# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=503

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 504

---

## [Elasticerach 8.5.1 version image gives this error curl: (52) Empty reply from server](https://discuss.elastic.co/t/elasticerach-8-5-1-version-image-gives-this-error-curl-52-empty-reply-from-server/336614)

<div class="topic-metadata">

**Author:** [@Piyumitha\_Nirman](https://discuss.elastic.co/u/Piyumitha_Nirman)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 5:53pm UTC](https://discuss.elastic.co/t/elasticerach-8-5-1-version-image-gives-this-error-curl-52-empty-reply-from-server/336614 "2023-06-21T17:53:56Z")

</div>

I used Elasticsearch 8.5.1 image for my Kubernetes cluster. After installing using the helm chart pod is running correctly. but when I tried to check Elasticsearch cluster healthiness. it gave this error. curl 127.0.0.1:…

---

## [Different versions of ELK cluster](https://discuss.elastic.co/t/different-versions-of-elk-cluster/336486)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 5\
**Last updated:** [June 21, 2023, 3:58pm UTC](https://discuss.elastic.co/t/different-versions-of-elk-cluster/336486 "2023-06-21T15:58:30Z")

</div>

Hi All, I was able to create a working cluster using variety of product versions. Please let me know if this is ok: Filebeat: 7.6.2 Logstash: 8.6.2 Elasticsearch: 8.7.0 Kibana: 8.5.3 Thanks in advance!

---

## [Elastic Agent for Windows - visibility of Docker Containers in Kibana](https://discuss.elastic.co/t/elastic-agent-for-windows-visibility-of-docker-containers-in-kibana/336597)

<div class="topic-metadata">

**Author:** [@JackBurton](https://discuss.elastic.co/u/JackBurton)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 3:48pm UTC](https://discuss.elastic.co/t/elastic-agent-for-windows-visibility-of-docker-containers-in-kibana/336597 "2023-06-21T15:48:39Z")

</div>

Hi, we are trialing a move to Fleet and the Elastic Agent. Everything looks good for Linux Hosts, but with our Windows one if I look at Observability \> Infrastructure \> Inventory, filter for the hosts and then select 'Sh…

---

## [Can I disable the ML controller?](https://discuss.elastic.co/t/can-i-disable-the-ml-controller/336206)

<div class="topic-metadata">

**Author:** [@theistian](https://discuss.elastic.co/u/theistian)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 3:31pm UTC](https://discuss.elastic.co/t/can-i-disable-the-ml-controller/336206 "2023-06-21T15:31:07Z")

</div>

Hi! I'm configuring an ES 8 cluster, and I'm not interested in the ML capabilities so I'm disabling them using xpack.ml.enabled: false But when I start the node I still can see the process /usr/share/elasticsearch/mod…

---

## [Unable to drop specific event code data using Kibana pipeline](https://discuss.elastic.co/t/unable-to-drop-specific-event-code-data-using-kibana-pipeline/336601)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 3:28pm UTC](https://discuss.elastic.co/t/unable-to-drop-specific-event-code-data-using-kibana-pipeline/336601 "2023-06-21T15:28:41Z")

</div>

Hi, I'm using Elasticsearch 8.1.2. Elastic agent type: winlogbeat Elastic agent version: 7.14.2 Currently I'm getting data from this Elastic agent. I tried to drop some event code using ingest pipeline that is config…

---

## [Not able to restart kibana](https://discuss.elastic.co/t/not-able-to-restart-kibana/336576)

<div class="topic-metadata">

**Author:** [@Samir\_Pawar](https://discuss.elastic.co/u/Samir_Pawar)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 3:20pm UTC](https://discuss.elastic.co/t/not-able-to-restart-kibana/336576 "2023-06-21T15:20:51Z")

</div>

Elasticsearch vesrion is 6.8. Elasticsearch install in GCP compute engine.

---

## [ES Index Rate drops after every few hours](https://discuss.elastic.co/t/es-index-rate-drops-after-every-few-hours/336540)

<div class="topic-metadata">

**Author:** [@mukularora89](https://discuss.elastic.co/u/mukularora89)\
**Replies:** 10\
**Last updated:** [June 21, 2023, 2:48pm UTC](https://discuss.elastic.co/t/es-index-rate-drops-after-every-few-hours/336540 "2023-06-21T14:48:51Z")

</div>

Hi, We are observing a drop in ES index rate after every few hours. We have indexes created on daily basis and data is pushed into ES from logstash. In a day we expect 8 billion documents pushed to given day index. At t…

---

## [Fleet Server Agent Communication issue](https://discuss.elastic.co/t/fleet-server-agent-communication-issue/336599)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 2:43pm UTC](https://discuss.elastic.co/t/fleet-server-agent-communication-issue/336599 "2023-06-21T14:43:25Z")

</div>

My fleet server and agents have become unhealthy and are presenting me with this error elastic\_agent\]\[warn\] Possible transient error during checkin with fleet-server, retrying \[elastic\_agent\]\[error\] Checkin request to …

---

## [Logstash docker-compose non root user](https://discuss.elastic.co/t/logstash-docker-compose-non-root-user/336598)

<div class="topic-metadata">

**Author:** [@maehue](https://discuss.elastic.co/u/maehue)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 2:41pm UTC](https://discuss.elastic.co/t/logstash-docker-compose-non-root-user/336598 "2023-06-21T14:41:07Z")

</div>

To date we have been running logstash 7.16.2 as a non-root user in docker using a docker-compose configuration similar to below: version: 3.3 services: logstash: image: logstash:7.16.2 user: 10002:1001 …

---

## [Elasticsearch code=exited, status=1/FAILURE](https://discuss.elastic.co/t/elasticsearch-code-exited-status-1-failure/336595)

<div class="topic-metadata">

**Author:** [@codepan](https://discuss.elastic.co/u/codepan)\
**Replies:** 4\
**Last updated:** [June 21, 2023, 2:23pm UTC](https://discuss.elastic.co/t/elasticsearch-code-exited-status-1-failure/336595 "2023-06-21T14:23:24Z")

</div>

Fiz a instalação do Elastic 8 no CentOs, mas o mesmo falha ao iniciar. systemctl status elasticsearch ● elasticsearch.service - Elasticsearch Loaded: loaded (/etc/systemd/system/elasticsearch.service; enabled; vendo…

---

## [No access to kibana role management UI](https://discuss.elastic.co/t/no-access-to-kibana-role-management-ui/336286)

<div class="topic-metadata">

**Author:** [@Calvy93](https://discuss.elastic.co/u/Calvy93)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 12:58pm UTC](https://discuss.elastic.co/t/no-access-to-kibana-role-management-ui/336286 "2023-06-21T12:58:54Z")

</div>

Hello everyone, I'm currently setting up the ELK-Stack + Filebeat and for the first configuration, I try to do without SSL as that was way too troublesome for a prototype when I first tried to implement it in every part…

---

## [Snapshot and restore using shared file system](https://discuss.elastic.co/t/snapshot-and-restore-using-shared-file-system/336365)

<div class="topic-metadata">

**Author:** [@Sann](https://discuss.elastic.co/u/Sann)\
**Replies:** 8\
**Last updated:** [June 21, 2023, 12:19pm UTC](https://discuss.elastic.co/t/snapshot-and-restore-using-shared-file-system/336365 "2023-06-21T12:19:19Z")

</div>

When using a cluster with more than one node is not enough to create local folders for shared fs repo. you need smb/nfs mounted drive because each node will check the "repo" and if there is no communication between nodes…

---

## [Does Edge Ngram Token filter creates Synonym for tokens?](https://discuss.elastic.co/t/does-edge-ngram-token-filter-creates-synonym-for-tokens/336572)

<div class="topic-metadata">

**Author:** [@Farnaz](https://discuss.elastic.co/u/Farnaz)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 12:03pm UTC](https://discuss.elastic.co/t/does-edge-ngram-token-filter-creates-synonym-for-tokens/336572 "2023-06-21T12:03:42Z")

</div>

ave added Edge Ngram Token Filter to my analyzer, ngram\_back\_fa. Here is my analyzer: "ngram\_back\_fa": { "tokenizer": "standard", "filter": \[ "lowercase", …

---

## [Elasticsearch and Hive integration failure with es-hadoop-connector 8.8.1](https://discuss.elastic.co/t/elasticsearch-and-hive-integration-failure-with-es-hadoop-connector-8-8-1/336423)

<div class="topic-metadata">

**Author:** [@Bob\_Dorous](https://discuss.elastic.co/u/Bob_Dorous)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 10:49am UTC](https://discuss.elastic.co/t/elasticsearch-and-hive-integration-failure-with-es-hadoop-connector-8-8-1/336423 "2023-06-21T10:49:43Z")

</div>

Hi there, I am trying to set up the newest release Elasticsearch (8.8.1) as a single-node service on an Ubuntu Azure VM and write and read to it with Hive 3.10+ on Hadoop HDInsight cluster (hortonworks based). For the …

---

## [Top hits aggregation does not work on nested object](https://discuss.elastic.co/t/top-hits-aggregation-does-not-work-on-nested-object/336347)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 10:29am UTC](https://discuss.elastic.co/t/top-hits-aggregation-does-not-work-on-nested-object/336347 "2023-06-21T10:29:19Z")

</div>

Hi all, This is my nested object field And, I manually update the mapping like this And, this is how my top\_hit query look like Lastly, this is the query response I expected it should be return the entir…

---

## [Migration from ES 6.8 to 7.17 : Issues with negative date epoch timestamp](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259)

<div class="topic-metadata">

**Author:** [@Abhilashsr2008](https://discuss.elastic.co/u/Abhilashsr2008)\
**Replies:** 7\
**Last updated:** [June 21, 2023, 10:19am UTC](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259 "2023-06-21T10:19:06Z")

</div>

Hi Guys We are migrating our applications from 6.8 ES cluster to 7.17.10 ES cluster . The one thing which we identified is that the negative values are not supported for date type fields( "format": "epoch\_millis") . Is …

---

## [Create Rule API not working](https://discuss.elastic.co/t/create-rule-api-not-working/335228)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 10:17am UTC](https://discuss.elastic.co/t/create-rule-api-not-working/335228 "2023-06-21T10:17:32Z")

</div>

Hi I'm a bit struggling using the Rules creation API I'm trying to create a "rule\_type\_id":".es-query". In the parameters it asks me for the \`"es-Query"', I tried to use the triple quotes but it gives me an error tha…

---

## [Kibana to Elastic search communication is ending up with failure](https://discuss.elastic.co/t/kibana-to-elastic-search-communication-is-ending-up-with-failure/336438)

<div class="topic-metadata">

**Author:** [@Deepaklal\_KB](https://discuss.elastic.co/u/Deepaklal_KB)\
**Replies:** 5\
**Last updated:** [June 21, 2023, 9:42am UTC](https://discuss.elastic.co/t/kibana-to-elastic-search-communication-is-ending-up-with-failure/336438 "2023-06-21T09:42:23Z")

</div>

Getting an error as ünable to get issuer certificate in kibana logs once after starting the service. I am using DigicertCA.crt file to communicate with mu Elastic server LB. Which is a SAN certificate. This is happening…

---

## [CVE-2022-1471 is not listed in Security Issues site](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/336553)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 8:38am UTC](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/336553 "2023-06-21T08:38:33Z")

</div>

Is there any fix for that in any Logstash version? Is there any plan to update the damaged package of snakeyaml 1.31=\>2.0? Can I manually change the snakeyaml version? if so then how?

---

## [Elasitc-Agent APM integration on Kubernetes](https://discuss.elastic.co/t/elasitc-agent-apm-integration-on-kubernetes/336552)

<div class="topic-metadata">

**Author:** [@Piotr\_Pietka](https://discuss.elastic.co/u/Piotr_Pietka)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 8:26am UTC](https://discuss.elastic.co/t/elasitc-agent-apm-integration-on-kubernetes/336552 "2023-06-21T08:26:44Z")

</div>

Hi, I've got deployed elastic-agents on kubernetes (rancher in my case). How to use APM integration to make it accessible to pods in cluster? Do I need to manualy create service or is that accessible by default? What is…

---

## [If condition loop on array](https://discuss.elastic.co/t/if-condition-loop-on-array/336518)

<div class="topic-metadata">

**Author:** [@plus](https://discuss.elastic.co/u/plus)\
**Replies:** 3\
**Last updated:** [June 21, 2023, 8:22am UTC](https://discuss.elastic.co/t/if-condition-loop-on-array/336518 "2023-06-21T08:22:29Z")

</div>

{ Hello, I was reading several posts how to loop through with array but I don't know how to iterate on each value and then rename. I tried with split but it creates a document for each value ( I want a doc with all val…

---

## [Why a cancelled task is still on the list?](https://discuss.elastic.co/t/why-a-cancelled-task-is-still-on-the-list/336413)

<div class="topic-metadata">

**Author:** [@HyebinHong](https://discuss.elastic.co/u/HyebinHong)\
**Replies:** 7\
**Last updated:** [June 21, 2023, 8:15am UTC](https://discuss.elastic.co/t/why-a-cancelled-task-is-still-on-the-list/336413 "2023-06-21T08:15:45Z")

</div>

Hello, elastic! While running multiple msearch API through Java clients, I found one of the tasks took abnormally long. So I executed Task Cancel API, but it doesn't seem cleanup properly. When I check the task via Ta…

---

## [java.util.concurrent.ExecutionException: ElasticsearchException\[java.util.concurrent.ExecutionException: CircuitBreakingException\[\[fielddata\] Data too large, data for \[apiVersion\] would be \[20659632080/19.2gb\], which is larger than the limit of \[206158430](https://discuss.elastic.co/t/java-util-concurrent-executionexception-elasticsearchexception-java-util-concurrent-executionexception-circuitbreakingexception-fielddata-data-too-large-data-for-apiversion-would-be-20659632080-19-2gb-which-is-larger-than-the-limit-of-206158430/336549)

<div class="topic-metadata">

**Author:** [@agusbuddi](https://discuss.elastic.co/u/agusbuddi)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 8:05am UTC](https://discuss.elastic.co/t/java-util-concurrent-executionexception-elasticsearchexception-java-util-concurrent-executionexception-circuitbreakingexception-fielddata-data-too-large-data-for-apiversion-would-be-20659632080-19-2gb-which-is-larger-than-the-limit-of-206158430/336549 "2023-06-21T08:05:40Z")

</div>

java.util.concurrent.ExecutionException: ElasticsearchException\[java.util.concurrent.ExecutionException: CircuitBreakingException\[\[fielddata\] Data too large, data for \[apiVersion\] would be \[20659632080/19.2gb\], which is …

---

## [How to clean all the identites from Sailpoint?](https://discuss.elastic.co/t/how-to-clean-all-the-identites-from-sailpoint/336146)

<div class="topic-metadata">

**Author:** [@srikanth\_bollu](https://discuss.elastic.co/u/srikanth_bollu)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 7:41am UTC](https://discuss.elastic.co/t/how-to-clean-all-the-identites-from-sailpoint/336146 "2023-06-21T07:41:41Z")

</div>

I want to clean all the identities and their accounts roles etc associated with identities. Is there any way to bulk delete sailpoint?

---

## [Workflow - ServiceNow](https://discuss.elastic.co/t/workflow-servicenow/336535)

<div class="topic-metadata">

**Author:** [@srikanth\_bollu](https://discuss.elastic.co/u/srikanth_bollu)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 7:40am UTC](https://discuss.elastic.co/t/workflow-servicenow/336535 "2023-06-21T07:40:44Z")

</div>

I'm new to ServiceNow and followed this tutorial Workflow for ServiceNow Incidents to create a simple workflow for an approval request. The steps that I took on studio of my developer instance: Created an application …

---

## [How to get Distinct results using Search API](https://discuss.elastic.co/t/how-to-get-distinct-results-using-search-api/336215)

<div class="topic-metadata">

**Author:** [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Replies:** 4\
**Last updated:** [June 21, 2023, 7:38am UTC](https://discuss.elastic.co/t/how-to-get-distinct-results-using-search-api/336215 "2023-06-21T07:38:07Z")

</div>

I have a "customer" index with fields "FirstName" and "LastName". My index contains data as follows: First Name | LastName Richard | Lockwood Richard | Lockwood 2 Richard | Lockwood 3 Richard | Lockwood 4 Richard …

---

## [Issue with Custom Nginx Ingest Pipeline in Elasticsearch 8.7](https://discuss.elastic.co/t/issue-with-custom-nginx-ingest-pipeline-in-elasticsearch-8-7/336543)

<div class="topic-metadata">

**Author:** [@MIDHUN\_KRISHNA](https://discuss.elastic.co/u/MIDHUN_KRISHNA)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 7:32am UTC](https://discuss.elastic.co/t/issue-with-custom-nginx-ingest-pipeline-in-elasticsearch-8-7/336543 "2023-06-21T07:32:57Z")

</div>

I'm currently facing an issue with Elasticsearch 8.7, specifically with the integration of Nginx logs and custom ingest pipelines. I have successfully installed Fleet Server with Elastic Agent, along with the Nginx integ…

---

## [API call to fetch kibana dashboard along with data in json format](https://discuss.elastic.co/t/api-call-to-fetch-kibana-dashboard-along-with-data-in-json-format/335940)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 7:15am UTC](https://discuss.elastic.co/t/api-call-to-fetch-kibana-dashboard-along-with-data-in-json-format/335940 "2023-06-21T07:15:17Z")

</div>

Hi, I am trying to generate the json file for kibana dashboard. I am trying this command but this gives me only the dashboard of the design. How can i get the data? curl -X GET 'http://demo.icebreaker.minutuscloud.com/…

---

## [Append a string to a field after mutate convert filter](https://discuss.elastic.co/t/append-a-string-to-a-field-after-mutate-convert-filter/336327)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 3\
**Last updated:** [June 21, 2023, 7:14am UTC](https://discuss.elastic.co/t/append-a-string-to-a-field-after-mutate-convert-filter/336327 "2023-06-21T07:14:11Z")

</div>

Hi I have the following log pattern \[19/Jun/2023:11:27:35 +0530\] | 503 | 1188 ms | 299 B | 172.31.40.179 | - | - | - | "GET /3dcomment/monitoring/healthcheck HTTP/1.1" I have applied grok to fetch the bytes field i.e 2…

---

## [Error in indexing polygon data in Elasticsearch 8.8](https://discuss.elastic.co/t/error-in-indexing-polygon-data-in-elasticsearch-8-8/335335)

<div class="topic-metadata">

**Author:** [@amal\_antony](https://discuss.elastic.co/u/amal_antony)\
**Replies:** 6\
**Last updated:** [June 21, 2023, 6:00am UTC](https://discuss.elastic.co/t/error-in-indexing-polygon-data-in-elasticsearch-8-8/335335 "2023-06-21T06:00:53Z")

</div>

Greetings to the community! I am experiencing issues while ingesting polygon data into Elasticsearch 8.8. An issue had been raised before in the same context, link. This was identified as a bug in Lucene, the fix for wh…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=502)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=504)
