# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=534

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 535

---

## [Should clause within nested query not giving results](https://discuss.elastic.co/t/should-clause-within-nested-query-not-giving-results/334167)

<div class="topic-metadata">

**Author:** [@discuss\_lipak](https://discuss.elastic.co/u/discuss_lipak)\
**Replies:** 0\
**Last updated:** [May 24, 2023, 5:07am UTC](https://discuss.elastic.co/t/should-clause-within-nested-query-not-giving-results/334167 "2023-05-24T05:07:40Z")

</div>

I am trying to retrieve a specific document with nested query on the identityLinks element. My requirement: either identityLinks.userId should match specific userid when identityLinks.type is "assignee" OR identityLin…

---

## [Using value from the returned documents and recalculating the score of the documents](https://discuss.elastic.co/t/using-value-from-the-returned-documents-and-recalculating-the-score-of-the-documents/334154)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 4:10am UTC](https://discuss.elastic.co/t/using-value-from-the-returned-documents-and-recalculating-the-score-of-the-documents/334154 "2023-05-24T04:10:01Z")

</div>

Hi, I have a use case where I need to perform a search request, then use a value from the returned documents in recalculating the score. Below is the example of returned documents for my search request { \_score: 1.7, \_…

---

## [How to resolve failed requests to ES database after rebuilding the site](https://discuss.elastic.co/t/how-to-resolve-failed-requests-to-es-database-after-rebuilding-the-site/333365)

<div class="topic-metadata">

**Author:** [@stan4o](https://discuss.elastic.co/u/stan4o)\
**Replies:** 4\
**Last updated:** [May 24, 2023, 1:54am UTC](https://discuss.elastic.co/t/how-to-resolve-failed-requests-to-es-database-after-rebuilding-the-site/333365 "2023-05-24T01:54:11Z")

</div>

After our website (system) was rebuilt on a new server (Digital Ocean) all the requests to the Elastic search are failing = we cannot access the Elastic search. How to resolve this issue? I am not a programmer. This is w…

---

## [Elasticsearch memory data ratio recommendations for logging use case](https://discuss.elastic.co/t/elasticsearch-memory-data-ratio-recommendations-for-logging-use-case/334076)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 6:15am UTC](https://discuss.elastic.co/t/elasticsearch-memory-data-ratio-recommendations-for-logging-use-case/334076 "2023-05-23T06:15:43Z")

</div>

Hello , I am planning to create an Elasticsearch Cluster for logging and metrics purpose I am using time-based indexes I want to calculate the optimal data nodes and shards this cluster requires The logs reach a maxi…

---

## [ElasticSearch NEST - Search Query Not Returning Expected Results](https://discuss.elastic.co/t/elasticsearch-nest-search-query-not-returning-expected-results/334160)

<div class="topic-metadata">

**Author:** [@mmobley](https://discuss.elastic.co/u/mmobley)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 10:12pm UTC](https://discuss.elastic.co/t/elasticsearch-nest-search-query-not-returning-expected-results/334160 "2023-05-23T22:12:41Z")

</div>

I'm working on a project that searches parts using Elasticsearch and NEST (7.x). Here's my Model (adjusted for simplicity): \[ElasticsearchType\] public class PartInfo { public string Make { get; set; } public str…

---

## [Write a RegEx to match the event pattern in log file](https://discuss.elastic.co/t/write-a-regex-to-match-the-event-pattern-in-log-file/334048)

<div class="topic-metadata">

**Author:** [@hamzeha](https://discuss.elastic.co/u/hamzeha)\
**Replies:** 1\
**Last updated:** [May 23, 2023, 9:31pm UTC](https://discuss.elastic.co/t/write-a-regex-to-match-the-event-pattern-in-log-file/334048 "2023-05-23T21:31:33Z")

</div>

Hi Everyone, I have application log file which contains the application requests and responses, the complete request and response looks like the below, I tried different patterns using RegEx but unfortunately without an…

---

## [Network Packet Capture integration still updates npcap](https://discuss.elastic.co/t/network-packet-capture-integration-still-updates-npcap/333659)

<div class="topic-metadata">

**Author:** [@jaegerschnitzel](https://discuss.elastic.co/u/jaegerschnitzel)\
**Replies:** 3\
**Last updated:** [May 23, 2023, 8:39pm UTC](https://discuss.elastic.co/t/network-packet-capture-integration-still-updates-npcap/333659 "2023-05-23T20:39:01Z")

</div>

Sorry for opening a third thread about npcap. The first and the second thread were closed in the meantime. We updated our servers to Elastic Agent 8.7.1 and Network Packet Capture integration 1.16.0. After that we roll…

---

## [Pipeline is running but index is not created at elasticsearch](https://discuss.elastic.co/t/pipeline-is-running-but-index-is-not-created-at-elasticsearch/333940)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 30\
**Last updated:** [May 23, 2023, 7:49pm UTC](https://discuss.elastic.co/t/pipeline-is-running-but-index-is-not-created-at-elasticsearch/333940 "2023-05-23T19:49:21Z")

</div>

I'm trying to create an index and loading one log file to Elasticsearch using logstash using below config: input { file { path =\> \["/mnt/c/databalanceInfo\_0.log"\] start\_position =\> "beginning" sincedb\_path =\> "…

---

## [How to increase queue capacity from 200 to 400?](https://discuss.elastic.co/t/how-to-increase-queue-capacity-from-200-to-400/333947)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 11\
**Last updated:** [May 23, 2023, 5:40pm UTC](https://discuss.elastic.co/t/how-to-increase-queue-capacity-from-200-to-400/333947 "2023-05-23T17:40:44Z")

</div>

How to increase queue capacity from 200 to 400?

---

## [Ruby API call when parser hit specific field](https://discuss.elastic.co/t/ruby-api-call-when-parser-hit-specific-field/334107)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 8\
**Last updated:** [May 23, 2023, 5:42pm UTC](https://discuss.elastic.co/t/ruby-api-call-when-parser-hit-specific-field/334107 "2023-05-23T17:42:03Z")

</div>

Hi, I'm trying to have Logstash make API call when it hits specific field using Ruby code but I'm unable to do so. Could someone smarter than me check what I'm doing wrong please? Ruby code: require 'uri' require 'net…

---

## [Micrometer metrics not showing on Kibana](https://discuss.elastic.co/t/micrometer-metrics-not-showing-on-kibana/334050)

<div class="topic-metadata">

**Author:** [@missael.denadai](https://discuss.elastic.co/u/missael.denadai)\
**Replies:** 2\
**Last updated:** [May 23, 2023, 5:15pm UTC](https://discuss.elastic.co/t/micrometer-metrics-not-showing-on-kibana/334050 "2023-05-23T17:15:35Z")

</div>

Hello, everyone. We are trying to make our Micronaut app push metrics to our APM server without using a Java agent. For that we are using this Elasticsearch Registry as the Micrometer metrics reporter. This lib first c…

---

## [Find 2 following ES entry](https://discuss.elastic.co/t/find-2-following-es-entry/334137)

<div class="topic-metadata">

**Author:** [@Kim2000](https://discuss.elastic.co/u/Kim2000)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 2:57pm UTC](https://discuss.elastic.co/t/find-2-following-es-entry/334137 "2023-05-23T14:57:02Z")

</div>

Hi, i have seen some info online about this and search about entity centric event but I can't figure out how to implement all of this. I am a newbie in the field. I am working with logstash and winlogbeat. I want to se…

---

## [Runtime Field Intermittently Working?](https://discuss.elastic.co/t/runtime-field-intermittently-working/334052)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 1\
**Last updated:** [May 23, 2023, 2:56pm UTC](https://discuss.elastic.co/t/runtime-field-intermittently-working/334052 "2023-05-23T14:56:32Z")

</div>

I've configured a runtime field in Kibana 8.7.1 under index template and named it drive.used emit(doc\['drive.capacity'\].value - doc\['drive.free'\].value) However, looking in Discover, the field doesn't always show up: …

---

## [Elastic license query](https://discuss.elastic.co/t/elastic-license-query/334120)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [May 23, 2023, 2:33pm UTC](https://discuss.elastic.co/t/elastic-license-query/334120 "2023-05-23T14:33:43Z")

</div>

Hello All, Can some please let me know when elastic paid/license is bought then license is bought only for elastic nodes or kibana as well. Though I use beats,logstash also,here license for these are not required.Curre…

---

## [: max virtual memory areas vm.max\_map\_count \[65530\] is too low, increase to at least \[262144\]](https://discuss.elastic.co/t/max-virtual-memory-areas-vm-max-map-count-65530-is-too-low-increase-to-at-least-262144/334132)

<div class="topic-metadata">

**Author:** [@Ramon\_Moraga](https://discuss.elastic.co/u/Ramon_Moraga)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 2:16pm UTC](https://discuss.elastic.co/t/max-virtual-memory-areas-vm-max-map-count-65530-is-too-low-increase-to-at-least-262144/334132 "2023-05-23T14:16:10Z")

</div>

I'm trying to mount elk in an aws ecs fargate container but I can't put the vm.max\_map\_count on it. And I get this error (bootstrap check failure \[1\] of \[1\]: max virtual memory areas vm.max\_map\_count \[65530\] is too low ,…

---

## [ES Transactions](https://discuss.elastic.co/t/es-transactions/334093)

<div class="topic-metadata">

**Author:** [@sajeeda](https://discuss.elastic.co/u/sajeeda)\
**Replies:** 6\
**Last updated:** [May 23, 2023, 2:10pm UTC](https://discuss.elastic.co/t/es-transactions/334093 "2023-05-23T14:10:16Z")

</div>

Hi All, I am trying to do an partial update on the document for 7 different process. i have been getting version control conflict. Is there a way where ES supports transactions so that there is no data loss. I do not wa…

---

## [Authentication using apikey failed](https://discuss.elastic.co/t/authentication-using-apikey-failed/333244)

<div class="topic-metadata">

**Author:** [@dmrlixos](https://discuss.elastic.co/u/dmrlixos)\
**Replies:** 5\
**Last updated:** [May 23, 2023, 2:08pm UTC](https://discuss.elastic.co/t/authentication-using-apikey-failed/333244 "2023-05-23T14:08:21Z")

</div>

Hi I have a cluster with 3 instances ( 1 Master 2 Data Nodes ) Recenty looking into my cluster, i found a lot of warnings about Authentication using apikey failed on specific apikey id EjkscocB14\*\*\*\*\*\*\*\* I try search…

---

## [How to manage array with dynamic\_templates](https://discuss.elastic.co/t/how-to-manage-array-with-dynamic-templates/334109)

<div class="topic-metadata">

**Author:** [@Julien\_Revol](https://discuss.elastic.co/u/Julien_Revol)\
**Replies:** 2\
**Last updated:** [May 23, 2023, 1:00pm UTC](https://discuss.elastic.co/t/how-to-manage-array-with-dynamic-templates/334109 "2023-05-23T13:00:42Z")

</div>

hello, i want to use dynamic mapping an manage array of object by making them defined as arrays. it works when i define the field directly: "tx.chargingSessionEvents": { "type": "nested" }, but i w…

---

## [Elasticsearch returns 10000 rows even when only ~100 documents are relevant](https://discuss.elastic.co/t/elasticsearch-returns-10000-rows-even-when-only-100-documents-are-relevant/332425)

<div class="topic-metadata">

**Author:** [@bonyolult](https://discuss.elastic.co/u/bonyolult)\
**Replies:** 5\
**Last updated:** [May 23, 2023, 1:00pm UTC](https://discuss.elastic.co/t/elasticsearch-returns-10000-rows-even-when-only-100-documents-are-relevant/332425 "2023-05-23T13:00:25Z")

</div>

Hello, i need some help with the following issue. I run wildcard queries on an index in Kibana Dev Tools. If i run one query at a time it returns only the relevant hits. If the queries are run paralell (2 browser tabs),…

---

## [Options list vizualization: some unique values of a field are missing in the dropdown list](https://discuss.elastic.co/t/options-list-vizualization-some-unique-values-of-a-field-are-missing-in-the-dropdown-list/333755)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 3\
**Last updated:** [May 23, 2023, 12:59pm UTC](https://discuss.elastic.co/t/options-list-vizualization-some-unique-values-of-a-field-are-missing-in-the-dropdown-list/333755 "2023-05-23T12:59:47Z")

</div>

Hi, We are using options list (drop down) on Dashboard to load ip addresses. But randomly some of the IP's were missing but when i look at the RAW data from Discovery, those ip addresses are showing up. i' am using max…

---

## [Kibana has a response "We couldn't log you in. Please try again."](https://discuss.elastic.co/t/kibana-has-a-response-we-couldnt-log-you-in-please-try-again/334069)

<div class="topic-metadata">

**Author:** [@Danuptraa](https://discuss.elastic.co/u/Danuptraa)\
**Replies:** 1\
**Last updated:** [May 23, 2023, 12:41pm UTC](https://discuss.elastic.co/t/kibana-has-a-response-we-couldnt-log-you-in-please-try-again/334069 "2023-05-23T12:41:08Z")

</div>

Hi everyone, Is there anyone who can help me? I have an issue with Kibana. When I try to log in, Kibana gives the response "We couldn't log you in. Please try again." I have read many forums, but none of them seem to ad…

---

## [Substring search NEST query](https://discuss.elastic.co/t/substring-search-nest-query/333980)

<div class="topic-metadata">

**Author:** [@LhamoDev](https://discuss.elastic.co/u/LhamoDev)\
**Replies:** 6\
**Last updated:** [May 23, 2023, 12:12pm UTC](https://discuss.elastic.co/t/substring-search-nest-query/333980 "2023-05-23T12:12:07Z")

</div>

Hello, I'm trying to search on an ID in my index with reservations for a test application. I can search on the full ID but when I search on the last part of the ID (something the PO requested), I don't get any results …

---

## [Elastic agents are becoming offline after some time](https://discuss.elastic.co/t/elastic-agents-are-becoming-offline-after-some-time/334100)

<div class="topic-metadata">

**Author:** [@Malik\_Bilal](https://discuss.elastic.co/u/Malik_Bilal)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 10:25am UTC](https://discuss.elastic.co/t/elastic-agents-are-becoming-offline-after-some-time/334100 "2023-05-23T10:25:46Z")

</div>

Elastic agents installed in the aks cluster are online for 3 minutes and then they become offline after every that . This loop keeps on continuing and therefore I have alot of elastic agents in the offline state. I see…

---

## [Kibana Log File not created](https://discuss.elastic.co/t/kibana-log-file-not-created/334099)

<div class="topic-metadata">

**Author:** [@Oriya](https://discuss.elastic.co/u/Oriya)\
**Replies:** 3\
**Last updated:** [May 23, 2023, 11:36am UTC](https://discuss.elastic.co/t/kibana-log-file-not-created/334099 "2023-05-23T11:36:53Z")

</div>

Hi, Recently we notice that kibana log file that should be written to the path : /var/log/kibana/kibana.log was not written for a long time. this is the kibana.yml : # Kibana is served by a back end server. This set…

---

## [Help! Is it possible to make alarm like this?](https://discuss.elastic.co/t/help-is-it-possible-to-make-alarm-like-this/333827)

<div class="topic-metadata">

**Author:** [@Isaac\_Lee](https://discuss.elastic.co/u/Isaac_Lee)\
**Replies:** 5\
**Last updated:** [May 23, 2023, 11:33am UTC](https://discuss.elastic.co/t/help-is-it-possible-to-make-alarm-like-this/333827 "2023-05-23T11:33:48Z")

</div>

Hi team, I am struggling to find whether Kibana is feasible to do this. Is it possible to make alarm like picture 2? If you know, would you guided me how I can do this? Thanks !

---

## [How to close HighLevelClient in thread pool](https://discuss.elastic.co/t/how-to-close-highlevelclient-in-thread-pool/334108)

<div class="topic-metadata">

**Author:** [@CatLoveFishma](https://discuss.elastic.co/u/CatLoveFishma)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 11:03am UTC](https://discuss.elastic.co/t/how-to-close-highlevelclient-in-thread-pool/334108 "2023-05-23T11:03:19Z")

</div>

Hi,I use the thread pool to batch query the data in the es cluster.It is performant and gives me good parallelization. However I am not able to figure out how to close the client. Actually, I do client.close() in child t…

---

## [Logs monitoring through Filebeat](https://discuss.elastic.co/t/logs-monitoring-through-filebeat/333753)

<div class="topic-metadata">

**Author:** [@Kumar\_Arsh](https://discuss.elastic.co/u/Kumar_Arsh)\
**Replies:** 7\
**Last updated:** [May 23, 2023, 10:04am UTC](https://discuss.elastic.co/t/logs-monitoring-through-filebeat/333753 "2023-05-23T10:04:04Z")

</div>

How can I use filebeat to read logs from another server? What will be the configuration that will be required?

---

## [Create rule using KQL query](https://discuss.elastic.co/t/create-rule-using-kql-query/333859)

<div class="topic-metadata">

**Author:** [@nitisha](https://discuss.elastic.co/u/nitisha)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 11:04am UTC](https://discuss.elastic.co/t/create-rule-using-kql-query/333859 "2023-05-22T11:04:37Z")

</div>

Hi , We are using metricbeat to monitor containers in our environment. We need to create an email alert to get triggered when any container's CPU usage exceeds 70%. I was trying to create a rule under "Alerts and Insig…

---

## [Duplication in logstash pipeline (input elasticsearch and output sql database)](https://discuss.elastic.co/t/duplication-in-logstash-pipeline-input-elasticsearch-and-output-sql-database/333982)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 2\
**Last updated:** [May 23, 2023, 8:27am UTC](https://discuss.elastic.co/t/duplication-in-logstash-pipeline-input-elasticsearch-and-output-sql-database/333982 "2023-05-23T08:27:35Z")

</div>

Hi , I am using elasicsearch index as my input in my logstash config and the output is jdbc-output plugin logstash that send logs to sql database table columns , and the problem is I have duplication in sql database , I…

---

## [How to calculate the no. of hours between the selected time range in Kibana?](https://discuss.elastic.co/t/how-to-calculate-the-no-of-hours-between-the-selected-time-range-in-kibana/332855)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 1\
**Last updated:** [May 23, 2023, 7:55am UTC](https://discuss.elastic.co/t/how-to-calculate-the-no-of-hours-between-the-selected-time-range-in-kibana/332855 "2023-05-23T07:55:16Z")

</div>

Hello, I would like to know how I can get the number of hours in the selected time range. For example, If last 2 days is selected in kibana time picker, then I want to get the no. of hours in 2 days (ie., 48 hours). We…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=533)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=535)
