# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=435

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 436

---

## [Elasticsearch remote cluster reindexing wildcard](https://discuss.elastic.co/t/elasticsearch-remote-cluster-reindexing-wildcard/342168)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 2\
**Last updated:** [September 3, 2023, 4:08pm UTC](https://discuss.elastic.co/t/elasticsearch-remote-cluster-reindexing-wildcard/342168 "2023-09-03T16:08:57Z")

</div>

Hi there, I am trying to use -e reindex.remote.whitelist="\*" in my docker run command to allow all domains in whitelist. But I am getting the following error when I try to run this:- Exception in thread "main" org.el…

---

## [What is the maximum dimensionality of a vector field?](https://discuss.elastic.co/t/what-is-the-maximum-dimensionality-of-a-vector-field/342159)

<div class="topic-metadata">

**Author:** [@panivan99pl](https://discuss.elastic.co/u/panivan99pl)\
**Replies:** 1\
**Last updated:** [September 3, 2023, 3:16pm UTC](https://discuss.elastic.co/t/what-is-the-maximum-dimensionality-of-a-vector-field/342159 "2023-09-03T15:16:40Z")

</div>

What is the maximum dimensionality of a vector field ? I am using elastik version 8.9.1 The documentation says that the maximum vector size is 1000, but if you set the index: False property, the dimensionality can be u…

---

## [Elastic snapshot to azure blob not deleting data](https://discuss.elastic.co/t/elastic-snapshot-to-azure-blob-not-deleting-data/341103)

<div class="topic-metadata">

**Author:** [@eh2021-elastic](https://discuss.elastic.co/u/eh2021-elastic)\
**Replies:** 8\
**Last updated:** [September 3, 2023, 2:53pm UTC](https://discuss.elastic.co/t/elastic-snapshot-to-azure-blob-not-deleting-data/341103 "2023-09-03T14:53:24Z")

</div>

I am running elastic 7.16.3 and snapshotting index's to azure blob storage for backup. The snapshot process is working, and after a couple of months we will go through and delete the snapshots. I have recently looked in …

---

## [Rust equivalent to simple requests.get for ES version 8?](https://discuss.elastic.co/t/rust-equivalent-to-simple-requests-get-for-es-version-8/342180)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 1\
**Last updated:** [September 3, 2023, 8:48am UTC](https://discuss.elastic.co/t/rust-equivalent-to-simple-requests-get-for-es-version-8/342180 "2023-09-03T08:48:27Z")

</div>

I found the leap to version 8 big enough in Python, not least because I know nothing about authentication, certificates, proxies, etc.. I'm now trying to get the simplest possible response from a local server running ver…

---

## [Help Needed: Setting Up Encrypted UDP Log Forwarding in Filebeat to Filebeat](https://discuss.elastic.co/t/help-needed-setting-up-encrypted-udp-log-forwarding-in-filebeat-to-filebeat/341952)

<div class="topic-metadata">

**Author:** [@randv](https://discuss.elastic.co/u/randv)\
**Replies:** 2\
**Last updated:** [September 3, 2023, 6:52am UTC](https://discuss.elastic.co/t/help-needed-setting-up-encrypted-udp-log-forwarding-in-filebeat-to-filebeat/341952 "2023-09-03T06:52:38Z")

</div>

Hello All, I am currently working on a project that involves securing log forwarding using encrypted UDP. I have a specific use case where I need to forward logs from one server to another over encrypted UDP, and I'm s…

---

## [Null\_pointer\_exception when trying to access any object type of field using ctx.\_source](https://discuss.elastic.co/t/null-pointer-exception-when-trying-to-access-any-object-type-of-field-using-ctx-source/342166)

<div class="topic-metadata">

**Author:** [@ankitpandoh](https://discuss.elastic.co/u/ankitpandoh)\
**Replies:** 3\
**Last updated:** [September 3, 2023, 3:59am UTC](https://discuss.elastic.co/t/null-pointer-exception-when-trying-to-access-any-object-type-of-field-using-ctx-source/342166 "2023-09-03T03:59:34Z")

</div>

I have a index mapping like below PUT /customer-index { "mappings":{ "properties":{ "customers.id": { "type": "long" }, "customers.name": { "type": "text", "norms": fals…

---

## [Checksum failed (hardware problem?)](https://discuss.elastic.co/t/checksum-failed-hardware-problem/341061)

<div class="topic-metadata">

**Author:** [@bigjohns97](https://discuss.elastic.co/u/bigjohns97)\
**Replies:** 6\
**Last updated:** [September 2, 2023, 2:07pm UTC](https://discuss.elastic.co/t/checksum-failed-hardware-problem/341061 "2023-09-02T14:07:09Z")

</div>

I am using a simple one node Elasticsearch instance on a Debian VM running on top of a Hyper-V Windows 11 system with an AMD 3950 CPU DDR4 RAM and SSD disk. Using elasticsearch as a index for a graylog instance and sendi…

---

## [Extract some words in a keyword field](https://discuss.elastic.co/t/extract-some-words-in-a-keyword-field/342135)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 4\
**Last updated:** [September 2, 2023, 3:36am UTC](https://discuss.elastic.co/t/extract-some-words-in-a-keyword-field/342135 "2023-09-02T03:36:42Z")

</div>

Hi, I have a field (keyword) with the following value (this value can be in different order and different values): {"sessRules":{"SetLTEQoS":{"authSessAmbr":{"uplink":"4200 Mbps","downlink":"4200 Mbps"},"authDefQos":{…

---

## [How to get the complete pdf report of a kibana dashboard instead of snapshot pdf?](https://discuss.elastic.co/t/how-to-get-the-complete-pdf-report-of-a-kibana-dashboard-instead-of-snapshot-pdf/341023)

<div class="topic-metadata">

**Author:** [@M\_S](https://discuss.elastic.co/u/M_S)\
**Replies:** 3\
**Last updated:** [September 1, 2023, 11:21pm UTC](https://discuss.elastic.co/t/how-to-get-the-complete-pdf-report-of-a-kibana-dashboard-instead-of-snapshot-pdf/341023 "2023-09-01T23:21:22Z")

</div>

I have a bunch of kibana dashboards which gives very relevant data. My ELK stack is having a valid platinum license and when I generate a pdf report using the share button in dashboard section it gives me a snapshot and …

---

## [Sort documents based on matched inner nested objects](https://discuss.elastic.co/t/sort-documents-based-on-matched-inner-nested-objects/342150)

<div class="topic-metadata">

**Author:** [@akarsh\_cholaveti](https://discuss.elastic.co/u/akarsh_cholaveti)\
**Replies:** 2\
**Last updated:** [September 1, 2023, 10:54pm UTC](https://discuss.elastic.co/t/sort-documents-based-on-matched-inner-nested-objects/342150 "2023-09-01T22:54:59Z")

</div>

Hello, I am working on a sort query for my documents in the index. Here are the documents look like: { "studentId": "123", "studentName": "Frodo", "year": "2023", "Scores": \[{ "subject": "Ph…

---

## [Why will writing to force merged indices make performance "much worse"?!](https://discuss.elastic.co/t/why-will-writing-to-force-merged-indices-make-performance-much-worse/342152)

<div class="topic-metadata">

**Author:** [@neo-anderson](https://discuss.elastic.co/u/neo-anderson)\
**Replies:** 0\
**Last updated:** [September 1, 2023, 9:18pm UTC](https://discuss.elastic.co/t/why-will-writing-to-force-merged-indices-make-performance-much-worse/342152 "2023-09-01T21:18:49Z")

</div>

I have been following the changes to the documentation regarding force merge warning. I understand that force merging to an index that's actively being written to is a bad idea. However, if I use force merge to bring dow…

---

## [Metricbeat x509 Certificate error](https://discuss.elastic.co/t/metricbeat-x509-certificate-error/342072)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 4\
**Last updated:** [September 1, 2023, 7:52pm UTC](https://discuss.elastic.co/t/metricbeat-x509-certificate-error/342072 "2023-09-01T19:52:33Z")

</div>

I've got an Elasticsearch instance running nicely, and I'd like to use metricbeat to monitor system performance (running on the same host). I'm getting an x509 certificate error when I start metricbeat using metricbeat …

---

## [Import saved object error on kibana](https://discuss.elastic.co/t/import-saved-object-error-on-kibana/342146)

<div class="topic-metadata">

**Author:** [@IJ\_Oma](https://discuss.elastic.co/u/IJ_Oma)\
**Replies:** 0\
**Last updated:** [September 1, 2023, 7:21pm UTC](https://discuss.elastic.co/t/import-saved-object-error-on-kibana/342146 "2023-09-01T19:21:21Z")

</div>

I tried importing a saved object on kibana several times and got this error message: The file could not be processed due to error: "" Both export and import were done on same kibana version 7.10.2 Please what do I do to…

---

## [Question regarding the development of an integration that has a dependency on other integrations](https://discuss.elastic.co/t/question-regarding-the-development-of-an-integration-that-has-a-dependency-on-other-integrations/342143)

<div class="topic-metadata">

**Author:** [@Sebastian\_Huettersen](https://discuss.elastic.co/u/Sebastian_Huettersen)\
**Replies:** 0\
**Last updated:** [September 1, 2023, 6:26pm UTC](https://discuss.elastic.co/t/question-regarding-the-development-of-an-integration-that-has-a-dependency-on-other-integrations/342143 "2023-09-01T18:26:24Z")

</div>

Hello all, I am currently developing an integration for an appliance where it is only possible to configure the entire logs to be sent out via a syslog configuration. However, many applications running on this appliance…

---

## [KIBANA FRONTEND VISUAL FEEDBACK](https://discuss.elastic.co/t/kibana-frontend-visual-feedback/342141)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [September 1, 2023, 5:45pm UTC](https://discuss.elastic.co/t/kibana-frontend-visual-feedback/342141 "2023-09-01T17:45:16Z")

</div>

Hello ElasticTeam, This is ingeneral feedback after working with two customers on elk stack usecases majorly with beats,kibana and logstash. In my opinion there is scope of lot of improvement to provide many visualizat…

---

## [How are double-quotes put into a bulk string (for POSTing)?](https://discuss.elastic.co/t/how-are-double-quotes-put-into-a-bulk-string-for-posting/342064)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 2\
**Last updated:** [September 1, 2023, 5:27pm UTC](https://discuss.elastic.co/t/how-are-double-quotes-put-into-a-bulk-string-for-posting/342064 "2023-09-01T17:27:29Z")

</div>

I'm trying to populate an index with bulk data. In fact this data is being generated by a Rust crate, docx-rs, and this escapes double-quotes by putting a backslash in front of them. So, where one field of my (Lucene) d…

---

## [Kibana-Authentication attempt failed: UNEXPECTED\_SESSION\_ERROR(using basic and anonymous auth)](https://discuss.elastic.co/t/kibana-authentication-attempt-failed-unexpected-session-error-using-basic-and-anonymous-auth/341895)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [September 1, 2023, 5:14pm UTC](https://discuss.elastic.co/t/kibana-authentication-attempt-failed-unexpected-session-error-using-basic-and-anonymous-auth/341895 "2023-09-01T17:14:08Z")

</div>

Hello All, I've a requirement where in while user will login to kibana then it should always ask username and password to login and I have custom webui which has integrated dashboards from kibana using iframe and here i…

---

## [Agg query that retturns bucket ranges so that buckets have the same number of documents?](https://discuss.elastic.co/t/agg-query-that-retturns-bucket-ranges-so-that-buckets-have-the-same-number-of-documents/342005)

<div class="topic-metadata">

**Author:** [@ankh](https://discuss.elastic.co/u/ankh)\
**Replies:** 3\
**Last updated:** [September 1, 2023, 4:00pm UTC](https://discuss.elastic.co/t/agg-query-that-retturns-bucket-ranges-so-that-buckets-have-the-same-number-of-documents/342005 "2023-09-01T16:00:00Z")

</div>

In order to process a large number of documents from an index I have a number of instances of an app running in parallel, each processing a subset of the documents. Each subset is defined by a particular date range. The …

---

## [Filebeat not collecting logs for hints based autodiscover in kubernetes](https://discuss.elastic.co/t/filebeat-not-collecting-logs-for-hints-based-autodiscover-in-kubernetes/342134)

<div class="topic-metadata">

**Author:** [@sayantanvlabs](https://discuss.elastic.co/u/sayantanvlabs)\
**Replies:** 0\
**Last updated:** [September 1, 2023, 3:50pm UTC](https://discuss.elastic.co/t/filebeat-not-collecting-logs-for-hints-based-autodiscover-in-kubernetes/342134 "2023-09-01T15:50:28Z")

</div>

I am trying to get logs from pods annotated with co.elastic.logs/enabled: "true" into elasticsearch using filebeat. But it is not working. I am attaching the configurations I am using, please let me know if I am missing …

---

## [Use operator with gsub](https://discuss.elastic.co/t/use-operator-with-gsub/342111)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 7\
**Last updated:** [September 1, 2023, 3:17pm UTC](https://discuss.elastic.co/t/use-operator-with-gsub/342111 "2023-09-01T15:17:56Z")

</div>

Hello, I need to change a logstash pipeline which use gsub but i've doubt of the syntax Instead of this mutate {gsub =\> \[ "status", "(?i)added", "plugged" \]} mutate {gsub =\> \[ "status", "(?i)installed", "plugged" …

---

## [How to define GeoIP in elastic agent v8.9?](https://discuss.elastic.co/t/how-to-define-geoip-in-elastic-agent-v8-9/342127)

<div class="topic-metadata">

**Author:** [@noor.muradi](https://discuss.elastic.co/u/noor.muradi)\
**Replies:** 0\
**Last updated:** [September 1, 2023, 12:44pm UTC](https://discuss.elastic.co/t/how-to-define-geoip-in-elastic-agent-v8-9/342127 "2023-09-01T12:44:52Z")

</div>

Hello all, How to define GeoIP in elastic agent policy, I have installed elastic agent v8.9 on a standalone ubuntu server, (my ELK stack version is 8.9) I have Nginx server running on that machine I want to monitor logs…

---

## [How to import iLO logs (Active health log, event log & Integrated Management log) to Elastic?](https://discuss.elastic.co/t/how-to-import-ilo-logs-active-health-log-event-log-integrated-management-log-to-elastic/342121)

<div class="topic-metadata">

**Author:** [@the4amfriend](https://discuss.elastic.co/u/the4amfriend)\
**Replies:** 0\
**Last updated:** [September 1, 2023, 11:42am UTC](https://discuss.elastic.co/t/how-to-import-ilo-logs-active-health-log-event-log-integrated-management-log-to-elastic/342121 "2023-09-01T11:42:17Z")

</div>

Say I have an Elastic stack setup, is there a better way to export the logs other than using SNMP or syslog? For using SNMP, I couldn't get the MIBs and for syslog, the formats are usually crazy so worried I may not be …

---

## [NodeJS Version](https://discuss.elastic.co/t/nodejs-version/342048)

<div class="topic-metadata">

**Author:** [@kfarr](https://discuss.elastic.co/u/kfarr)\
**Replies:** 1\
**Last updated:** [September 1, 2023, 10:03am UTC](https://discuss.elastic.co/t/nodejs-version/342048 "2023-09-01T10:03:57Z")

</div>

Would like NodeJS to be updated in Kibana v7.17 to 16.20.2 or later due to its vulnerability

---

## [Elastic.Apm.NetCoreAll with Serilog](https://discuss.elastic.co/t/elastic-apm-netcoreall-with-serilog/341991)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 2\
**Last updated:** [September 1, 2023, 10:01am UTC](https://discuss.elastic.co/t/elastic-apm-netcoreall-with-serilog/341991 "2023-09-01T10:01:06Z")

</div>

Good afternoon, I have services in .net6 and in this moment I'm using the next nugets: Elastic.Apm.NetCoreAll (1.20.0) Elastic.Apm.SerilogEnricher(1.5.3) I would like upgrade the packages but when I use the version 1…

---

## [Logstash fails to start listener due to Error: failed to create a child event loop in io.netty.util.concurrent.MultithreadEventExecutorGroup.\<init\>(io/netty/util/concurrent/MultithreadEventExecutorGroup.java:88)](https://discuss.elastic.co/t/logstash-fails-to-start-listener-due-to-error-failed-to-create-a-child-event-loop-in-io-netty-util-concurrent-multithreadeventexecutorgroup-init-io-netty-util-concurrent-multithreadeventexecutorgroup-java-88/341295)

<div class="topic-metadata">

**Author:** [@tlukac](https://discuss.elastic.co/u/tlukac)\
**Replies:** 7\
**Last updated:** [September 1, 2023, 9:54am UTC](https://discuss.elastic.co/t/logstash-fails-to-start-listener-due-to-error-failed-to-create-a-child-event-loop-in-io-netty-util-concurrent-multithreadeventexecutorgroup-init-io-netty-util-concurrent-multithreadeventexecutorgroup-java-88/341295 "2023-09-01T09:54:32Z")

</div>

Logstash continually raises this error when attempting to start LogStash::Inputs::Beats plugin. There is no "Caused by" info in the stack trace so cannot determine what is causing the issue. Any ideas on how to diagnos…

---

## [Logstash Stdout empty](https://discuss.elastic.co/t/logstash-stdout-empty/342073)

<div class="topic-metadata">

**Author:** [@Bountardos](https://discuss.elastic.co/u/Bountardos)\
**Replies:** 3\
**Last updated:** [September 1, 2023, 9:33am UTC](https://discuss.elastic.co/t/logstash-stdout-empty/342073 "2023-09-01T09:33:35Z")

</div>

Hi there, i'm having issues with a recent configuration on my logstash and i can't understand why it's not working. I have multiple configuration files running, and working. This one was working also as of a week ago, b…

---

## [Exiting: error connecting to Kibana: fail to get the Kibana version](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version/341353)

<div class="topic-metadata">

**Author:** [@BenKenobi](https://discuss.elastic.co/u/BenKenobi)\
**Replies:** 11\
**Last updated:** [September 1, 2023, 9:14am UTC](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version/341353 "2023-09-01T09:14:30Z")

</div>

Hi, I am new to ElasticStack and trying to load dashboards into Kibana. Kibana and Elastic Search run on same cluster and I want to monitor a remote server with metricbeat. When I enter the command metricbeat setup --…

---

## [Index is not creating in logstash through mule](https://discuss.elastic.co/t/index-is-not-creating-in-logstash-through-mule/342100)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 0\
**Last updated:** [September 1, 2023, 7:53am UTC](https://discuss.elastic.co/t/index-is-not-creating-in-logstash-through-mule/342100 "2023-09-01T07:53:06Z")

</div>

Hi I am not able to push the logs from my mule application to logstash which is running in ecs in aws and it is up . input { tcp { port =\> 4560 codec =\> json } } filter { date { match =\> \[ "timeMillis", "UNIX\_MS…

---

## [No uptime monitors found after upgrading to 8.8.2](https://discuss.elastic.co/t/no-uptime-monitors-found-after-upgrading-to-8-8-2/341998)

<div class="topic-metadata">

**Author:** [@tecbox41](https://discuss.elastic.co/u/tecbox41)\
**Replies:** 3\
**Last updated:** [September 1, 2023, 6:54am UTC](https://discuss.elastic.co/t/no-uptime-monitors-found-after-upgrading-to-8-8-2/341998 "2023-09-01T06:54:24Z")

</div>

Recently upgraded from Elasticsearch 7.16.2 to 8.8.2 and Uptime now shows "No uptime monitors found" for Monitors. I ran the setup for heartbeat once I upgraded it to 8.8.2 and the index template & data stream got create…

---

## [Filebeat pod continuously restarting : Liveness probe failed: rss\_mem 341245952](https://discuss.elastic.co/t/filebeat-pod-continuously-restarting-liveness-probe-failed-rss-mem-341245952/341980)

<div class="topic-metadata">

**Author:** [@Sam\_John](https://discuss.elastic.co/u/Sam_John)\
**Replies:** 2\
**Last updated:** [September 1, 2023, 6:28am UTC](https://discuss.elastic.co/t/filebeat-pod-continuously-restarting-liveness-probe-failed-rss-mem-341245952/341980 "2023-09-01T06:28:25Z")

</div>

filebeat pod in a k8s worker node is continuously restarting with following error message when the pods in the worker node increases: Error Message from filebeat pod: Warning Unhealthy 44m kubelet, k8s-worker-2 Livenes…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=434)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=436)
