitha](https://discuss.elastic.co/u/Senith_Dilitha)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 3:37am UTC](https://discuss.elastic.co/t/elk-stack-kibana-fails-time-to-time-giving-the-same-error-elasticsearch-failed-search-rejected-due-to-missing-shards-kibana-task-manager-7-17-7-001-0/343414 "2023-09-20T03:37:46Z")

</div>

I am using the ELK stack deployed in a docker swarm for logging. From time to time I get the below error and Kibana service fails. \[Elasticsearch failed Search rejected due to missing shards \[\[.kibana\_task\_manager\_7.17.…

---

## [Elastic Cloud: Defining roles to user in Okta using SAML](https://discuss.elastic.co/t/elastic-cloud-defining-roles-to-user-in-okta-using-saml/343153)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 1:59am UTC](https://discuss.elastic.co/t/elastic-cloud-defining-roles-to-user-in-okta-using-saml/343153 "2023-09-20T01:59:37Z")

</div>

Hello, Right now, I'm defining roles for user using the security api POST /\_security/role\_mapping/viewer\_mapping { "roles": \[ "custome\_role\_viewer"\], "enabled": true, "rules": { "field" : { "username" : \["us…

---

## [I got the exception when I added kerberos authentication to es](https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116)

<div class="topic-metadata">

**Author:** [@zytine](https://discuss.elastic.co/u/zytine)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 1:53am UTC](https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116 "2023-09-20T01:53:49Z")

</div>

Hello, My es was running fine, but when I added kerberos authentication and restarted，I got the following error \[2023-09-15T23:09:36,876\]\[WARN \]\[o.e.x.s.a.s.m.NativeRoleMappingStore\] \[bsa264\] Failed to clear cache for…

---

## [Error: Config validation of xpack.fleet.proxy - Docker - kibana.yml - v8.10.1](https://discuss.elastic.co/t/error-config-validation-of-xpack-fleet-proxy-docker-kibana-yml-v8-10-1/343408)

<div class="topic-metadata">

**Author:** [@Peeki](https://discuss.elastic.co/u/Peeki)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 11:58pm UTC](https://discuss.elastic.co/t/error-config-validation-of-xpack-fleet-proxy-docker-kibana-yml-v8-10-1/343408 "2023-09-19T23:58:19Z")

</div>

Hi, When i start my Kibana container i get the following error. Error: \[config validation of \[xpack.fleet\].proxy\] kibana.yml configs are xpack.fleet.proxy: - id: aproxy name: aproxy url: http://fleetserver…

---

## [Fleet-server and elastic-agent metricbeat x509 unknown CA on kubernetes](https://discuss.elastic.co/t/fleet-server-and-elastic-agent-metricbeat-x509-unknown-ca-on-kubernetes/343279)

<div class="topic-metadata">

**Author:** [@Eric-Domeier](https://discuss.elastic.co/u/Eric-Domeier)\
**Replies:** 1\
**Last updated:** [September 19, 2023, 9:30pm UTC](https://discuss.elastic.co/t/fleet-server-and-elastic-agent-metricbeat-x509-unknown-ca-on-kubernetes/343279 "2023-09-19T21:30:04Z")

</div>

Environment details Kubernetes cluster RKE2 v1.27.3 with DISA STIG's ECK Operator: 2.9.0 (Ironbank image) Elastic Agent Image: 8.9.0 (Ironbank image) Issue: After getting the pod(s) fleet server and agents to a runn…

---

## [Unable to authenticate user \[elastic\] for REST request \[/\]](https://discuss.elastic.co/t/unable-to-authenticate-user-elastic-for-rest-request/343393)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 1\
**Last updated:** [September 19, 2023, 8:14pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-elastic-for-rest-request/343393 "2023-09-19T20:14:00Z")

</div>

Hello, I'm trying to configure logs for my Elasticsearch cluster, by following this: and even though i set verification\_mode to none, i still getting 401 {"log.level":"error","@timestamp":"2023-09-19T19:13:02.623Z…

---

## [InferenceConfig doesn't support text\_expansion value when creating a pipeline from java](https://discuss.elastic.co/t/inferenceconfig-doesnt-support-text-expansion-value-when-creating-a-pipeline-from-java/342377)

<div class="topic-metadata">

**Author:** [@ajperez](https://discuss.elastic.co/u/ajperez)\
**Replies:** 6\
**Last updated:** [September 19, 2023, 9:04pm UTC](https://discuss.elastic.co/t/inferenceconfig-doesnt-support-text-expansion-value-when-creating-a-pipeline-from-java/342377 "2023-09-19T21:04:33Z")

</div>

When creating a PutPipelineRequest with the Java client version 8.9.1, InferenceConfig doesn’t support “text\_expansion” value, an error is thrown co.elastic.clients.json.JsonpMappingException: Error deserializing co.elas…

---

## [Cancel after time interval clarification](https://discuss.elastic.co/t/cancel-after-time-interval-clarification/343401)

<div class="topic-metadata">

**Author:** [@maxfriz](https://discuss.elastic.co/u/maxfriz)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 8:48pm UTC](https://discuss.elastic.co/t/cancel-after-time-interval-clarification/343401 "2023-09-19T20:48:29Z")

</div>

To ensure a clear understanding of our global search configuration for a given cluster, I would like to clarify the following as written: The search.cancel\_after\_time\_interval configures (at the data node level) the t…

---

## [What's the secret to fast recovery when adding a new node?](https://discuss.elastic.co/t/whats-the-secret-to-fast-recovery-when-adding-a-new-node/343397)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 8:08pm UTC](https://discuss.elastic.co/t/whats-the-secret-to-fast-recovery-when-adding-a-new-node/343397 "2023-09-19T20:08:45Z")

</div>

We are on on version 7.15. Still experiencing issues during recovery. The cluster will often (very likely) move shards from new node back to old nodes even though the new node(s) are still have way fewer shards (and lo…

---

## [Pfelk logstash data parsing](https://discuss.elastic.co/t/pfelk-logstash-data-parsing/343284)

<div class="topic-metadata">

**Author:** [@kozistan](https://discuss.elastic.co/u/kozistan)\
**Replies:** 8\
**Last updated:** [September 19, 2023, 7:54pm UTC](https://discuss.elastic.co/t/pfelk-logstash-data-parsing/343284 "2023-09-19T19:54:03Z")

</div>

Hello would appreciate help with logstash parsing data into elastisearch. Please check my log output. Using opnsense syslog to logstash's pfelk addon and can not figure out whe right mutate filter to get this done. Thank…

---

## [Failed to start the service winlogbeat](https://discuss.elastic.co/t/failed-to-start-the-service-winlogbeat/343289)

<div class="topic-metadata">

**Author:** [@Waseem.M](https://discuss.elastic.co/u/Waseem.M)\
**Replies:** 3\
**Last updated:** [September 19, 2023, 7:26pm UTC](https://discuss.elastic.co/t/failed-to-start-the-service-winlogbeat/343289 "2023-09-19T19:26:24Z")

</div>

Hi everyone, I'm facing the issue to start the winlogbeat server on my windows servers " windows couldn't start the winlogbeat on your local computer. Error 1067 Please assist if anyone faced this issues and solved. Th…

---

## [Logstash 7.x Log4j CVE remediation on Windows server](https://discuss.elastic.co/t/logstash-7-x-log4j-cve-remediation-on-windows-server/343374)

<div class="topic-metadata">

**Author:** [@newschapmj1](https://discuss.elastic.co/u/newschapmj1)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 2:22pm UTC](https://discuss.elastic.co/t/logstash-7-x-log4j-cve-remediation-on-windows-server/343374 "2023-09-19T14:22:04Z")

</div>

Logstash 7.x Log4j Windows script Contains Linux and MacOs Installations and Docker. Has anyone got the same script/steps for Windows server?

---

## [Pipeline date\_time parser failure beats me (sorry for the pun :)](https://discuss.elastic.co/t/pipeline-date-time-parser-failure-beats-me-sorry-for-the-pun/343380)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 4\
**Last updated:** [September 19, 2023, 5:30pm UTC](https://discuss.elastic.co/t/pipeline-date-time-parser-failure-beats-me-sorry-for-the-pun/343380 "2023-09-19T17:30:51Z")

</div>

I'm ingesting Redhat AMQ log with filebeat, only filebeat claims the ingest pipeline fails to parse date time of every event. But testing a sample event/document from fiebeat log, pipeline works fine, that beats me. Hint…

---

## [Calculate percentage based on status of max per group in Elasticsearch](https://discuss.elastic.co/t/calculate-percentage-based-on-status-of-max-per-group-in-elasticsearch/343171)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 5\
**Last updated:** [September 19, 2023, 4:27pm UTC](https://discuss.elastic.co/t/calculate-percentage-based-on-status-of-max-per-group-in-elasticsearch/343171 "2023-09-19T16:27:48Z")

</div>

Given the dataset below, I'd like to calculate percentage of status over unique count of workflow. id,workflow,status 1,A,FAILURE 2,A,ABORTED 3,A,SUCCESS 4,A,SUCCESS 1,B,FAILURE 2,B,SUCCESS 3,B,FAILURE 1,C,FAILURE 2,C,F…

---

## [Cardinality problem](https://discuss.elastic.co/t/cardinality-problem/343387)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 4:27pm UTC](https://discuss.elastic.co/t/cardinality-problem/343387 "2023-09-19T16:27:18Z")

</div>

Hi, I'm not sure if this can be done, but it's worth asking :slight\_smile: I would like to see a specific metric, but it'd need a lot of conditions and cardinality. Let's say I have an index where I have documents fro…

---

## [ECK sample config to run elastiic agent for synthetic monitoring](https://discuss.elastic.co/t/eck-sample-config-to-run-elastiic-agent-for-synthetic-monitoring/343386)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 4:06pm UTC](https://discuss.elastic.co/t/eck-sample-config-to-run-elastiic-agent-for-synthetic-monitoring/343386 "2023-09-19T16:06:26Z")

</div>

Looking to setup synthetic monitoring private location with elastic agent deployment using ECK operator. is there ECK operator recipe or sample config to run standalone elastic agent with elastic-agent-complete Docker im…

---

## [Enrolling agent on Graviton ARM processor](https://discuss.elastic.co/t/enrolling-agent-on-graviton-arm-processor/342351)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 4\
**Last updated:** [September 19, 2023, 3:26pm UTC](https://discuss.elastic.co/t/enrolling-agent-on-graviton-arm-processor/342351 "2023-09-19T15:26:59Z")

</div>

Hi, I was wondering if it is possible to run the agent on aarm64 architecture? We're potentially aiming to migrate all of our hosts from x86\_64 to aarm64. However when I try to run the agent install command on a host r…

---

## [Transaction\_sample\_rate post 8 release versions](https://discuss.elastic.co/t/transaction-sample-rate-post-8-release-versions/343290)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 4\
**Last updated:** [September 19, 2023, 3:10pm UTC](https://discuss.elastic.co/t/transaction-sample-rate-post-8-release-versions/343290 "2023-09-19T15:10:40Z")

</div>

We haev java agent 1.42 and Elasticsearch/APM servers are in 8.10 version. I haev tried with sampling rate of .2 and .5. Both values and 1 are getting response time/throughput for all samples. But document has change in…

---

## [FileBeat filestream ndjson breaking array with nested objects](https://discuss.elastic.co/t/filebeat-filestream-ndjson-breaking-array-with-nested-objects/343383)

<div class="topic-metadata">

**Author:** [@dusatvoj](https://discuss.elastic.co/u/dusatvoj)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 3:07pm UTC](https://discuss.elastic.co/t/filebeat-filestream-ndjson-breaking-array-with-nested-objects/343383 "2023-09-19T15:07:30Z")

</div>

Hello, I have ndjson which is scraped by filebeat, transferred via redis and logstash (which has no filter rule, except date) into elasticsearch. The ndjson structure is smth like: { "array\_of\_objects": \[ { "a…

---

## [What's the equivalent for NEST's MultiTermQueryRewrite class and/or RewriteMultiTerm enum in Elastic.Clients.Elasticsearch (8.x)](https://discuss.elastic.co/t/whats-the-equivalent-for-nests-multitermqueryrewrite-class-and-or-rewritemultiterm-enum-in-elastic-clients-elasticsearch-8-x/343379)

<div class="topic-metadata">

**Author:** [@yansklyarenko](https://discuss.elastic.co/u/yansklyarenko)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 2:45pm UTC](https://discuss.elastic.co/t/whats-the-equivalent-for-nests-multitermqueryrewrite-class-and-or-rewritemultiterm-enum-in-elastic-clients-elasticsearch-8-x/343379 "2023-09-19T14:45:41Z")

</div>

Basically, the title says it all. During migration from the NEST (7.x) client to Elastic.Clients.Elasticsearch (8.x) client I can't find the equivalent of MultiTermQueryRewrite class and/or RewriteMultiTerm enum. Could …

---

## [Add\_field processor on empty env provider fields stop ingest](https://discuss.elastic.co/t/add-field-processor-on-empty-env-provider-fields-stop-ingest/343371)

<div class="topic-metadata">

**Author:** [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 1:36pm UTC](https://discuss.elastic.co/t/add-field-processor-on-empty-env-provider-fields-stop-ingest/343371 "2023-09-19T13:36:06Z")

</div>

Hi, Our nodes have some attributes to define what asset they belong to (environment, application, component). With migrating to agent these fields got lost and we have utilized the environment provider and the add\_field…

---

## [How to map ambiguous data](https://discuss.elastic.co/t/how-to-map-ambiguous-data/343271)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 3\
**Last updated:** [September 19, 2023, 1:56pm UTC](https://discuss.elastic.co/t/how-to-map-ambiguous-data/343271 "2023-09-19T13:56:36Z")

</div>

There is a more practical way to map ambiguous data other than deleting and creating index, I need to make a query to the canvas but try to show a column with an error because the data cannot be ambiguous

---

## [Clarification regarding filebeat and metricbeat support policy](https://discuss.elastic.co/t/clarification-regarding-filebeat-and-metricbeat-support-policy/342940)

<div class="topic-metadata">

**Author:** [@ishaq](https://discuss.elastic.co/u/ishaq)\
**Replies:** 3\
**Last updated:** [September 19, 2023, 1:04pm UTC](https://discuss.elastic.co/t/clarification-regarding-filebeat-and-metricbeat-support-policy/342940 "2023-09-19T13:04:53Z")

</div>

Hey :wave: I've been going over the docs and this forum for an official version support policy for metricbeat and filebeat but I have not had any luck yet. I'd be grateful if someone could link me to it, if it exists. I…

---

## [Trying to find the plugin download url for Kibana](https://discuss.elastic.co/t/trying-to-find-the-plugin-download-url-for-kibana/342179)

<div class="topic-metadata">

**Author:** [@Max\_Karimi](https://discuss.elastic.co/u/Max_Karimi)\
**Replies:** 8\
**Last updated:** [September 19, 2023, 12:57pm UTC](https://discuss.elastic.co/t/trying-to-find-the-plugin-download-url-for-kibana/342179 "2023-09-19T12:57:00Z")

</div>

Hi, I am trying to download and install APM plugin for Kibana according to this document Install Kibana plugins | Elastic Cloud on Kubernetes \[2.9\] | Elastic but I cannot find any download link for that plugin. anyone c…

---

## [Substituting Match Phrase Prefix Query with a MUST combination of Match Phrase and Prefix](https://discuss.elastic.co/t/substituting-match-phrase-prefix-query-with-a-must-combination-of-match-phrase-and-prefix/343218)

<div class="topic-metadata">

**Author:** [@aliyanamu](https://discuss.elastic.co/u/aliyanamu)\
**Replies:** 1\
**Last updated:** [September 19, 2023, 12:24pm UTC](https://discuss.elastic.co/t/substituting-match-phrase-prefix-query-with-a-must-combination-of-match-phrase-and-prefix/343218 "2023-09-19T12:24:55Z")

</div>

Hi, I am using match phrase prefix for suggestion and querying search result. I'm using this for searching employee name, skill name, etc... basically name / title field which is not long. When I'm searching name like …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=418)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=420)
