# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=432

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 433

---

## [Stored fields and SearchResponse](https://discuss.elastic.co/t/stored-fields-and-searchresponse/342062)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 7\
**Last updated:** [September 5, 2023, 7:00pm UTC](https://discuss.elastic.co/t/stored-fields-and-searchresponse/342062 "2023-09-05T19:00:34Z")

</div>

Example: SearchResponse\<ObjectNode\> searchResponse = elasticsearchClient.search(searchRequest, ObjectNode.class); Hit\<ObjectNode\> hit = searchResponse.hits().hits().get(0); Map\<String, JsonData\> fields = hit.fields(); J…

---

## [Can't set a replication factor for some hidden indices](https://discuss.elastic.co/t/cant-set-a-replication-factor-for-some-hidden-indices/341839)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 4\
**Last updated:** [September 5, 2023, 6:26pm UTC](https://discuss.elastic.co/t/cant-set-a-replication-factor-for-some-hidden-indices/341839 "2023-09-05T18:26:52Z")

</div>

Hi, I can't seem to change a replication factor for some hidden indices: i.e. curl -X PUT "x.x.x.x:9200/.\*/\_settings" -H 'Content-Type: application/json' -d'{ "index" : { "number\_of\_replicas" : 2 } }' {"acknowledged":…

---

## [I don't understand why my bill is more than the cents per hour stated on the dashboard](https://discuss.elastic.co/t/i-dont-understand-why-my-bill-is-more-than-the-cents-per-hour-stated-on-the-dashboard/342079)

<div class="topic-metadata">

**Author:** [@tonyfam](https://discuss.elastic.co/u/tonyfam)\
**Replies:** 5\
**Last updated:** [September 5, 2023, 6:05pm UTC](https://discuss.elastic.co/t/i-dont-understand-why-my-bill-is-more-than-the-cents-per-hour-stated-on-the-dashboard/342079 "2023-09-05T18:05:29Z")

</div>

Hello, can someone please help me understand our bill? Budget crunch. On the dashboard, it says our one deployment is supposed to cost .0957 cents per hour. We have 2 x 45 GB. Enterprise search and Kibana is suppose…

---

## [Logstash SSL/TLS error](https://discuss.elastic.co/t/logstash-ssl-tls-error/342368)

<div class="topic-metadata">

**Author:** [@Kvoyce2023](https://discuss.elastic.co/u/Kvoyce2023)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 5:56pm UTC](https://discuss.elastic.co/t/logstash-ssl-tls-error/342368 "2023-09-05T17:56:55Z")

</div>

My ELK stack got 3 ES nodes and 2 logstash nodes. Kibana is installed on one of the Logstash nodes. I was able to generate CA and all certificates. Distributed the certificates to all nodes.Confirmed Elasticsearch nodes …

---

## [Fleet not showing latest version of Elastic Agent](https://discuss.elastic.co/t/fleet-not-showing-latest-version-of-elastic-agent/342367)

<div class="topic-metadata">

**Author:** [@JP\_1987](https://discuss.elastic.co/u/JP_1987)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 5:50pm UTC](https://discuss.elastic.co/t/fleet-not-showing-latest-version-of-elastic-agent/342367 "2023-09-05T17:50:50Z")

</div>

Have setup a fleet server with several agents. My fleet server is running agent 8.91, but version of Elastic agent is only allowing updates to version 8.8.2 Is this an automatic update when a new version is released th…

---

## [Doubts about any field of wildcard](https://discuss.elastic.co/t/doubts-about-any-field-of-wildcard/342365)

<div class="topic-metadata">

**Author:** [@caixukun](https://discuss.elastic.co/u/caixukun)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 5:21pm UTC](https://discuss.elastic.co/t/doubts-about-any-field-of-wildcard/342365 "2023-09-05T17:21:34Z")

</div>

hello everyone I currently have a problem. I want to search exactly for field a and match the search for field b. this is my code GET /\_search { "query": { "bool": { "must": \[ { "multi\_match": { "q…

---

## [Extract specific log set from others indexed togheter](https://discuss.elastic.co/t/extract-specific-log-set-from-others-indexed-togheter/341262)

<div class="topic-metadata">

**Author:** [@necromancer](https://discuss.elastic.co/u/necromancer)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 4:33pm UTC](https://discuss.elastic.co/t/extract-specific-log-set-from-others-indexed-togheter/341262 "2023-09-05T16:33:44Z")

</div>

I want to know ihow can I extract/separate my nginx logs from an index where they are saved along with systemd logs and others (cron, fail2ban, etc)? I have it indexed with the ident "nginx". My point with it is be abl…

---

## [Aggregation with max field value](https://discuss.elastic.co/t/aggregation-with-max-field-value/341723)

<div class="topic-metadata">

**Author:** [@Mauricio\_Castrillon](https://discuss.elastic.co/u/Mauricio_Castrillon)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 4:24pm UTC](https://discuss.elastic.co/t/aggregation-with-max-field-value/341723 "2023-09-05T16:24:57Z")

</div>

Hello, I'm trying to create a metric in Kibana for a dashboard with some information from servers. The main idea is to have the total amount of objects by location. The challenge is, in each location, I have a certain …

---

## [Sort results by inner hits (min/max)](https://discuss.elastic.co/t/sort-results-by-inner-hits-min-max/342359)

<div class="topic-metadata">

**Author:** [@LeoAdamek](https://discuss.elastic.co/u/LeoAdamek)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 4:11pm UTC](https://discuss.elastic.co/t/sort-results-by-inner-hits-min-max/342359 "2023-09-05T16:11:18Z")

</div>

I'm using a join field and an has\_child filter in my search to join products with their various configuration permutations. There's a single level join from a product to a configuration. When a user searches for somethi…

---

## [Filebeat threshold set](https://discuss.elastic.co/t/filebeat-threshold-set/342356)

<div class="topic-metadata">

**Author:** [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 4:02pm UTC](https://discuss.elastic.co/t/filebeat-threshold-set/342356 "2023-09-05T16:02:41Z")

</div>

Thanks in advance, Is there any possibility to implement the below requirement. We are using filebeat agent to forward data to logstash. To avoid log burst, is there a way to set a threshold limit on the amount of log…

---

## [Import trained model to ElastichSearch](https://discuss.elastic.co/t/import-trained-model-to-elastichsearch/342197)

<div class="topic-metadata">

**Author:** [@Khanh\_Dao\_Minh](https://discuss.elastic.co/u/Khanh_Dao_Minh)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 3:43pm UTC](https://discuss.elastic.co/t/import-trained-model-to-elastichsearch/342197 "2023-09-05T15:43:23Z")

</div>

hello everyone. I have a question about importing my model to Elasticsearch. When i imported the model for task text embedding and started deployment mode on Kibana web, i got an error message " Couldn't start trained …

---

## [Is rrf available in the free, self-hosted version of elastic search?](https://discuss.elastic.co/t/is-rrf-available-in-the-free-self-hosted-version-of-elastic-search/342354)

<div class="topic-metadata">

**Author:** [@panivan99pl](https://discuss.elastic.co/u/panivan99pl)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 3:39pm UTC](https://discuss.elastic.co/t/is-rrf-available-in-the-free-self-hosted-version-of-elastic-search/342354 "2023-09-05T15:39:40Z")

</div>

I am using Elasticsearch as self-hosted in docker container, 8.9.1. When I query with the parameter rrf Reciprocal rank fusion, I get this message elasticsearch.AuthorizationException: AuthorizationException(403, 'secur…

---

## [Query cache is getting cleared under heavy query load](https://discuss.elastic.co/t/query-cache-is-getting-cleared-under-heavy-query-load/341704)

<div class="topic-metadata">

**Author:** [@mahesh44](https://discuss.elastic.co/u/mahesh44)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 2:38pm UTC](https://discuss.elastic.co/t/query-cache-is-getting-cleared-under-heavy-query-load/341704 "2023-09-05T14:38:15Z")

</div>

We are seeing exact same issue mentioned in the below post after upgrading to ES 7.17.8. This issue still exists even in the ES 8.8.0. Can someone please help with the solution for this. ES 7.17 | Exponentially growing …

---

## [ELK monog module printing null value in event.original](https://discuss.elastic.co/t/elk-monog-module-printing-null-value-in-event-original/342349)

<div class="topic-metadata">

**Author:** [@Shubham\_Singh](https://discuss.elastic.co/u/Shubham_Singh)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 2:10pm UTC](https://discuss.elastic.co/t/elk-monog-module-printing-null-value-in-event-original/342349 "2023-09-05T14:10:55Z")

</div>

We are exporting the mongo logs using mongodb filebeat module but few values in event.original comes as blank value but when we switch to json i can see the field has a value in it. Can somebody help in identifying the i…

---

## [Filtered alias not working](https://discuss.elastic.co/t/filtered-alias-not-working/342139)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 2:01pm UTC](https://discuss.elastic.co/t/filtered-alias-not-working/342139 "2023-09-05T14:01:27Z")

</div>

Hi , I'm trying to create an alias filtered based on existing field but it seems not working Does anyone have any idea about this issue? POST /\_aliases { "actions" : \[ { "add" : { "index" : "myIndex", "alias" : …

---

## [How to filtering the data in api level while offloading in eastic search](https://discuss.elastic.co/t/how-to-filtering-the-data-in-api-level-while-offloading-in-eastic-search/342315)

<div class="topic-metadata">

**Author:** [@sahithi](https://discuss.elastic.co/u/sahithi)\
**Replies:** 6\
**Last updated:** [September 5, 2023, 2:00pm UTC](https://discuss.elastic.co/t/how-to-filtering-the-data-in-api-level-while-offloading-in-eastic-search/342315 "2023-09-05T14:00:39Z")

</div>

How to filtering the data in api level while offloading the data in eastic search ? Can any one help me here plz?

---

## [How to create a simple CPU usage graph?](https://discuss.elastic.co/t/how-to-create-a-simple-cpu-usage-graph/342036)

<div class="topic-metadata">

**Author:** [@gornication](https://discuss.elastic.co/u/gornication)\
**Replies:** 9\
**Last updated:** [September 5, 2023, 1:39pm UTC](https://discuss.elastic.co/t/how-to-create-a-simple-cpu-usage-graph/342036 "2023-09-05T13:39:40Z")

</div>

Hi! How to create a simple CPU usage graph? I have incoming records with CPU metrics. Using the cpu\_p field, I want to plot the load percentage versus time. Why do I need Break down by? (this is a required paramete…

---

## [Problems with Number of replicas and UNASSIGNED errors](https://discuss.elastic.co/t/problems-with-number-of-replicas-and-unassigned-errors/342138)

<div class="topic-metadata">

**Author:** [@Ednei\_Rodrigues](https://discuss.elastic.co/u/Ednei_Rodrigues)\
**Replies:** 9\
**Last updated:** [September 5, 2023, 1:32pm UTC](https://discuss.elastic.co/t/problems-with-number-of-replicas-and-unassigned-errors/342138 "2023-09-05T13:32:54Z")

</div>

Hello, how are you doing ? So, I have a standalone ELK Stack and I am suffering with the error messages "UNASSIGNED" replicas. I know, to not use replica, I need to set 'number\_of\_replicas': 0 to the index. As I am usin…

---

## [Elasticsearch Index is exist or not](https://discuss.elastic.co/t/elasticsearch-index-is-exist-or-not/342224)

<div class="topic-metadata">

**Author:** [@hld942614](https://discuss.elastic.co/u/hld942614)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 1:28pm UTC](https://discuss.elastic.co/t/elasticsearch-index-is-exist-or-not/342224 "2023-09-05T13:28:23Z")

</div>

How can I know if an index is exist or not? I am using co.elastic.clients 8.6.2 in Java below is my code String index = "test"+ date; try { ElasticsearchClient client = elasticsearchConfig.getClient(); SearchR…

---

## [Where the KNN index is stored?](https://discuss.elastic.co/t/where-the-knn-index-is-stored/342157)

<div class="topic-metadata">

**Author:** [@panivan99pl](https://discuss.elastic.co/u/panivan99pl)\
**Replies:** 3\
**Last updated:** [September 5, 2023, 1:18pm UTC](https://discuss.elastic.co/t/where-the-knn-index-is-stored/342157 "2023-09-05T13:18:04Z")

</div>

Where is the KNN index stored, in RAM or disk memory ? I came across that I used to use ChromaDB to store vectors, I had about 1 million vectors and it stores them all in RAM, it took about 24gb. That's too much, and I'…

---

## [How to create Alerts for cluster health (green/yellow/red) and Circuit Breaker errors?](https://discuss.elastic.co/t/how-to-create-alerts-for-cluster-health-green-yellow-red-and-circuit-breaker-errors/341842)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 1:12pm UTC](https://discuss.elastic.co/t/how-to-create-alerts-for-cluster-health-green-yellow-red-and-circuit-breaker-errors/341842 "2023-09-05T13:12:59Z")

</div>

In Kibana 8.9.0, I managed to successfully create an alert for Cluster Health, so that if cluster health transitions from green to yellow or red, I receive an alert. I did the following: Go to Stack Monitoring In th…

---

## [Offload apic analytics to elastic search, while offloading exclude one of the api](https://discuss.elastic.co/t/offload-apic-analytics-to-elastic-search-while-offloading-exclude-one-of-the-api/342339)

<div class="topic-metadata">

**Author:** [@sahithi](https://discuss.elastic.co/u/sahithi)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 12:38pm UTC](https://discuss.elastic.co/t/offload-apic-analytics-to-elastic-search-while-offloading-exclude-one-of-the-api/342339 "2023-09-05T12:38:53Z")

</div>

we implemented the Elasticsearch and kibana, and we are able to see analytics data and all for all APIs which are running . But now i want to exclude ( remove) one api analytics from the index . How can we achieve this t…

---

## [Calculating time interval manually in Vega](https://discuss.elastic.co/t/calculating-time-interval-manually-in-vega/341837)

<div class="topic-metadata">

**Author:** [@Tankut\_Koray](https://discuss.elastic.co/u/Tankut_Koray)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 10:57am UTC](https://discuss.elastic.co/t/calculating-time-interval-manually-in-vega/341837 "2023-09-05T10:57:18Z")

</div>

Hi, I have a Vega chart where I want to specify my own time intervals according to min-max time differences. auto\_interval is not given me what I want, so I want to calculate it manually and give to aggr query. Is it po…

---

## [Enabling null values on expanded document in Kibana Discover](https://discuss.elastic.co/t/enabling-null-values-on-expanded-document-in-kibana-discover/341052)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 10:54am UTC](https://discuss.elastic.co/t/enabling-null-values-on-expanded-document-in-kibana-discover/341052 "2023-09-05T10:54:40Z")

</div>

Hi. I am using version 8.5.3. I created a Data View under Stack Management. Displayed an index with multiple fields successfully If we filter results and click the diagonal button on document, expanded document comes …

---

## [Filebeat now working on Kubernetes 1.24](https://discuss.elastic.co/t/filebeat-now-working-on-kubernetes-1-24/342334)

<div class="topic-metadata">

**Author:** [@Marco\_Lagalla](https://discuss.elastic.co/u/Marco_Lagalla)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 10:34am UTC](https://discuss.elastic.co/t/filebeat-now-working-on-kubernetes-1-24/342334 "2023-09-05T10:34:13Z")

</div>

Hi, I have a cluster running Kubernetes version 1.24, hosted on AWS EKS. Into the cluster there are multiple workloads segregated by namespace. Filebeat is installed to run as a DaemonSet, and should be able to collec…

---

## [Query latency spike when a node joins the cluster](https://discuss.elastic.co/t/query-latency-spike-when-a-node-joins-the-cluster/342213)

<div class="topic-metadata">

**Author:** [@marinko](https://discuss.elastic.co/u/marinko)\
**Replies:** 6\
**Last updated:** [September 5, 2023, 10:30am UTC](https://discuss.elastic.co/t/query-latency-spike-when-a-node-joins-the-cluster/342213 "2023-09-05T10:30:11Z")

</div>

Hi, We have Elasticsearch 8.6.0 with ltr plugin running on AWS EC2. Each time a new instance (data node) joins the cluster, we see a short (\< 1 min) spike in latency. The maximum latency can rise to 4-5 seconds. This h…

---

## [Does synonym\_graph work on Percolator Query?](https://discuss.elastic.co/t/does-synonym-graph-work-on-percolator-query/342331)

<div class="topic-metadata">

**Author:** [@jspark9812](https://discuss.elastic.co/u/jspark9812)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 10:16am UTC](https://discuss.elastic.co/t/does-synonym-graph-work-on-percolator-query/342331 "2023-09-05T10:16:15Z")

</div>

Hello. There was a question from the percolator query, so I wrote it like this. The link below is a description of token-graphs. The description states that the positionLength of synonym\_graph is ignored in index time. …

---

## [logstash can no longer write to elasticsearch](https://discuss.elastic.co/t/logstash-can-no-longer-write-to-elasticsearch/342260)

<div class="topic-metadata">

**Author:** [@TaF](https://discuss.elastic.co/u/TaF)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 9:51am UTC](https://discuss.elastic.co/t/logstash-can-no-longer-write-to-elasticsearch/342260 "2023-09-05T09:51:40Z")

</div>

Hello, I'm new to this platform and I need your help for my ELK stack Indeed logstash has not been able to write to elasticsearch for a while below is my logstash/conf.d flow management configuration \< input { tcp …

---

## [How trigger page with asking for built-in rules and conncectors?](https://discuss.elastic.co/t/how-trigger-page-with-asking-for-built-in-rules-and-conncectors/342304)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 7:47am UTC](https://discuss.elastic.co/t/how-trigger-page-with-asking-for-built-in-rules-and-conncectors/342304 "2023-09-05T07:47:12Z")

</div>

Hi there, I am running 7.17.4 and would like to see the pop-up coming up in monitoring asking me if I want to install the the standard rules & connectors for Kibana alerting. No such page is showing up in the standard …

---

## [Aggregate filter plugin - aggregation exception](https://discuss.elastic.co/t/aggregate-filter-plugin-aggregation-exception/342314)

<div class="topic-metadata">

**Author:** [@Anca\_Linca](https://discuss.elastic.co/u/Anca_Linca)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 8:15am UTC](https://discuss.elastic.co/t/aggregate-filter-plugin-aggregation-exception/342314 "2023-09-05T08:15:44Z")

</div>

Hello, Logstash version: 7.17 Aggregate filter plugin: v2.10.0 I have the following input of logs: {"@timestamp": "2023-07-27T08:40:27.849Z", "message": "Activity Stream update entry for job", "host": "tower-host", "…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=431)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=433)
