# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=510

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 511

---

## [Search.max\_async\_search\_response\_size](https://discuss.elastic.co/t/search-max-async-search-response-size/336060)

<div class="topic-metadata">

**Author:** [@pavlod](https://discuss.elastic.co/u/pavlod)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 8:39am UTC](https://discuss.elastic.co/t/search-max-async-search-response-size/336060 "2023-06-15T08:39:09Z")

</div>

Hi! I got the mistake: Can't store an async search response larger than \[10485760\] bytes. This limit can be set by changing the \[search.max\_async\_search\_response\_size\] setting. I have a Deployment in Elastic.co (Elast…

---

## [Does versions of logstash\>7.3.0 support addKeyValue() in the slf4j fluent API?](https://discuss.elastic.co/t/does-versions-of-logstash-7-3-0-support-addkeyvalue-in-the-slf4j-fluent-api/336058)

<div class="topic-metadata">

**Author:** [@Steinar\_Bang](https://discuss.elastic.co/u/Steinar_Bang)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 8:23am UTC](https://discuss.elastic.co/t/does-versions-of-logstash-7-3-0-support-addkeyvalue-in-the-slf4j-fluent-api/336058 "2023-06-15T08:23:38Z")

</div>

I just discovered slf4j's fluent API yesterday, and tried to use it. Unfortunately the key/value pairs I added with addKeyValue() in slf4j 2.0.7/logstash 7.3.0 were lost from the output. I had hoped for at least the de…

---

## [Unable to launch Kibana Portal](https://discuss.elastic.co/t/unable-to-launch-kibana-portal/336056)

<div class="topic-metadata">

**Author:** [@rohit.tps123](https://discuss.elastic.co/u/rohit.tps123)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 8:19am UTC](https://discuss.elastic.co/t/unable-to-launch-kibana-portal/336056 "2023-06-15T08:19:38Z")

</div>

Hi I am not able to launch the Kibana portal. although I all the 3 ELK containers are up . I have check the logs, no error is showing up. Can anyone please help. Attaching the log files Kibana Logs sudo podman log…

---

## [Query task running for over 17shours](https://discuss.elastic.co/t/query-task-running-for-over-17shours/336054)

<div class="topic-metadata">

**Author:** [@fanqiaoqing](https://discuss.elastic.co/u/fanqiaoqing)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 8:17am UTC](https://discuss.elastic.co/t/query-task-running-for-over-17shours/336054 "2023-06-15T08:17:26Z")

</div>

Hi elasticsearch, We found that some tasks had been executed for a long time without completion. You can see this task has been running for 17 hours. { "completed" : false, "task" : { "node" : "cpzJKvmdQM-lIj2…

---

## [Is it possible to setup kibana and multiple elastic nodes in a secure network without TLS, and use token authentication?](https://discuss.elastic.co/t/is-it-possible-to-setup-kibana-and-multiple-elastic-nodes-in-a-secure-network-without-tls-and-use-token-authentication/335998)

<div class="topic-metadata">

**Author:** [@Wpq](https://discuss.elastic.co/u/Wpq)\
**Replies:** 4\
**Last updated:** [June 15, 2023, 7:55am UTC](https://discuss.elastic.co/t/is-it-possible-to-setup-kibana-and-multiple-elastic-nodes-in-a-secure-network-without-tls-and-use-token-authentication/335998 "2023-06-15T07:55:04Z")

</div>

I have a dedicated docker engine for my ELK stack. It is composed of a caddy web server that proxifies traffic to kibana and the elastic nodes exposes a HTTPS endpoint for both services to the "external world" My i…

---

## [Upgrading Elasticsearch and Kibana running on Kubernetes from 7.12.0 to 7.17.10](https://discuss.elastic.co/t/upgrading-elasticsearch-and-kibana-running-on-kubernetes-from-7-12-0-to-7-17-10/336050)

<div class="topic-metadata">

**Author:** [@kuber\_netes](https://discuss.elastic.co/u/kuber_netes)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 7:52am UTC](https://discuss.elastic.co/t/upgrading-elasticsearch-and-kibana-running-on-kubernetes-from-7-12-0-to-7-17-10/336050 "2023-06-15T07:52:39Z")

</div>

I am trying to upgrade my cluster to latest supported image and I am having issues. According to Elastic documentation I should be able to upgrade directly from any version between 7.0–7.16 to 7.17.10, yet when I tried…

---

## [Elastic Agent Cloudwatch is not fetching all data](https://discuss.elastic.co/t/elastic-agent-cloudwatch-is-not-fetching-all-data/336047)

<div class="topic-metadata">

**Author:** [@slogger](https://discuss.elastic.co/u/slogger)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 7:21am UTC](https://discuss.elastic.co/t/elastic-agent-cloudwatch-is-not-fetching-all-data/336047 "2023-06-15T07:21:11Z")

</div>

Hello I have our elastic agents collecting metrics about a MSK Kafka cluster using the following config: - namespace: AWS/Kafka And I am filtering by eu-central-1 Thats it. It used to work 100%, but now it is not pu…

---

## [Exists does not seem to work for Object type fields](https://discuss.elastic.co/t/exists-does-not-seem-to-work-for-object-type-fields/336042)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 2\
**Last updated:** [June 15, 2023, 6:59am UTC](https://discuss.elastic.co/t/exists-does-not-seem-to-work-for-object-type-fields/336042 "2023-06-15T06:59:26Z")

</div>

Hi, so my query looks like this { "query": { "bool": { "must\_not": \[ { "exists": { "field": "custom\_fields" } …

---

## [If I omit an field from Document can i still search documents where field is not present](https://discuss.elastic.co/t/if-i-omit-an-field-from-document-can-i-still-search-documents-where-field-is-not-present/336037)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 5:07am UTC](https://discuss.elastic.co/t/if-i-omit-an-field-from-document-can-i-still-search-documents-where-field-is-not-present/336037 "2023-06-15T05:07:01Z")

</div>

Hi @Christian\_Dahlqvist, so I re mentioned omit the field from document. So my query regarding this is can I perform searches like: Give me the list / aggregate of documents where a field is not present?

---

## [Enriching log data with database or other sources](https://discuss.elastic.co/t/enriching-log-data-with-database-or-other-sources/336016)

<div class="topic-metadata">

**Author:** [@Tomahawk](https://discuss.elastic.co/u/Tomahawk)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 2:27am UTC](https://discuss.elastic.co/t/enriching-log-data-with-database-or-other-sources/336016 "2023-06-15T02:27:02Z")

</div>

Hey, I could use some help please. I have two questions I have log data coming in (Log4J, Log4Net etc etc) and this contains a user ID, for example “12345” I want to enrich each log line with more information about th…

---

## [PKCS#12 vs PEM for Elastic Cluster](https://discuss.elastic.co/t/pkcs-12-vs-pem-for-elastic-cluster/336001)

<div class="topic-metadata">

**Author:** [@algo](https://discuss.elastic.co/u/algo)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 2:08am UTC](https://discuss.elastic.co/t/pkcs-12-vs-pem-for-elastic-cluster/336001 "2023-06-15T02:08:21Z")

</div>

I am running a cluster on 7.17 and am looking at updating the TLS certs for internode communication. Currently, I'm using PEM certs for this, but I saw that the documentation for both setting up basic security and updati…

---

## [seqNo generation strategy - seqNo question](https://discuss.elastic.co/t/seqno-generation-strategy-seqno-question/336027)

<div class="topic-metadata">

**Author:** [@SnowFlakeLeaf](https://discuss.elastic.co/u/SnowFlakeLeaf)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 2:06am UTC](https://discuss.elastic.co/t/seqno-generation-strategy-seqno-question/336027 "2023-06-15T02:06:24Z")

</div>

The source of the problem is that we request in multiple concurrent modification in production in a lot of the same document VersionConflictEngineException, And we didn't include if\_seq\_no in the request, so we wanted to…

---

## [How to calculate the user growth rate in Kibana?](https://discuss.elastic.co/t/how-to-calculate-the-user-growth-rate-in-kibana/335945)

<div class="topic-metadata">

**Author:** [@Amber](https://discuss.elastic.co/u/Amber)\
**Replies:** 2\
**Last updated:** [June 15, 2023, 1:12am UTC](https://discuss.elastic.co/t/how-to-calculate-the-user-growth-rate-in-kibana/335945 "2023-06-15T01:12:05Z")

</div>

How can I make a growth rate from Kibana, searched for all the posted discuss, I find it could be implemented in TSVB, but I still cannot figure out how to make it... Here is my idea: I want to make day as the inter…

---

## [Stack Monitoring problem after update Elasticsearch](https://discuss.elastic.co/t/stack-monitoring-problem-after-update-elasticsearch/335991)

<div class="topic-metadata">

**Author:** [@freeman999](https://discuss.elastic.co/u/freeman999)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 1:06am UTC](https://discuss.elastic.co/t/stack-monitoring-problem-after-update-elasticsearch/335991 "2023-06-15T01:06:27Z")

</div>

Hello everyone, Stack Monitoring doesn't work after I've updated elasticsearch from 7.10.1 to 7.17.10 at all cluster nodes I get an error: Monitoring Request Error \[illegal\_argument\_exception\] node \[prod-elk-data-3\] …

---

## [How to create multiple separate index using single conf file in logstash through filebeat?](https://discuss.elastic.co/t/how-to-create-multiple-separate-index-using-single-conf-file-in-logstash-through-filebeat/335949)

<div class="topic-metadata">

**Author:** [@KRISHNA\_KUMAR1](https://discuss.elastic.co/u/KRISHNA_KUMAR1)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 12:49am UTC](https://discuss.elastic.co/t/how-to-create-multiple-separate-index-using-single-conf-file-in-logstash-through-filebeat/335949 "2023-06-15T00:49:24Z")

</div>

Hi, I want to create separate indices based on the condition of the logs, for example if my log consist of api1 then it should create index named "api1" and if it consist api2 then create another index named "api2". Pl…

---

## [Cannot setup Kibana with SSL](https://discuss.elastic.co/t/cannot-setup-kibana-with-ssl/335997)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 8:02pm UTC](https://discuss.elastic.co/t/cannot-setup-kibana-with-ssl/335997 "2023-06-14T20:02:19Z")

</div>

Hello. I am trying to change my Kibana setup to SSL. But I could not achieve it. What am I missing here? server.host: "HOSTIP" server.publicBaseUrl: "https://HOST:5601" server.ssl.enabled: true server.ssl.certificate: …

---

## [Runtime field field conversion problem,](https://discuss.elastic.co/t/runtime-field-field-conversion-problem/336013)

<div class="topic-metadata">

**Author:** [@rexxdad](https://discuss.elastic.co/u/rexxdad)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 9:34pm UTC](https://discuss.elastic.co/t/runtime-field-field-conversion-problem/336013 "2023-06-14T21:34:45Z")

</div>

followup on I found one other thing, . when the data is long ""longitude":-99.628611894415343,"latitude":37.463502579397019 the painless script has trouble figuring out what data type it is.. "script…

---

## [Update elasticsearch from 7.15 to 7.17 version](https://discuss.elastic.co/t/update-elasticsearch-from-7-15-to-7-17-version/336006)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 8:49pm UTC](https://discuss.elastic.co/t/update-elasticsearch-from-7-15-to-7-17-version/336006 "2023-06-14T20:49:09Z")

</div>

Hi, I'm migrating elasticsearch from 7.15 to 7.17 version and i want to ensure that the jvm options is it correct this way : the java version is: openjdk version "1.8.0\_372" pl\_elasticstack::params::jvm\_options: \[ '-…

---

## [Filebeat send logs to different port](https://discuss.elastic.co/t/filebeat-send-logs-to-different-port/335729)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 9\
**Last updated:** [June 14, 2023, 8:40pm UTC](https://discuss.elastic.co/t/filebeat-send-logs-to-different-port/335729 "2023-06-14T20:40:51Z")

</div>

Hi there, i have a question according to the title of this topic. if i have 8 logstash, then i config the filebeat to send the logs to 4 logstash using port 5045 and 5090 to another 4 logstash. is it possible? if yes, …

---

## [Kibana 8.8.0 - External plugins not running on Kibana Docker images (production)](https://discuss.elastic.co/t/kibana-8-8-0-external-plugins-not-running-on-kibana-docker-images-production/335555)

<div class="topic-metadata">

**Author:** [@brenoandrade](https://discuss.elastic.co/u/brenoandrade)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 8:08pm UTC](https://discuss.elastic.co/t/kibana-8-8-0-external-plugins-not-running-on-kibana-docker-images-production/335555 "2023-06-14T20:08:25Z")

</div>

hey, Kibana experts I'm experiencing an issue where external plugins are not able to run within Kibana Docker images. I have followed the necessary steps to set up an empty plugin using an open GraphQL API, the latest v…

---

## [Dev console suddenly just a blank canvas](https://discuss.elastic.co/t/dev-console-suddenly-just-a-blank-canvas/335981)

<div class="topic-metadata">

**Author:** [@supernat10](https://discuss.elastic.co/u/supernat10)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 8:00pm UTC](https://discuss.elastic.co/t/dev-console-suddenly-just-a-blank-canvas/335981 "2023-06-14T20:00:07Z")

</div>

This is the same issue as was reported in March but closed: Dev console suddenly just a blank canvas We are using Kibana 8.7.0 and have been for a couple of weeks without issue as we migrate from version 6. I use Chrom…

---

## [Kibana 8.8.8 external plugin failure](https://discuss.elastic.co/t/kibana-8-8-8-external-plugin-failure/335240)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 11\
**Last updated:** [June 14, 2023, 7:52pm UTC](https://discuss.elastic.co/t/kibana-8-8-8-external-plugin-failure/335240 "2023-06-14T19:52:00Z")

</div>

Hi we have upgraded our plugin from Kibana 8.6.2 to Kibana 8.8.0. We now get this error when launching the plugin from Kibana. We build like before using RUN BUILD\_TS\_REFS\_DISABLE=true yarn kbn bootstrap --no-cache --d…

---

## [Accuracy of the scores and rankings in ANN output](https://discuss.elastic.co/t/accuracy-of-the-scores-and-rankings-in-ann-output/336009)

<div class="topic-metadata">

**Author:** [@rajivhs](https://discuss.elastic.co/u/rajivhs)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 7:37pm UTC](https://discuss.elastic.co/t/accuracy-of-the-scores-and-rankings-in-ann-output/336009 "2023-06-14T19:37:26Z")

</div>

As per the ES8 documentation, when running an ANN query with k=100, Elastic will: Find the 100 closest neighbors, using the HNSW approximation Calculate each result's similarity and rank them using the specified simila…

---

## [ML Kibana: Clarification regarding the model change with "removed all seasonality" annotation text](https://discuss.elastic.co/t/ml-kibana-clarification-regarding-the-model-change-with-removed-all-seasonality-annotation-text/335309)

<div class="topic-metadata">

**Author:** [@c\_rox](https://discuss.elastic.co/u/c_rox)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 7:34pm UTC](https://discuss.elastic.co/t/ml-kibana-clarification-regarding-the-model-change-with-removed-all-seasonality-annotation-text/335309 "2023-06-14T19:34:19Z")

</div>

Hi, I have defined a machine learning with a high\_mean detector using both by\_field\_name and the partition\_field. But in last 3 weeks one of the dimention is started to behave differently and as expected machine learnin…

---

## [Rescoring the output of a knn-query hybrid retrieval](https://discuss.elastic.co/t/rescoring-the-output-of-a-knn-query-hybrid-retrieval/336008)

<div class="topic-metadata">

**Author:** [@rajivhs](https://discuss.elastic.co/u/rajivhs)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 6:58pm UTC](https://discuss.elastic.co/t/rescoring-the-output-of-a-knn-query-hybrid-retrieval/336008 "2023-06-14T18:58:07Z")

</div>

According to the kNN documentation: You can perform hybrid retrieval by providing both the knn option and a query. This search finds the global top k = 5 vector matches, combines them with the matches from the match qu…

---

## [Removing text qualifier double quotes from Logstash CSV output](https://discuss.elastic.co/t/removing-text-qualifier-double-quotes-from-logstash-csv-output/335990)

<div class="topic-metadata">

**Author:** [@mhoward](https://discuss.elastic.co/u/mhoward)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 6:35pm UTC](https://discuss.elastic.co/t/removing-text-qualifier-double-quotes-from-logstash-csv-output/335990 "2023-06-14T18:35:18Z")

</div>

Not sure if possible but I'm creating a CSV using Logstash. When I open the CSV in Notepad++ it adds double quotations around one specific field. The field itself is a city state zip code field that is created using a …

---

## [I can't reopen a closed index](https://discuss.elastic.co/t/i-cant-reopen-a-closed-index/335895)

<div class="topic-metadata">

**Author:** [@Hatef](https://discuss.elastic.co/u/Hatef)\
**Replies:** 8\
**Last updated:** [June 14, 2023, 6:34pm UTC](https://discuss.elastic.co/t/i-cant-reopen-a-closed-index/335895 "2023-06-14T18:34:15Z")

</div>

Hi all, I'm pretty new to ES but have played around with ELK stack a bit and I'm more familiar now to run some API queries and modifying configs. I have closed an index called accelerate which is the main source of our…

---

## [Canvas filters - is it possible to filter a visualization](https://discuss.elastic.co/t/canvas-filters-is-it-possible-to-filter-a-visualization/334165)

<div class="topic-metadata">

**Author:** [@azulgrana](https://discuss.elastic.co/u/azulgrana)\
**Replies:** 5\
**Last updated:** [June 14, 2023, 6:11pm UTC](https://discuss.elastic.co/t/canvas-filters-is-it-possible-to-filter-a-visualization/334165 "2023-06-14T18:11:15Z")

</div>

Hi there, I'm playing with Canvas and I have particular use case where I need to place a filter on a kibana object to filter the data out by a range from 3 thru 5 (event severity), I don't want to modify the visualizati…

---

## [Advantages of getting data from Elastic using Python](https://discuss.elastic.co/t/advantages-of-getting-data-from-elastic-using-python/335118)

<div class="topic-metadata">

**Author:** [@Jeferson\_Schiavinato](https://discuss.elastic.co/u/Jeferson_Schiavinato)\
**Replies:** 3\
**Last updated:** [June 14, 2023, 5:16pm UTC](https://discuss.elastic.co/t/advantages-of-getting-data-from-elastic-using-python/335118 "2023-06-14T17:16:31Z")

</div>

Hello guys, I am a begginer at ELK and I am studying elasticsearch package in python. I have a shell script which reads large logs, extract data and send them to Zabbix. Theses large log files are now at Elasticsearch. …

---

## [Is there a way to convert a unicode escape sequence within the Logstash pipeline so that the actual emoji icon is show within Elastic?](https://discuss.elastic.co/t/is-there-a-way-to-convert-a-unicode-escape-sequence-within-the-logstash-pipeline-so-that-the-actual-emoji-icon-is-show-within-elastic/336002)

<div class="topic-metadata">

**Author:** [@farnazpatel](https://discuss.elastic.co/u/farnazpatel)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 5:04pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-convert-a-unicode-escape-sequence-within-the-logstash-pipeline-so-that-the-actual-emoji-icon-is-show-within-elastic/336002 "2023-06-14T17:04:38Z")

</div>

I am sending messages from Kafka in to Logstash and then through to Elastic, some of the messages contain emojis, these emojis are converted to Unicode escape characters when being stored in Kafka e.g. :blush: ---\> is c…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=509)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=511)
