# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=423

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 424

---

## [MySQL Slow query log](https://discuss.elastic.co/t/mysql-slow-query-log/343003)

<div class="topic-metadata">

**Author:** [@ELK\_USR1](https://discuss.elastic.co/u/ELK_USR1)\
**Replies:** 1\
**Last updated:** [September 14, 2023, 8:02pm UTC](https://discuss.elastic.co/t/mysql-slow-query-log/343003 "2023-09-14T20:02:53Z")

</div>

Hi All, Version: Elasticserch:8.8.1 Filebeat:8.8.1 kibana:8.8.1 I am configuring the ELK stack for MySQL component. I referred the below URL for configuration. I have successfully implemented for error log and is…

---

## [Elasticsearch JNA unavailable / elastic no start](https://discuss.elastic.co/t/elasticsearch-jna-unavailable-elastic-no-start/343072)

<div class="topic-metadata">

**Author:** [@deepx](https://discuss.elastic.co/u/deepx)\
**Replies:** 3\
**Last updated:** [September 14, 2023, 8:02pm UTC](https://discuss.elastic.co/t/elasticsearch-jna-unavailable-elastic-no-start/343072 "2023-09-14T20:02:33Z")

</div>

Hello, I installed elasticsearch on ubuntu , but when i start elastic I always get an error. The log is showing me the following: JNA not available java.lang.UnsatisfiedLinkError: /tmp/elasticsearch-1125708853983863618…

---

## [Exiting: error importing Kibana dashboards: fail to import the dashboards in Kibana](https://discuss.elastic.co/t/exiting-error-importing-kibana-dashboards-fail-to-import-the-dashboards-in-kibana/342912)

<div class="topic-metadata">

**Author:** [@ELK\_USR1](https://discuss.elastic.co/u/ELK_USR1)\
**Replies:** 3\
**Last updated:** [September 14, 2023, 7:33pm UTC](https://discuss.elastic.co/t/exiting-error-importing-kibana-dashboards-fail-to-import-the-dashboards-in-kibana/342912 "2023-09-14T19:33:55Z")

</div>

While running ./kibana setup -e getting below error {"log.level":"error","@timestamp":"2023-09-13T12:47:44.064+0530","log.origin":{"file.name":"instance/beat.go","file.line":1274},"message":"Exiting: error importing Kib…

---

## [Understanding transform stats](https://discuss.elastic.co/t/understanding-transform-stats/343053)

<div class="topic-metadata">

**Author:** [@pulsy](https://discuss.elastic.co/u/pulsy)\
**Replies:** 4\
**Last updated:** [September 14, 2023, 6:22pm UTC](https://discuss.elastic.co/t/understanding-transform-stats/343053 "2023-09-14T18:22:59Z")

</div>

I am currently in the process of figuring out how to implement a transform on a quite large index. Especially the monitoring part of it is a bit puzzling for me. For example, the search\_time\_in\_ms on the transform curre…

---

## [Fail to update index data on Elasticsearch](https://discuss.elastic.co/t/fail-to-update-index-data-on-elasticsearch/342825)

<div class="topic-metadata">

**Author:** [@Antra](https://discuss.elastic.co/u/Antra)\
**Replies:** 3\
**Last updated:** [September 14, 2023, 5:56pm UTC](https://discuss.elastic.co/t/fail-to-update-index-data-on-elasticsearch/342825 "2023-09-14T17:56:05Z")

</div>

Hi team, I am facing an issue while using an Elasticsearch update query. I have given the detailed description of the issue below: Version of Elasticsearch: 7.17.0 Problem Description: My application has different te…

---

## [Joining and mapping](https://discuss.elastic.co/t/joining-and-mapping/343069)

<div class="topic-metadata">

**Author:** [@Hamed\_Ahmadi](https://discuss.elastic.co/u/Hamed_Ahmadi)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 5:25pm UTC](https://discuss.elastic.co/t/joining-and-mapping/343069 "2023-09-14T17:25:51Z")

</div>

Hi guys! I have a relational Database which I have synchronised with Elasticsearch over logstash. I have a work table, article table and comment table. One work has multiple comments and articles, basically work is pare…

---

## [\[search\_phase\_execution\_exception Caused by: es\_rejected\_execution\_exception: rejected execution](https://discuss.elastic.co/t/search-phase-execution-exception-caused-by-es-rejected-execution-exception-rejected-execution/342081)

<div class="topic-metadata">

**Author:** [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Replies:** 9\
**Last updated:** [September 14, 2023, 4:39pm UTC](https://discuss.elastic.co/t/search-phase-execution-exception-caused-by-es-rejected-execution-exception-rejected-execution/342081 "2023-09-14T16:39:55Z")

</div>

I am using grafana k6 stress tool to generate some load in elastic and sooner or later i always get this error es\_rejected\_execution\_exception. All are search operations to get 30 docs. On small indices of 20-30mb it …

---

## [How should I configure HAProxy logging to make it work with Filebeat?](https://discuss.elastic.co/t/how-should-i-configure-haproxy-logging-to-make-it-work-with-filebeat/342547)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 1\
**Last updated:** [September 14, 2023, 4:21pm UTC](https://discuss.elastic.co/t/how-should-i-configure-haproxy-logging-to-make-it-work-with-filebeat/342547 "2023-09-14T16:21:46Z")

</div>

The Filebeat docs do not give any instructions on what format to use. The Elastic Agent Integration docs mention support for the default, tcplog, httplog, httpslog, and errorlog formats. So far though, I only get "Provi…

---

## [Unable to install elastic search curator](https://discuss.elastic.co/t/unable-to-install-elastic-search-curator/342751)

<div class="topic-metadata">

**Author:** [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Replies:** 4\
**Last updated:** [September 14, 2023, 4:02pm UTC](https://discuss.elastic.co/t/unable-to-install-elastic-search-curator/342751 "2023-09-14T16:02:06Z")

</div>

Hi Team, Is there any RPM package available for curator v8.0? Recently, we upgraded from 7.17 to 8.9 version of ELK stack, and our curator version is not compatible with the ELK stack. Our env is an air-gap env and does…

---

## [Search\_phase\_execution\_exception Caused by: script\_exception: compile error, caused by: "compile error,cannot resolve symbol \[B\]"](https://discuss.elastic.co/t/search-phase-execution-exception-caused-by-script-exception-compile-error-caused-by-compile-error-cannot-resolve-symbol-b/342462)

<div class="topic-metadata">

**Author:** [@Gelinski](https://discuss.elastic.co/u/Gelinski)\
**Replies:** 1\
**Last updated:** [September 14, 2023, 3:31pm UTC](https://discuss.elastic.co/t/search-phase-execution-exception-caused-by-script-exception-compile-error-caused-by-compile-error-cannot-resolve-symbol-b/342462 "2023-09-14T15:31:05Z")

</div>

Hello folks, I am trying to create an Alert Rule of 'Metric threshold' type where I am using the 'custom equation' condition option to calculate a percentage. The details of the rule are bellow: Condition When custom…

---

## [I want to use Beats to generate files with event-type data to later analyze on my own](https://discuss.elastic.co/t/i-want-to-use-beats-to-generate-files-with-event-type-data-to-later-analyze-on-my-own/343062)

<div class="topic-metadata">

**Author:** [@Oscar\_Llerena](https://discuss.elastic.co/u/Oscar_Llerena)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 3:04pm UTC](https://discuss.elastic.co/t/i-want-to-use-beats-to-generate-files-with-event-type-data-to-later-analyze-on-my-own/343062 "2023-09-14T15:04:42Z")

</div>

Hello everyone, I am new to Elastic Search and I've been referred to this solution to solve the following problem. However, given the tons of documentation, I barely know where to start. Here is my problem: I want to …

---

## [Fuzzy\_terms\_exception when matching against keyword fields](https://discuss.elastic.co/t/fuzzy-terms-exception-when-matching-against-keyword-fields/343057)

<div class="topic-metadata">

**Author:** [@David\_Kolb](https://discuss.elastic.co/u/David_Kolb)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 2:19pm UTC](https://discuss.elastic.co/t/fuzzy-terms-exception-when-matching-against-keyword-fields/343057 "2023-09-14T14:19:52Z")

</div>

Hi, I'm getting a ElasticsearchException\[Elasticsearch exception \[type=fuzzy\_terms\_exception, reason=Term too complex when running a fuzzy (AUTO) multi match query with a query String that contains long terms against …

---

## [Transform and simplify long regex with dissect or grok?](https://discuss.elastic.co/t/transform-and-simplify-long-regex-with-dissect-or-grok/342973)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 4\
**Last updated:** [September 14, 2023, 2:09pm UTC](https://discuss.elastic.co/t/transform-and-simplify-long-regex-with-dissect-or-grok/342973 "2023-09-14T14:09:35Z")

</div>

Hello, I have some long and heavy regex and i wonder if i can simplify and gain in term of performances by using dissect here are some examples "^\<%{NONNEGINT:syslog\_priority:int}\>1 (?:-|%{TIMESTAMP\_ISO8601:syslog\_t…

---

## [I want only get Disk Usage of multiple path with metricbeat](https://discuss.elastic.co/t/i-want-only-get-disk-usage-of-multiple-path-with-metricbeat/343055)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 1:41pm UTC](https://discuss.elastic.co/t/i-want-only-get-disk-usage-of-multiple-path-with-metricbeat/343055 "2023-09-14T13:41:39Z")

</div>

Hey, I want only disk usage for some path. example : du -sh /home/applicationA/data du -sh /home/applicationB/data 9.1G /home/applicationA/data 2.5G /home/applicationB/data how do that ? i dont want /home t…

---

## [Issue - Update security certificates with a different CA](https://discuss.elastic.co/t/issue-update-security-certificates-with-a-different-ca/342908)

<div class="topic-metadata">

**Author:** [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Replies:** 3\
**Last updated:** [September 14, 2023, 12:56pm UTC](https://discuss.elastic.co/t/issue-update-security-certificates-with-a-different-ca/342908 "2023-09-14T12:56:01Z")

</div>

Hi all I followed the instructions at :-Update security certificates with a different CA | Elasticsearch Guide \[7.17\] | Elastic I first tried restarting one node and get the below error \[2023-09-13T18:49:49,292\]\[WARN …

---

## [How to properly find one string in another using vector search](https://discuss.elastic.co/t/how-to-properly-find-one-string-in-another-using-vector-search/343024)

<div class="topic-metadata">

**Author:** [@andriy.afanasev](https://discuss.elastic.co/u/andriy.afanasev)\
**Replies:** 1\
**Last updated:** [September 14, 2023, 12:14pm UTC](https://discuss.elastic.co/t/how-to-properly-find-one-string-in-another-using-vector-search/343024 "2023-09-14T12:14:08Z")

</div>

I need to search for the words in string (document) by their similarity to examples. For example I have string "I love the container with no. SADB21235236" and I have ref in elastic "SREB125136767". Then I need to find S…

---

## [A way to reduced needed storage space for Elastic Agent?](https://discuss.elastic.co/t/a-way-to-reduced-needed-storage-space-for-elastic-agent/343052)

<div class="topic-metadata">

**Author:** [@Amadeus](https://discuss.elastic.co/u/Amadeus)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 12:13pm UTC](https://discuss.elastic.co/t/a-way-to-reduced-needed-storage-space-for-elastic-agent/343052 "2023-09-14T12:13:51Z")

</div>

Hello everyone, I have two questions. When installing/enrolling a Fleet-managed Elastic Agent (as tar) I'm required to download the tar.gz, extract the files and execute the install/enroll command. By doing so the …

---

## [Transform "pipeline with id \[blah\] does not exist" & "user \[foo\] with effective roles \[\] (assigned roles \[bar\] were not found)"](https://discuss.elastic.co/t/transform-pipeline-with-id-blah-does-not-exist-user-foo-with-effective-roles-assigned-roles-bar-were-not-found/343046)

<div class="topic-metadata">

**Author:** [@Mark\_Duncan](https://discuss.elastic.co/u/Mark_Duncan)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 11:14am UTC](https://discuss.elastic.co/t/transform-pipeline-with-id-blah-does-not-exist-user-foo-with-effective-roles-assigned-roles-bar-were-not-found/343046 "2023-09-14T11:14:14Z")

</div>

We have updated to ELK 8.9.1, and have had a few transforms now stop with this error, "Transform "pipeline with id \[blah\] does not exist". The pipeline does indeed exist, and we can stop/start the transform again, after …

---

## [Disable fuzzy match ion matchquery on search and return only desired set of fields in response](https://discuss.elastic.co/t/disable-fuzzy-match-ion-matchquery-on-search-and-return-only-desired-set-of-fields-in-response/343030)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 4\
**Last updated:** [September 14, 2023, 11:04am UTC](https://discuss.elastic.co/t/disable-fuzzy-match-ion-matchquery-on-search-and-return-only-desired-set-of-fields-in-response/343030 "2023-09-14T11:04:42Z")

</div>

1- In elastic java rest client, How I can disable the fuzzy match? with below source builder, I need only properly matching records. if I give 456-ABC, it should not return anything. if I give just ABC or 123-ABC, it s…

---

## [\[es 5.6.8\] How to tanslate this postgre sql to es ver -- order by count(id) over (partition by org\_name, visit\_datetime) desc](https://discuss.elastic.co/t/es-5-6-8-how-to-tanslate-this-postgre-sql-to-es-ver-order-by-count-id-over-partition-by-org-name-visit-datetime-desc/343042)

<div class="topic-metadata">

**Author:** [@vvneedspeed](https://discuss.elastic.co/u/vvneedspeed)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 10:25am UTC](https://discuss.elastic.co/t/es-5-6-8-how-to-tanslate-this-postgre-sql-to-es-ver-order-by-count-id-over-partition-by-org-name-visit-datetime-desc/343042 "2023-09-14T10:25:57Z")

</div>

Hi there, I'm stuck. How to tanslate this postgre sql to Elasticsearch ver? The Elasticsearch is 5.6.8, but the solution with higher version is also welcome! select user\_name from tablea order by count(meid) over (p…

---

## [Could not initialize class org.elasticsearch.ElasticsearchException 	at org.elasticsearch.client.RestHighLevelClient.performClientRequest(RestHighLevelClient.java:2695) ~\[elasticsearch-rest-high-level-client-7.17.10.jar:7.17.10\]](https://discuss.elastic.co/t/could-not-initialize-class-org-elasticsearch-elasticsearchexception-at-org-elasticsearch-client-resthighlevelclient-performclientrequest-resthighlevelclient-java-2695-elasticsearch-rest-high-level-client-7-17-10-jar-7-17-10/343007)

<div class="topic-metadata">

**Author:** [@Vishal\_Yadav2](https://discuss.elastic.co/u/Vishal_Yadav2)\
**Replies:** 1\
**Last updated:** [September 14, 2023, 10:04am UTC](https://discuss.elastic.co/t/could-not-initialize-class-org-elasticsearch-elasticsearchexception-at-org-elasticsearch-client-resthighlevelclient-performclientrequest-resthighlevelclient-java-2695-elasticsearch-rest-high-level-client-7-17-10-jar-7-17-10/343007 "2023-09-14T10:04:20Z")

</div>

I have an Elasticsearch exception I have created a simple API where I am using the reactive mongo repository to find the data from the DB and I am trying to send this data to Elasticsearch which save operation one by one…

---

## [Filebeat: send data from a dynamic log + static file version.txt in one event](https://discuss.elastic.co/t/filebeat-send-data-from-a-dynamic-log-static-file-version-txt-in-one-event/343033)

<div class="topic-metadata">

**Author:** [@john123](https://discuss.elastic.co/u/john123)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 9:27am UTC](https://discuss.elastic.co/t/filebeat-send-data-from-a-dynamic-log-static-file-version-txt-in-one-event/343033 "2023-09-14T09:27:00Z")

</div>

Hi, we have a dynamic log 'app.log' and a static file version.txt with th version of the app. We have to send both as a single event with the purpose to have a trace of the errors in function of changing version of the …

---

## [Index size and doc\_count of a customer or field filter](https://discuss.elastic.co/t/index-size-and-doc-count-of-a-customer-or-field-filter/343025)

<div class="topic-metadata">

**Author:** [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 8:05am UTC](https://discuss.elastic.co/t/index-size-and-doc-count-of-a-customer-or-field-filter/343025 "2023-09-14T08:05:24Z")

</div>

Hi, i have one index where i store documents from different customerid differentiated but a customerid field. I want to know how many documents and storage size each customer is consuming in my index, I can see this for…

---

## [Elastic Logging Plugin SSL certificates issue](https://discuss.elastic.co/t/elastic-logging-plugin-ssl-certificates-issue/343021)

<div class="topic-metadata">

**Author:** [@Vladimir7172](https://discuss.elastic.co/u/Vladimir7172)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 7:23am UTC](https://discuss.elastic.co/t/elastic-logging-plugin-ssl-certificates-issue/343021 "2023-09-14T07:23:48Z")

</div>

Hello! I'm trying to transfer logs from a docker container to ELK using elastic-logging-plugin:8.9.2 On the Elastic side I see this type of error: "error.message":"javax.net.ssl.SSLHandshakeException: Received fatal a…

---

## [Installing Elasticsearch Error](https://discuss.elastic.co/t/installing-elasticsearch-error/342976)

<div class="topic-metadata">

**Author:** [@heureux](https://discuss.elastic.co/u/heureux)\
**Replies:** 2\
**Last updated:** [September 14, 2023, 6:56am UTC](https://discuss.elastic.co/t/installing-elasticsearch-error/342976 "2023-09-14T06:56:38Z")

</div>

Hi, By executing the command: ./bin/elasticsearch I have this error: \< \[ERROR\]\[o.e.b.Elasticsearch \] \[wazuh-server\] fatal exception while booting Elasticsearchjava.lang.RuntimeException: can not run elasticsearc…

---

## [How to show only 2 numbers in vertical axis](https://discuss.elastic.co/t/how-to-show-only-2-numbers-in-vertical-axis/342897)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 3\
**Last updated:** [September 14, 2023, 6:48am UTC](https://discuss.elastic.co/t/how-to-show-only-2-numbers-in-vertical-axis/342897 "2023-09-14T06:48:24Z")

</div>

Hi, I have only 2 servers and in the time series graph I want to show which server is online. Is there any way in Kibana to show only 2 numbers in X-axis ? I know Kibana dynamically set the ranges and display values but…

---

## [The Elasticsearch process is experiencing rapid memory growth in the older generation](https://discuss.elastic.co/t/the-elasticsearch-process-is-experiencing-rapid-memory-growth-in-the-older-generation/343013)

<div class="topic-metadata">

**Author:** [@liguifa](https://discuss.elastic.co/u/liguifa)\
**Replies:** 5\
**Last updated:** [September 14, 2023, 6:46am UTC](https://discuss.elastic.co/t/the-elasticsearch-process-is-experiencing-rapid-memory-growth-in-the-older-generation/343013 "2023-09-14T06:46:43Z")

</div>

As shown in the above figure, my Elasticsearch cluster has experienced rapid memory growth in its old age, and after a period of time, it will be reclaimed, which will also occupy a large amount of memory. How should …

---

## [Help me - The speed of filebeat collection cannot keep up with the speed of file writing](https://discuss.elastic.co/t/help-me-the-speed-of-filebeat-collection-cannot-keep-up-with-the-speed-of-file-writing/343017)

<div class="topic-metadata">

**Author:** [@evanzhang87](https://discuss.elastic.co/u/evanzhang87)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 6:35am UTC](https://discuss.elastic.co/t/help-me-the-speed-of-filebeat-collection-cannot-keep-up-with-the-speed-of-file-writing/343017 "2023-09-14T06:35:50Z")

</div>

My log writing rate is about 3M/s, single log input, my output is kafka, I checked the metrics, pipeline.events.active keeps 4118, {"monitoring": {"metrics": {"beat":{"cgroup":{"cpuacct":{"total":{"ns":1024565234}},"mem…

---

## [No Logs from logstash docker](https://discuss.elastic.co/t/no-logs-from-logstash-docker/342882)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 10\
**Last updated:** [September 14, 2023, 6:12am UTC](https://discuss.elastic.co/t/no-logs-from-logstash-docker/342882 "2023-09-14T06:12:18Z")

</div>

I call logstash from commandline /usr/share/logstash/bin/logstash --path.settings=/usr/share/logstash/config -f /usr/share/logstash/conf.d/ But no logs written bash-4.4$ ls -ld logs1 drwxrwxrwx 2 logstash logstash 6 S…

---

## [Filebeat unable to collect logs from 'nodeSelector' deployment](https://discuss.elastic.co/t/filebeat-unable-to-collect-logs-from-nodeselector-deployment/343011)

<div class="topic-metadata">

**Author:** [@Achu](https://discuss.elastic.co/u/Achu)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 5:58am UTC](https://discuss.elastic.co/t/filebeat-unable-to-collect-logs-from-nodeselector-deployment/343011 "2023-09-14T05:58:25Z")

</div>

I’m experiencing a peculiar issue with Filebeat. I can collect logs from all deployments except a couple of deployments that have a node selection. Filebeat Daemonset is running on this node, and I don’t see any errors f…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=422)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=424)
