# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=421

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 422

---

## [Is this library subject to US EAR (Encryption and Export administration regulations)?](https://discuss.elastic.co/t/is-this-library-subject-to-us-ear-encryption-and-export-administration-regulations/343211)

<div class="topic-metadata">

**Author:** [@ztest-dev](https://discuss.elastic.co/u/ztest-dev)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 11:00am UTC](https://discuss.elastic.co/t/is-this-library-subject-to-us-ear-encryption-and-export-administration-regulations/343211 "2023-09-18T11:00:02Z")

</div>

Hello everyone, First, thank you so much for developing this open-source software which is powerful and feature-rich but also simple and easy to use. I prepare to use it in my projects. However, I wonder whether this so…

---

## [Enhanced Table Computed Columns can handle null values](https://discuss.elastic.co/t/enhanced-table-computed-columns-can-handle-null-values/343131)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 10:41am UTC](https://discuss.elastic.co/t/enhanced-table-computed-columns-can-handle-null-values/343131 "2023-09-18T10:41:03Z")

</div>

Hello @fbaligand , I am using computed columns to show Hyperlink values. The issue I'm facing is that this columns not always contains the value and somethimes the data from backend itself is not available, hence comput…

---

## [Node validation exception \[1\] bootstrap checks failed](https://discuss.elastic.co/t/node-validation-exception-1-bootstrap-checks-failed/343239)

<div class="topic-metadata">

**Author:** [@dev008](https://discuss.elastic.co/u/dev008)\
**Replies:** 3\
**Last updated:** [September 18, 2023, 10:30am UTC](https://discuss.elastic.co/t/node-validation-exception-1-bootstrap-checks-failed/343239 "2023-09-18T10:30:01Z")

</div>

Hi Team, I am getting the below error while configuring Elastic clustering on master node. I have gone through documentation still the error persist . Can someone please guide me where am i going wrong. Here are the lo…

---

## [Problems with GeoPoint field after switching to Elasticsearch Java API Client](https://discuss.elastic.co/t/problems-with-geopoint-field-after-switching-to-elasticsearch-java-api-client/342739)

<div class="topic-metadata">

**Author:** [@MonikaS](https://discuss.elastic.co/u/MonikaS)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 10:15am UTC](https://discuss.elastic.co/t/problems-with-geopoint-field-after-switching-to-elasticsearch-java-api-client/342739 "2023-09-18T10:15:52Z")

</div>

Hi. I'm trying to switch from RestHighLevelClient to Elasticsearch Java API Client in my Java application, and now it causes some problems with indexing geo\_point fields. Specifically, I get. { "index":{ "\_id"…

---

## [Isolating and restoring the Data node](https://discuss.elastic.co/t/isolating-and-restoring-the-data-node/343244)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 9:50am UTC](https://discuss.elastic.co/t/isolating-and-restoring-the-data-node/343244 "2023-09-18T09:50:15Z")

</div>

What is the procedure for isolating and restoring the Data node for version 8.8.1?

---

## [Unable to create elk cluster due to Node validation error](https://discuss.elastic.co/t/unable-to-create-elk-cluster-due-to-node-validation-error/343117)

<div class="topic-metadata">

**Author:** [@Bhakti\_Bhabal](https://discuss.elastic.co/u/Bhakti_Bhabal)\
**Replies:** 4\
**Last updated:** [September 18, 2023, 9:45am UTC](https://discuss.elastic.co/t/unable-to-create-elk-cluster-due-to-node-validation-error/343117 "2023-09-18T09:45:46Z")

</div>

Hello All, I am setting up elastic cluster in my environment. I have setup a master node and i want the elastic to run on the IP address of master node in order to get the clustering working . When i add the below lines…

---

## [Grok not parsing](https://discuss.elastic.co/t/grok-not-parsing/343098)

<div class="topic-metadata">

**Author:** [@pshas](https://discuss.elastic.co/u/pshas)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 9:24am UTC](https://discuss.elastic.co/t/grok-not-parsing/343098 "2023-09-18T09:24:33Z")

</div>

logstash.conf # Sample Logstash configuration for creating a simple # Beats -\> Logstash -\> Elasticsearch pipeline. input { beats { port =\> 5044 type = "test" } } filter { if \[type\] == "log" { grok { …

---

## [Backup and restoration possibilities](https://discuss.elastic.co/t/backup-and-restoration-possibilities/343234)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 3\
**Last updated:** [September 18, 2023, 9:19am UTC](https://discuss.elastic.co/t/backup-and-restoration-possibilities/343234 "2023-09-18T09:19:30Z")

</div>

What are all the backup and restoration possibilities offered by the ELK stack version 8.8.1 pls.

---

## [Varnish Metrics with Metricbeat:](https://discuss.elastic.co/t/varnish-metrics-with-metricbeat/342921)

<div class="topic-metadata">

**Author:** [@Deepika\_Gupta](https://discuss.elastic.co/u/Deepika_Gupta)\
**Replies:** 5\
**Last updated:** [September 18, 2023, 9:02am UTC](https://discuss.elastic.co/t/varnish-metrics-with-metricbeat/342921 "2023-09-18T09:02:33Z")

</div>

Hello Team, Greetings! I want to use Metricbeat, part of the Elastic Stack, to collect and monitor Varnish metrics. Metricbeat's Varnish module allows to gather information about cache hits, cache misses, cache size, a…

---

## [Min\_score not working as expected](https://discuss.elastic.co/t/min-score-not-working-as-expected/342970)

<div class="topic-metadata">

**Author:** [@Ayush\_Mehta\_Engineer](https://discuss.elastic.co/u/Ayush_Mehta_Engineer)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 3:06pm UTC](https://discuss.elastic.co/t/min-score-not-working-as-expected/342970 "2023-09-13T15:06:37Z")

</div>

I am trying to fetch the results with a minimum score of 1 using min\_score using the following query but I am still getting responses with null score I know that my query is bit complex and there could be better ways to…

---

## [Why my filebeat settings can only read /var/log/messages. I need to read all files in /var/log and my customized log folder: /suselv/log](https://discuss.elastic.co/t/why-my-filebeat-settings-can-only-read-var-log-messages-i-need-to-read-all-files-in-var-log-and-my-customized-log-folder-suselv-log/343232)

<div class="topic-metadata">

**Author:** [@huanghaiqing1](https://discuss.elastic.co/u/huanghaiqing1)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 8:20am UTC](https://discuss.elastic.co/t/why-my-filebeat-settings-can-only-read-var-log-messages-i-need-to-read-all-files-in-var-log-and-my-customized-log-folder-suselv-log/343232 "2023-09-18T08:20:27Z")

</div>

filebeat.yml part about included logs --\> type: filestream Unique ID among all inputs, an ID is required. id: autoyast1-filestream Change to true to enable this input configuration. enabled: true Paths that should …

---

## [Monitoring filebeat, heartbeat, metricbeat, logstash, kibana stats in kibana dashboards](https://discuss.elastic.co/t/monitoring-filebeat-heartbeat-metricbeat-logstash-kibana-stats-in-kibana-dashboards/342937)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 4\
**Last updated:** [September 18, 2023, 8:12am UTC](https://discuss.elastic.co/t/monitoring-filebeat-heartbeat-metricbeat-logstash-kibana-stats-in-kibana-dashboards/342937 "2023-09-18T08:12:14Z")

</div>

Hello All, Currently all the beats and logstash sends data directly to Elasticsearch. I have multiple servers installed with heartbeat,metricbeat,logstash and filebeat and now I've requirement to monitor all these comp…

---

## [Group documents by similarity using Elser](https://discuss.elastic.co/t/group-documents-by-similarity-using-elser/342913)

<div class="topic-metadata">

**Author:** [@Anton\_Dambrouski](https://discuss.elastic.co/u/Anton_Dambrouski)\
**Replies:** 3\
**Last updated:** [September 18, 2023, 7:48am UTC](https://discuss.elastic.co/t/group-documents-by-similarity-using-elser/342913 "2023-09-18T07:48:46Z")

</div>

Hello, Is it possible to use ML tokens generated by ELSER (Elastic Learned Sparse EncodeR) to group documents? Let's imagine I have the following list of documents: \[ { "name" : "Apple", price: 1234, "nameTokens" : \<t…

---

## [Filebeat queue.disk keeps piling up even when Logstash persisted queue remains relatively empty](https://discuss.elastic.co/t/filebeat-queue-disk-keeps-piling-up-even-when-logstash-persisted-queue-remains-relatively-empty/343221)

<div class="topic-metadata">

**Author:** [@sergeyarl](https://discuss.elastic.co/u/sergeyarl)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 6:40am UTC](https://discuss.elastic.co/t/filebeat-queue-disk-keeps-piling-up-even-when-logstash-persisted-queue-remains-relatively-empty/343221 "2023-09-18T06:40:03Z")

</div>

Hi! So we are using the following chain: Filebeats, that run in a K8s cluster (1 Filebeat instance on each k8s worker node) -\> 2 Logstash nodes behind AWS ALB -\> Elastic search cluster Everything works pretty well. …

---

## [FsCrawler 2.10 Rest Service upload returns error for file more than 20 MB](https://discuss.elastic.co/t/fscrawler-2-10-rest-service-upload-returns-error-for-file-more-than-20-mb/342706)

<div class="topic-metadata">

**Author:** [@Nilesh\_Pegasus](https://discuss.elastic.co/u/Nilesh_Pegasus)\
**Replies:** 12\
**Last updated:** [September 18, 2023, 6:00am UTC](https://discuss.elastic.co/t/fscrawler-2-10-rest-service-upload-returns-error-for-file-more-than-20-mb/342706 "2023-09-18T06:00:00Z")

</div>

Hi, I am using FsCrawler 2.10 with elasticsearch 8.9, I am trying to upload a 20Mb .msg file using rest service of FsCrawler, but it gives error. Please note that I am able to upload smaller files without any issues. F…

---

## [Add nested and sibling aggregation in data.search() in plugin](https://discuss.elastic.co/t/add-nested-and-sibling-aggregation-in-data-search-in-plugin/340763)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 5:45am UTC](https://discuss.elastic.co/t/add-nested-and-sibling-aggregation-in-data-search-in-plugin/340763 "2023-09-18T05:45:24Z")

</div>

Hi, I am developing a custom plugin in Kibana using React, in Kibana 8.8.1. I am using search (low-level) of data plugin to query Elasticsearch. This is the request body: const request = { id: searchId, t…

---

## [Logstash stop working due to FFI not available: null](https://discuss.elastic.co/t/logstash-stop-working-due-to-ffi-not-available-null/343174)

<div class="topic-metadata">

**Author:** [@lalchand\_rajak](https://discuss.elastic.co/u/lalchand_rajak)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 5:37am UTC](https://discuss.elastic.co/t/logstash-stop-working-due-to-ffi-not-available-null/343174 "2023-09-18T05:37:38Z")

</div>

Logstash stopped working due to FFI not available: null . I have already provided the tmp path in Jvm.options # set the I/O temp directory #-Djava.io.tmpdir=$HOME -Djava.io.tmpdir=/home/apmuser/tmp drwxrwxr-x. 2 logsta…

---

## [Infer model Text embedding in Java](https://discuss.elastic.co/t/infer-model-text-embedding-in-java/343192)

<div class="topic-metadata">

**Author:** [@Khanh\_Dao\_Minh](https://discuss.elastic.co/u/Khanh_Dao_Minh)\
**Replies:** 1\
**Last updated:** [September 17, 2023, 12:37pm UTC](https://discuss.elastic.co/t/infer-model-text-embedding-in-java/343192 "2023-09-17T12:37:52Z")

</div>

Hi there, Is there any document or instruction on how to use the machine learning api in java? For example, how can I convert this query into java POST /\_ml/trained\_models/My\_model/\_infer { "docs": { "text\_field…

---

## [Get analytics with potential alerts if anomalies detected](https://discuss.elastic.co/t/get-analytics-with-potential-alerts-if-anomalies-detected/343177)

<div class="topic-metadata">

**Author:** [@O\_K](https://discuss.elastic.co/u/O_K)\
**Replies:** 5\
**Last updated:** [September 17, 2023, 11:20am UTC](https://discuss.elastic.co/t/get-analytics-with-potential-alerts-if-anomalies-detected/343177 "2023-09-17T11:20:31Z")

</div>

I'm researching options how to get some analytics, for instance, I want to look into ERRORs in log\_level column, and if its amount increases drastically, I want to receive an alert. There should be many such cases and it…

---

## [Winlogbeat unable to start due to error](https://discuss.elastic.co/t/winlogbeat-unable-to-start-due-to-error/343190)

<div class="topic-metadata">

**Author:** [@risshukla](https://discuss.elastic.co/u/risshukla)\
**Replies:** 0\
**Last updated:** [September 17, 2023, 9:23am UTC](https://discuss.elastic.co/t/winlogbeat-unable-to-start-due-to-error/343190 "2023-09-17T09:23:28Z")

</div>

We've been using Winlogbeat to forward Workstation logs to Logstash. However, we've encountered an issue after installing Winlogbeat (versions 8.9.2 and 8.10.0) on our Windows Server 2022. The issue is as follows: Exce…

---

## [Filebeat query EKS worker node /var/log](https://discuss.elastic.co/t/filebeat-query-eks-worker-node-var-log/342745)

<div class="topic-metadata">

**Author:** [@xUmaRix](https://discuss.elastic.co/u/xUmaRix)\
**Replies:** 2\
**Last updated:** [September 17, 2023, 3:38am UTC](https://discuss.elastic.co/t/filebeat-query-eks-worker-node-var-log/342745 "2023-09-17T03:38:12Z")

</div>

Hi, I'm trying to ship EKS worker node auth.log, syslog and audit.log files which located under /var/log. I've deploy filebeat and logstash in EKS cluster however I saw under filebeat pods there's a lot of error log s…

---

## [ElasticSearch on giant compute nodes](https://discuss.elastic.co/t/elasticsearch-on-giant-compute-nodes/343183)

<div class="topic-metadata">

**Author:** [@Don\_Boscow](https://discuss.elastic.co/u/Don_Boscow)\
**Replies:** 0\
**Last updated:** [September 16, 2023, 9:10pm UTC](https://discuss.elastic.co/t/elasticsearch-on-giant-compute-nodes/343183 "2023-09-16T21:10:30Z")

</div>

The standard paradigm which I see is usually recommended for ES (mainly for query purpose) is a collection or cluster of nodes - the nodes being typically SSD, the RAM usually recommended as 64 GB, with shard size not ex…

---

## [Elastic Search .Net client doesnt have Fuzziness?](https://discuss.elastic.co/t/elastic-search-net-client-doesnt-have-fuzziness/343176)

<div class="topic-metadata">

**Author:** [@senadk](https://discuss.elastic.co/u/senadk)\
**Replies:** 0\
**Last updated:** [September 16, 2023, 12:30pm UTC](https://discuss.elastic.co/t/elastic-search-net-client-doesnt-have-fuzziness/343176 "2023-09-16T12:30:24Z")

</div>

Hello, Im having trouble with adding Fuzziness to my Match query, see the below code: var client = new ElasticsearchClient(new Uri("http://elasticsearch:9200")); var response = await client.SearchAsync\<Ex…

---

## [ELK SSL config problem](https://discuss.elastic.co/t/elk-ssl-config-problem/342668)

<div class="topic-metadata">

**Author:** [@p81061473525](https://discuss.elastic.co/u/p81061473525)\
**Replies:** 3\
**Last updated:** [September 16, 2023, 11:26am UTC](https://discuss.elastic.co/t/elk-ssl-config-problem/342668 "2023-09-16T11:26:22Z")

</div>

Hello, recently I've been practicing setting up ELK 8.9. My target architecture looks like this: Filebeat -\> Logstash -\> ES \<- Kibana. I encountered difficulties when configuring encryption. Currently, my architecture …

---

## [How can I visualize aggregation results using Vega?](https://discuss.elastic.co/t/how-can-i-visualize-aggregation-results-using-vega/342907)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 1\
**Last updated:** [September 16, 2023, 6:50am UTC](https://discuss.elastic.co/t/how-can-i-visualize-aggregation-results-using-vega/342907 "2023-09-16T06:50:23Z")

</div>

I'm a newbie to Vega. Appreciate it if you can help me to build a visualizer on the aggregated results that I have as follows. For every release, I'd like to show the sum of duration per workflow (e.g., A, B, and C) bas…

---

## [Sum of duration field of max per group in Elasticsearch](https://discuss.elastic.co/t/sum-of-duration-field-of-max-per-group-in-elasticsearch/342285)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 22\
**Last updated:** [September 16, 2023, 6:31am UTC](https://discuss.elastic.co/t/sum-of-duration-field-of-max-per-group-in-elasticsearch/342285 "2023-09-16T06:31:01Z")

</div>

I would like to create a visualizer by summing up duration field after retrieving max id per group in Elasticsearch. For example: Data is: id workflow sid duration 1 A x1 1m 1 A x2 2m 2 A x1 2m 2 A x2 3m …

---

## [Need help in finding dependency map for nimbus jose jwt](https://discuss.elastic.co/t/need-help-in-finding-dependency-map-for-nimbus-jose-jwt/343169)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 1\
**Last updated:** [September 16, 2023, 5:07am UTC](https://discuss.elastic.co/t/need-help-in-finding-dependency-map-for-nimbus-jose-jwt/343169 "2023-09-16T05:07:04Z")

</div>

i have this vulnerability from elastic docker image net.minidev:json-smart 2.4.8 2.4.9 Java usr/share/elasticsearch/modules/x-pack-security/nimbus-jose-jwt-9.23.jar where can i find the nimbus config to update and what…

---

## [Fixing vulnerablities in logstash code](https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 1\
**Last updated:** [September 16, 2023, 5:05am UTC](https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168 "2023-09-16T05:05:34Z")

</div>

my company check for vulnerablities and i see bunch of vulnerablities in logstash. an example is below to fix this vulnerablity, should i upgrade guava or does jruby needs to be upgraded. if jruby needs to be upgraded …

---

## [Disk usage/shard allocation problems during snapshot creation](https://discuss.elastic.co/t/disk-usage-shard-allocation-problems-during-snapshot-creation/342768)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 4\
**Last updated:** [September 16, 2023, 4:51am UTC](https://discuss.elastic.co/t/disk-usage-shard-allocation-problems-during-snapshot-creation/342768 "2023-09-16T04:51:22Z")

</div>

version 7.17.12 last night my cluster stoped ingesting data. One node ran out of disk after snapshot started. That node normally has plenty of headroom: 57% available: 1.85TB total: 4.30TB logs show: \[2023-09-12T00…

---

## [Mapping date in milliseconds to basic\_date\_time](https://discuss.elastic.co/t/mapping-date-in-milliseconds-to-basic-date-time/343160)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 2\
**Last updated:** [September 15, 2023, 11:19pm UTC](https://discuss.elastic.co/t/mapping-date-in-milliseconds-to-basic-date-time/343160 "2023-09-15T23:19:06Z")

</div>

I followed the instructions here: I ran this command as instructed: PUT /\_index\_template/itential\_jobs\_template { "index\_patterns": \["itential-jobs-\*"\], "template": { "mappings": { "properties": { "start\_ti…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=420)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=422)
