# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=462

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 463

---

## [Caused by: java.lang.NoSuchMethodError: 'void co.elastic.clients.transport.rest\_client.RestClientTransport.\<init\>](https://discuss.elastic.co/t/caused-by-java-lang-nosuchmethoderror-void-co-elastic-clients-transport-rest-client-restclienttransport-init/339573)

<div class="topic-metadata">

**Author:** [@aph](https://discuss.elastic.co/u/aph)\
**Replies:** 8\
**Last updated:** [August 2, 2023, 12:04pm UTC](https://discuss.elastic.co/t/caused-by-java-lang-nosuchmethoderror-void-co-elastic-clients-transport-rest-client-restclienttransport-init/339573 "2023-08-02T12:04:08Z")

</div>

Maven build is failing with no method found error. Caused by: java.lang.NoSuchMethodError: 'void co.elastic.clients.transport.rest\_client.RestClientTransport.\<init\> Here is the pom.xml \<?xml version="1.0" encoding="UT…

---

## [Auditbeat lost events](https://discuss.elastic.co/t/auditbeat-lost-events/339935)

<div class="topic-metadata">

**Author:** [@KevinShi](https://discuss.elastic.co/u/KevinShi)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 11:34am UTC](https://discuss.elastic.co/t/auditbeat-lost-events/339935 "2023-08-02T11:34:50Z")

</div>

My auditbeat drop all events when it start a minutes. And auditbeat status info: Aug 02 19:11:51 auditbeat\[29357\]: 2023-08-02T19:11:51.440+0800 INFO \[auditd\] auditd/audit\_linux.go:286 audit…

---

## [Not able to see watcher option in kibana using entrerprise edition](https://discuss.elastic.co/t/not-able-to-see-watcher-option-in-kibana-using-entrerprise-edition/339541)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 11:09am UTC](https://discuss.elastic.co/t/not-able-to-see-watcher-option-in-kibana-using-entrerprise-edition/339541 "2023-08-02T11:09:50Z")

</div>

Hello All, I'm unable to see watcher option in kibana and using enterprise edition. I want to configure alerts based on some string or if certain condition meets.For this watcher is required, but unable to see that opt…

---

## [Fail to start Elasticsearch in Linux](https://discuss.elastic.co/t/fail-to-start-elasticsearch-in-linux/339920)

<div class="topic-metadata">

**Author:** [@Saeed\_Ramezani](https://discuss.elastic.co/u/Saeed_Ramezani)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 10:11am UTC](https://discuss.elastic.co/t/fail-to-start-elasticsearch-in-linux/339920 "2023-08-02T10:11:49Z")

</div>

I'm just trying to install Elasticsearch on Linux(ubuntu 22) by this article All the following commands passed by but when I reach to command ./bin/elasticsearch this error accord: ERROR: Elasticsearch exited unexpecte…

---

## [Kibana Calculations Give Wrong Results](https://discuss.elastic.co/t/kibana-calculations-give-wrong-results/339778)

<div class="topic-metadata">

**Author:** [@Nabeel\_Ahmed\_NAK](https://discuss.elastic.co/u/Nabeel_Ahmed_NAK)\
**Replies:** 10\
**Last updated:** [August 2, 2023, 9:49am UTC](https://discuss.elastic.co/t/kibana-calculations-give-wrong-results/339778 "2023-08-02T09:49:42Z")

</div>

I'm Getting wrong counts in version 8.5.0 Time range is selected absolute values. The count of records are 102,118 hits When I create it's widget metrics of count it's same as expected: 102118 When I create unique co…

---

## [Increase in container memory when pipelines reload in logstash](https://discuss.elastic.co/t/increase-in-container-memory-when-pipelines-reload-in-logstash/338738)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 11\
**Last updated:** [August 2, 2023, 9:24am UTC](https://discuss.elastic.co/t/increase-in-container-memory-when-pipelines-reload-in-logstash/338738 "2023-08-02T09:24:02Z")

</div>

We have a service for which certificate renewal happens for every half an hour. Whenever the certificate renewal happens , when the change is detected in the certificates, automatic reload happens in logstash and all the…

---

## [Kibana dashboard to limited anonymous user](https://discuss.elastic.co/t/kibana-dashboard-to-limited-anonymous-user/338086)

<div class="topic-metadata">

**Author:** [@sunny2502](https://discuss.elastic.co/u/sunny2502)\
**Replies:** 11\
**Last updated:** [August 2, 2023, 9:16am UTC](https://discuss.elastic.co/t/kibana-dashboard-to-limited-anonymous-user/338086 "2023-08-02T09:16:24Z")

</div>

Hi I want my dashboard to be viewable to limited no of users, but I dont want them to get into login page. Can it be done? I know kibana support anonymous authentication but that will open my dashboard for public which…

---

## [Cannot use \_delete\_by\_query in ESSingleNodeTestCase tests with 8.X version.](https://discuss.elastic.co/t/cannot-use-delete-by-query-in-essinglenodetestcase-tests-with-8-x-version/338564)

<div class="topic-metadata">

**Author:** [@fusiasty](https://discuss.elastic.co/u/fusiasty)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 8:32am UTC](https://discuss.elastic.co/t/cannot-use-delete-by-query-in-essinglenodetestcase-tests-with-8-x-version/338564 "2023-08-02T08:32:12Z")

</div>

Hi, I'm just migrating my application from ES 7.17 to ES 8.8.2 and faced one issue. I'm using ESSingleNodeTestCase to check my implementation. My application uses Java API Client 8.8. I figured out how to run HTTP in…

---

## [How to wait for indexing to finish before closing bulkingester](https://discuss.elastic.co/t/how-to-wait-for-indexing-to-finish-before-closing-bulkingester/339875)

<div class="topic-metadata">

**Author:** [@ALX\_DM](https://discuss.elastic.co/u/ALX_DM)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 8:15am UTC](https://discuss.elastic.co/t/how-to-wait-for-indexing-to-finish-before-closing-bulkingester/339875 "2023-08-02T08:15:08Z")

</div>

how to wait for indexing to finish before closing bulkingester. previously we have awaitClose() for bulkprocessor. is is same for bulkingester? there is no awaitClose, but there is wait() in bulkIngester. I am not sur…

---

## [Why are my indexes automatically removed?](https://discuss.elastic.co/t/why-are-my-indexes-automatically-removed/339857)

<div class="topic-metadata">

**Author:** [@Miguel3](https://discuss.elastic.co/u/Miguel3)\
**Replies:** 5\
**Last updated:** [August 2, 2023, 8:13am UTC](https://discuss.elastic.co/t/why-are-my-indexes-automatically-removed/339857 "2023-08-02T08:13:59Z")

</div>

I have a problem with my elastic instance, after a few days of creating and uploading data to my indexes they are automatically deleted, I don't understand why it's happening and I don't see any message in the logs that …

---

## [Wildcard in control](https://discuss.elastic.co/t/wildcard-in-control/339687)

<div class="topic-metadata">

**Author:** [@martinsbleu](https://discuss.elastic.co/u/martinsbleu)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 7:45am UTC](https://discuss.elastic.co/t/wildcard-in-control/339687 "2023-08-02T07:45:12Z")

</div>

Hello Team, Is there a way for control in Dashboard to have wildcard search ? If not, how can I open a request for it ? Thanks in advance,

---

## [Too\_many\_clauses: maxClauseCount is set to 1337](https://discuss.elastic.co/t/too-many-clauses-maxclausecount-is-set-to-1337/339894)

<div class="topic-metadata">

**Author:** [@drorp\_korra](https://discuss.elastic.co/u/drorp_korra)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 7:29am UTC](https://discuss.elastic.co/t/too-many-clauses-maxclausecount-is-set-to-1337/339894 "2023-08-02T07:29:16Z")

</div>

Hello, i'm getting the this error: ApiError(500, 'search\_phase\_execution\_exception', 'too\_many\_clauses: maxClauseCount is set to 1337') The query that is use is: { "bool": { "filter": \[ { "term": { "fi…

---

## [{“statusCode”:503,”error”:”Service Unavailable”,”message”:”License is not available.”}](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/339891)

<div class="topic-metadata">

**Author:** [@R1d3rBG](https://discuss.elastic.co/u/R1d3rBG)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 7:15am UTC](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/339891 "2023-08-02T07:15:18Z")

</div>

Hello, Since a few days its starting again with the same error. Almost every morning when I check the machine its stopped with the following error when I open the URL. {"statusCode":503,"error":"Service Unavailable","m…

---

## [When I signed up for Elastic Cloud and clicked on "Create deployment," after logging in, the dashboard appears empty.](https://discuss.elastic.co/t/when-i-signed-up-for-elastic-cloud-and-clicked-on-create-deployment-after-logging-in-the-dashboard-appears-empty/339859)

<div class="topic-metadata">

**Author:** [@danbeeStudy](https://discuss.elastic.co/u/danbeeStudy)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 5:20am UTC](https://discuss.elastic.co/t/when-i-signed-up-for-elastic-cloud-and-clicked-on-create-deployment-after-logging-in-the-dashboard-appears-empty/339859 "2023-08-02T05:20:29Z")

</div>

When I signed up for Elastic Cloud and clicked on "Create deployment," after logging in, the dashboard appears empty. How can I proceed? By creating the "Create deployment," is it possible for the Elasticsearch Servic…

---

## [Field mapping \[field with constant name\]. --\> \[field with a changing/dynamic name\] --\> \[fields with constant names\]](https://discuss.elastic.co/t/field-mapping-field-with-constant-name-field-with-a-changing-dynamic-name-fields-with-constant-names/339886)

<div class="topic-metadata">

**Author:** [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 5:12am UTC](https://discuss.elastic.co/t/field-mapping-field-with-constant-name-field-with-a-changing-dynamic-name-fields-with-constant-names/339886 "2023-08-02T05:12:34Z")

</div>

hi.. i've run into a problem with elasticsearch mapping.. i'm sure there is a way to deal with it.. but i cant figure it out.. or even the terminology to use to search for a solution. i'm trying to import a json from sh…

---

## [Installing Elasticsearch 7.17](https://discuss.elastic.co/t/installing-elasticsearch-7-17/339887)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar\_Jaiswal](https://discuss.elastic.co/u/Rahul_Kumar_Jaiswal)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 5:12am UTC](https://discuss.elastic.co/t/installing-elasticsearch-7-17/339887 "2023-08-02T05:12:10Z")

</div>

I am trying to reinstall the elasticsearch same version on ubuntu 20.04 but I am getting the below error again and again. I have tried almost all the solution given on google but the error was not resolved. Previously sa…

---

## [Using Maxmind databases without access to ES cluster](https://discuss.elastic.co/t/using-maxmind-databases-without-access-to-es-cluster/339736)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 5\
**Last updated:** [August 2, 2023, 4:47am UTC](https://discuss.elastic.co/t/using-maxmind-databases-without-access-to-es-cluster/339736 "2023-08-02T04:47:38Z")

</div>

Hi, I'm using a ES cluster (v8.8.0) running on Kubenetes that is managed by someone else, and I was told by them that I would not be able to directly access the cluster. Previously, when I was managing my own cluster r…

---

## [ELK Update](https://discuss.elastic.co/t/elk-update/339880)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 3:19am UTC](https://discuss.elastic.co/t/elk-update/339880 "2023-08-02T03:19:27Z")

</div>

Hello everyone, I currently have an ELK version 7.6.0 implementation which I use hand in hand with Splunk version 8.0.1. I realize they are old versions, but it is working for what I need. The plugin I use from Splunk…

---

## [Unable to create a new Field in Logstash ElasticSearch please help](https://discuss.elastic.co/t/unable-to-create-a-new-field-in-logstash-elasticsearch-please-help/339874)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 12:58am UTC](https://discuss.elastic.co/t/unable-to-create-a-new-field-in-logstash-elasticsearch-please-help/339874 "2023-08-02T00:58:14Z")

</div>

hello sir, I really need an help, I'm new to elasticsearch Kibana but learnt in recent days to understand terms used. I have a Index name "logstash-\*" which receives logs constantly, my task is to filter from all logs …

---

## [Logstash pipeline getting terminated](https://discuss.elastic.co/t/logstash-pipeline-getting-terminated/339871)

<div class="topic-metadata">

**Author:** [@Arinjay\_Jain](https://discuss.elastic.co/u/Arinjay_Jain)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 12:10am UTC](https://discuss.elastic.co/t/logstash-pipeline-getting-terminated/339871 "2023-08-02T00:10:06Z")

</div>

Hi Experts, I am running Logstash in a docker container and have the following pipeline configuration. input { tcp { port =\> 5000 codec =\> line } } filter { grok { match =\> {"message…

---

## [Multi-index query returning no results](https://discuss.elastic.co/t/multi-index-query-returning-no-results/339855)

<div class="topic-metadata">

**Author:** [@PedroD](https://discuss.elastic.co/u/PedroD)\
**Replies:** 4\
**Last updated:** [August 2, 2023, 12:01am UTC](https://discuss.elastic.co/t/multi-index-query-returning-no-results/339855 "2023-08-02T00:01:47Z")

</div>

Hey guys, I have 2 different indexes that store information about my users. Both use a hashed version of their id\_number as their doc\_id, I\`m trying to create a query that will look for different fields in both indexes …

---

## [Aggregate latest values of documents](https://discuss.elastic.co/t/aggregate-latest-values-of-documents/339868)

<div class="topic-metadata">

**Author:** [@MrFuxi](https://discuss.elastic.co/u/MrFuxi)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 10:40pm UTC](https://discuss.elastic.co/t/aggregate-latest-values-of-documents/339868 "2023-08-01T22:40:42Z")

</div>

I have items that over the time can go from one category to the other. Each change results in a new document with current state of the item. I'm tying to get run basic analytics based on the latest state of the item li…

---

## [Logstash filtering](https://discuss.elastic.co/t/logstash-filtering/339864)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 9:45pm UTC](https://discuss.elastic.co/t/logstash-filtering/339864 "2023-08-01T21:45:00Z")

</div>

In my logstash every second logs will update, In a field name "message" consists group of data like '2023-08-01T21:11:54 \<local.info\> web.site.com IncomingMax1\[123\] 2023-08-01 11:10:54,123 INFO 987654321 Message.py 12 I…

---

## [CSV and XLS import to Elastic Cloud](https://discuss.elastic.co/t/csv-and-xls-import-to-elastic-cloud/339120)

<div class="topic-metadata">

**Author:** [@Vog93](https://discuss.elastic.co/u/Vog93)\
**Replies:** 14\
**Last updated:** [August 1, 2023, 9:36pm UTC](https://discuss.elastic.co/t/csv-and-xls-import-to-elastic-cloud/339120 "2023-08-01T21:36:08Z")

</div>

Hello, I would like to automatically integrate some CSV and XLS files into Elastic Cloud. How could I do this?

---

## [How to create a field that filters the data](https://discuss.elastic.co/t/how-to-create-a-field-that-filters-the-data/339861)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 9:01pm UTC](https://discuss.elastic.co/t/how-to-create-a-field-that-filters-the-data/339861 "2023-08-01T21:01:50Z")

</div>

I have a "message" field contains bulk of data(like customerName,number,address) in logstash, Now I want to create a new field that filter the data contains only word "Incoming Message:" I'm using ELK 8.6.0 I am tryin…

---

## [Can't set my log file timestamp as Time Filter in Kibana](https://discuss.elastic.co/t/cant-set-my-log-file-timestamp-as-time-filter-in-kibana/339628)

<div class="topic-metadata">

**Author:** [@younes-gr](https://discuss.elastic.co/u/younes-gr)\
**Replies:** 7\
**Last updated:** [August 1, 2023, 8:23pm UTC](https://discuss.elastic.co/t/cant-set-my-log-file-timestamp-as-time-filter-in-kibana/339628 "2023-08-01T20:23:52Z")

</div>

I am trying to process my log file in logstash using the following configuration: Example of log file content: 2023-07-15T07:32:01,645 ERROR \[00000003\] :01234567891011 - ERROR: Some error message 2023-07-15T07:32:01,64…

---

## [How to use runtime mapping on field that is nested](https://discuss.elastic.co/t/how-to-use-runtime-mapping-on-field-that-is-nested/339853)

<div class="topic-metadata">

**Author:** [@jlucas](https://discuss.elastic.co/u/jlucas)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 7:57pm UTC](https://discuss.elastic.co/t/how-to-use-runtime-mapping-on-field-that-is-nested/339853 "2023-08-01T19:57:18Z")

</div>

Lets say I have the following document on some index. { "\_source" : { "process1": { "part1": { "start": "2022-10-04T18:35:01.540Z", "end": "2022-10-04T18:35:01.540Z" }, "part2": {…

---

## [KEYSTORE\_PASSWORD\_FILE](https://discuss.elastic.co/t/keystore-password-file/339627)

<div class="topic-metadata">

**Author:** [@toughcoding](https://discuss.elastic.co/u/toughcoding)\
**Replies:** 3\
**Last updated:** [August 1, 2023, 7:27pm UTC](https://discuss.elastic.co/t/keystore-password-file/339627 "2023-08-01T19:27:39Z")

</div>

Running Elasticsearch as docker container with --env KEYSTORE\_PASSWORD\_FILE=/run/secrets/keystore\_password does not setup password for elasticsearch keystore. Although I am successfull with Elasticsearch password itse…

---

## [Indices.fielddata.cache.size will be allocated within heap or outside heap?](https://discuss.elastic.co/t/indices-fielddata-cache-size-will-be-allocated-within-heap-or-outside-heap/339846)

<div class="topic-metadata">

**Author:** [@mannoj87](https://discuss.elastic.co/u/mannoj87)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 6:54pm UTC](https://discuss.elastic.co/t/indices-fielddata-cache-size-will-be-allocated-within-heap-or-outside-heap/339846 "2023-08-01T18:54:49Z")

</div>

Hi Team, Q1). indices.fielddata.cache.size is set as 10% of heap by default. Does it mean it will consider 10% of heap lets say 1.2GB and it will allocate within heap or will it go outside of heap and take from overall …

---

## [Minimal Filebeat configuration for sending Logstash message in JSON format to Logstash](https://discuss.elastic.co/t/minimal-filebeat-configuration-for-sending-logstash-message-in-json-format-to-logstash/339811)

<div class="topic-metadata">

**Author:** [@jba](https://discuss.elastic.co/u/jba)\
**Replies:** 8\
**Last updated:** [August 1, 2023, 6:51pm UTC](https://discuss.elastic.co/t/minimal-filebeat-configuration-for-sending-logstash-message-in-json-format-to-logstash/339811 "2023-08-01T18:51:32Z")

</div>

Until now, we have had Logstash produce its log messages in plain-text format (written to /var/log/logstash/logstash-plain.log). And we had Filebeat ship the log messages to a Logstash cluster where the log messages were…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=461)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=463)
