# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=445

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 446

---

## [Connect Salesforce with Elastic](https://discuss.elastic.co/t/connect-salesforce-with-elastic/341255)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 1:51pm UTC](https://discuss.elastic.co/t/connect-salesforce-with-elastic/341255 "2023-08-22T13:51:02Z")

</div>

Hi everyone, im using elastic cloud and i need to integrate Salesforce. What i need to do is analize logs coming from salesforce like SetupAuditTrail. I have found different solution for my problem: Using the Integra…

---

## [High latency issue with inner\_hits](https://discuss.elastic.co/t/high-latency-issue-with-inner-hits/341375)

<div class="topic-metadata">

**Author:** [@Gilat\_Naveh](https://discuss.elastic.co/u/Gilat_Naveh)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 1:46pm UTC](https://discuss.elastic.co/t/high-latency-issue-with-inner-hits/341375 "2023-08-22T13:46:56Z")

</div>

I’m trying to install a new cluster on ECK (version 8.8.1) and I’m having latency issues (~300ms). We already have a similar cluster working in version 6.5.3 (EC2) and for the same query timing is good (~20ms) The quer…

---

## [Microsoft-sentinel-log-analytics-logstash-output-plugin functionality](https://discuss.elastic.co/t/microsoft-sentinel-log-analytics-logstash-output-plugin-functionality/341374)

<div class="topic-metadata">

**Author:** [@shadu88](https://discuss.elastic.co/u/shadu88)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 1:40pm UTC](https://discuss.elastic.co/t/microsoft-sentinel-log-analytics-logstash-output-plugin-functionality/341374 "2023-08-22T13:40:10Z")

</div>

Hello Dear ELKs i was using "microsoft-sentinel-log-analytics-logstash-output-plugin" to forward the logs to azure sentinel but we switched to AMA( azure native) recently but post this switch the amount of logs doubled/…

---

## [Search scroll](https://discuss.elastic.co/t/search-scroll/341283)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 4\
**Last updated:** [August 22, 2023, 1:25pm UTC](https://discuss.elastic.co/t/search-scroll/341283 "2023-08-22T13:25:36Z")

</div>

Can anyone point me to any documentation regarding search scroll for the new java api client? I'm talking about this from the HLRC - Search Scroll API | Java REST Client \[7.17\] | Elastic. Thanks.

---

## [Cant start kibana on docker any more](https://discuss.elastic.co/t/cant-start-kibana-on-docker-any-more/341108)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 1:20pm UTC](https://discuss.elastic.co/t/cant-start-kibana-on-docker-any-more/341108 "2023-08-22T13:20:16Z")

</div>

I am using this with docker image - and now , sundly I cant start the kibana any more . it showed this message - Kibana server is not ready yet. I runned the command - docker-compose logs , and shoed this message …

---

## [Elasticsearch docker cluster](https://discuss.elastic.co/t/elasticsearch-docker-cluster/341371)

<div class="topic-metadata">

**Author:** [@Swapnadeep\_Mondal](https://discuss.elastic.co/u/Swapnadeep_Mondal)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 1:18pm UTC](https://discuss.elastic.co/t/elasticsearch-docker-cluster/341371 "2023-08-22T13:18:33Z")

</div>

Hi, I am trying to create the Elasticsearch cluster in remote servers using the docker containers, one catch is that I am not using the docker-compose file. When I start the docker containers in different remote hosts …

---

## [Iam trying to get the Duplicate Industries within the Column Industries in ABC index!](https://discuss.elastic.co/t/iam-trying-to-get-the-duplicate-industries-within-the-column-industries-in-abc-index/341367)

<div class="topic-metadata">

**Author:** [@Manasa\_BR](https://discuss.elastic.co/u/Manasa_BR)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 12:32pm UTC](https://discuss.elastic.co/t/iam-trying-to-get-the-duplicate-industries-within-the-column-industries-in-abc-index/341367 "2023-08-22T12:32:15Z")

</div>

as mentioned iam trying to get the Duplicate Industries within the Column Industries in ABC index, and when i execute the below query iam getting other results GET /abc/\_search { "query": { "match": { "industries.…

---

## [Aggregations and sub-Aggregations in java API client](https://discuss.elastic.co/t/aggregations-and-sub-aggregations-in-java-api-client/341363)

<div class="topic-metadata">

**Author:** [@dt2244](https://discuss.elastic.co/u/dt2244)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 12:13pm UTC](https://discuss.elastic.co/t/aggregations-and-sub-aggregations-in-java-api-client/341363 "2023-08-22T12:13:22Z")

</div>

i am trying to rewrite my code from elasticsearch version 7.10.2 to latest version es 8.9 but i am having some problems: code version 7.10.2: FilterAggregationBuilder filteredAggs = AggregationBuilders …

---

## [Elaticsearch SQL CLI is not working](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/340615)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 10\
**Last updated:** [August 22, 2023, 11:41am UTC](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/340615 "2023-08-22T11:41:02Z")

</div>

Hi Team, I am trying to execute some sql commands from SQL CLI in elasticsearch -8.8.2 but while executing below commands to open SQL CLI ./bin/elasticsearch-sql-cli I am getting below error ERROR: Cannot communicat…

---

## [Geo-distance query to match geo\_point within a given distance of a geopoint](https://discuss.elastic.co/t/geo-distance-query-to-match-geo-point-within-a-given-distance-of-a-geopoint/341356)

<div class="topic-metadata">

**Author:** [@Allen\_Liang](https://discuss.elastic.co/u/Allen_Liang)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 11:27am UTC](https://discuss.elastic.co/t/geo-distance-query-to-match-geo-point-within-a-given-distance-of-a-geopoint/341356 "2023-08-22T11:27:27Z")

</div>

Hello, I'm seeking clarification regarding the distance utilised for filtering documents using the geo-distance query (Geo-distance query | Elasticsearch Guide \[8.9\] | Elastic). In each of my documents, there exists a …

---

## [Annotations in stacked vertical bar graph](https://discuss.elastic.co/t/annotations-in-stacked-vertical-bar-graph/341327)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 3\
**Last updated:** [August 22, 2023, 10:29am UTC](https://discuss.elastic.co/t/annotations-in-stacked-vertical-bar-graph/341327 "2023-08-22T10:29:25Z")

</div>

Hi I have created the following stacked bar graph I have used annotation to display extra data at a specific time on x axis. When i hover on the number in the pink circle at the top but i am not able to take co…

---

## [Line Chart](https://discuss.elastic.co/t/line-chart/341269)

<div class="topic-metadata">

**Author:** [@Lorenz\_Bucago](https://discuss.elastic.co/u/Lorenz_Bucago)\
**Replies:** 3\
**Last updated:** [August 22, 2023, 10:20am UTC](https://discuss.elastic.co/t/line-chart/341269 "2023-08-22T10:20:42Z")

</div>

This might be a stupid question but Im just new with Kibana. Im trying to add legend on top of each data points but I tried but its still not showing. n

---

## [Fleet Server Cluster](https://discuss.elastic.co/t/fleet-server-cluster/341326)

<div class="topic-metadata">

**Author:** [@Mohsin\_Ashraf](https://discuss.elastic.co/u/Mohsin_Ashraf)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 9:29am UTC](https://discuss.elastic.co/t/fleet-server-cluster/341326 "2023-08-22T09:29:54Z")

</div>

Hi, I want to set up a fleet server cluster for high availability purposes. but I got nothing related to this. please help me in this regard.

---

## [Elastic Integrations fail to install and lead to broken Dashboards when used with multiple Kibana Spaces](https://discuss.elastic.co/t/elastic-integrations-fail-to-install-and-lead-to-broken-dashboards-when-used-with-multiple-kibana-spaces/337246)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 6\
**Last updated:** [August 22, 2023, 9:26am UTC](https://discuss.elastic.co/t/elastic-integrations-fail-to-install-and-lead-to-broken-dashboards-when-used-with-multiple-kibana-spaces/337246 "2023-08-22T09:26:07Z")

</div>

Production Environment: Elastic-Stack 8.8.2 Debian 12 7 Elasticsearch Nodes 3 Kibana Nodes 2 Fleet Agents 5 Kibana spaces 70 Elastic-Agents Since about Elastic-Stack 8.8.0 we have issues installing or reinstalling Ela…

---

## [How to perform with condition divide math operation in elasticsearch](https://discuss.elastic.co/t/how-to-perform-with-condition-divide-math-operation-in-elasticsearch/341329)

<div class="topic-metadata">

**Author:** [@Huy\_Vu\_Quang](https://discuss.elastic.co/u/Huy_Vu_Quang)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 6:54am UTC](https://discuss.elastic.co/t/how-to-perform-with-condition-divide-math-operation-in-elasticsearch/341329 "2023-08-22T06:54:06Z")

</div>

I have a query like this how I perform a query in Elasticsearch with this condition if wager == 0 : payout/1 \>= multiplier else: payout/wager \>= multiplier filter multiplier according to this condition I wrote this …

---

## [How to Optimize time start Logstash with than 100 condition in output](https://discuss.elastic.co/t/how-to-optimize-time-start-logstash-with-than-100-condition-in-output/341335)

<div class="topic-metadata">

**Author:** [@quoctuan2311](https://discuss.elastic.co/u/quoctuan2311)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 7:37am UTC](https://discuss.elastic.co/t/how-to-optimize-time-start-logstash-with-than-100-condition-in-output/341335 "2023-08-22T07:37:58Z")

</div>

Hi, I have built an ES with architect such as picture. And deploy it on AWS EKS. My expected is filebeat will collect logs all pods on EKS. And send it to Logstash. And Logstash will send this to Elasticsearch. At…

---

## [Coerce seems not working](https://discuss.elastic.co/t/coerce-seems-not-working/341019)

<div class="topic-metadata">

**Author:** [@Jan\_Vavra](https://discuss.elastic.co/u/Jan_Vavra)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 7:33am UTC](https://discuss.elastic.co/t/coerce-seems-not-working/341019 "2023-08-22T07:33:54Z")

</div>

I am constructing datetime from directory structure, eg. 2023\\08\\17\\15\\08 represent files stored at 2023-08-17 15:08. I have this logstash.conf that parses each directory name into variables and hours and minutes are opt…

---

## [Index creating through logstash and show on kibana index pattern](https://discuss.elastic.co/t/index-creating-through-logstash-and-show-on-kibana-index-pattern/340972)

<div class="topic-metadata">

**Author:** [@bharti](https://discuss.elastic.co/u/bharti)\
**Replies:** 5\
**Last updated:** [August 22, 2023, 7:05am UTC](https://discuss.elastic.co/t/index-creating-through-logstash-and-show-on-kibana-index-pattern/340972 "2023-08-22T07:05:35Z")

</div>

Hello , I need a help on configuration of logstash output section....i want to create an index and fetch some particular logs on that index...whenever am creating a new index it is not showing on kibana output { if "…

---

## [Failed to retrieve password hash for reserved user \[elastic\]](https://discuss.elastic.co/t/failed-to-retrieve-password-hash-for-reserved-user-elastic/341330)

<div class="topic-metadata">

**Author:** [@nairobi](https://discuss.elastic.co/u/nairobi)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 7:03am UTC](https://discuss.elastic.co/t/failed-to-retrieve-password-hash-for-reserved-user-elastic/341330 "2023-08-22T07:03:20Z")

</div>

I upgraded elasticsearch cluster 7.17 to 8.9 version. I used "yum update elasticsearch" command to upgrade. It is upgraded successfully. But when i try to start elasticsearch, it couldn't start. How can i solve it? e…

---

## [UDP-input Receiving an encoding value �](https://discuss.elastic.co/t/udp-input-receiving-an-encoding-value/341199)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 7\
**Last updated:** [August 22, 2023, 6:36am UTC](https://discuss.elastic.co/t/udp-input-receiving-an-encoding-value/341199 "2023-08-22T06:36:03Z")

</div>

Hi I am using logstash udp input and in elasticsearch field event.original have true values. but in a document field.DeviceCapabilities value is "�" and for field.PoleCapabilities is empty. fieldname: event.original Va…

---

## [Elasticsearch cluster certs configuration](https://discuss.elastic.co/t/elasticsearch-cluster-certs-configuration/341320)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 5:18am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-certs-configuration/341320 "2023-08-22T05:18:10Z")

</div>

Hey there, I am trying to run ES cluster of let's say 3 nodes. I am using volume mount in docker to mount my self signed certificates. And here is the command I am using:- sudo docker run -it --privileged -p 9200:92…

---

## [AFTER changed DATA STREAM INDEX template, index stay 225b,](https://discuss.elastic.co/t/after-changed-data-stream-index-template-index-stay-225b/341293)

<div class="topic-metadata">

**Author:** [@cLaYYs](https://discuss.elastic.co/u/cLaYYs)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 4:54am UTC](https://discuss.elastic.co/t/after-changed-data-stream-index-template-index-stay-225b/341293 "2023-08-22T04:54:20Z")

</div>

Hi All, We use custom UDP integration(fleet managed integration) to collect Linux auth logs. We set the default pipeline for auth logs which is \[logs-system.auth-default\]. We did parse the data as we expected. This dat…

---

## [Geo fields at root?](https://discuss.elastic.co/t/geo-fields-at-root/341307)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 12:58am UTC](https://discuss.elastic.co/t/geo-fields-at-root/341307 "2023-08-22T00:58:17Z")

</div>

ECS geo docs say: The geo fields are expected to be nested at: client.geo destination.geo host.geo server.geo ... Note also that the geo fields are not expected to be used directly at the root of the events. I was …

---

## [A good place for "state of being a canary" field](https://discuss.elastic.co/t/a-good-place-for-state-of-being-a-canary-field/340690)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 5\
**Last updated:** [August 21, 2023, 11:21pm UTC](https://discuss.elastic.co/t/a-good-place-for-state-of-being-a-canary-field/340690 "2023-08-21T23:21:14Z")

</div>

Where do you think is a good place to indicate that a log message is from a canary? orchestration.\* doesn't seem appropriate. Maybe something in the upcoming node field set? (Where do I find information about that?) I…

---

## [How to specify ILM policies in Elastic agent policy config?](https://discuss.elastic.co/t/how-to-specify-ilm-policies-in-elastic-agent-policy-config/341296)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 5\
**Last updated:** [August 21, 2023, 10:48pm UTC](https://discuss.elastic.co/t/how-to-specify-ilm-policies-in-elastic-agent-policy-config/341296 "2023-08-21T22:48:50Z")

</div>

I have about 2000 Elastic agents (version 8.9.0) connected to a system with 3 Fleet servers (version 8.9.0). We have about 20 different agent policies, because the various Elastic agents are sending slightly different …

---

## [Update indices replica set in Elasticsearch cluster](https://discuss.elastic.co/t/update-indices-replica-set-in-elasticsearch-cluster/341149)

<div class="topic-metadata">

**Author:** [@ahmed.emad](https://discuss.elastic.co/u/ahmed.emad)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 10:32pm UTC](https://discuss.elastic.co/t/update-indices-replica-set-in-elasticsearch-cluster/341149 "2023-08-21T22:32:59Z")

</div>

Hello, I would like to update the number of replicas for newly creating indices to be 5 automatically, so i used the below curl curl -XPUT -k -u elastic:password 'https://192.168.x.x:9200/\_index\_template/my\_template' -…

---

## [Docker image "elastic-connectors:8.9.1.0" for ARM64 architecture?](https://discuss.elastic.co/t/docker-image-elastic-connectors-8-9-1-0-for-arm64-architecture/341302)

<div class="topic-metadata">

**Author:** [@lenny1](https://discuss.elastic.co/u/lenny1)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 9:16pm UTC](https://discuss.elastic.co/t/docker-image-elastic-connectors-8-9-1-0-for-arm64-architecture/341302 "2023-08-21T21:16:09Z")

</div>

Hello, I want to deploy the Enterprise Search MySQL connector docker image on an ARM64 architecture host. Is there a ARM64 docker image for: "enterprise-search/elastic-connectors:8.9.1.0" ? Best regards, Martin

---

## [Pinned Filters Passed Through Dashboard URL Are Not Applied](https://discuss.elastic.co/t/pinned-filters-passed-through-dashboard-url-are-not-applied/340162)

<div class="topic-metadata">

**Author:** [@kevfar](https://discuss.elastic.co/u/kevfar)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 8:41pm UTC](https://discuss.elastic.co/t/pinned-filters-passed-through-dashboard-url-are-not-applied/340162 "2023-08-21T20:41:20Z")

</div>

Hello! I recently posted a question regarding this issue, but unfortunately the topic was closed before I got around to responding to the first reply. I am working for a company that utilizes Kibana dashboards to view cl…

---

## [Replica count 3 for .security-7](https://discuss.elastic.co/t/replica-count-3-for-security-7/341274)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 7:27pm UTC](https://discuss.elastic.co/t/replica-count-3-for-security-7/341274 "2023-08-21T19:27:06Z")

</div>

I'm trying to set the replica count for .security-7 to 3 so that if 2 nodes go down it's still ok. But it seems superuser can't update it. What's the best path forward for this situation. The docs don't really answer …

---

## [Filebeat Intermittently Hanging with Increasing Memory Cache while Processing High-Traffic Nginx Accesslog](https://discuss.elastic.co/t/filebeat-intermittently-hanging-with-increasing-memory-cache-while-processing-high-traffic-nginx-accesslog/339335)

<div class="topic-metadata">

**Author:** [@ryoni88](https://discuss.elastic.co/u/ryoni88)\
**Replies:** 5\
**Last updated:** [August 21, 2023, 5:07pm UTC](https://discuss.elastic.co/t/filebeat-intermittently-hanging-with-increasing-memory-cache-while-processing-high-traffic-nginx-accesslog/339335 "2023-08-21T17:07:09Z")

</div>

Hello, I have set up a process using Filebeat to send a high traffic Nginx accesslog to Logstash. However, Filebeat intermittently hangs, with a consistent pattern of increasing memory cache. Both Filebeat and Nginx ar…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=444)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=446)
