# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=469

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 470

---

## [Hardware Requiremenr](https://discuss.elastic.co/t/hardware-requiremenr/339383)

<div class="topic-metadata">

**Author:** [@umangpatel](https://discuss.elastic.co/u/umangpatel)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 5:51am UTC](https://discuss.elastic.co/t/hardware-requiremenr/339383 "2023-07-27T05:51:06Z")

</div>

Hello There!!! I have one question about Elasticsearch hardware requiremnet. So let's say if i want to setup Elasticsearch cluster in on-premises data center and i have daily 20 TB of data is ingress or i would say inge…

---

## [Watcher alert status](https://discuss.elastic.co/t/watcher-alert-status/339374)

<div class="topic-metadata">

**Author:** [@jaja](https://discuss.elastic.co/u/jaja)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 5:16am UTC](https://discuss.elastic.co/t/watcher-alert-status/339374 "2023-07-27T05:16:10Z")

</div>

Hi Team, We have tried with the watcher it worked for us but we can't go as in watcher the alert status does not change like as in alert we have active , recover options we have. I tried with Index Threshold alert but …

---

## [Elastic Agent GUI Installation](https://discuss.elastic.co/t/elastic-agent-gui-installation/334780)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 10:50pm UTC](https://discuss.elastic.co/t/elastic-agent-gui-installation/334780 "2023-05-31T22:50:56Z")

</div>

Elastic Will the elastic agent be installed in a way that supports gui in the future?

---

## [Will the snapshot repository able to capture the changes in mappings?](https://discuss.elastic.co/t/will-the-snapshot-repository-able-to-capture-the-changes-in-mappings/339244)

<div class="topic-metadata">

**Author:** [@ian.chan](https://discuss.elastic.co/u/ian.chan)\
**Replies:** 6\
**Last updated:** [July 27, 2023, 5:19am UTC](https://discuss.elastic.co/t/will-the-snapshot-repository-able-to-capture-the-changes-in-mappings/339244 "2023-07-27T05:19:09Z")

</div>

Hi. Let's say I have registered a snapshot repository for an index A, with slm policy taking snapshot every hour. Then I add a new field in the mapping of the index A, and add some new documents with values in this new…

---

## [RefreshPolicy WAIT\_UNTIL does not work when using BulkProcessor in Java Client](https://discuss.elastic.co/t/refreshpolicy-wait-until-does-not-work-when-using-bulkprocessor-in-java-client/337857)

<div class="topic-metadata">

**Author:** [@ChiMu\_Yuan](https://discuss.elastic.co/u/ChiMu_Yuan)\
**Replies:** 5\
**Last updated:** [July 27, 2023, 4:53am UTC](https://discuss.elastic.co/t/refreshpolicy-wait-until-does-not-work-when-using-bulkprocessor-in-java-client/337857 "2023-07-27T04:53:47Z")

</div>

Hello everyone, I am a beginner, and my English is not very good. I am using ES 7.10 with the Java programming language, so I am using the Java High-Level REST Client. I want to be able to search for relevant content i…

---

## [The indexing or search request send to down node](https://discuss.elastic.co/t/the-indexing-or-search-request-send-to-down-node/339022)

<div class="topic-metadata">

**Author:** [@Chimu](https://discuss.elastic.co/u/Chimu)\
**Replies:** 10\
**Last updated:** [July 27, 2023, 3:35am UTC](https://discuss.elastic.co/t/the-indexing-or-search-request-send-to-down-node/339022 "2023-07-27T03:35:03Z")

</div>

I have an Elasticsearch (v5.6.10) cluster with 3 nodes. Node A : Master Node B : Master + Data Node C : Master + Data There are 6 shards per data node with replication set as 1. All 6 primary nodes are in Node B and a…

---

## [Rollup job is not working if page size is greater than 65000](https://discuss.elastic.co/t/rollup-job-is-not-working-if-page-size-is-greater-than-65000/339367)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 3:08am UTC](https://discuss.elastic.co/t/rollup-job-is-not-working-if-page-size-is-greater-than-65000/339367 "2023-07-27T03:08:48Z")

</div>

Hi, I am facing an issue with rollup jobs. If I give the page size as 100000 it is not working and if I give the size as 65000 it works. I tried with different numbers like 70000, 50000 - when the number is greater than…

---

## [How to test for indexes NOT being created?](https://discuss.elastic.co/t/how-to-test-for-indexes-not-being-created/339346)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 2:08am UTC](https://discuss.elastic.co/t/how-to-test-for-indexes-not-being-created/339346 "2023-07-27T02:08:27Z")

</div>

Hi all. My ELK should be receiving data regularly, and creating a new index daily. Is there any way to automatically test if either of those is NOT happening?

---

## [Physicals host with beats to server with ELK docker containers?](https://discuss.elastic.co/t/physicals-host-with-beats-to-server-with-elk-docker-containers/339352)

<div class="topic-metadata">

**Author:** [@rhyejam](https://discuss.elastic.co/u/rhyejam)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 1:48am UTC](https://discuss.elastic.co/t/physicals-host-with-beats-to-server-with-elk-docker-containers/339352 "2023-07-27T01:48:00Z")

</div>

So here’s my conundrum. Currently using a vm with a bunch of docker containers on it. Included in these is the ELK docker compose by deviantony on GitHub Now I have a few laptops that I want forwarding logs to the serve…

---

## [Struggling with '-' into field as value](https://discuss.elastic.co/t/struggling-with-into-field-as-value/339230)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 3\
**Last updated:** [July 26, 2023, 10:51pm UTC](https://discuss.elastic.co/t/struggling-with-into-field-as-value/339230 "2023-07-26T22:51:09Z")

</div>

Greetings, For very long time, I'm struggling with those errors into my logstash server: \[2023-07-25T17:13:15,009\]\[WARN \]\[logstash.outputs.elasticsearch\]\[5555\_winlogbeat\]\[413af53fed5d62fe27389e3c6e0cc4781e6d3cffc048c8a…

---

## [Winlogbeat 8.8.2 is not sending events to any pipeline](https://discuss.elastic.co/t/winlogbeat-8-8-2-is-not-sending-events-to-any-pipeline/339349)

<div class="topic-metadata">

**Author:** [@pctrindade](https://discuss.elastic.co/u/pctrindade)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 9:11pm UTC](https://discuss.elastic.co/t/winlogbeat-8-8-2-is-not-sending-events-to-any-pipeline/339349 "2023-07-26T21:11:56Z")

</div>

I am currently indexing the Windows Security log, and the events are being sent to Elasticsearch and successfully indexed. However, if I do not specify the pipeline named 'winlogbeat-8.8.2-security' in the output, the ev…

---

## [ELK storage on prem](https://discuss.elastic.co/t/elk-storage-on-prem/339348)

<div class="topic-metadata">

**Author:** [@carl56846453](https://discuss.elastic.co/u/carl56846453)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 9:03pm UTC](https://discuss.elastic.co/t/elk-storage-on-prem/339348 "2023-07-26T21:03:54Z")

</div>

ELK is not storing much log data. The log seem to keep turning over. ELK is consuming a lot of syslog data. how do I increase the storge of data.

---

## [Post data to elasticsearch sometimes throws error 429](https://discuss.elastic.co/t/post-data-to-elasticsearch-sometimes-throws-error-429/339345)

<div class="topic-metadata">

**Author:** [@111407](https://discuss.elastic.co/u/111407)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 7:37pm UTC](https://discuss.elastic.co/t/post-data-to-elasticsearch-sometimes-throws-error-429/339345 "2023-07-26T19:37:00Z")

</div>

command: curl -u username:pw -X POST 'http://sd-4531-6c55:9200/testindex/\_doc' -H 'Content-type: application/json' -d '{"test":11234}' response: {"error":{"root\_cause":\[{"type":"remote\_transport\_exception","reason":"\[…

---

## [Kibana is not working](https://discuss.elastic.co/t/kibana-is-not-working/338991)

<div class="topic-metadata">

**Author:** [@Miguel2](https://discuss.elastic.co/u/Miguel2)\
**Replies:** 11\
**Last updated:** [July 26, 2023, 7:29pm UTC](https://discuss.elastic.co/t/kibana-is-not-working/338991 "2023-07-26T19:29:34Z")

</div>

Hello I'm trying to learn the ELK stack from scratch, I'm currently having problems with kibana not getting active as shown below: myuser@myuser-pc:~$ systemctl status kibana × kibana.service - Kibana Loaded: loade…

---

## [Elasticsearch REST API Authorization](https://discuss.elastic.co/t/elasticsearch-rest-api-authorization/339332)

<div class="topic-metadata">

**Author:** [@ksobon](https://discuss.elastic.co/u/ksobon)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 7:16pm UTC](https://discuss.elastic.co/t/elasticsearch-rest-api-authorization/339332 "2023-07-26T19:16:26Z")

</div>

OK, so I tried using the Elastic.Client.Elasticsearch library to get an index template, but it had some JSON serialization issues that was causing an exception. Next up, I tried using just a regular REST call. I have cr…

---

## [Kibana Error Unable to revive connection](https://discuss.elastic.co/t/kibana-error-unable-to-revive-connection/339344)

<div class="topic-metadata">

**Author:** [@fjcd1990](https://discuss.elastic.co/u/fjcd1990)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 7:08pm UTC](https://discuss.elastic.co/t/kibana-error-unable-to-revive-connection/339344 "2023-07-26T19:08:19Z")

</div>

hi everyone i need help with this error in my kibana service, because the credencial SSL TLS has expired and i don't know how to use the elastic elasticsearch-certutil. "path" : "/usr/share/elasticsearch/config/http-ce…

---

## [GetIndexTemplate() call throws an exception](https://discuss.elastic.co/t/getindextemplate-call-throws-an-exception/339329)

<div class="topic-metadata">

**Author:** [@ksobon](https://discuss.elastic.co/u/ksobon)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 6:25pm UTC](https://discuss.elastic.co/t/getindextemplate-call-throws-an-exception/339329 "2023-07-26T18:25:47Z")

</div>

I am trying to get an index template using the .NET APIs via Elastic.Clients.Elasticsearch and Elastic.Transport libraries. I got my client setup like this: var credentials = new BasicAuthentication(elasticUsername, el…

---

## [Logstash pipeline is getting killed with jnr.enxio.channels.NativeException: Error closing fd 272: Stale file handle"](https://discuss.elastic.co/t/logstash-pipeline-is-getting-killed-with-jnr-enxio-channels-nativeexception-error-closing-fd-272-stale-file-handle/339328)

<div class="topic-metadata">

**Author:** [@jayanthi\_c](https://discuss.elastic.co/u/jayanthi_c)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 6:23pm UTC](https://discuss.elastic.co/t/logstash-pipeline-is-getting-killed-with-jnr-enxio-channels-nativeexception-error-closing-fd-272-stale-file-handle/339328 "2023-07-26T18:23:59Z")

</div>

I am using filebeat to transfer log to logstash but we see that pipeline is getting killed with the below error jnr.enxio.channels.NativeException: Error closing fd 272: Stale file handle" Can someone please help

---

## [How to view the backend log of the Python class \`Elasticsearch\`?](https://discuss.elastic.co/t/how-to-view-the-backend-log-of-the-python-class-elasticsearch/339133)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 6:21pm UTC](https://discuss.elastic.co/t/how-to-view-the-backend-log-of-the-python-class-elasticsearch/339133 "2023-07-26T18:21:22Z")

</div>

We are using an instance of the Python class Elasticsearch, e.g., by es = Elasticsearch(hosts="http://test-elastic-host:9200"). For example, when calling the search() method, we need to know what exactly the request is,…

---

## [I want to know why the indices.id\_field\_data.enabled configuration is turned off by default](https://discuss.elastic.co/t/i-want-to-know-why-the-indices-id-field-data-enabled-configuration-is-turned-off-by-default/339338)

<div class="topic-metadata">

**Author:** [@Kurt\_Rudolph](https://discuss.elastic.co/u/Kurt_Rudolph)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 5:50pm UTC](https://discuss.elastic.co/t/i-want-to-know-why-the-indices-id-field-data-enabled-configuration-is-turned-off-by-default/339338 "2023-07-26T17:50:36Z")

</div>

This topic got automatically closed without an answer I want to know why the indices.id\_field\_data.enabled configuration is turned off by default I'm evaluating the impacts of upgrading from v7 -\> v8 and found an issue…

---

## [Logstash stops processing syslog messages when DNS server not available](https://discuss.elastic.co/t/logstash-stops-processing-syslog-messages-when-dns-server-not-available/339334)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 5:07pm UTC](https://discuss.elastic.co/t/logstash-stops-processing-syslog-messages-when-dns-server-not-available/339334 "2023-07-26T17:07:09Z")

</div>

Running Logstash 8.5.2 on RHEL. I implemented DNS filter plugin to resolve IP addresses to hostnames for all syslog nodes reporting to this logstash server. I am using our local DNS server. It all worked perfectly unti…

---

## [Data duplication problem after server migration](https://discuss.elastic.co/t/data-duplication-problem-after-server-migration/339186)

<div class="topic-metadata">

**Author:** [@charlielin](https://discuss.elastic.co/u/charlielin)\
**Replies:** 8\
**Last updated:** [July 26, 2023, 4:41pm UTC](https://discuss.elastic.co/t/data-duplication-problem-after-server-migration/339186 "2023-07-26T16:41:44Z")

</div>

Hi There: Currently, we are using Filebeat (version 7.15.2) to harvest logs of program A and send them to Kafka. Due to some reason, we will do some operations called Server Migration freqently. Server Migration means…

---

## [Vega Sankey Diagram](https://discuss.elastic.co/t/vega-sankey-diagram/338149)

<div class="topic-metadata">

**Author:** [@Ranger\_Rick](https://discuss.elastic.co/u/Ranger_Rick)\
**Replies:** 4\
**Last updated:** [July 26, 2023, 4:09pm UTC](https://discuss.elastic.co/t/vega-sankey-diagram/338149 "2023-07-26T16:09:34Z")

</div>

Good afternoon! I created some Sankeys to better visualize certain relationships and they mostly work well. Following the example provided here: Sankey Creation resulting in clean graphs but with a slight issue. The da…

---

## [Alerts are not triggering in Kibana 7.17.11](https://discuss.elastic.co/t/alerts-are-not-triggering-in-kibana-7-17-11/339285)

<div class="topic-metadata">

**Author:** [@malak](https://discuss.elastic.co/u/malak)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 3:29pm UTC](https://discuss.elastic.co/t/alerts-are-not-triggering-in-kibana-7-17-11/339285 "2023-07-26T15:29:27Z")

</div>

Hello, I have a basic license where I create a Threat matching rule. Previewing rule is showing the expected result however, the rule is not triggering. Any idea?

---

## [Pagination + Sorted Aggregations: Efficiently Retrieve Sorted List of Values?](https://discuss.elastic.co/t/pagination-sorted-aggregations-efficiently-retrieve-sorted-list-of-values/339325)

<div class="topic-metadata">

**Author:** [@openelasticsearch](https://discuss.elastic.co/u/openelasticsearch)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 3:15pm UTC](https://discuss.elastic.co/t/pagination-sorted-aggregations-efficiently-retrieve-sorted-list-of-values/339325 "2023-07-26T15:15:05Z")

</div>

Hi, I'm looking for some advice on the best way to implement an aggregation query that supports pagination and sorting. Quick Overview of My Documents & Desired Use Case: I have indexes that contain documents with a nu…

---

## [Error logstash \[logstash.outputs.elasticsearch\] Encountered a retryable error code=\>503](https://discuss.elastic.co/t/error-logstash-logstash-outputs-elasticsearch-encountered-a-retryable-error-code-503/328331)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 13\
**Last updated:** [July 26, 2023, 2:56pm UTC](https://discuss.elastic.co/t/error-logstash-logstash-outputs-elasticsearch-encountered-a-retryable-error-code-503/328331 "2023-07-26T14:56:45Z")

</div>

Hi all. I'm a beginner at this. When setting up another pipelayer, after starting it, the following errors started to appear in the log for all other pipelines: logstash\[363391\]: \[2023-03-23T08:05:49,424\]\[ERROR\]\[logsta…

---

## [Installing Elasticsearch as an external service at OpenShift](https://discuss.elastic.co/t/installing-elasticsearch-as-an-external-service-at-openshift/338845)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 2:38pm UTC](https://discuss.elastic.co/t/installing-elasticsearch-as-an-external-service-at-openshift/338845 "2023-07-26T14:38:21Z")

</div>

We have OpenShift cluster and we want to install elasticsearch at ocp to serve both internal and external audit shipment. our design should be something like this: FileBeat (outside ocp) --\> Logstash (inside ocp) --\> El…

---

## [Which is the most stable version of elastic search in 8.x?](https://discuss.elastic.co/t/which-is-the-most-stable-version-of-elastic-search-in-8-x/339314)

<div class="topic-metadata">

**Author:** [@Pankaj\_Goyal](https://discuss.elastic.co/u/Pankaj_Goyal)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 1:57pm UTC](https://discuss.elastic.co/t/which-is-the-most-stable-version-of-elastic-search-in-8-x/339314 "2023-07-26T13:57:34Z")

</div>

We are working on a use case where we have to most rely on vector matching searched. Please suggest most stable version for elastic 8.x.

---

## [Log Retention Issue - Only 10 Days of Logs Kept, Need Assistance](https://discuss.elastic.co/t/log-retention-issue-only-10-days-of-logs-kept-need-assistance/339307)

<div class="topic-metadata">

**Author:** [@7a6b6f](https://discuss.elastic.co/u/7a6b6f)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 1:16pm UTC](https://discuss.elastic.co/t/log-retention-issue-only-10-days-of-logs-kept-need-assistance/339307 "2023-07-26T13:16:23Z")

</div>

Hi everyone, I am facing an issue with log retention in my Elastic Stack setup and could use some help in troubleshooting it. Currently, my system is only retaining logs for 10 days, and after that, the logs are being d…

---

## [\[filebeat ASA Module\] outbound traffic log is parsed in reverse for the source and destination IP](https://discuss.elastic.co/t/filebeat-asa-module-outbound-traffic-log-is-parsed-in-reverse-for-the-source-and-destination-ip/339269)

<div class="topic-metadata">

**Author:** [@Keunwoo\_Lee](https://discuss.elastic.co/u/Keunwoo_Lee)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 12:54pm UTC](https://discuss.elastic.co/t/filebeat-asa-module-outbound-traffic-log-is-parsed-in-reverse-for-the-source-and-destination-ip/339269 "2023-07-26T12:54:04Z")

</div>

Hi. I am collecting logs using the cisco asa module, and the outbound traffic log is parsed in reverse for the source and destination IP. eg) DNS query traffic elasticsearch 8.8.1 kibana 8.8.1 filebeat 8.8.2 /mo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=468)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=470)
