# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=537

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 538

---

## [Kibana Import JSON : File structure cannot be determined](https://discuss.elastic.co/t/kibana-import-json-file-structure-cannot-be-determined/333275)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 1:42pm UTC](https://discuss.elastic.co/t/kibana-import-json-file-structure-cannot-be-determined/333275 "2023-05-19T13:42:20Z")

</div>

Hi , I want to import this index-pattern : Kibana index-pattern When I import it , I have this error : I tried to override Timestamp with this option but it doesn't work : I tried to make timestamp\_format to n…

---

## [Kibana 8.7.1 plugin fails to launch](https://discuss.elastic.co/t/kibana-8-7-1-plugin-fails-to-launch/333506)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 1:15pm UTC](https://discuss.elastic.co/t/kibana-8-7-1-plugin-fails-to-launch/333506 "2023-05-19T13:15:12Z")

</div>

Hi, Our plugin which was working in ELK 8.6.2 is failing in 8.7.1 with this failure "\[FATAL\]\[root\] Error: Cannot find module '../../../../../../packages/kbn-config-schema'" This should still be supported? 'yarn kbn boo…

---

## [Knn vectors](https://discuss.elastic.co/t/knn-vectors/333199)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 12:41pm UTC](https://discuss.elastic.co/t/knn-vectors/333199 "2023-05-19T12:41:37Z")

</div>

Let us say I am building an ecommerce app and there are 2 users: user A : always searches for electronics (laptop, headphones, etc) user B: searches for snacks, beverages Is it possible to show a page with banner that…

---

## [Logstash w/ s3 output plugin - slow/delay](https://discuss.elastic.co/t/logstash-w-s3-output-plugin-slow-delay/333836)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 12:32pm UTC](https://discuss.elastic.co/t/logstash-w-s3-output-plugin-slow-delay/333836 "2023-05-19T12:32:12Z")

</div>

Hello, I'm using Logstash 7.17.10 with S3 output plugin, and getting poor performance (possibly not related to performance) my pipeline: input { elasticsearch { docinfo =\> true docinfo\_fields =\> \[ …

---

## [Elasticsearch 8.7 2-node cluster](https://discuss.elastic.co/t/elasticsearch-8-7-2-node-cluster/333772)

<div class="topic-metadata">

**Author:** [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Replies:** 6\
**Last updated:** [May 19, 2023, 11:22am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-2-node-cluster/333772 "2023-05-19T11:22:54Z")

</div>

Hello, I want to create 2-node cluster and it doesn't work node-01: path.data: /bitnami/elasticsearch/data cluster.name: zephyr node.name: node-01 node.roles: \[ master, data \] http.port: 9200 transport.port: 9300 boot…

---

## [Elasticsearch monitoring using telegraf](https://discuss.elastic.co/t/elasticsearch-monitoring-using-telegraf/333862)

<div class="topic-metadata">

**Author:** [@mhr](https://discuss.elastic.co/u/mhr)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 10:58am UTC](https://discuss.elastic.co/t/elasticsearch-monitoring-using-telegraf/333862 "2023-05-19T10:58:07Z")

</div>

I am using telegraf to monitor elasticsearch. i am using below doc. i am not able to get the data elasticsearch\_network ' tcp\_in\_errs value=0 tcp\_passive\_opens value=16 tcp\_curr\_estab value=29 tcp\_in\_segs value=11…

---

## [Unassigned shards, with status "Elasticsearch can allocate the shard" for all of them](https://discuss.elastic.co/t/unassigned-shards-with-status-elasticsearch-can-allocate-the-shard-for-all-of-them/333806)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 6\
**Last updated:** [May 19, 2023, 9:49am UTC](https://discuss.elastic.co/t/unassigned-shards-with-status-elasticsearch-can-allocate-the-shard-for-all-of-them/333806 "2023-05-19T09:49:27Z")

</div>

Can you help me to explain why I have for several days 25 unassigned replica shards wich can\_allocate status = yes and allocation\_explanation = Elasticsearch can allocate the shard. I supposed rebalancing job will alloc…

---

## [Elastic pipeline processors grok for question!](https://discuss.elastic.co/t/elastic-pipeline-processors-grok-for-question/333852)

<div class="topic-metadata">

**Author:** [@Teresajw](https://discuss.elastic.co/u/Teresajw)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 9:13am UTC](https://discuss.elastic.co/t/elastic-pipeline-processors-grok-for-question/333852 "2023-05-19T09:13:51Z")

</div>

When I parsed the nginx log using Filebeat pipeline, a user\_agent field in the log failed to be parsed. The following error is displayed. {"type":"mapper\_parsing\_exception","reason":"object mapping for \[user\_agent\] trie…

---

## [Which process comes first in Filebeat v.8？](https://discuss.elastic.co/t/which-process-comes-first-in-filebeat-v-8/333822)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 9:13am UTC](https://discuss.elastic.co/t/which-process-comes-first-in-filebeat-v-8/333822 "2023-05-19T09:13:30Z")

</div>

Hello. I'm using Filebeat v.8.6.2 to send data to Logstash with filestream input type and I'm curious about which process comes first. Harvest input file data(end of file reached) Connecting Filebeat to Logstash

---

## [Logstash is not working properly. \_grokparsefailure](https://discuss.elastic.co/t/logstash-is-not-working-properly-grokparsefailure/333851)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 9:07am UTC](https://discuss.elastic.co/t/logstash-is-not-working-properly-grokparsefailure/333851 "2023-05-19T09:07:16Z")

</div>

strange behavior of the logstash, everything is parsed in the debugger, but not in the config - gives an error - \_grokparsefailure my logs 10.10.10.10.1680263940261.385400.G\_B2C\_BETA,03/31/2023 15:02:05.465,sf\_sap\_put\_…

---

## [Ilm question/troubleshooting](https://discuss.elastic.co/t/ilm-question-troubleshooting/333676)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 8:25am UTC](https://discuss.elastic.co/t/ilm-question-troubleshooting/333676 "2023-05-19T08:25:20Z")

</div>

My ilm policy does not work, although I have created a similar one a couple of weeks before in another cluster and it is working just fine.. Here is what I did: I pointed Logstash towards ind\_alias Created index templ…

---

## [Logstash JDBC input plugin: Java::OrgPostgresqlUtil::PSQLException: An I/O error occurred while sending to the backend](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-java-an-i-o-error-occurred-while-sending-to-the-backend/333848)

<div class="topic-metadata">

**Author:** [@Captain](https://discuss.elastic.co/u/Captain)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 7:46am UTC](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-java-an-i-o-error-occurred-while-sending-to-the-backend/333848 "2023-05-19T07:46:32Z")

</div>

I encountered this problem some time ago and have not been able to find a good solution. Finally, after I modified the configuration in the jvm.options file, the problem did not occur again. The original configuration "-…

---

## [Disk space is 100% after running a "delete by query" in devtool in kibana](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647)

<div class="topic-metadata">

**Author:** [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Replies:** 5\
**Last updated:** [May 19, 2023, 5:24am UTC](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647 "2023-05-19T05:24:34Z")

</div>

After running the query below, server space is getting full in all data nodes ( ELK cluster: 3 masters, 3 data, 1 kibana node). POST /apic\_sandbox/\_delete\_by\_query?wait\_for\_completion=false //change index here accordi…

---

## [How to add Sudachi NLP into Elastic Cloud?](https://discuss.elastic.co/t/how-to-add-sudachi-nlp-into-elastic-cloud/333838)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 4:23am UTC](https://discuss.elastic.co/t/how-to-add-sudachi-nlp-into-elastic-cloud/333838 "2023-05-19T04:23:53Z")

</div>

Hello. I want to use Japanese NLP Sudachi instead of the default library Kuromoji in Workplace Search in the deployment of Elastic Cloud. Is it possible to add Sudachi in the Elastic Cloud and install it to the specifi…

---

## [While accessing Kibana facing data view pulgin issue](https://discuss.elastic.co/t/while-accessing-kibana-facing-data-view-pulgin-issue/333834)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 3:42am UTC](https://discuss.elastic.co/t/while-accessing-kibana-facing-data-view-pulgin-issue/333834 "2023-05-19T03:42:00Z")

</div>

Hi Team, Deployed both V7.17 (kibana and elasticsearch ) through helm, While accessing kibana facing data view plugin issue some time, after refreshing its working \< 46635/bundles/plugin/dataViews/kibana/dataViews.…

---

## [Expected behavior of tcp/input/ssl\_verify=true?](https://discuss.elastic.co/t/expected-behavior-of-tcp-input-ssl-verify-true/333835)

<div class="topic-metadata">

**Author:** [@bennbrian65](https://discuss.elastic.co/u/bennbrian65)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 3:48am UTC](https://discuss.elastic.co/t/expected-behavior-of-tcp-input-ssl-verify-true/333835 "2023-05-19T03:48:38Z")

</div>

logstash 8.7.1, tcp input w/ssl\_verify=true. I expect that a sender using a cert w/no SANS and the sender’s host name does not match the cert’s CN would be rejected, but it is accepted. What does ssl\_verify=true govern?

---

## [Unable to authenticate with provided credentials and anonymous access is not allowed for this request](https://discuss.elastic.co/t/unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/333518)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 3\
**Last updated:** [May 19, 2023, 1:26am UTC](https://discuss.elastic.co/t/unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/333518 "2023-05-19T01:26:48Z")

</div>

I getting case errror when I configure Fleetserver with run file script ./elastic-agents install. . And now show detail log error "message":"Fleet Server - Error - info fail \[401 Unauthorized\] {"error":{"root\_cause":\[{…

---

## [GCP LOGGING TO ELASTIC | security](https://discuss.elastic.co/t/gcp-logging-to-elastic-security/332596)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 11\
**Last updated:** [May 19, 2023, 12:30am UTC](https://discuss.elastic.co/t/gcp-logging-to-elastic-security/332596 "2023-05-19T00:30:00Z")

</div>

Hi, We have elasticsearch running on VMs and we are trying to share the logs from GCP to local elastic cluster. Thing is, GCP uses service account and key. Is there a way where we can add GCP service account credential…

---

## [Warning: Body deprecated in hybrid search](https://discuss.elastic.co/t/warning-body-deprecated-in-hybrid-search/330613)

<div class="topic-metadata">

**Author:** [@Francisco\_Rocha](https://discuss.elastic.co/u/Francisco_Rocha)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 10:04pm UTC](https://discuss.elastic.co/t/warning-body-deprecated-in-hybrid-search/330613 "2023-05-18T22:04:29Z")

</div>

Hi there, don't know how to remove this warning: DeprecationWarning: The 'body' parameter is deprecated for the 'search' API and will be removed in a future version. Instead use API parameters directly. The following …

---

## [Having an empty hits and response from elasticsearch when trying to query them via an api](https://discuss.elastic.co/t/having-an-empty-hits-and-response-from-elasticsearch-when-trying-to-query-them-via-an-api/333698)

<div class="topic-metadata">

**Author:** [@Bettaieb\_Walid](https://discuss.elastic.co/u/Bettaieb_Walid)\
**Replies:** 3\
**Last updated:** [May 18, 2023, 9:56pm UTC](https://discuss.elastic.co/t/having-an-empty-hits-and-response-from-elasticsearch-when-trying-to-query-them-via-an-api/333698 "2023-05-18T21:56:27Z")

</div>

hello , I am developing backend using strapi , and i am going to store some data inside elasticsearch , and i would like to be able to consume the data, and fetch them. here is the different configuration files routes: …

---

## [Exclude a lost of mac addresses in alert with elasticsearch query](https://discuss.elastic.co/t/exclude-a-lost-of-mac-addresses-in-alert-with-elasticsearch-query/333590)

<div class="topic-metadata">

**Author:** [@odelacruzc93](https://discuss.elastic.co/u/odelacruzc93)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 9:40pm UTC](https://discuss.elastic.co/t/exclude-a-lost-of-mac-addresses-in-alert-with-elasticsearch-query/333590 "2023-05-18T21:40:25Z")

</div>

Hi There! Please I need your help, I am ingesting logs ARP and DHCP to find IPs outside my porganizatión, so I implemented an alarm but I must exclude 1650 MAC addresses, can I create a list with these MAC addresses to a…

---

## [@elastic/apm-rum-angular Integration with Angular 16 Not Working](https://discuss.elastic.co/t/elastic-apm-rum-angular-integration-with-angular-16-not-working/333819)

<div class="topic-metadata">

**Author:** [@Tucker\_Schell](https://discuss.elastic.co/u/Tucker_Schell)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 9:37pm UTC](https://discuss.elastic.co/t/elastic-apm-rum-angular-integration-with-angular-16-not-working/333819 "2023-05-18T21:37:46Z")

</div>

Hi, two weeks ago I integrated the apm-rum-angular package (2.1.7) in an Angular 15 application by following this doc and it worked just fine: Today, I updated Angular to 16 and now I get the following error: 'ApmMod…

---

## [Elasticsearch not able to form a cluster](https://discuss.elastic.co/t/elasticsearch-not-able-to-form-a-cluster/333817)

<div class="topic-metadata">

**Author:** [@neerajg](https://discuss.elastic.co/u/neerajg)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 9:19pm UTC](https://discuss.elastic.co/t/elasticsearch-not-able-to-form-a-cluster/333817 "2023-05-18T21:19:10Z")

</div>

Hi, We have 3 nodes (Linux Ubuntu 20.04) I have modified the /etc/hosts file to add node1 node2 and node3 as DNS with their IPs I have installed elasticsearch but for some reason elasticsearch is not able to form a cl…

---

## [I installed elasticsearch 8.7 but icant acess it through my browser down here is my yml file](https://discuss.elastic.co/t/i-installed-elasticsearch-8-7-but-icant-acess-it-through-my-browser-down-here-is-my-yml-file/333538)

<div class="topic-metadata">

**Author:** [@coolin\_dady](https://discuss.elastic.co/u/coolin_dady)\
**Replies:** 4\
**Last updated:** [May 18, 2023, 9:04pm UTC](https://discuss.elastic.co/t/i-installed-elasticsearch-8-7-but-icant-acess-it-through-my-browser-down-here-is-my-yml-file/333538 "2023-05-18T21:04:55Z")

</div>

\# ======================== Elasticsearch Configuration ========================= # # NOTE: Elasticsearch comes with reasonable defaults for most settings. # Before you set out to tweak and tune the configuration, make…

---

## [Move shard to another node error](https://discuss.elastic.co/t/move-shard-to-another-node-error/333235)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 3\
**Last updated:** [May 18, 2023, 9:02pm UTC](https://discuss.elastic.co/t/move-shard-to-another-node-error/333235 "2023-05-18T21:02:02Z")

</div>

Hello, I need to move shards to another node. I get the following error. The command is first and the error after it: error to check post \_cluster/reroute { "commands": \[ { "move": { "index": "yeshut\_2022.03.31-0…

---

## [Apply ingest pipeline to custom logs](https://discuss.elastic.co/t/apply-ingest-pipeline-to-custom-logs/333539)

<div class="topic-metadata">

**Author:** [@temuccio](https://discuss.elastic.co/u/temuccio)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 8:51pm UTC](https://discuss.elastic.co/t/apply-ingest-pipeline-to-custom-logs/333539 "2023-05-18T20:51:58Z")

</div>

Hi all. I have installed a fresh installation of stack ELK. Into kibana, I have installed a Elastic Agent for get custom logs from a syslog server. It works fine ad I see the log. I have make a Ingest Pipeline and I …

---

## [elasticsearch/client.go:408 Cannot index event publisher.Event](https://discuss.elastic.co/t/elasticsearch-client-go-408-cannot-index-event-publisher-event/333809)

<div class="topic-metadata">

**Author:** [@reddyk001](https://discuss.elastic.co/u/reddyk001)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 8:50pm UTC](https://discuss.elastic.co/t/elasticsearch-client-go-408-cannot-index-event-publisher-event/333809 "2023-05-18T20:50:17Z")

</div>

Hello All, i was trying to send k8s container logs to Elasticsearch through filebeat. we are getting more logs that expected and also it is trigger the below warning continuously from filebeat side and it trying write …

---

## [Elasticsearch "delete by query" not released disk space](https://discuss.elastic.co/t/elasticsearch-delete-by-query-not-released-disk-space/333768)

<div class="topic-metadata">

**Author:** [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Replies:** 3\
**Last updated:** [May 18, 2023, 8:35pm UTC](https://discuss.elastic.co/t/elasticsearch-delete-by-query-not-released-disk-space/333768 "2023-05-18T20:35:10Z")

</div>

After running "delete by query ", disk space did not released. What should I do to make disk space release?

---

## [DSL compound Queries](https://discuss.elastic.co/t/dsl-compound-queries/330591)

<div class="topic-metadata">

**Author:** [@waitangi](https://discuss.elastic.co/u/waitangi)\
**Replies:** 4\
**Last updated:** [May 18, 2023, 8:25pm UTC](https://discuss.elastic.co/t/dsl-compound-queries/330591 "2023-05-18T20:25:11Z")

</div>

Hi everyone I have following DSL queries: GET eclaims-logs-2023.04.21/\_search { "query": { "bool": { "must": \[ { "match": { "thread\_name" : "http-nio-5050-exec-7" } …

---

## [KIbana failover to a healthy ES node](https://discuss.elastic.co/t/kibana-failover-to-a-healthy-es-node/333574)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [May 18, 2023, 6:35pm UTC](https://discuss.elastic.co/t/kibana-failover-to-a-healthy-es-node/333574 "2023-05-18T18:35:15Z")

</div>

Hi All, We are facing an issue where Kibana does not failover to a healthy Elasticsearch node in case a node goes down. Login into Kibana console stops working unless the bad node is brought up. KIbana config is as fo…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=536)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=538)
