# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=446

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 447

---

## [Filebeat Intermittently Hanging with Increasing Memory Cache while Processing High-Traffic Nginx Accesslog](https://discuss.elastic.co/t/filebeat-intermittently-hanging-with-increasing-memory-cache-while-processing-high-traffic-nginx-accesslog/339335)

<div class="topic-metadata">

**Author:** [@ryoni88](https://discuss.elastic.co/u/ryoni88)\
**Replies:** 5\
**Last updated:** [August 21, 2023, 5:07pm UTC](https://discuss.elastic.co/t/filebeat-intermittently-hanging-with-increasing-memory-cache-while-processing-high-traffic-nginx-accesslog/339335 "2023-08-21T17:07:09Z")

</div>

Hello, I have set up a process using Filebeat to send a high traffic Nginx accesslog to Logstash. However, Filebeat intermittently hangs, with a consistent pattern of increasing memory cache. Both Filebeat and Nginx ar…

---

## [Difference between Elasticsearch Security and Watcher Setting in Elasticsearch](https://discuss.elastic.co/t/difference-between-elasticsearch-security-and-watcher-setting-in-elasticsearch/341173)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 20\
**Last updated:** [August 21, 2023, 4:59pm UTC](https://discuss.elastic.co/t/difference-between-elasticsearch-security-and-watcher-setting-in-elasticsearch/341173 "2023-08-21T16:59:38Z")

</div>

Hi there, I am looking to set security on http and transport layer. But I am confused in what to use between the following: xpack.security.transport.ssl.verification\_mode=certificate xpack.transport.ssl.verification\_…

---

## [Null value in field type with nested](https://discuss.elastic.co/t/null-value-in-field-type-with-nested/341278)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 4:18pm UTC](https://discuss.elastic.co/t/null-value-in-field-type-with-nested/341278 "2023-08-21T16:18:24Z")

</div>

I have a filed , that if has value , it has ID and TITLE . so , wold be like this - category: { id: 2, title: 'monitor' } but can be like this as well category: NULL So I did like this the mapping - "category":…

---

## [Cannot change log format with pipeline config file, pipeline config file is not getting read](https://discuss.elastic.co/t/cannot-change-log-format-with-pipeline-config-file-pipeline-config-file-is-not-getting-read/340081)

<div class="topic-metadata">

**Author:** [@Jenkins-Jobs](https://discuss.elastic.co/u/Jenkins-Jobs)\
**Replies:** 7\
**Last updated:** [August 21, 2023, 4:04pm UTC](https://discuss.elastic.co/t/cannot-change-log-format-with-pipeline-config-file-pipeline-config-file-is-not-getting-read/340081 "2023-08-21T16:04:30Z")

</div>

Greetings, First time posting here, elasticsearch 8.9 rhel 7 I am getting logs from jenkins jobs using logstash plugin with no issues the only mime type that seems to work is "application/json" If i try any other t…

---

## [Watcher API - ACK with Action Conditions](https://discuss.elastic.co/t/watcher-api-ack-with-action-conditions/341277)

<div class="topic-metadata">

**Author:** [@Charles614](https://discuss.elastic.co/u/Charles614)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 3:59pm UTC](https://discuss.elastic.co/t/watcher-api-ack-with-action-conditions/341277 "2023-08-21T15:59:54Z")

</div>

Hello all, I have been building a Watcher that has a transform and then any number of actions dependent upon user input. I want to make it to where a user can ACK a specific action in order to allow throttling. The way…

---

## [Can I use hints based autodiscovery with Docker Swarm secrets?](https://discuss.elastic.co/t/can-i-use-hints-based-autodiscovery-with-docker-swarm-secrets/340497)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 3:21pm UTC](https://discuss.elastic.co/t/can-i-use-hints-based-autodiscovery-with-docker-swarm-secrets/340497 "2023-08-21T15:21:54Z")

</div>

Per Securely manage credentials while monitoring Kubernetes workloads with autodiscovery | Elastic Blog it is possible to use Kubernetes secrets with hints based autodiscovery. Can I do the same with Docker Swarm secret…

---

## [Can we trigger alert to end user filter from log message](https://discuss.elastic.co/t/can-we-trigger-alert-to-end-user-filter-from-log-message/341030)

<div class="topic-metadata">

**Author:** [@SumitSingh](https://discuss.elastic.co/u/SumitSingh)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 2:56pm UTC](https://discuss.elastic.co/t/can-we-trigger-alert-to-end-user-filter-from-log-message/341030 "2023-08-21T14:56:27Z")

</div>

Hi, I want to send alert to user whose name in log message field. For example a user tried to access a project but he is not authorized, in this case log captured (access is forbidden for user: 'xyx') in message field. …

---

## [Should I disable scroll time if I don't explicitly use scroll in any search or index operation?](https://discuss.elastic.co/t/should-i-disable-scroll-time-if-i-dont-explicitly-use-scroll-in-any-search-or-index-operation/341158)

<div class="topic-metadata">

**Author:** [@arifd](https://discuss.elastic.co/u/arifd)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 2:39pm UTC](https://discuss.elastic.co/t/should-i-disable-scroll-time-if-i-dont-explicitly-use-scroll-in-any-search-or-index-operation/341158 "2023-08-21T14:39:40Z")

</div>

Hello! So I am not (as far as I am aware) using the Scroll API, and yet I was able to get the "Trying to create too many scroll contexts. Must be less than or equal to: \[500\]" error. From searching around, I am under t…

---

## [Two custom analyzers with the same synonym filter - why no match](https://discuss.elastic.co/t/two-custom-analyzers-with-the-same-synonym-filter-why-no-match/341264)

<div class="topic-metadata">

**Author:** [@Lukas\_Cern](https://discuss.elastic.co/u/Lukas_Cern)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 2:17pm UTC](https://discuss.elastic.co/t/two-custom-analyzers-with-the-same-synonym-filter-why-no-match/341264 "2023-08-21T14:17:23Z")

</div>

I have index with two fields. Each field uses different custom analyzer. Each of those analyzers use the same synonym filter. When querying with bool + should + match on both fields, it matches no document. I dont under…

---

## [High Index Count impacting Elasticsearch Performance](https://discuss.elastic.co/t/high-index-count-impacting-elasticsearch-performance/341259)

<div class="topic-metadata">

**Author:** [@Nitish\_Goyal](https://discuss.elastic.co/u/Nitish_Goyal)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 2:07pm UTC](https://discuss.elastic.co/t/high-index-count-impacting-elasticsearch-performance/341259 "2023-08-21T14:07:43Z")

</div>

Problem Statement : Decrease in cluster throughput as we increase the number of indices in the cluster Cluster Set up Nodes = 8 Cores per node = 18 Memory = 90 GB Heap = 28 GB Version = 8.9.0 We are seeing decrease…

---

## [Elaticsearch SQL CLI is not working](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/341258)

<div class="topic-metadata">

**Author:** [@SivaPrasadELK](https://discuss.elastic.co/u/SivaPrasadELK)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 2:02pm UTC](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/341258 "2023-08-21T14:02:32Z")

</div>

Hi team, I am not able to run the SQL commands in SQL CLI tool. Any pointers how to use it or any supporting docs to refer. i am getting different kind of error messages when trying to run the queries in SQL CLI . "er…

---

## [Render Json strings from Elastic API client objects](https://discuss.elastic.co/t/render-json-strings-from-elastic-api-client-objects/341238)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 2\
**Last updated:** [August 21, 2023, 1:59pm UTC](https://discuss.elastic.co/t/render-json-strings-from-elastic-api-client-objects/341238 "2023-08-21T13:59:53Z")

</div>

Hi, I am using the Elasticsearch API client (8.9) for java and wondering how to render those Queries and Responses as json strings. For example I can do a simple query like so: val query = Query.of { q -\> q.matchAll {…

---

## [Update-by-query: No mapping found for \[id\] in order to sort on](https://discuss.elastic.co/t/update-by-query-no-mapping-found-for-id-in-order-to-sort-on/339671)

<div class="topic-metadata">

**Author:** [@davysteegen](https://discuss.elastic.co/u/davysteegen)\
**Replies:** 6\
**Last updated:** [August 21, 2023, 1:34pm UTC](https://discuss.elastic.co/t/update-by-query-no-mapping-found-for-id-in-order-to-sort-on/339671 "2023-08-21T13:34:27Z")

</div>

Hi, We are in the process of migrating from Elasticsearch 2.3 to 8.6. One thing I noticed is that the sorting in the update-by-query API now only allows to provide a comma separated list of field/sort direction combos. …

---

## [Using kube-state-metrics (custom resource state metrics) breaks metricbeat](https://discuss.elastic.co/t/using-kube-state-metrics-custom-resource-state-metrics-breaks-metricbeat/341249)

<div class="topic-metadata">

**Author:** [@MKruger777](https://discuss.elastic.co/u/MKruger777)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 1:32pm UTC](https://discuss.elastic.co/t/using-kube-state-metrics-custom-resource-state-metrics-breaks-metricbeat/341249 "2023-08-21T13:32:04Z")

</div>

Hi there, I am running metricbeat:8.6.1 and prometheus:2.43.1 on AKS 1.25.6 Both of these are scraping metrics from kube-state-metrics:2.8.2 Because of an edge case we were forced to make use of the Custom Resource St…

---

## [Is it possible to disable or remove log4j-core-2.17.1.jar from Logstash?](https://discuss.elastic.co/t/is-it-possible-to-disable-or-remove-log4j-core-2-17-1-jar-from-logstash/341221)

<div class="topic-metadata">

**Author:** [@kam89](https://discuss.elastic.co/u/kam89)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 1:20pm UTC](https://discuss.elastic.co/t/is-it-possible-to-disable-or-remove-log4j-core-2-17-1-jar-from-logstash/341221 "2023-08-21T13:20:59Z")

</div>

Hi, We are running on Logstash 8.8.0 and our IT security team has concern about the log4j-core-2.17.1.jar in the logstash-core\\lib\\jars. Can we disable log4j totally in Logstash and remove the log4j-core-2.17.1.jar fro…

---

## [Decode\_base64\_field giving weird results](https://discuss.elastic.co/t/decode-base64-field-giving-weird-results/340962)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 1:09pm UTC](https://discuss.elastic.co/t/decode-base64-field-giving-weird-results/340962 "2023-08-21T13:09:29Z")

</div>

Hello, Requirement: We are sending emails (using custom cron jobs) whenever host is down in Elasticsearch Uptime (Heartbeat). We have a need to send link to single monitor, whenever it is down. Not sure how to achieve …

---

## [Spring + elastic 8.9.0 How to create index template](https://discuss.elastic.co/t/spring-elastic-8-9-0-how-to-create-index-template/340033)

<div class="topic-metadata">

**Author:** [@Prasanth\_Gutlapalli](https://discuss.elastic.co/u/Prasanth_Gutlapalli)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 1:09pm UTC](https://discuss.elastic.co/t/spring-elastic-8-9-0-how-to-create-index-template/340033 "2023-08-21T13:09:26Z")

</div>

How to create index template give java example

---

## [Best way to load an elastic query and manipulate it](https://discuss.elastic.co/t/best-way-to-load-an-elastic-query-and-manipulate-it/341099)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 12:10pm UTC](https://discuss.elastic.co/t/best-way-to-load-an-elastic-query-and-manipulate-it/341099 "2023-08-21T12:10:06Z")

</div>

Hi, I am using the Elasticsearch Java client and what I basically want to achieve is the following: Our backend is basically a ES Proxy, so there is an endpoint that takes an ES query as input, adds a clause (to scope t…

---

## [Configure Elasticsearch monitoring integration 8.9.0](https://discuss.elastic.co/t/configure-elasticsearch-monitoring-integration-8-9-0/341231)

<div class="topic-metadata">

**Author:** [@aaszxc](https://discuss.elastic.co/u/aaszxc)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 11:56am UTC](https://discuss.elastic.co/t/configure-elasticsearch-monitoring-integration-8-9-0/341231 "2023-08-21T11:56:27Z")

</div>

I am trying to configure Elasticsearch Elastic Agent integration to monitor the elasticsearch cluster as specified here: Collecting Elasticsearch monitoring data with Elastic Agent | Elasticsearch Guide \[8.11\] | Elastic …

---

## [Troubleshooting Netflow Logs Display Issue in Kibana with Elasticsearch](https://discuss.elastic.co/t/troubleshooting-netflow-logs-display-issue-in-kibana-with-elasticsearch/341146)

<div class="topic-metadata">

**Author:** [@abntkpi](https://discuss.elastic.co/u/abntkpi)\
**Replies:** 8\
**Last updated:** [August 21, 2023, 11:21am UTC](https://discuss.elastic.co/t/troubleshooting-netflow-logs-display-issue-in-kibana-with-elasticsearch/341146 "2023-08-21T11:21:42Z")

</div>

Hello and good time to you, I have installed Elasticsearch along with Kibana, and I installed the Netflow record on Kibana to receive Netflow from Cisco Switch 2960. However, the Cisco Netflow logs are not being display…

---

## [Filestream data duplication in filebeat 8.9.1](https://discuss.elastic.co/t/filestream-data-duplication-in-filebeat-8-9-1/341222)

<div class="topic-metadata">

**Author:** [@germain\_nganko](https://discuss.elastic.co/u/germain_nganko)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 10:28am UTC](https://discuss.elastic.co/t/filestream-data-duplication-in-filebeat-8-9-1/341222 "2023-08-21T10:28:48Z")

</div>

Hello, I read various issues regarding the data duplication error messages in filebeat logs, However I haven't really understood what the root cause is. Please can some one explain me really what the root cause is? below…

---

## [After Update from Kibana 7.x to Kibana 8.9 =\>security\_exception: unable to authenticate user \[kibana\_system\] for REST request \[/\_cluster/settings?include\_defaults=true&f](https://discuss.elastic.co/t/after-update-from-kibana-7-x-to-kibana-8-9-security-exception-unable-to-authenticate-user-kibana-system-for-rest-request-cluster-settings-include-defaults-true-f/340984)

<div class="topic-metadata">

**Author:** [@Wolfgang\_Winter](https://discuss.elastic.co/u/Wolfgang_Winter)\
**Replies:** 6\
**Last updated:** [August 21, 2023, 10:24am UTC](https://discuss.elastic.co/t/after-update-from-kibana-7-x-to-kibana-8-9-security-exception-unable-to-authenticate-user-kibana-system-for-rest-request-cluster-settings-include-defaults-true-f/340984 "2023-08-21T10:24:36Z")

</div>

Hello, we updated yesterday our elasticsearch-stack to 8.9.0. Now, kibana don't start and i found this error in /var/log/messages FATAL ResponseError: security\_exception Aug 17 10:42:58 elasticserver kibana\[342912\]: …

---

## [Securing Elasticsearch/Kibana / "Bad Decrypt" Error](https://discuss.elastic.co/t/securing-elasticsearch-kibana-bad-decrypt-error/340944)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 15\
**Last updated:** [August 21, 2023, 10:08am UTC](https://discuss.elastic.co/t/securing-elasticsearch-kibana-bad-decrypt-error/340944 "2023-08-21T10:08:59Z")

</div>

Hi! I think I totally lost the thread, I don't know where my error is right now. I wanted to change my Elasticsearch-Kibana-WinlogBeat installation, which was working flawlessly so far, to an encrypted connection. The …

---

## [SESSION\_EXPIRED after logging in another Kibana](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003)

<div class="topic-metadata">

**Author:** [@theo2](https://discuss.elastic.co/u/theo2)\
**Replies:** 8\
**Last updated:** [August 21, 2023, 9:59am UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003 "2023-08-21T09:59:25Z")

</div>

Hello, I have a cluster with 3 Elasticsearch on it, individually it works fine. But if I have an instance A connected, and I connect to instance B or C, I receive a SESSION\_EXPIRED timeout. I run kibana locally with d…

---

## [How to get values of filters to a variable in Canvas](https://discuss.elastic.co/t/how-to-get-values-of-filters-to-a-variable-in-canvas/341216)

<div class="topic-metadata">

**Author:** [@KLM](https://discuss.elastic.co/u/KLM)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 9:24am UTC](https://discuss.elastic.co/t/how-to-get-values-of-filters-to-a-variable-in-canvas/341216 "2023-08-21T09:24:41Z")

</div>

I have set of filters on the canvas and values of these will be used in an essql query to pick data to a line chart. filters | essql query="SELECT .." .. .. | render But based on some of the selected values in filter…

---

## [How to query list of offline agents using the Fleet API?](https://discuss.elastic.co/t/how-to-query-list-of-offline-agents-using-the-fleet-api/340783)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 11\
**Last updated:** [August 21, 2023, 8:36am UTC](https://discuss.elastic.co/t/how-to-query-list-of-offline-agents-using-the-fleet-api/340783 "2023-08-21T08:36:03Z")

</div>

I looked at these two docs: and came up with this query: curl --request GET --url 'https://mykibana/api/fleet/agents?kuery=status:offline' \\ --header 'Accept: \*/\*' \\ --header 'Authorization: ApiKey myk…

---

## [How many Meticbeat modules can be processed at the same time?](https://discuss.elastic.co/t/how-many-meticbeat-modules-can-be-processed-at-the-same-time/341210)

<div class="topic-metadata">

**Author:** [@rhakdnj](https://discuss.elastic.co/u/rhakdnj)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 8:17am UTC](https://discuss.elastic.co/t/how-many-meticbeat-modules-can-be-processed-at-the-same-time/341210 "2023-08-21T08:17:25Z")

</div>

Hello. First of all, thank you for providing such a simple beat. Now I'm running haproxy as a process unit. As a result, we provide a specific haproxy\_id for each process. Accordingly, we make a haproxy module for eac…

---

## [Continuously get data from Elasticsearch, when new poll data comes in](https://discuss.elastic.co/t/continuously-get-data-from-elasticsearch-when-new-poll-data-comes-in/339254)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 8:22am UTC](https://discuss.elastic.co/t/continuously-get-data-from-elasticsearch-when-new-poll-data-comes-in/339254 "2023-08-21T08:22:56Z")

</div>

Hi, I am creating an external plugin in Kibana 8.1.1 using React. I am retrieving the data I have in ES using the data plugin. Is it possible to fetch and update the plugin state as and when data is inserted into the i…

---

## [Large indice, a lot of IO read](https://discuss.elastic.co/t/large-indice-a-lot-of-io-read/341211)

<div class="topic-metadata">

**Author:** [@pdgaaa](https://discuss.elastic.co/u/pdgaaa)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 8:17am UTC](https://discuss.elastic.co/t/large-indice-a-lot-of-io-read/341211 "2023-08-21T08:17:35Z")

</div>

Hi ! Having an elastic cluster with 3 nodes under docker. 2 data nodes (indices with replica 1 and only 1 shard) and one node for the master eligibilty. ES 7.17.x 8 GB RAM / data node, 6 GB for docker, 3 GB XMX for ES.…

---

## [Single click option in drilldown](https://discuss.elastic.co/t/single-click-option-in-drilldown/341200)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 7:36am UTC](https://discuss.elastic.co/t/single-click-option-in-drilldown/341200 "2023-08-21T07:36:08Z")

</div>

I am used self deploy kibana application with basic licence and I want Single click option in drilldown for dashboard visualizations . Can anyone suggest me to approach for this?

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=445)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=447)
