# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=455

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 456

---

## [Scripted Fields not showing up in visualizations](https://discuss.elastic.co/t/scripted-fields-not-showing-up-in-visualizations/340417)

<div class="topic-metadata">

**Author:** [@thomas.kelly](https://discuss.elastic.co/u/thomas.kelly)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 6:16am UTC](https://discuss.elastic.co/t/scripted-fields-not-showing-up-in-visualizations/340417 "2023-08-10T06:16:57Z")

</div>

Hi, I am attempting to create a dashboard based off a scripted field. The scripted field is a pretty simple boolean evaluation, and I tested the expression using the preview results feature. The visualization I am attemp…

---

## [This node doesn't appear to be auto-configured for security. Expected configuration is missing from elasticsearch.yml](https://discuss.elastic.co/t/this-node-doesnt-appear-to-be-auto-configured-for-security-expected-configuration-is-missing-from-elasticsearch-yml/339649)

<div class="topic-metadata">

**Author:** [@KunwarAkanksha](https://discuss.elastic.co/u/KunwarAkanksha)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 4:14am UTC](https://discuss.elastic.co/t/this-node-doesnt-appear-to-be-auto-configured-for-security-expected-configuration-is-missing-from-elasticsearch-yml/339649 "2023-08-10T04:14:28Z")

</div>

Kindly Help, While the Elasticsearch is with the default elasticsearch.yml it is giving such error /usr/share/elasticsearch/bin/elasticsearch-reconfigure-node --enrollment-token Generates all the necessary security c…

---

## [Failed to pull data from Salesforce into logstash](https://discuss.elastic.co/t/failed-to-pull-data-from-salesforce-into-logstash/340503)

<div class="topic-metadata">

**Author:** [@Lazaro\_O\_Farrill](https://discuss.elastic.co/u/Lazaro_O_Farrill)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 3:44am UTC](https://discuss.elastic.co/t/failed-to-pull-data-from-salesforce-into-logstash/340503 "2023-08-10T03:44:35Z")

</div>

I am trying to pull my data from my Salesforce sandbox into logstash, and I am getting the following error. Does anyone have any idea what it might mean? I have tested the credentials directly through the API endpoints a…

---

## [After I uncomment xpack.security.enabled: true line in elasticsearch.service Failed to start Elasticsearch](https://discuss.elastic.co/t/after-i-uncomment-xpack-security-enabled-true-line-in-elasticsearch-service-failed-to-start-elasticsearch/339661)

<div class="topic-metadata">

**Author:** [@janitha\_ilangage](https://discuss.elastic.co/u/janitha_ilangage)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 3:43am UTC](https://discuss.elastic.co/t/after-i-uncomment-xpack-security-enabled-true-line-in-elasticsearch-service-failed-to-start-elasticsearch/339661 "2023-08-10T03:43:16Z")

</div>

After I uncomment xpack.security.enabled: true line in elasticsearch.service Failed to start Elasticsearch. root@kibana:~# systemctl status elasticsearch.service ● elasticsearch.service - Elasticsearch Loaded: load…

---

## [Elasticdump is getting failed for uploading the index into elastic](https://discuss.elastic.co/t/elasticdump-is-getting-failed-for-uploading-the-index-into-elastic/340501)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:38am UTC](https://discuss.elastic.co/t/elasticdump-is-getting-failed-for-uploading-the-index-into-elastic/340501 "2023-08-10T01:38:09Z")

</div>

hello all, i am trying to upload the index dump which i have taken using the elasticdump while uploading i am facing issue, as below - Tue, 08 Aug 2023 10:21:37 GMT | sent 10000 objects to destination elasticsearch, wr…

---

## [Difference in filebeat + ES performance](https://discuss.elastic.co/t/difference-in-filebeat-es-performance/340500)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:10am UTC](https://discuss.elastic.co/t/difference-in-filebeat-es-performance/340500 "2023-08-10T01:10:10Z")

</div>

Hi, I currently have 2 setups: Filebeat v8.3.3 + ES v8.3.3 different physical servers connected to the same subnet 3-node ES (each configured as master + data) Total of 90GB JVM heap Total of 18TB hard disk space (ru…

---

## [Documentation - get index api- why there is no info about what api is returning](https://discuss.elastic.co/t/documentation-get-index-api-why-there-is-no-info-about-what-api-is-returning/340495)

<div class="topic-metadata">

**Author:** [@Krzysztof\_Lempicki](https://discuss.elastic.co/u/Krzysztof_Lempicki)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 9:16pm UTC](https://discuss.elastic.co/t/documentation-get-index-api-why-there-is-no-info-about-what-api-is-returning/340495 "2023-08-09T21:16:42Z")

</div>

In doc: Get index information | Elasticsearch API documentation there is no info about what is returned. Is this in purpose? If yes why? For example: From console I see that keys of returned map are index names. With…

---

## [Kibana RAM usage allocation | ELK running too slow](https://discuss.elastic.co/t/kibana-ram-usage-allocation-elk-running-too-slow/340445)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 8:08pm UTC](https://discuss.elastic.co/t/kibana-ram-usage-allocation-elk-running-too-slow/340445 "2023-08-09T20:08:54Z")

</div>

ELK running too slow and in kibana stack monitoring section this is what kibana memory shows my doubt is why it shows 4 gb for kibana when server ram is 64 gb

---

## [Snapshot/restore repository-s3 --\> Using IAM roles for Kubernetes service accounts for authentication is not working](https://discuss.elastic.co/t/snapshot-restore-repository-s3-using-iam-roles-for-kubernetes-service-accounts-for-authentication-is-not-working/340125)

<div class="topic-metadata">

**Author:** [@Celal\_SAHIN](https://discuss.elastic.co/u/Celal_SAHIN)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 7:15pm UTC](https://discuss.elastic.co/t/snapshot-restore-repository-s3-using-iam-roles-for-kubernetes-service-accounts-for-authentication-is-not-working/340125 "2023-08-09T19:15:43Z")

</div>

Hi, Currently we are following the guide here\[1\]. We can successfully assign proper service account(hence AWS iam role) to the es pods. If relevant here\[2\] you can see our redacted elasticsearch CRD file. This correctl…

---

## [Parse the values from aggregation results in watcher transform painless script](https://discuss.elastic.co/t/parse-the-values-from-aggregation-results-in-watcher-transform-painless-script/340485)

<div class="topic-metadata">

**Author:** [@Pavani\_Reddy](https://discuss.elastic.co/u/Pavani_Reddy)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 5:51pm UTC](https://discuss.elastic.co/t/parse-the-values-from-aggregation-results-in-watcher-transform-painless-script/340485 "2023-08-09T17:51:14Z")

</div>

Hello @Badger , @magnusbaeck Please help on painless script for parsing the timestamp and compare with now-1h. ''' "aggs": { "by\_index": { "terms": { "field": "\_index" }, "aggs": { "by\_timestamp": { "max": { "…

---

## [Custom integration for a KVM](https://discuss.elastic.co/t/custom-integration-for-a-kvm/340483)

<div class="topic-metadata">

**Author:** [@divygobi](https://discuss.elastic.co/u/divygobi)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 5:30pm UTC](https://discuss.elastic.co/t/custom-integration-for-a-kvm/340483 "2023-08-09T17:30:14Z")

</div>

If I want to monitor user info(through ecs and kibana) from a KVM instance without installing anything on the KVM, would making a custom integration be the right way to do it? If so, how would we get started on that?

---

## [Separate result by category](https://discuss.elastic.co/t/separate-result-by-category/340479)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 5:05pm UTC](https://discuss.elastic.co/t/separate-result-by-category/340479 "2023-08-09T17:05:07Z")

</div>

Hello , I have nested filed . And I want to bring the result separated by broker , something like this - \[ "broker\_one" =\> \[ result \], "broker\_two" =\> \[ result \] I know that I can aggregate the result , and co…

---

## [Elasticsearch node stats api showing high cpu when nodes are idle](https://discuss.elastic.co/t/elasticsearch-node-stats-api-showing-high-cpu-when-nodes-are-idle/340455)

<div class="topic-metadata">

**Author:** [@Pradeep\_B1](https://discuss.elastic.co/u/Pradeep_B1)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 3:21pm UTC](https://discuss.elastic.co/t/elasticsearch-node-stats-api-showing-high-cpu-when-nodes-are-idle/340455 "2023-08-09T15:21:51Z")

</div>

We are observing high CPU usage in elastic cluster master node even when cluster is Idle. We are using elasticsearch version 7.12 We are using cluster with 3 master nodes and 5 data nodes . All data nodes are having 36…

---

## [Filebeat output.kafka with SASL oauthbearer mecanism](https://discuss.elastic.co/t/filebeat-output-kafka-with-sasl-oauthbearer-mecanism/340474)

<div class="topic-metadata">

**Author:** [@chatim](https://discuss.elastic.co/u/chatim)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 3:09pm UTC](https://discuss.elastic.co/t/filebeat-output-kafka-with-sasl-oauthbearer-mecanism/340474 "2023-08-09T15:09:35Z")

</div>

Hello, i have a kafka cluster that use authentication with sasl oauthbearer mecanism (keycloak), i would like to know if filebeat support sasl/oauthbearer. I already found that it supports sasl/plain & sasl/scram, what…

---

## [Can Elastic Stack replace tools like zabbix?](https://discuss.elastic.co/t/can-elastic-stack-replace-tools-like-zabbix/340357)

<div class="topic-metadata">

**Author:** [@musialny](https://discuss.elastic.co/u/musialny)\
**Replies:** 3\
**Last updated:** [August 9, 2023, 2:57pm UTC](https://discuss.elastic.co/t/can-elastic-stack-replace-tools-like-zabbix/340357 "2023-08-09T14:57:42Z")

</div>

Is Elasticsearch stack capable of distribute network monitoring?

---

## [Filter and search through python](https://discuss.elastic.co/t/filter-and-search-through-python/340386)

<div class="topic-metadata">

**Author:** [@IamExperimenting\_Now](https://discuss.elastic.co/u/IamExperimenting_Now)\
**Replies:** 3\
**Last updated:** [August 9, 2023, 2:51pm UTC](https://discuss.elastic.co/t/filter-and-search-through-python/340386 "2023-08-09T14:51:49Z")

</div>

Hi, I'm new to elasticsearch, I'm using elasticsearch for semantic search. I have pushed 5pdf files after converting into vector. when I do search i'm not getting right index value. so, I thought I would do the filter …

---

## [Which version of Kibana do we find "Formula" tab for Metrics visualization?](https://discuss.elastic.co/t/which-version-of-kibana-do-we-find-formula-tab-for-metrics-visualization/340355)

<div class="topic-metadata">

**Author:** [@Prathamesh\_S\_Pai](https://discuss.elastic.co/u/Prathamesh_S_Pai)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 2:09pm UTC](https://discuss.elastic.co/t/which-version-of-kibana-do-we-find-formula-tab-for-metrics-visualization/340355 "2023-08-09T14:09:33Z")

</div>

---

## [Elasticsearch failed Search rejected due to missing shards \[\[.kibana\_task\_manager\_7.17.7\_001\]\[0\]\]](https://discuss.elastic.co/t/elasticsearch-failed-search-rejected-due-to-missing-shards-kibana-task-manager-7-17-7-001-0/340192)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 7\
**Last updated:** [August 9, 2023, 1:42pm UTC](https://discuss.elastic.co/t/elasticsearch-failed-search-rejected-due-to-missing-shards-kibana-task-manager-7-17-7-001-0/340192 "2023-08-09T13:42:03Z")

</div>

Hello, Current Conf - Version - Elasticsearch| Kibana - 7.17.3 2 Node Cluster Recently i am facing lot of trouble to keep the cluster in healthy state. The error which i am facing is - Caused by: org.elasticsearch…

---

## [Elasticsearch started by Windows Service needs keystore password](https://discuss.elastic.co/t/elasticsearch-started-by-windows-service-needs-keystore-password/340463)

<div class="topic-metadata">

**Author:** [@stephencoffman](https://discuss.elastic.co/u/stephencoffman)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 1:22pm UTC](https://discuss.elastic.co/t/elasticsearch-started-by-windows-service-needs-keystore-password/340463 "2023-08-09T13:22:15Z")

</div>

We are using VM’s in Azure to host Elasticsearch in a FedRAMP High (FIPS enabled) environment. The VM’s have their own disk space. We are currently using the “zip” distribution type for Windows. We install a Windows S…

---

## [EsHadoopRemoteException: illegal\_argument\_exception: only write ops with an op\_type of create are allowed in data streams?](https://discuss.elastic.co/t/eshadoopremoteexception-illegal-argument-exception-only-write-ops-with-an-op-type-of-create-are-allowed-in-data-streams/340267)

<div class="topic-metadata">

**Author:** [@Zephery\_Wen](https://discuss.elastic.co/u/Zephery_Wen)\
**Replies:** 4\
**Last updated:** [August 9, 2023, 1:07pm UTC](https://discuss.elastic.co/t/eshadoopremoteexception-illegal-argument-exception-only-write-ops-with-an-op-type-of-create-are-allowed-in-data-streams/340267 "2023-08-09T13:07:05Z")

</div>

I want to use Spark to save data to a data stream. JavaEsSparkSQL.saveToEs(result, dataStream, map); It seems like 'saveToEs' only allows index. EsHadoopRemoteException: illegal\_argument\_exception: only write ops with…

---

## [How can i update the data in index when i have multiple docementId](https://discuss.elastic.co/t/how-can-i-update-the-data-in-index-when-i-have-multiple-docementid/340167)

<div class="topic-metadata">

**Author:** [@Mohit\_Rajput](https://discuss.elastic.co/u/Mohit_Rajput)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 1:06pm UTC](https://discuss.elastic.co/t/how-can-i-update-the-data-in-index-when-i-have-multiple-docementid/340167 "2023-08-09T13:06:34Z")

</div>

How can i update the data in index when i have multiple docementtId?

---

## [Populate a dense vector field for only a subset of the documents](https://discuss.elastic.co/t/populate-a-dense-vector-field-for-only-a-subset-of-the-documents/340326)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 4\
**Last updated:** [August 9, 2023, 12:56pm UTC](https://discuss.elastic.co/t/populate-a-dense-vector-field-for-only-a-subset-of-the-documents/340326 "2023-08-09T12:56:58Z")

</div>

I have an index of over 10 million documents. On those documents, I want to store an openai (or similar) embedding vector using an indexed dense vector field. I will be using cosine similarity to search through those vec…

---

## [Metricbeat not working on Docker desktop for windows](https://discuss.elastic.co/t/metricbeat-not-working-on-docker-desktop-for-windows/340459)

<div class="topic-metadata">

**Author:** [@BEIIKS](https://discuss.elastic.co/u/BEIIKS)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 12:56pm UTC](https://discuss.elastic.co/t/metricbeat-not-working-on-docker-desktop-for-windows/340459 "2023-08-09T12:56:09Z")

</div>

Hi there, my first issue here :smiley: Im a rookie in ELK, and today I try to use metricbeat to monitor my cpu, ram and etc... ofc that I work with docker desktop as its in development stage so, therefore I understand …

---

## [Upgrade Elastic Stack 7.15.1 to 7.17.10](https://discuss.elastic.co/t/upgrade-elastic-stack-7-15-1-to-7-17-10/339706)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 24\
**Last updated:** [August 9, 2023, 12:50pm UTC](https://discuss.elastic.co/t/upgrade-elastic-stack-7-15-1-to-7-17-10/339706 "2023-08-09T12:50:14Z")

</div>

Hello Team, After Upgrade ELK from 7.15.1 to 7.17.10 : logstash-kibana-filebeat-Elastic search , i can't receive log IIS in KIBANA. when i check log logstash i get this error : " LogStash::PipelineAction::Create/pipel…

---

## [JVM for logstash](https://discuss.elastic.co/t/jvm-for-logstash/340424)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [August 9, 2023, 12:48pm UTC](https://discuss.elastic.co/t/jvm-for-logstash/340424 "2023-08-09T12:48:48Z")

</div>

Hi there, just want to confirm, is there any limit for JVM for logstash? if the JVM limit for elastic is 30 - 32 GB, does it also apply for logstash? Thanks

---

## [Elasticsearch v2.3 disk throughput Throttle](https://discuss.elastic.co/t/elasticsearch-v2-3-disk-throughput-throttle/340453)

<div class="topic-metadata">

**Author:** [@ram\_222](https://discuss.elastic.co/u/ram_222)\
**Replies:** 3\
**Last updated:** [August 9, 2023, 11:58am UTC](https://discuss.elastic.co/t/elasticsearch-v2-3-disk-throughput-throttle/340453 "2023-08-09T11:58:02Z")

</div>

we are currently using Elasticsearch v2.3 Cluster configuration Details: 3 master Nodes ( t2.medium.search ) and 9 Data Nodes ( r4.xlarge.search ) EBS changed from gp2 to Provision IOPS Storage is 250 Gib/Node CPU Ut…

---

## [How Elasticsearch works with OIDC realm](https://discuss.elastic.co/t/how-elasticsearch-works-with-oidc-realm/340442)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 9:10am UTC](https://discuss.elastic.co/t/how-elasticsearch-works-with-oidc-realm/340442 "2023-08-09T09:10:51Z")

</div>

Hi Team, Recently we have integrated Azure AD OIDC with Elasticsearch and kibana. The OP will provide the token to users of kibana User of kibana will present the token to elasticsearch for accessing the resources Ela…

---

## [Adding noeud for elasticsearch cluster](https://discuss.elastic.co/t/adding-noeud-for-elasticsearch-cluster/340441)

<div class="topic-metadata">

**Author:** [@Ali\_Trache](https://discuss.elastic.co/u/Ali_Trache)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 9:09am UTC](https://discuss.elastic.co/t/adding-noeud-for-elasticsearch-cluster/340441 "2023-08-09T09:09:56Z")

</div>

hello community , i need help please , i had installer ELK stack in my virtuelle machine with one noeud ( elasticsearch , kibana , logstash) now i wish add a second noeud for my cluster so i had installed a second V…

---

## [Logstash date filter](https://discuss.elastic.co/t/logstash-date-filter/340427)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 10\
**Last updated:** [August 9, 2023, 8:29am UTC](https://discuss.elastic.co/t/logstash-date-filter/340427 "2023-08-09T08:29:42Z")

</div>

Hi i have a short\_date field in the following format 09/Aug/2023:12:44:15 +0530 This field is created as text. To convert it to date i am doing the following date { match =\> \[ "short\_date", "dd/MMM/yyyy…

---

## [How to use predicate / expression with C# client](https://discuss.elastic.co/t/how-to-use-predicate-expression-with-c-client/340437)

<div class="topic-metadata">

**Author:** [@Daniel\_Dudek](https://discuss.elastic.co/u/Daniel_Dudek)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 8:29am UTC](https://discuss.elastic.co/t/how-to-use-predicate-expression-with-c-client/340437 "2023-08-09T08:29:15Z")

</div>

Hi, I was looking for a solution to use expression with Elasticsearch C# client. I'm using the Elastic.Clients.Elasticsearch in 8.9.1 version. In my repository I have a specification (based on the specification design …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=454)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=456)
