# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=533

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 534

---

## [How to view inner IP packet detail](https://discuss.elastic.co/t/how-to-view-inner-ip-packet-detail/334267)

<div class="topic-metadata">

**Author:** [@a\_techie](https://discuss.elastic.co/u/a_techie)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 4:50am UTC](https://discuss.elastic.co/t/how-to-view-inner-ip-packet-detail/334267 "2023-05-25T04:50:21Z")

</div>

Hello, We send flow data from network gears to Elasticsearch. There are packets that are encapsulated in another IP header. For example, please refer: CS Enterprise on cloudshark.org In the flow data search using Kiban…

---

## [Calculate percentage based on other aggregation](https://discuss.elastic.co/t/calculate-percentage-based-on-other-aggregation/334264)

<div class="topic-metadata">

**Author:** [@Wanching\_Teoh](https://discuss.elastic.co/u/Wanching_Teoh)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 4:21am UTC](https://discuss.elastic.co/t/calculate-percentage-based-on-other-aggregation/334264 "2023-05-25T04:21:53Z")

</div>

Hi, I am using data table to display the API response for 200, 4xx and 5xx errors. I need to calculate percentage of 4xx and 5xx errors based on the grand total count of all response types. Any idea on how to do this o…

---

## [I am getting the error in elasticsearch Rollup jobs](https://discuss.elastic.co/t/i-am-getting-the-error-in-elasticsearch-rollup-jobs/334262)

<div class="topic-metadata">

**Author:** [@daemon](https://discuss.elastic.co/u/daemon)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 12:32am UTC](https://discuss.elastic.co/t/i-am-getting-the-error-in-elasticsearch-rollup-jobs/334262 "2023-05-25T00:32:24Z")

</div>

I am getting the error in Kibana Rollup Jobs screen as shown in the image. Is there any solution?

---

## [Logstash plugin is installed and not listed and found by logstash](https://discuss.elastic.co/t/logstash-plugin-is-installed-and-not-listed-and-found-by-logstash/333595)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 5\
**Last updated:** [May 23, 2023, 9:24pm UTC](https://discuss.elastic.co/t/logstash-plugin-is-installed-and-not-listed-and-found-by-logstash/333595 "2023-05-23T21:24:34Z")

</div>

Hi Team, Microsoft-sentinel-logstash-output-plugin is installed on logstash (7.15.1) server Linux but is not listed and found by logstash : /usr/share/logstash/bin #./logstash-plugin list Plugin successfully install…

---

## [Installing Elastic Cloud Enterprise Offline](https://discuss.elastic.co/t/installing-elastic-cloud-enterprise-offline/334240)

<div class="topic-metadata">

**Author:** [@geomandry](https://discuss.elastic.co/u/geomandry)\
**Replies:** 3\
**Last updated:** [May 24, 2023, 4:25pm UTC](https://discuss.elastic.co/t/installing-elastic-cloud-enterprise-offline/334240 "2023-05-24T16:25:30Z")

</div>

There are too many documents! Can someone reply with the correct guides for installing Elastic Cloud Enterprise offline on a Linux box?

---

## [COPY - PASTE from KIBANA without “ROW” and “COLUMN” information - 2](https://discuss.elastic.co/t/copy-paste-from-kibana-without-row-and-column-information-2/334026)

<div class="topic-metadata">

**Author:** [@mch](https://discuss.elastic.co/u/mch)\
**Replies:** 3\
**Last updated:** [May 24, 2023, 2:57pm UTC](https://discuss.elastic.co/t/copy-paste-from-kibana-without-row-and-column-information-2/334026 "2023-05-24T14:57:41Z")

</div>

Hello everyone, I have the same problem as described in the following ticket: COPY - PASTE from KIBANA without "ROW" and "COLUMN" information It's a real pain to export the selection we're interested in every time, whe…

---

## [How can I handle typos in synonyms?](https://discuss.elastic.co/t/how-can-i-handle-typos-in-synonyms/334141)

<div class="topic-metadata">

**Author:** [@gennadii](https://discuss.elastic.co/u/gennadii)\
**Replies:** 12\
**Last updated:** [May 24, 2023, 2:54pm UTC](https://discuss.elastic.co/t/how-can-i-handle-typos-in-synonyms/334141 "2023-05-24T14:54:38Z")

</div>

I have synonyms in synonyms.txt - "auto, vehicle =\> car". In index I have a document with string "car" and an analyzer to handle synonyms. When you use "auto", for example, it will also return you results for "car". B…

---

## [Date Range filter is not working ? NEST C# MVC.NET](https://discuss.elastic.co/t/date-range-filter-is-not-working-nest-c-mvc-net/334129)

<div class="topic-metadata">

**Author:** [@Samer\_Abdelwahed](https://discuss.elastic.co/u/Samer_Abdelwahed)\
**Replies:** 5\
**Last updated:** [May 24, 2023, 2:48pm UTC](https://discuss.elastic.co/t/date-range-filter-is-not-working-nest-c-mvc-net/334129 "2023-05-24T14:48:28Z")

</div>

hi every one Why date Range filter is not working in my code: public static DateRangeQuery GetSearchFromDate(int DayFrom, int DayTo, int MonthFrom, int MonthTo, int YearFrom, int YearTo, string fieldName) …

---

## [Not able to stop the tasks in devtool (Kibana)](https://discuss.elastic.co/t/not-able-to-stop-the-tasks-in-devtool-kibana/333857)

<div class="topic-metadata">

**Author:** [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 2:36pm UTC](https://discuss.elastic.co/t/not-able-to-stop-the-tasks-in-devtool-kibana/333857 "2023-05-24T14:36:43Z")

</div>

1.Firstly, "delete by query" was run. it exhausted 100 % of disk space, then I tried POST /\_forcemerge after adding more disk space but this space is also getting consumed rapidly can I cancel the tasks which are …

---

## [Corrupt index in Logstash causing primary shard is not active](https://discuss.elastic.co/t/corrupt-index-in-logstash-causing-primary-shard-is-not-active/334229)

<div class="topic-metadata">

**Author:** [@Vaibhav\_Aher](https://discuss.elastic.co/u/Vaibhav_Aher)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 2:34pm UTC](https://discuss.elastic.co/t/corrupt-index-in-logstash-causing-primary-shard-is-not-active/334229 "2023-05-24T14:34:19Z")

</div>

Elasticsearch Version- opendistroforelasticsearch-1.4.0 Logstash Version - logstash-7.4.2 Error on Logstash: retrying failed action with response code: 503 ({"type"=\>"unavailable\_shards\_exception", "reason"=\>"\[ABC-20…

---

## [Time zone abbr is ambigous which cause @timestamp parsed wrong \[for Postgresql module\]](https://discuss.elastic.co/t/time-zone-abbr-is-ambigous-which-cause-timestamp-parsed-wrong-for-postgresql-module/333863)

<div class="topic-metadata">

**Author:** [@yanhj93](https://discuss.elastic.co/u/yanhj93)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 2:33pm UTC](https://discuss.elastic.co/t/time-zone-abbr-is-ambigous-which-cause-timestamp-parsed-wrong-for-postgresql-module/333863 "2023-05-24T14:33:13Z")

</div>

Our postgre server log with timezone CST, in this case it represents China standard time. pipeline(module provid) will parse the log message and read timezone value use WORD pattern, finally date processor parse the tim…

---

## [Elasticsearch Get All data which has specified value for some of the field](https://discuss.elastic.co/t/elasticsearch-get-all-data-which-has-specified-value-for-some-of-the-field/334201)

<div class="topic-metadata">

**Author:** [@Mustafa\_AYDOGDU](https://discuss.elastic.co/u/Mustafa_AYDOGDU)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 2:22pm UTC](https://discuss.elastic.co/t/elasticsearch-get-all-data-which-has-specified-value-for-some-of-the-field/334201 "2023-05-24T14:22:57Z")

</div>

Hello, I have a query which gets data with project\_id=1 and project\_user\_id=1: GET /tweet\_user\_id\_index/\_search { "query": { "bool": { "should": \[ { "term": { "project\_id": { …

---

## ['\_source' filtering is slower than query without '\_source' field](https://discuss.elastic.co/t/source-filtering-is-slower-than-query-without-source-field/333556)

<div class="topic-metadata">

**Author:** [@nadeem.akhter](https://discuss.elastic.co/u/nadeem.akhter)\
**Replies:** 7\
**Last updated:** [May 24, 2023, 2:17pm UTC](https://discuss.elastic.co/t/source-filtering-is-slower-than-query-without-source-field/333556 "2023-05-24T14:17:17Z")

</div>

I have an elasticsearch instance with some data on it, and when trying queries on the data, it is slower to filter '\_source' in query than not mentioning the '\_source' key at all. Is there any specific reason for this? P…

---

## [Writing PySpark dataframe to Elastic Cloud (Cannot detect ES version)](https://discuss.elastic.co/t/writing-pyspark-dataframe-to-elastic-cloud-cannot-detect-es-version/334176)

<div class="topic-metadata">

**Author:** [@Dmytro\_Ostapchuk](https://discuss.elastic.co/u/Dmytro_Ostapchuk)\
**Replies:** 6\
**Last updated:** [May 24, 2023, 2:06pm UTC](https://discuss.elastic.co/t/writing-pyspark-dataframe-to-elastic-cloud-cannot-detect-es-version/334176 "2023-05-24T14:06:12Z")

</div>

Hi there! My use case Run PySpark job on EMR Serverless that reads data from S3 and writes it into Elastic cloud. Errors Cannot detect ES version - typically this happens if the network/Elasticsearch cluster is not a…

---

## [Filebeat not sending logs to elasticsearch](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-elasticsearch/334106)

<div class="topic-metadata">

**Author:** [@mohammad\_messiah](https://discuss.elastic.co/u/mohammad_messiah)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 1:47pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-logs-to-elasticsearch/334106 "2023-05-24T13:47:04Z")

</div>

Filebeat not sending logs to elasticsearch. Tried restart of elasticstack, reinstall of filebeat agent on few nodes, renaming the registry files to force index rebuild, removing lock file under /var/lib/filebeat but noth…

---

## [Unable to create index with %{type} in logstash output](https://discuss.elastic.co/t/unable-to-create-index-with-type-in-logstash-output/334079)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 1:18pm UTC](https://discuss.elastic.co/t/unable-to-create-index-with-type-in-logstash-output/334079 "2023-05-24T13:18:10Z")

</div>

Hi here is my logstash config file input { beats { port =\> 5044 } } output { elasticsearch { hosts =\> "http://IP:9200" index =\> "%{type}%{+YYYY.MM.dd}" user =\> "elastic" password =\> "pwd" } …

---

## [Need Watcher configuration and settings ElasticSearch yml](https://discuss.elastic.co/t/need-watcher-configuration-and-settings-elasticsearch-yml/330291)

<div class="topic-metadata">

**Author:** [@Praveen\_kr](https://discuss.elastic.co/u/Praveen_kr)\
**Replies:** 20\
**Last updated:** [May 24, 2023, 1:11pm UTC](https://discuss.elastic.co/t/need-watcher-configuration-and-settings-elasticsearch-yml/330291 "2023-05-24T13:11:06Z")

</div>

Hi Team, , Anyone one Could you please help me with the watcher configuration elasticsearch yml setup as we have 13 nodes I need to add the watcher settings to send a mail alert (outlook). Challenges what am facing her…

---

## [.kibana\_task\_manager UNASSIGNED ALLOCATION\_FAILED](https://discuss.elastic.co/t/kibana-task-manager-unassigned-allocation-failed/334211)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 11:44am UTC](https://discuss.elastic.co/t/kibana-task-manager-unassigned-allocation-failed/334211 "2023-05-24T11:44:27Z")

</div>

I have a single node (without a cluster of several machines) that had an uncontrolled reboot due to power failure. How can I fix this problem? kibana\[4428\]: no\_shard\_available\_action\_exception: null'. Re…

---

## [Kibana Error - Failed to open PIT](https://discuss.elastic.co/t/kibana-error-failed-to-open-pit/334166)

<div class="topic-metadata">

**Author:** [@Yos](https://discuss.elastic.co/u/Yos)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 12:16pm UTC](https://discuss.elastic.co/t/kibana-error-failed-to-open-pit/334166 "2023-05-24T12:16:39Z")

</div>

Kibana Version : 8.5.3 Hello The following error is intermittently logged in Kibana's logs Please let me know the cause of this and how to address it. Best Regards \[2023-05-24T11:30:54.572+09:00\]\[ERROR\]\[savedobject…

---

## [NiFi flow not able to write into Elasticsearch because of exceeding maximum shards](https://discuss.elastic.co/t/nifi-flow-not-able-to-write-into-elasticsearch-because-of-exceeding-maximum-shards/334204)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 3\
**Last updated:** [May 24, 2023, 10:52am UTC](https://discuss.elastic.co/t/nifi-flow-not-able-to-write-into-elasticsearch-because-of-exceeding-maximum-shards/334204 "2023-05-24T10:52:49Z")

</div>

I have only one node elasticsearch at my cluster. I'm trying to write into elasticsearch using PutElasticsearchHttp control at my NiFi flow but I get an error: 2023-05-24 07:00:17,347 ERROR \[Timer-Driven Process Thread-…

---

## [Sending all elasticsearch logs to a diode](https://discuss.elastic.co/t/sending-all-elasticsearch-logs-to-a-diode/334207)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 10:49am UTC](https://discuss.elastic.co/t/sending-all-elasticsearch-logs-to-a-diode/334207 "2023-05-24T10:49:57Z")

</div>

Hi there, I am completing some dev work and trying to input all of the ingested elasticsearch data from my system, into logstash (on the same server as elasticsearch) and output this to a one way data diode to allow the…

---

## [Cluster State Yellow: 2 shards initializing with multiple failed attempts: IllegalArgumentException \[ReleasableBytesStreamOutput cannot hold more than 2GB of data](https://discuss.elastic.co/t/cluster-state-yellow-2-shards-initializing-with-multiple-failed-attempts-illegalargumentexception-releasablebytesstreamoutput-cannot-hold-more-than-2gb-of-data/334008)

<div class="topic-metadata">

**Author:** [@Sarit\_Ghosh](https://discuss.elastic.co/u/Sarit_Ghosh)\
**Replies:** 5\
**Last updated:** [May 24, 2023, 9:43am UTC](https://discuss.elastic.co/t/cluster-state-yellow-2-shards-initializing-with-multiple-failed-attempts-illegalargumentexception-releasablebytesstreamoutput-cannot-hold-more-than-2gb-of-data/334008 "2023-05-24T09:43:51Z")

</div>

For about a week, we are seeing the following error and cluster state yellow. On checking the \_cluster/state we get this - Elastic Search Version - 7.17 (Please let me know if more data is needed) {"state":"INITIALIZIN…

---

## [Service unavailable error code 503 all shard failed](https://discuss.elastic.co/t/service-unavailable-error-code-503-all-shard-failed/333976)

<div class="topic-metadata">

**Author:** [@target\_test](https://discuss.elastic.co/u/target_test)\
**Replies:** 11\
**Last updated:** [May 24, 2023, 9:30am UTC](https://discuss.elastic.co/t/service-unavailable-error-code-503-all-shard-failed/333976 "2023-05-24T09:30:24Z")

</div>

Hello all, I got this problem showing that service unavailable {"statusCode":503,"error":"Service Unavailable","message":"\[all shards failed: search\_phase\_execution\_exception\\n\\tRoot causes:\\n\\t\\tno\_shard\_available\_act…

---

## [Same Query different results in .NET client](https://discuss.elastic.co/t/same-query-different-results-in-net-client/334180)

<div class="topic-metadata">

**Author:** [@LhamoDev](https://discuss.elastic.co/u/LhamoDev)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 9:25am UTC](https://discuss.elastic.co/t/same-query-different-results-in-net-client/334180 "2023-05-24T09:25:01Z")

</div>

Hello, I've been working on a query that can search a Document from my reservation index, These Reservations has a "SequenceId" on which thesearch query works with. This is the format of the ID: LLL-0000-000000 Produ…

---

## [How to show several docs with the same field?](https://discuss.elastic.co/t/how-to-show-several-docs-with-the-same-field/334198)

<div class="topic-metadata">

**Author:** [@asebalo98](https://discuss.elastic.co/u/asebalo98)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 9:20am UTC](https://discuss.elastic.co/t/how-to-show-several-docs-with-the-same-field/334198 "2023-05-24T09:20:52Z")

</div>

I have documents that have a ”CompanyId” field that can be the same for multiple documents. I want Elasticsearch to take up to 3 documents with the same “CompanyId” and the highest score, and then rank them in the overa…

---

## [Warm tier shards being allocated to data nodes](https://discuss.elastic.co/t/warm-tier-shards-being-allocated-to-data-nodes/334136)

<div class="topic-metadata">

**Author:** [@Mirko\_Katunar](https://discuss.elastic.co/u/Mirko_Katunar)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 8:18am UTC](https://discuss.elastic.co/t/warm-tier-shards-being-allocated-to-data-nodes/334136 "2023-05-24T08:18:29Z")

</div>

Hello, I have a hot, warm architecture and 3 master nodes that are also data nodes. At some point Elastic started to allocate data stream shards that are in warm tier to master/data nodes. As plain data node can fill a…

---

## [How to find openssl Version](https://discuss.elastic.co/t/how-to-find-openssl-version/334038)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 8:08am UTC](https://discuss.elastic.co/t/how-to-find-openssl-version/334038 "2023-05-24T08:08:43Z")

</div>

Hello Team, Does Elasticsearch use openssl when using the SSL / TLS protocol? If so, where can I find the version of openssl? Regards Kannan P

---

## [Pytorch\_inference silenty disappear during reindex using pretrained machine learning model](https://discuss.elastic.co/t/pytorch-inference-silenty-disappear-during-reindex-using-pretrained-machine-learning-model/330896)

<div class="topic-metadata">

**Author:** [@tomotaka](https://discuss.elastic.co/u/tomotaka)\
**Replies:** 4\
**Last updated:** [May 24, 2023, 8:05am UTC](https://discuss.elastic.co/t/pytorch-inference-silenty-disappear-during-reindex-using-pretrained-machine-learning-model/330896 "2023-05-24T08:05:57Z")

</div>

We are planning to build a vector-based search application with pretrained machine learning model which is based on mBERT model. So now I wrote some code to check how Elasticsearch works and I found that pytorch\_inferen…

---

## [How to get list of documents created by reindex API in destination index](https://discuss.elastic.co/t/how-to-get-list-of-documents-created-by-reindex-api-in-destination-index/333540)

<div class="topic-metadata">

**Author:** [@Sumeet\_Koli](https://discuss.elastic.co/u/Sumeet_Koli)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 6:44am UTC](https://discuss.elastic.co/t/how-to-get-list-of-documents-created-by-reindex-api-in-destination-index/333540 "2023-05-24T06:44:27Z")

</div>

I have a query around the reindex API . Is there a way to get a list of all the documents created by the reindex API in the destination index? Context: I am using the reindex API to migrate a few indices from a remote …

---

## [Sending logs from Filebeat(windows) to Logstash(Linux)](https://discuss.elastic.co/t/sending-logs-from-filebeat-windows-to-logstash-linux/334112)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 6:18am UTC](https://discuss.elastic.co/t/sending-logs-from-filebeat-windows-to-logstash-linux/334112 "2023-05-24T06:18:57Z")

</div>

Hi, I have installed filebeat on windows machine and configured it to send logs to logstash. Here is my filebeat config filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=532)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=534)
