# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=494

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 495

---

## [How to connect Angular logs](https://discuss.elastic.co/t/how-to-connect-angular-logs/337193)

<div class="topic-metadata">

**Author:** [@pavlod](https://discuss.elastic.co/u/pavlod)\
**Replies:** 7\
**Last updated:** [June 30, 2023, 8:56am UTC](https://discuss.elastic.co/t/how-to-connect-angular-logs/337193 "2023-06-30T08:56:05Z")

</div>

Hello! I have a task to connect frontend to Elasticsearch but I cannot find instructions how to connect it... For example I need to connect Angular to Elastic. Thanks!

---

## [Vega tree layout is not working in kibana](https://discuss.elastic.co/t/vega-tree-layout-is-not-working-in-kibana/337157)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 8:43am UTC](https://discuss.elastic.co/t/vega-tree-layout-is-not-working-in-kibana/337157 "2023-06-30T08:43:38Z")

</div>

Hi, I am trying the example given in the following link Tree Layout Example | Vega Here is the output after adding "autosize": "none", I am still getting the the error Data ingestion failed data/flare.json I am n…

---

## [ELK cluster issue after removing one of the master](https://discuss.elastic.co/t/elk-cluster-issue-after-removing-one-of-the-master/337267)

<div class="topic-metadata">

**Author:** [@Alwyn\_Tiu](https://discuss.elastic.co/u/Alwyn_Tiu)\
**Replies:** 5\
**Last updated:** [June 30, 2023, 8:00am UTC](https://discuss.elastic.co/t/elk-cluster-issue-after-removing-one-of-the-master/337267 "2023-06-30T08:00:06Z")

</div>

\[2023-06-30T13:43:27,396\]\[ERROR\]\[o.e.x.m.c.c.ClusterStatsCollector\] \[xxx-es-master-2.xxx.com\] collector \[cluster\_stats\] failed to collect data org.elasticsearch.action.search.SearchPhaseExecutionException: all shards fai…

---

## [ELK cluster issue failed after data node restart](https://discuss.elastic.co/t/elk-cluster-issue-failed-after-data-node-restart/337266)

<div class="topic-metadata">

**Author:** [@Alwyn\_Tiu](https://discuss.elastic.co/u/Alwyn_Tiu)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 5:50am UTC](https://discuss.elastic.co/t/elk-cluster-issue-failed-after-data-node-restart/337266 "2023-06-30T05:50:52Z")

</div>

ELK cluster issue failed after data node restart Tried restarting all nodes, after restart the index starts to restore but during restoring there is an error message: .text-only,.text-card-text{white-space: pre;}.rich-t…

---

## [Get the hit count in EQL](https://discuss.elastic.co/t/get-the-hit-count-in-eql/335529)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 5:42am UTC](https://discuss.elastic.co/t/get-the-hit-count-in-eql/335529 "2023-06-30T05:42:48Z")

</div>

Hi, I'm using the EQL queries for my search and want to get the hits.total.value . When I try the below query, i'm getting the hits.total.value as 10. But I'm not getting the total count of the hits for the search. G…

---

## [Is it possible to get http.max\_content\_length in AWS Elasticsearch?](https://discuss.elastic.co/t/is-it-possible-to-get-http-max-content-length-in-aws-elasticsearch/337223)

<div class="topic-metadata">

**Author:** [@a-moondance-94](https://discuss.elastic.co/u/a-moondance-94)\
**Replies:** 10\
**Last updated:** [June 30, 2023, 3:40am UTC](https://discuss.elastic.co/t/is-it-possible-to-get-http-max-content-length-in-aws-elasticsearch/337223 "2023-06-30T03:40:45Z")

</div>

I need to get the max\_content\_length to limit the size of the bulk request I am sending to AWS Elasticsearch. In my local installation of Elasticsearch I am able to do this using GET \_cluster/settings?include\_defaults A…

---

## [SHA1 error msgs from 'dnf update' (centos9.x)](https://discuss.elastic.co/t/sha1-error-msgs-from-dnf-update-centos9-x/337206)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 2:10am UTC](https://discuss.elastic.co/t/sha1-error-msgs-from-dnf-update-centos9-x/337206 "2023-06-30T02:10:36Z")

</div>

Looks like elastic is signing 8.8.x \*beat package updates with SHA1. CentOS 9 doesn't support this anymore. I can bypass it but maybe it's time to update these to something that's supported? journal is chock full of er…

---

## [Why count(distinct patient\_id) is larger than count(patient\_id)?](https://discuss.elastic.co/t/why-count-distinct-patient-id-is-larger-than-count-patient-id/337250)

<div class="topic-metadata">

**Author:** [@DongPoJuShi\_Dj](https://discuss.elastic.co/u/DongPoJuShi_Dj)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 1:24am UTC](https://discuss.elastic.co/t/why-count-distinct-patient-id-is-larger-than-count-patient-id/337250 "2023-06-30T01:24:29Z")

</div>

There is an index alias that includes two indexes, and the index structure is as follows: { "scientific\_data\_group1": { "aliases": { "scientific\_data\_group": {} }, "mappings": { "properties": {…

---

## [Elasticsearch Query cache shows no data](https://discuss.elastic.co/t/elasticsearch-query-cache-shows-no-data/336306)

<div class="topic-metadata">

**Author:** [@mhr](https://discuss.elastic.co/u/mhr)\
**Replies:** 8\
**Last updated:** [June 30, 2023, 1:08am UTC](https://discuss.elastic.co/t/elasticsearch-query-cache-shows-no-data/336306 "2023-06-30T01:08:42Z")

</div>

The problem we are facing is that query cache is not being used at all in our ES cluster except version 7.8.1. We are using ES version 7.8.1 and we see data in Query Cache as show below. After upgrading to ES versio…

---

## [Call runtime field to another runtime field while creating](https://discuss.elastic.co/t/call-runtime-field-to-another-runtime-field-while-creating/337235)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 10:11pm UTC](https://discuss.elastic.co/t/call-runtime-field-to-another-runtime-field-while-creating/337235 "2023-06-29T22:11:59Z")

</div>

I have question about runtime field, I want to call a runtime field to another runtime field. Suppose I have created a runtime field called (numberOfdays) which is calculating count of days between two dates. Now I ha…

---

## [Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\]](https://discuss.elastic.co/t/authentication-of-elastic-was-terminated-by-realm-reserved-failed-to-authenticate-user-elastic/336330)

<div class="topic-metadata">

**Author:** [@aaronlbk](https://discuss.elastic.co/u/aaronlbk)\
**Replies:** 8\
**Last updated:** [June 29, 2023, 10:10pm UTC](https://discuss.elastic.co/t/authentication-of-elastic-was-terminated-by-realm-reserved-failed-to-authenticate-user-elastic/336330 "2023-06-29T22:10:24Z")

</div>

Hello When I start elastic, I am getting the error below: Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\] I didn't have this error previously. When I try to auth…

---

## [Authentication using apikey failed - unable to find apikey with id](https://discuss.elastic.co/t/authentication-using-apikey-failed-unable-to-find-apikey-with-id/337217)

<div class="topic-metadata">

**Author:** [@p\_vimal](https://discuss.elastic.co/u/p_vimal)\
**Replies:** 3\
**Last updated:** [June 29, 2023, 9:58pm UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed-unable-to-find-apikey-with-id/337217 "2023-06-29T21:58:01Z")

</div>

Hello, We are running Elasticsearch 7.17.8 and have many error entries like this on in the elastic logs: \[WARN \]\[o.e.x.s.a.ApiKeyAuthenticator\] \[NODENAMEE\] Authentication using apikey failed - unable to find apikey wi…

---

## [Child document is occasionally not searchable](https://discuss.elastic.co/t/child-document-is-occasionally-not-searchable/337240)

<div class="topic-metadata">

**Author:** [@kved](https://discuss.elastic.co/u/kved)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 8:33pm UTC](https://discuss.elastic.co/t/child-document-is-occasionally-not-searchable/337240 "2023-06-29T20:33:36Z")

</div>

Child documents are sometimes not searchable. I have a parent-child relationship where the mapping looks like { "parent": { "id": "keyword", "name": "text" } "childId": "keyword", …

---

## [Filebeat setup. could not load template error](https://discuss.elastic.co/t/filebeat-setup-could-not-load-template-error/337135)

<div class="topic-metadata">

**Author:** [@ashmistry](https://discuss.elastic.co/u/ashmistry)\
**Replies:** 7\
**Last updated:** [June 29, 2023, 6:38pm UTC](https://discuss.elastic.co/t/filebeat-setup-could-not-load-template-error/337135 "2023-06-29T18:38:14Z")

</div>

Trying to setup filebeat on my stack. It's Elasticsearch OSS 7.10.2 with opensearch 2.4.1. I am using filebeat oss 7.12.1 and got a successful test output \[root\]# filebeat test output elasticsearch: https://xyz:9200... …

---

## [ElasticSearch does not start and not even cluster](https://discuss.elastic.co/t/elasticsearch-does-not-start-and-not-even-cluster/337017)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 10\
**Last updated:** [June 29, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-and-not-even-cluster/337017 "2023-06-29T18:29:46Z")

</div>

I'm trying to create an Elasticsearch cluster with 3 nodes, each node being eligible as a master, as stated in this doc. This cluster will be used by the end user only on our local network through an nginx proxy that wi…

---

## [JsonProviderImpl not found but only for UpdateByQuery responses](https://discuss.elastic.co/t/jsonproviderimpl-not-found-but-only-for-updatebyquery-responses/337051)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 6:00pm UTC](https://discuss.elastic.co/t/jsonproviderimpl-not-found-but-only-for-updatebyquery-responses/337051 "2023-06-29T18:00:42Z")

</div>

I'm getting the following error only when deserialising UpdateByQuery responses: 2023-06-27 18:00:18:193 +0000 \[http-nio-8080-exec-4\] ERROR Error: Provider org.glassfish.json.JsonProviderImpl not found jakarta.json.Json…

---

## [Help with grok filter for \[::ffff:127.0.0.1\] hybrid + port](https://discuss.elastic.co/t/help-with-grok-filter-for-127-0-0-1-hybrid-port/337198)

<div class="topic-metadata">

**Author:** [@SedonD](https://discuss.elastic.co/u/SedonD)\
**Replies:** 2\
**Last updated:** [June 29, 2023, 5:26pm UTC](https://discuss.elastic.co/t/help-with-grok-filter-for-127-0-0-1-hybrid-port/337198 "2023-06-29T17:26:19Z")

</div>

Hi there, I need some help to filter (Grok) the following, f.e.: \[::ffff:88.88.88.88\]:4262,... this is a log snippet where I need to filter out the IP and port from the following formats... "New request 366c89e6-9c94-…

---

## [I can't filter nested](https://discuss.elastic.co/t/i-cant-filter-nested/337230)

<div class="topic-metadata">

**Author:** [@Vahid\_Hajiagazadeh](https://discuss.elastic.co/u/Vahid_Hajiagazadeh)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 5:06pm UTC](https://discuss.elastic.co/t/i-cant-filter-nested/337230 "2023-06-29T17:06:10Z")

</div>

I have a document that is in the form of nested data But I can't filter in a nested way and all the products return a category, while in the query I have only filtered products that have attribute\_id 40. my mapping { …

---

## [Problems connecting to ES Cross cluster search cluster indexes from Databricks using spark connector](https://discuss.elastic.co/t/problems-connecting-to-es-cross-cluster-search-cluster-indexes-from-databricks-using-spark-connector/335030)

<div class="topic-metadata">

**Author:** [@srinivas\_a1](https://discuss.elastic.co/u/srinivas_a1)\
**Replies:** 3\
**Last updated:** [June 29, 2023, 4:56pm UTC](https://discuss.elastic.co/t/problems-connecting-to-es-cross-cluster-search-cluster-indexes-from-databricks-using-spark-connector/335030 "2023-06-29T16:56:32Z")

</div>

Hi All, I am trying to connect with ES from our Databricks cluster using elasticsearch\_spark\_30\_2\_12\_7\_16\_3.jar. I'm not able to read the data from cross cluster indexes which are starting with "\*:xxxxxxx", However able…

---

## [Logstash input S3 module problem](https://discuss.elastic.co/t/logstash-input-s3-module-problem/334662)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 7\
**Last updated:** [June 29, 2023, 3:12pm UTC](https://discuss.elastic.co/t/logstash-input-s3-module-problem/334662 "2023-06-29T15:12:08Z")

</div>

The problem is in the operation of the S3 module, the module starts for some time, everything works, but after a couple of hours the module is left with an error: Error: Too many open files - Too many open files May 25 …

---

## [Elasticsearch Java API Client throwing error for empty fields](https://discuss.elastic.co/t/elasticsearch-java-api-client-throwing-error-for-empty-fields/337221)

<div class="topic-metadata">

**Author:** [@Shakhzod\_Khashimov](https://discuss.elastic.co/u/Shakhzod_Khashimov)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 2:50pm UTC](https://discuss.elastic.co/t/elasticsearch-java-api-client-throwing-error-for-empty-fields/337221 "2023-06-29T14:50:26Z")

</div>

Hi, we changed our elasticsearch from RestHighLevelClient to ElasticsearchClient, our document can have empty values, but in new Elasticsearch Java API Client it is throwing error saying: org.springframework.data.elasti…

---

## [Add more metrics](https://discuss.elastic.co/t/add-more-metrics/337046)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 4\
**Last updated:** [June 29, 2023, 2:37pm UTC](https://discuss.elastic.co/t/add-more-metrics/337046 "2023-06-29T14:37:05Z")

</div>

Hi Team, We are using ELK stack with platinum license . In our architecture we are using metricbeat for monitoring Oracle database . We are using metricbeat 7.17 version but in that only few metricsets are available t…

---

## [Kibana upgrade is getting failed](https://discuss.elastic.co/t/kibana-upgrade-is-getting-failed/337061)

<div class="topic-metadata">

**Author:** [@Vicky\_Thakor](https://discuss.elastic.co/u/Vicky_Thakor)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 2:21pm UTC](https://discuss.elastic.co/t/kibana-upgrade-is-getting-failed/337061 "2023-06-29T14:21:48Z")

</div>

A few days back our kibana stopped working and elastic.co asking for an upgrade of Kibana. I tried kibana upgrade but it's not working can someone please help? Its production grade issue

---

## [Setting "logging.dest" is deprecated](https://discuss.elastic.co/t/setting-logging-dest-is-deprecated/337100)

<div class="topic-metadata">

**Author:** [@GuillaumeBA](https://discuss.elastic.co/u/GuillaumeBA)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 1:37pm UTC](https://discuss.elastic.co/t/setting-logging-dest-is-deprecated/337100 "2023-06-29T13:37:50Z")

</div>

Hi I'm trying to upgrade my ELK from 7.16.2 to 8.x and i'm facing this last critical error : I have already replaced the "logging.dest:" in kibana.yml by the parameters I have founded in the upgrade assistant for ELK…

---

## [Only one instance of metricbeat/filebeat can connect to elastic](https://discuss.elastic.co/t/only-one-instance-of-metricbeat-filebeat-can-connect-to-elastic/337200)

<div class="topic-metadata">

**Author:** [@marcin8352](https://discuss.elastic.co/u/marcin8352)\
**Replies:** 0\
**Last updated:** [June 29, 2023, 1:19pm UTC](https://discuss.elastic.co/t/only-one-instance-of-metricbeat-filebeat-can-connect-to-elastic/337200 "2023-06-29T13:19:57Z")

</div>

Hello, I have an issue connecting 2 machines to elasticsearch. I have 2 redundant machines in azure which have the same software installed, both have metricbeat and filebeat installed which works just fine. Lets call t…

---

## [Unable to access Elasticsearch connected to company server via Python](https://discuss.elastic.co/t/unable-to-access-elasticsearch-connected-to-company-server-via-python/335288)

<div class="topic-metadata">

**Author:** [@cyl](https://discuss.elastic.co/u/cyl)\
**Replies:** 4\
**Last updated:** [June 29, 2023, 1:09pm UTC](https://discuss.elastic.co/t/unable-to-access-elasticsearch-connected-to-company-server-via-python/335288 "2023-06-29T13:09:01Z")

</div>

Hi Elastic community! :smiley: I have just started using Elastic and Kibana as my company has opted for this tech stack to store much of our data. To analyse the data, I would prefer the use of Python, and hence have b…

---

## [Kafka to Logstash](https://discuss.elastic.co/t/kafka-to-logstash/337173)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 4\
**Last updated:** [June 29, 2023, 12:58pm UTC](https://discuss.elastic.co/t/kafka-to-logstash/337173 "2023-06-29T12:58:33Z")

</div>

Hi Team , In Logstash I can see below error for pipeline having input as Kafka (Oracle Cloud) It fails to connect and then discover . Any idea on what needs to be checked. Once it is stable automatically, we gets data…

---

## [Kibana service failing in version 7.16.3 after importing saved\_objects from 7.9.2](https://discuss.elastic.co/t/kibana-service-failing-in-version-7-16-3-after-importing-saved-objects-from-7-9-2/337156)

<div class="topic-metadata">

**Author:** [@Stephy\_Jacob](https://discuss.elastic.co/u/Stephy_Jacob)\
**Replies:** 2\
**Last updated:** [June 29, 2023, 12:32pm UTC](https://discuss.elastic.co/t/kibana-service-failing-in-version-7-16-3-after-importing-saved-objects-from-7-9-2/337156 "2023-06-29T12:32:09Z")

</div>

Hello, I am trying to upgrade elasticsearch and kibana to 7.16.3 from version 7.9.2. Below are the steps executed. Created a new elasticsearch cluster with 7.16.3 version of elasticsearch and 7.16.3 version of Kibana…

---

## [Logstash 8 cannot run with JRE](https://discuss.elastic.co/t/logstash-8-cannot-run-with-jre/337171)

<div class="topic-metadata">

**Author:** [@sxwnhxwx](https://discuss.elastic.co/u/sxwnhxwx)\
**Replies:** 1\
**Last updated:** [June 29, 2023, 12:22pm UTC](https://discuss.elastic.co/t/logstash-8-cannot-run-with-jre/337171 "2023-06-29T12:22:36Z")

</div>

When I start logstash 8 with jre, it is failed , jdk is ok Logstash 7 works fine with jre logstash version：8.8.1 jre version: 11.0.18 testing configuration： input{ stdin{} } output{ stdout{} } The error message is…

---

## [Documentation - Wildcard query DSL](https://discuss.elastic.co/t/documentation-wildcard-query-dsl/337182)

<div class="topic-metadata">

**Author:** [@Pawel123](https://discuss.elastic.co/u/Pawel123)\
**Replies:** 2\
**Last updated:** [June 29, 2023, 11:32am UTC](https://discuss.elastic.co/t/documentation-wildcard-query-dsl/337182 "2023-06-29T11:32:08Z")

</div>

Running on ES 7.10.0. Sending a search query with "case\_insensitive" parameter: Getting response \[wildcard\] query does not support \[case\_insensitive\] as in documentation -\> Wildcard query | Elasticsearch Guide \[8.8\] |…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=493)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=495)
