# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=516

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 517

---

## [Kibana - TypeError: Failed to fetch](https://discuss.elastic.co/t/kibana-typeerror-failed-to-fetch/335612)

<div class="topic-metadata">

**Author:** [@YaroslavSh](https://discuss.elastic.co/u/YaroslavSh)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 10:10am UTC](https://discuss.elastic.co/t/kibana-typeerror-failed-to-fetch/335612 "2023-06-09T10:10:45Z")

</div>

Hi. I cannot find referenced anywhere. I was wondering if anyone has come across this? An internal server error occurred. Version: 7.17.7 Build: 47059 Error at fetch\_Fetch.fetchResponse (https://development-kibana.…

---

## [How to limit logs ingestion into Elastic?](https://discuss.elastic.co/t/how-to-limit-logs-ingestion-into-elastic/335527)

<div class="topic-metadata">

**Author:** [@irshadalam](https://discuss.elastic.co/u/irshadalam)\
**Replies:** 4\
**Last updated:** [June 9, 2023, 9:40am UTC](https://discuss.elastic.co/t/how-to-limit-logs-ingestion-into-elastic/335527 "2023-06-09T09:40:55Z")

</div>

How to limit logs ingestion into Elastic ?

---

## [Filebeat failed to start](https://discuss.elastic.co/t/filebeat-failed-to-start/335601)

<div class="topic-metadata">

**Author:** [@Terkea](https://discuss.elastic.co/u/Terkea)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 9:20am UTC](https://discuss.elastic.co/t/filebeat-failed-to-start/335601 "2023-06-09T09:20:46Z")

</div>

Hello guys, I have been struggling for quite some time with my filebeat setup. I have installed filebeat 7.10 on an ubuntu instance. Somehow part of the logs were sent to my cluster, but now when I check the systemctl …

---

## [What can go wrong in ES cluster without replicas](https://discuss.elastic.co/t/what-can-go-wrong-in-es-cluster-without-replicas/335595)

<div class="topic-metadata">

**Author:** [@Don\_Boscow](https://discuss.elastic.co/u/Don_Boscow)\
**Replies:** 6\
**Last updated:** [June 9, 2023, 9:19am UTC](https://discuss.elastic.co/t/what-can-go-wrong-in-es-cluster-without-replicas/335595 "2023-06-09T09:19:03Z")

</div>

Hi, the typical paradigm in ES is that sharding involves replica nodes, which serve two main purposes - act as a backup, so that in case one shard or one node is down, its replica continues to provide the same data until…

---

## [Single Elasticsearch node abruptly ran out of disk space (possibly due to a giant temp file)](https://discuss.elastic.co/t/single-elasticsearch-node-abruptly-ran-out-of-disk-space-possibly-due-to-a-giant-temp-file/335515)

<div class="topic-metadata">

**Author:** [@username11](https://discuss.elastic.co/u/username11)\
**Replies:** 5\
**Last updated:** [June 9, 2023, 6:21am UTC](https://discuss.elastic.co/t/single-elasticsearch-node-abruptly-ran-out-of-disk-space-possibly-due-to-a-giant-temp-file/335515 "2023-06-09T06:21:30Z")

</div>

Hi. I have recently observed that one of our Elasticsearch nodes ran out of disk space and fell out of the cluster. Upon investigating it, I found several things that are very, very weird about this situation: I haven'…

---

## [Elasticsearch user dictionary space include](https://discuss.elastic.co/t/elasticsearch-user-dictionary-space-include/335588)

<div class="topic-metadata">

**Author:** [@dms6978](https://discuss.elastic.co/u/dms6978)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 6:07am UTC](https://discuss.elastic.co/t/elasticsearch-user-dictionary-space-include/335588 "2023-06-09T06:07:15Z")

</div>

Hello. I have problem with Nori user dictionary. I want to register words that include space, but it's not working. I tried to register in the dictionary by including words in double quotes or even in small quotes, but…

---

## [Kibana uses Client Side rendering or Server Side rendereing](https://discuss.elastic.co/t/kibana-uses-client-side-rendering-or-server-side-rendereing/335586)

<div class="topic-metadata">

**Author:** [@Suleman\_Ahmed](https://discuss.elastic.co/u/Suleman_Ahmed)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 5:34am UTC](https://discuss.elastic.co/t/kibana-uses-client-side-rendering-or-server-side-rendereing/335586 "2023-06-09T05:34:46Z")

</div>

I am new to kibana and trying to understand that when highlight or search some text from logs, Kibana uses server side react rendering or client side react rendering and/or is there any way to reduce load on server side …

---

## [Minimum Permission to run ElasticSearch as windows service](https://discuss.elastic.co/t/minimum-permission-to-run-elasticsearch-as-windows-service/335581)

<div class="topic-metadata">

**Author:** [@mochammad.yusup](https://discuss.elastic.co/u/mochammad.yusup)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 1:09am UTC](https://discuss.elastic.co/t/minimum-permission-to-run-elasticsearch-as-windows-service/335581 "2023-06-09T01:09:50Z")

</div>

Hi, I would like to know what's the minimum permission of an account that is used to run Elasticsearch Windows Service. My client actually asked this question and I don't know the answer as there's nothing in the docume…

---

## [Heap usage holds steady at max and GC does not run. Need to force restart the cluster](https://discuss.elastic.co/t/heap-usage-holds-steady-at-max-and-gc-does-not-run-need-to-force-restart-the-cluster/335176)

<div class="topic-metadata">

**Author:** [@Jorge\_Eguiguren](https://discuss.elastic.co/u/Jorge_Eguiguren)\
**Replies:** 4\
**Last updated:** [June 8, 2023, 11:53pm UTC](https://discuss.elastic.co/t/heap-usage-holds-steady-at-max-and-gc-does-not-run-need-to-force-restart-the-cluster/335176 "2023-06-08T23:53:39Z")

</div>

Cluster configuration: 3 Nodes GET \_nodes/\_all/jvm Elasticsearch version: 7.10.1 Java version: 15.0.1 gc\_collectors: \[ "G1 Young Generation", "G1 Old Generation"\] heap\_max\_in\_bytes: 30064771072 (30 GB) Circuit bre…

---

## [Connecting Winlogbeat with pfsense](https://discuss.elastic.co/t/connecting-winlogbeat-with-pfsense/334811)

<div class="topic-metadata">

**Author:** [@mariya](https://discuss.elastic.co/u/mariya)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 11:07pm UTC](https://discuss.elastic.co/t/connecting-winlogbeat-with-pfsense/334811 "2023-06-08T23:07:14Z")

</div>

Hi ! I have set up a CentOS virtual machine running ELK server. Also in vmware I installed Windows virtual machine with Winlogbeat, and a pfSense virtual machine. I want to configure Winlogbeat to send Windows logs to Lo…

---

## [Sending stdout and stderr to different elasticsearch hosts and kibana](https://discuss.elastic.co/t/sending-stdout-and-stderr-to-different-elasticsearch-hosts-and-kibana/335445)

<div class="topic-metadata">

**Author:** [@Shobana\_Nagarajan](https://discuss.elastic.co/u/Shobana_Nagarajan)\
**Replies:** 3\
**Last updated:** [June 8, 2023, 10:51pm UTC](https://discuss.elastic.co/t/sending-stdout-and-stderr-to-different-elasticsearch-hosts-and-kibana/335445 "2023-06-08T22:51:22Z")

</div>

Hi, I have a requirement to send stdout and stderr to different Elastic and Kibana hosts. I have deployed two filebeat containers. Here are my filebeat.yml. 1.filebeat.stdout.yml filebeat.config: modules: path: …

---

## [Failed to flush export bulks, Caused by: 413 Request Entity Too Large](https://discuss.elastic.co/t/failed-to-flush-export-bulks-caused-by-413-request-entity-too-large/335272)

<div class="topic-metadata">

**Author:** [@vikasp](https://discuss.elastic.co/u/vikasp)\
**Replies:** 3\
**Last updated:** [June 8, 2023, 10:26pm UTC](https://discuss.elastic.co/t/failed-to-flush-export-bulks-caused-by-413-request-entity-too-large/335272 "2023-06-08T22:26:28Z")

</div>

I have elasticsearch monitoring enabled via setting: xpack.monitoring.collection.enabled: true, and logstash and kibana, or any other beats sends their monitoring data to the elastic cluster which forwards/exports all t…

---

## [Removing extra characters in Grok](https://discuss.elastic.co/t/removing-extra-characters-in-grok/335375)

<div class="topic-metadata">

**Author:** [@Datt\_Mamon](https://discuss.elastic.co/u/Datt_Mamon)\
**Replies:** 5\
**Last updated:** [June 8, 2023, 9:27pm UTC](https://discuss.elastic.co/t/removing-extra-characters-in-grok/335375 "2023-06-08T21:27:11Z")

</div>

Hello, I am converting an original windows event log from json to syslog at the Logstash server. Here is a partial output: \<13\>May 31 14:27:55 {"name":'TEST'} LOGSTASH\[-\]: 2023-05-31T14:27:55.283Z {name=TEST} Permissi…

---

## [Logstash, remove all fields that contain a specific value](https://discuss.elastic.co/t/logstash-remove-all-fields-that-contain-a-specific-value/335569)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 9:21pm UTC](https://discuss.elastic.co/t/logstash-remove-all-fields-that-contain-a-specific-value/335569 "2023-06-08T21:21:54Z")

</div>

how to remove all fields that contain a specific value or reg expression

---

## [Display data in 2nd index based dashboard based on 1st index value](https://discuss.elastic.co/t/display-data-in-2nd-index-based-dashboard-based-on-1st-index-value/335525)

<div class="topic-metadata">

**Author:** [@RahulWagh](https://discuss.elastic.co/u/RahulWagh)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 8:29pm UTC](https://discuss.elastic.co/t/display-data-in-2nd-index-based-dashboard-based-on-1st-index-value/335525 "2023-06-08T20:29:56Z")

</div>

Hi, I have first index based on which filter control is created. It contains 1st field year-month and 2nd field contains date based on year-month selection. I have created 2nd index that contains completely different d…

---

## [ELSER - Elastic Learned Sparse EncodeR model is unable using Trial License](https://discuss.elastic.co/t/elser-elastic-learned-sparse-encoder-model-is-unable-using-trial-license/334643)

<div class="topic-metadata">

**Author:** [@Rahul\_Agarwal1](https://discuss.elastic.co/u/Rahul_Agarwal1)\
**Replies:** 8\
**Last updated:** [June 8, 2023, 7:21pm UTC](https://discuss.elastic.co/t/elser-elastic-learned-sparse-encoder-model-is-unable-using-trial-license/334643 "2023-06-08T19:21:18Z")

</div>

I want to play with the new ELSER model released by Elasticsearch in new release 8.8. I tried installing Elasticsearch 8.8 in my local system and tried with the trial license but the model is not available under: Stack M…

---

## [Active-Active Cross Cluster Replication](https://discuss.elastic.co/t/active-active-cross-cluster-replication/335562)

<div class="topic-metadata">

**Author:** [@vmummadi](https://discuss.elastic.co/u/vmummadi)\
**Replies:** 0\
**Last updated:** [June 8, 2023, 5:30pm UTC](https://discuss.elastic.co/t/active-active-cross-cluster-replication/335562 "2023-06-08T17:30:21Z")

</div>

Hi, We have 2 Elasticsearch clusters that has been deployed on 2 different regions in an active-standby mode. The CCR has been enabled on one another so that any index that gets created on leader is replicated on the fo…

---

## [Can someone guide me where can I find prometheus exporter for Elasticsearch version 7.17.10](https://discuss.elastic.co/t/can-someone-guide-me-where-can-i-find-prometheus-exporter-for-elasticsearch-version-7-17-10/335549)

<div class="topic-metadata">

**Author:** [@Jasmine\_Blooms](https://discuss.elastic.co/u/Jasmine_Blooms)\
**Replies:** 2\
**Last updated:** [June 8, 2023, 5:38pm UTC](https://discuss.elastic.co/t/can-someone-guide-me-where-can-i-find-prometheus-exporter-for-elasticsearch-version-7-17-10/335549 "2023-06-08T17:38:50Z")

</div>

Hi All, We are trying to integrate prometheus exporter plugin in elasticsearch for health and monitoring and I could find Releases · vvanholl/elasticsearch-prometheus-exporter · GitHub which has 7.17.7 as the latest ver…

---

## [How do I get a list of search results?](https://discuss.elastic.co/t/how-do-i-get-a-list-of-search-results/335541)

<div class="topic-metadata">

**Author:** [@Nad.Chel](https://discuss.elastic.co/u/Nad.Chel)\
**Replies:** 4\
**Last updated:** [June 8, 2023, 4:17pm UTC](https://discuss.elastic.co/t/how-do-i-get-a-list-of-search-results/335541 "2023-06-08T16:17:20Z")

</div>

I honestly tried to read the official tutorials. Unfortunately, I got completely bogged down: I find them hard to understand and they don't appear to give me the very specific information I need which is: how do I get a L…

---

## [Defender\_atp module error message](https://discuss.elastic.co/t/defender-atp-module-error-message/335551)

<div class="topic-metadata">

**Author:** [@phager](https://discuss.elastic.co/u/phager)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 3:43pm UTC](https://discuss.elastic.co/t/defender-atp-module-error-message/335551 "2023-06-08T15:43:24Z")

</div>

I have Filebeat configured with defender atp module and am seeing very few valid records coming into Elasticsearch. Most records contain the following cannot access method/field \[length\] from a null def reference Can a…

---

## [I cant add an agent](https://discuss.elastic.co/t/i-cant-add-an-agent/335547)

<div class="topic-metadata">

**Author:** [@Charnpreet\_Singh](https://discuss.elastic.co/u/Charnpreet_Singh)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 3:41pm UTC](https://discuss.elastic.co/t/i-cant-add-an-agent/335547 "2023-06-08T15:41:38Z")

</div>

I am trying to enroll agent onto my fleet server, the server is live but whenever I try to connect my agent it doesn't work. I keep encountering the same error ,{"log.level":"warn","@timestamp":"2023-06-06T19:28:55.258+…

---

## [Auditbeat inputs question](https://discuss.elastic.co/t/auditbeat-inputs-question/335328)

<div class="topic-metadata">

**Author:** [@zaheerabbas1988](https://discuss.elastic.co/u/zaheerabbas1988)\
**Replies:** 2\
**Last updated:** [June 8, 2023, 3:37pm UTC](https://discuss.elastic.co/t/auditbeat-inputs-question/335328 "2023-06-08T15:37:51Z")

</div>

Hello ELK community, I have a scenario where I need to input a specific log file into Auditbeat. In Filebeat, I can achieve this easily by configuring the log file path in the filebeat.inputs section. However, I was won…

---

## [Extract certain fields from JSON](https://discuss.elastic.co/t/extract-certain-fields-from-json/335487)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 4\
**Last updated:** [June 8, 2023, 3:33pm UTC](https://discuss.elastic.co/t/extract-certain-fields-from-json/335487 "2023-06-08T15:33:48Z")

</div>

Hi, I am forwarding filebeat logs to an ES, and I would like to only extract certain fields in the JSON message and write them to ES. For example, if I have the JSON message below: { "field1": "info", "field2":…

---

## [Index\_not\_found\_exception Root causes: index\_not\_found\_exception: no such index \[apm-\*\]](https://discuss.elastic.co/t/index-not-found-exception-root-causes-index-not-found-exception-no-such-index-apm/335463)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 6\
**Last updated:** [June 8, 2023, 3:25pm UTC](https://discuss.elastic.co/t/index-not-found-exception-root-causes-index-not-found-exception-no-such-index-apm/335463 "2023-06-08T15:25:44Z")

</div>

I get this error in Kibana and cannot trace the root or find a simple resolution. Checked all the views.... thinking of just creating it, but would like to know where it is trying to be called. Using traces-apm-default f…

---

## [How to change elasticsearch.slowlog.id?](https://discuss.elastic.co/t/how-to-change-elasticsearch-slowlog-id/335184)

<div class="topic-metadata">

**Author:** [@Ghouneim](https://discuss.elastic.co/u/Ghouneim)\
**Replies:** 3\
**Last updated:** [June 8, 2023, 3:25pm UTC](https://discuss.elastic.co/t/how-to-change-elasticsearch-slowlog-id/335184 "2023-06-08T15:25:07Z")

</div>

Hello, I want to be able to track the user who send the \_bulk request for indexing some data so I am trying to use X-Opaque-Id in bulk requests to be displayed in \*\_index\_indexing\_slowlog.json but I always get a differe…

---

## [Extract value from a field using painless script](https://discuss.elastic.co/t/extract-value-from-a-field-using-painless-script/335343)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [June 8, 2023, 2:50pm UTC](https://discuss.elastic.co/t/extract-value-from-a-field-using-painless-script/335343 "2023-06-08T14:50:05Z")

</div>

Hi there, i have a use case and i want to try it using painless. so the use case is there is a field containing a valid json and i want to extract just one field from it. basically it's a bit like using grok. the field …

---

## [/etc/elasticsearch/certs/ - 3 files](https://discuss.elastic.co/t/etc-elasticsearch-certs-3-files/335459)

<div class="topic-metadata">

**Author:** [@Timberwolve77](https://discuss.elastic.co/u/Timberwolve77)\
**Replies:** 5\
**Last updated:** [June 8, 2023, 2:52pm UTC](https://discuss.elastic.co/t/etc-elasticsearch-certs-3-files/335459 "2023-06-08T14:52:57Z")

</div>

I saw there is a directory /etc/elasticsearch/certs/ and inside there are three files: http\_ca.crt, http.p12 and transport.p12. What if these files were deleted? Is there a way to generate new ones?

---

## [Increased memory requirements for geo search queries in Elasticsearch 8](https://discuss.elastic.co/t/increased-memory-requirements-for-geo-search-queries-in-elasticsearch-8/334594)

<div class="topic-metadata">

**Author:** [@Tomas\_Bartek](https://discuss.elastic.co/u/Tomas_Bartek)\
**Replies:** 15\
**Last updated:** [June 8, 2023, 2:33pm UTC](https://discuss.elastic.co/t/increased-memory-requirements-for-geo-search-queries-in-elasticsearch-8/334594 "2023-06-08T14:33:30Z")

</div>

After upgrading from Elasticsearch 7.17.10 to Elasticsearch 8.7.1, our geosearch workloads started to hit memory circuitbreaker leading to the unstable cluster (cluster rejecting requests which leads to degradation of …

---

## [Export-csv doesn't work for a big size of data v7.17.0](https://discuss.elastic.co/t/export-csv-doesnt-work-for-a-big-size-of-data-v7-17-0/334653)

<div class="topic-metadata">

**Author:** [@mounah](https://discuss.elastic.co/u/mounah)\
**Replies:** 4\
**Last updated:** [June 8, 2023, 1:43pm UTC](https://discuss.elastic.co/t/export-csv-doesnt-work-for-a-big-size-of-data-v7-17-0/334653 "2023-06-08T13:43:45Z")

</div>

Hello, Can you help me resolve an issue generating a CSV? CSV download failed We couldn't generate your CSV at this time. For a small amount of data, it works, but when we try to download a large amount of data, I re…

---

## [ElasticSearch rest-high-level client compatibility and licensing](https://discuss.elastic.co/t/elasticsearch-rest-high-level-client-compatibility-and-licensing/335471)

<div class="topic-metadata">

**Author:** [@Nikita\_Bratukhin](https://discuss.elastic.co/u/Nikita_Bratukhin)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 1:35pm UTC](https://discuss.elastic.co/t/elasticsearch-rest-high-level-client-compatibility-and-licensing/335471 "2023-06-08T13:35:24Z")

</div>

Hello! I faced the problem the same as in this issue : stackoverflow/a/74102828 We would like to use newer ES client with old ES cluster( in order to gracefully migrate everything). But es client validates X-Elastic-P…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=515)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=517)
