# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=485

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 486

---

## [Why isElectionQuorum need lastCommitedConfiguration and lastAcceptedConfiguration all pass?](https://discuss.elastic.co/t/why-iselectionquorum-need-lastcommitedconfiguration-and-lastacceptedconfiguration-all-pass/338048)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 1\
**Last updated:** [July 11, 2023, 6:43am UTC](https://discuss.elastic.co/t/why-iselectionquorum-need-lastcommitedconfiguration-and-lastacceptedconfiguration-all-pass/338048 "2023-07-11T06:43:01Z")

</div>

Why does Elasticsearch need to check if both lastAcceptedConfiguration and lastCommitedConfiguration are over the majority threshold when deciding whether to start an election? What is the reasoning behind this, and are …

---

## [Implementing machine learning API in Rust using elasticsearch8.4.0-alpha.1 library](https://discuss.elastic.co/t/implementing-machine-learning-api-in-rust-using-elasticsearch8-4-0-alpha-1-library/337770)

<div class="topic-metadata">

**Author:** [@aniket\_mandhare](https://discuss.elastic.co/u/aniket_mandhare)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 6:11am UTC](https://discuss.elastic.co/t/implementing-machine-learning-api-in-rust-using-elasticsearch8-4-0-alpha-1-library/337770 "2023-07-11T06:11:23Z")

</div>

Hey folks, I am trying to implement machine learning API in Rust programming language using elasticsearch8.4.0-alpha.1 library and now I am stuck. I want to use ML model which is already imported in Elasticsearch which c…

---

## [Can I install both agent winlogbeat and exabeam on same server?](https://discuss.elastic.co/t/can-i-install-both-agent-winlogbeat-and-exabeam-on-same-server/338054)

<div class="topic-metadata">

**Author:** [@witsarut](https://discuss.elastic.co/u/witsarut)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 4:35am UTC](https://discuss.elastic.co/t/can-i-install-both-agent-winlogbeat-and-exabeam-on-same-server/338054 "2023-07-11T04:35:36Z")

</div>

Hello Everyone, Can I do install both agent winlogbeat and exabeam on same server ? If can do that, It's have a effected to server i.e. high CPU consume. Thanks,

---

## [Logstash automatic shutdown normal](https://discuss.elastic.co/t/logstash-automatic-shutdown-normal/337946)

<div class="topic-metadata">

**Author:** [@lz840408](https://discuss.elastic.co/u/lz840408)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 2:44am UTC](https://discuss.elastic.co/t/logstash-automatic-shutdown-normal/337946 "2023-07-11T02:44:48Z")

</div>

logstash: 7.17.9 cfg file: input { elasticsearch { hosts =\> \["10.251.0.11:39202"\] index =\> "new\_index\_001" docinfo =\> true scroll =\> "30s" size =\> 500 } } filter { mutate { remove\_field =\> \["…

---

## [Failed to create outliear detection](https://discuss.elastic.co/t/failed-to-create-outliear-detection/337878)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 4\
**Last updated:** [July 11, 2023, 1:59am UTC](https://discuss.elastic.co/t/failed-to-create-outliear-detection/337878 "2023-07-11T01:59:31Z")

</div>

Hi, I was trying to create a machine learning which is simply to identify a distinct record Below is my data: In my index, I have 20 documents, and 7 fields Codenum is a keyword A,B,C,V+,V-,P are boolean only …

---

## [CPU heavy load after indexing 1.5M vectors](https://discuss.elastic.co/t/cpu-heavy-load-after-indexing-1-5m-vectors/338002)

<div class="topic-metadata">

**Author:** [@mwon](https://discuss.elastic.co/u/mwon)\
**Replies:** 1\
**Last updated:** [July 11, 2023, 12:23am UTC](https://discuss.elastic.co/t/cpu-heavy-load-after-indexing-1-5m-vectors/338002 "2023-07-11T00:23:00Z")

</div>

Hi, I want to build an index with more than 4M vectors of dimension 768. My setup for now is a DigitalOcean droplet with 4GB and 2vCPU (planning to increase as needed). I first started to add the first million which se…

---

## [Overwriting a whole index without downtime best practices](https://discuss.elastic.co/t/overwriting-a-whole-index-without-downtime-best-practices/338039)

<div class="topic-metadata">

**Author:** [@krezno](https://discuss.elastic.co/u/krezno)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 9:15pm UTC](https://discuss.elastic.co/t/overwriting-a-whole-index-without-downtime-best-practices/338039 "2023-07-10T21:15:46Z")

</div>

I have several batch pipelines that produce a new version of the result each time. The data can't have any downtime so I can't just delete the index before writing. The current solution is to create a new index with the …

---

## [UNASSIGNED state after REPLICA\_ADDED](https://discuss.elastic.co/t/unassigned-state-after-replica-added/336326)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 24\
**Last updated:** [July 10, 2023, 8:31pm UTC](https://discuss.elastic.co/t/unassigned-state-after-replica-added/336326 "2023-07-10T20:31:54Z")

</div>

We are indexing around 7TB on a daily basis. All the indices are being replaced once a day with a new ones (fresh data). Each index represent one customer (business). The variety of indices is big, from a few kilobyte…

---

## [{Invalid NEST response built from a successful (200) low level call on POST: /\_bulk}](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-successful-200-low-level-call-on-post-bulk/338042)

<div class="topic-metadata">

**Author:** [@Janderson\_Goncalves](https://discuss.elastic.co/u/Janderson_Goncalves)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 7:46pm UTC](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-successful-200-low-level-call-on-post-bulk/338042 "2023-07-10T19:46:00Z")

</div>

I am trying to create a Middleware that captures the Request and Response of a given application and indexes it in Elastic. But the elastic always returns the following error and already when debugging is going an object…

---

## [Kibana filtering issue](https://discuss.elastic.co/t/kibana-filtering-issue/336880)

<div class="topic-metadata">

**Author:** [@VirusProtect](https://discuss.elastic.co/u/VirusProtect)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 5:37pm UTC](https://discuss.elastic.co/t/kibana-filtering-issue/336880 "2023-07-10T17:37:22Z")

</div>

When I search for a value, it is only able to find it in the message field. If I specify the field name using the format 'field\_name: value', it works fine. How can I solve this issue so that I can simply type the value …

---

## [403 in Discover View](https://discuss.elastic.co/t/403-in-discover-view/336981)

<div class="topic-metadata">

**Author:** [@lenn\_rt](https://discuss.elastic.co/u/lenn_rt)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 5:35pm UTC](https://discuss.elastic.co/t/403-in-discover-view/336981 "2023-07-10T17:35:14Z")

</div>

Hey, we trying to implement the ELK Stack (8.7.1) in an AKS via Helm Charts. We are using an NGINX controller to reverse proxy our request and are loadbalancing the requests with an application gateway. We are able to r…

---

## [Search\_phase\_execution\_exception: \[no\_shard\_available\_action\_exception\] Reason: null; \[no\_shard\_available\_action\_exception\] Reason: null (500)](https://discuss.elastic.co/t/search-phase-execution-exception-no-shard-available-action-exception-reason-null-no-shard-available-action-exception-reason-null-500/338003)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 5:28pm UTC](https://discuss.elastic.co/t/search-phase-execution-exception-no-shard-available-action-exception-reason-null-no-shard-available-action-exception-reason-null-500/338003 "2023-07-10T17:28:56Z")

</div>

Hi after i've receive disk full i try to remove some indices from this path: /opt/elasticsearch/var/lib/elasticsearch/indices/ after that APM dashboard not load and give below errors. seems some indices that related t…

---

## [In Dev Tools Console, \_reindex gets error of Client request timeout](https://discuss.elastic.co/t/in-dev-tools-console-reindex-gets-error-of-client-request-timeout/337920)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 4\
**Last updated:** [July 10, 2023, 4:38pm UTC](https://discuss.elastic.co/t/in-dev-tools-console-reindex-gets-error-of-client-request-timeout/337920 "2023-07-10T16:38:04Z")

</div>

When trying to duplicate an index by the \_reindex command, it always gets an error saying "502, Bad Gateway" and "Client request timeout". However, the command GET \_cat/indices/\_all shows, right after the above error, t…

---

## [Mail alerts generation through Kibana](https://discuss.elastic.co/t/mail-alerts-generation-through-kibana/338025)

<div class="topic-metadata">

**Author:** [@Surabhi\_Pol](https://discuss.elastic.co/u/Surabhi_Pol)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 3:14pm UTC](https://discuss.elastic.co/t/mail-alerts-generation-through-kibana/338025 "2023-07-10T15:14:53Z")

</div>

Hi All, We want to generate automatic mail alerts system from Kibana (Stack Management 7.16.1) dashboard so that every critical or warning alerts we can captured easily which will helps in for fast monitoring purpose. K…

---

## [Running Logstash on multiple servers, avoiding double processing](https://discuss.elastic.co/t/running-logstash-on-multiple-servers-avoiding-double-processing/337780)

<div class="topic-metadata">

**Author:** [@BenSeb](https://discuss.elastic.co/u/BenSeb)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 3:00pm UTC](https://discuss.elastic.co/t/running-logstash-on-multiple-servers-avoiding-double-processing/337780 "2023-07-10T15:00:20Z")

</div>

Hi We have logstash running on our worker servers, and they run with an identical config, to ensure if one hosts goes down, we are still processing events. The source data is Mysql, then logstash pushes the latest reco…

---

## [When Search goes to Replica shard?](https://discuss.elastic.co/t/when-search-goes-to-replica-shard/338021)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 4\
**Last updated:** [July 10, 2023, 2:52pm UTC](https://discuss.elastic.co/t/when-search-goes-to-replica-shard/338021 "2023-07-10T14:52:01Z")

</div>

I have a scenario , wherein I would need to perform searches in Elastic , but the number of "concurrent searches" are very less. In this case , can I assume that the searches will go to Primary shards? My understanding …

---

## [Recognition of similar words in a search?](https://discuss.elastic.co/t/recognition-of-similar-words-in-a-search/337311)

<div class="topic-metadata">

**Author:** [@Paul-III](https://discuss.elastic.co/u/Paul-III)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 2:32pm UTC](https://discuss.elastic.co/t/recognition-of-similar-words-in-a-search/337311 "2023-07-10T14:32:46Z")

</div>

Is Elastic Search able to recognize that search for housedoor is the same as search for house door and so delivering results for both?

---

## [Reindexed Documents are not showing up, Response says it has created but it does not show up in destination index](https://discuss.elastic.co/t/reindexed-documents-are-not-showing-up-response-says-it-has-created-but-it-does-not-show-up-in-destination-index/337987)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 9\
**Last updated:** [July 10, 2023, 2:15pm UTC](https://discuss.elastic.co/t/reindexed-documents-are-not-showing-up-response-says-it-has-created-but-it-does-not-show-up-in-destination-index/337987 "2023-07-10T14:15:13Z")

</div>

http://localhost:9201/restored\_index/\_search Response: { "took": 2, "timed\_out": false, "\_shards": { "total": 1, "successful": 1, "skipped": 0, "failed": 0 }, "hits":…

---

## [Creating Alerts for rollup jobs](https://discuss.elastic.co/t/creating-alerts-for-rollup-jobs/338030)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 1:47pm UTC](https://discuss.elastic.co/t/creating-alerts-for-rollup-jobs/338030 "2023-07-10T13:47:16Z")

</div>

Hi, Is it possible to get alerts for rollup jobs. If I schedule my rollup job to trigger for every hour, can I get alerts for the stats in rollup jobs. Ex: an alert for number of documents processed and number of rollup…

---

## [How do I setup pipelines with no direct access from Filebeat to Elastic?](https://discuss.elastic.co/t/how-do-i-setup-pipelines-with-no-direct-access-from-filebeat-to-elastic/337836)

<div class="topic-metadata">

**Author:** [@jbilbro](https://discuss.elastic.co/u/jbilbro)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 1:31pm UTC](https://discuss.elastic.co/t/how-do-i-setup-pipelines-with-no-direct-access-from-filebeat-to-elastic/337836 "2023-07-10T13:31:45Z")

</div>

Post my company being aquired, we have been asked to migrate from our on-prem Splunk to our parent company's AWS ELK. This is all new to me, so I'm needing some help knowing the right path forward. They are having us us…

---

## [Logstash issues when writing from s3 to elastic](https://discuss.elastic.co/t/logstash-issues-when-writing-from-s3-to-elastic/338014)

<div class="topic-metadata">

**Author:** [@Keren\_Cohen](https://discuss.elastic.co/u/Keren_Cohen)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 1:09pm UTC](https://discuss.elastic.co/t/logstash-issues-when-writing-from-s3-to-elastic/338014 "2023-07-10T13:09:53Z")

</div>

Hi, I am trying to write logs from AWS s3 bucket and write them to elastic. I'm using logstash 7.17 and get the following error: /usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/aws-sdk-core-2.11.632/lib/seahorse/cl…

---

## [System.auth.ssh.event field not created](https://discuss.elastic.co/t/system-auth-ssh-event-field-not-created/338027)

<div class="topic-metadata">

**Author:** [@Nishant\_Chauhan](https://discuss.elastic.co/u/Nishant_Chauhan)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 12:41pm UTC](https://discuss.elastic.co/t/system-auth-ssh-event-field-not-created/338027 "2023-07-10T12:41:59Z")

</div>

I installed "System" Integration into a policy. however ssh dashboard is not working. \[root@elastic-agent-8-nis elastic-agent-8.7.1-linux-x86\_64\]# sudo elastic-agent status State: HEALTHY Message: Running Fleet St…

---

## [ElasticSearch cluster down due to high memory usage](https://discuss.elastic.co/t/elasticsearch-cluster-down-due-to-high-memory-usage/337975)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 12:32pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-down-due-to-high-memory-usage/337975 "2023-07-10T12:32:26Z")

</div>

I have ran some queries on ES, which fetched huge amount of data and due to that Memory utilization reached high and ES cluster went down. Below is the error that ES-java client has thrown {"error":{"root\_cause":\[{"typ…

---

## [Exporting Anomaly Detection Result](https://discuss.elastic.co/t/exporting-anomaly-detection-result/337854)

<div class="topic-metadata">

**Author:** [@Tania\_Ciu](https://discuss.elastic.co/u/Tania_Ciu)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 12:28pm UTC](https://discuss.elastic.co/t/exporting-anomaly-detection-result/337854 "2023-07-10T12:28:15Z")

</div>

We have created anomaly detection job using kibana machine learning. Is there any solution for exporting anomaly detection result? So that, we can use the result in various kind of data visualization tools?

---

## [Transaction is not logging in elastic](https://discuss.elastic.co/t/transaction-is-not-logging-in-elastic/337985)

<div class="topic-metadata">

**Author:** [@sapna\_jain](https://discuss.elastic.co/u/sapna_jain)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 12:18pm UTC](https://discuss.elastic.co/t/transaction-is-not-logging-in-elastic/337985 "2023-07-10T12:18:55Z")

</div>

Hi all, I am using elastic apm version 1.18.0 in dot net core application. In my application ,I am starting transaction, setting labels to transactions and ending the transaction. This I am doing multiple times. I am f…

---

## [Increase the number of shards in the cluster](https://discuss.elastic.co/t/increase-the-number-of-shards-in-the-cluster/337916)

<div class="topic-metadata">

**Author:** [@karlanakamura](https://discuss.elastic.co/u/karlanakamura)\
**Replies:** 4\
**Last updated:** [July 10, 2023, 12:04pm UTC](https://discuss.elastic.co/t/increase-the-number-of-shards-in-the-cluster/337916 "2023-07-10T12:04:54Z")

</div>

Hello, I'm using version 8.6.0 of elastic cloud. I tried to create an index but got this message: Validation Failed: 1: this action would add \[2\] shards, but this cluster currently has \[2000\]/\[2000\] maximum normal sh…

---

## [What is the function of CPU and Memory for elastic](https://discuss.elastic.co/t/what-is-the-function-of-cpu-and-memory-for-elastic/338017)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 11:19am UTC](https://discuss.elastic.co/t/what-is-the-function-of-cpu-and-memory-for-elastic/338017 "2023-07-10T11:19:10Z")

</div>

Hi there, just want to confirm, as far as i know. memory is used by elastic for JVM, shard. is it correct? or anything else? and for cpu, what actually elastic does with cpu other than to run the service? your explana…

---

## [.net ElasticsearchClient internal json serializer](https://discuss.elastic.co/t/net-elasticsearchclient-internal-json-serializer/337219)

<div class="topic-metadata">

**Author:** [@Jere](https://discuss.elastic.co/u/Jere)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 10:54am UTC](https://discuss.elastic.co/t/net-elasticsearchclient-internal-json-serializer/337219 "2023-07-10T10:54:37Z")

</div>

Hi, using the .net ElasticsearchClient is it possible to configure the DefaultRequestResponseSerializer to prevent the following exception? Elastic.Transport.UnexpectedTransportException Message=The maximum configur…

---

## [The es service on all nodes stops unexpectedly](https://discuss.elastic.co/t/the-es-service-on-all-nodes-stops-unexpectedly/337979)

<div class="topic-metadata">

**Author:** [@alanzc](https://discuss.elastic.co/u/alanzc)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 10:41am UTC](https://discuss.elastic.co/t/the-es-service-on-all-nodes-stops-unexpectedly/337979 "2023-07-10T10:41:58Z")

</div>

When I update openjdk from 1.8-u312 to 1.8-u372, then 12 hours later I got this error from all nodes. Does anyone know the reason? \[2023-07-07T08:47:54,794\]\[ERROR\]\[o.e.b.ElasticsearchUncaughtExceptionHandler\] \[rcvaes01\]…

---

## [Splitting Using Runtime Field / Scripting Field](https://discuss.elastic.co/t/splitting-using-runtime-field-scripting-field/336468)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 10:25am UTC](https://discuss.elastic.co/t/splitting-using-runtime-field-scripting-field/336468 "2023-07-10T10:25:51Z")

</div>

In one of the alerts, in the field host.ip, I am seeing a bunch of IP addresses. So I want to create a scripted or runtime field where I want to split each IP address and place them in a new field like host.ip1 and host.…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=484)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=486)
