# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=551

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 552

---

## [Parallel execution of bulk request](https://discuss.elastic.co/t/parallel-execution-of-bulk-request/332627)

<div class="topic-metadata">

**Author:** [@Daniel\_Schneider](https://discuss.elastic.co/u/Daniel_Schneider)\
**Replies:** 5\
**Last updated:** [May 8, 2023, 3:19am UTC](https://discuss.elastic.co/t/parallel-execution-of-bulk-request/332627 "2023-05-08T03:19:21Z")

</div>

Hi, In topic: Parallel execution of bulk request it was clarified that if a bulk contains multiple operations on the same document then they are processed in order. On the other hand in documentation I did not find any…

---

## [If i use log\_file config. The apm agent is not starting. If i not using this config. Its starting](https://discuss.elastic.co/t/if-i-use-log-file-config-the-apm-agent-is-not-starting-if-i-not-using-this-config-its-starting/332619)

<div class="topic-metadata">

**Author:** [@Stephen\_Joseph](https://discuss.elastic.co/u/Stephen_Joseph)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 3:15am UTC](https://discuss.elastic.co/t/if-i-use-log-file-config-the-apm-agent-is-not-starting-if-i-not-using-this-config-its-starting/332619 "2023-05-08T03:15:08Z")

</div>

APM Server: 8.5.0 Elastic search:8.5.0 Kibana:8.5.0 apm agent: 1.38.0 elasticapm.properties:- recording: true enabled: true server\_urls: http://apm-server.logging.svc.cluster.local:8200 service\_name: test-app log\_fi…

---

## [ECK 8.7.1 elastic agent error](https://discuss.elastic.co/t/eck-8-7-1-elastic-agent-error/332625)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 3:11am UTC](https://discuss.elastic.co/t/eck-8-7-1-elastic-agent-error/332625 "2023-05-08T03:11:43Z")

</div>

Following Quickstart | Elastic Cloud on Kubernetes \[2.7\] | Elastic to install and run ECK fleet on my EKS but observe the following error in the agent logs: \[elastic-agent-agent-gdpzn\] {"log.level":"info","@timestamp":"…

---

## [Migrate snapshot repository](https://discuss.elastic.co/t/migrate-snapshot-repository/332510)

<div class="topic-metadata">

**Author:** [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 3:01am UTC](https://discuss.elastic.co/t/migrate-snapshot-repository/332510 "2023-05-08T03:01:02Z")

</div>

Hello, I backuped my data into a nfs share and now received a bigger one, so I have to migrate the old snapshot repository into the new nfs share because I want to keep the data. Can I just copy the files from the moun…

---

## [Understanding node.max\_local\_storage\_nodes?](https://discuss.elastic.co/t/understanding-node-max-local-storage-nodes/332682)

<div class="topic-metadata">

**Author:** [@lakh](https://discuss.elastic.co/u/lakh)\
**Replies:** 1\
**Last updated:** [May 8, 2023, 2:51am UTC](https://discuss.elastic.co/t/understanding-node-max-local-storage-nodes/332682 "2023-05-08T02:51:05Z")

</div>

Hi, my setup is that I have multiple people running their own docker containers on different machines that have access to shared storage. I've put the elasticsearch- folder in that shared location (so the /data/index fol…

---

## [Why traffic between filebeat and elasticsearch contains “Apache Struts2 OGNL Remote Code Execution Vulnerability”](https://discuss.elastic.co/t/why-traffic-between-filebeat-and-elasticsearch-contains-apache-struts2-ognl-remote-code-execution-vulnerability/332505)

<div class="topic-metadata">

**Author:** [@wlane](https://discuss.elastic.co/u/wlane)\
**Replies:** 3\
**Last updated:** [May 8, 2023, 2:44am UTC](https://discuss.elastic.co/t/why-traffic-between-filebeat-and-elasticsearch-contains-apache-struts2-ognl-remote-code-execution-vulnerability/332505 "2023-05-08T02:44:07Z")

</div>

Hi guys, We used Filebeat to send application logs to Elasticsearch. And these two components are deployed in different environments with firewall PaloAlto in between. We found that after transmitting for a period of t…

---

## [Cross cluster search question](https://discuss.elastic.co/t/cross-cluster-search-question/332439)

<div class="topic-metadata">

**Author:** [@elastic\_user4](https://discuss.elastic.co/u/elastic_user4)\
**Replies:** 1\
**Last updated:** [May 7, 2023, 10:45pm UTC](https://discuss.elastic.co/t/cross-cluster-search-question/332439 "2023-05-07T22:45:30Z")

</div>

Hello, I have 3 clusters in my infrastructure and I wanted to know if it was possible to transfer data from the index of these clusters using cross cluster search. Or is there another way to transfer data. I am using the…

---

## [409 conflict](https://discuss.elastic.co/t/409-conflict/332457)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [May 7, 2023, 10:44pm UTC](https://discuss.elastic.co/t/409-conflict/332457 "2023-05-07T22:44:49Z")

</div>

If I have 100 indexing requests in a bulk, and 2 requests are updating the same document, will a 409 be thrown?

---

## [Elastic Cloud - Elastic Security EDR/XDR](https://discuss.elastic.co/t/elastic-cloud-elastic-security-edr-xdr/332731)

<div class="topic-metadata">

**Author:** [@Lelc79](https://discuss.elastic.co/u/Lelc79)\
**Replies:** 0\
**Last updated:** [May 6, 2023, 9:56pm UTC](https://discuss.elastic.co/t/elastic-cloud-elastic-security-edr-xdr/332731 "2023-05-06T21:56:59Z")

</div>

I want to configure 200 Endpoints with Windows 10/11 in elastic cloud with Enterprise license, to be able to use Elastic Security. ¿What would be the appropriate configuration to be able to calculate the costs?

---

## [How to make elasticsearch.keystore persistent?](https://discuss.elastic.co/t/how-to-make-elasticsearch-keystore-persistent/332530)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 3\
**Last updated:** [May 7, 2023, 10:16pm UTC](https://discuss.elastic.co/t/how-to-make-elasticsearch-keystore-persistent/332530 "2023-05-07T22:16:46Z")

</div>

Hi, I am running elasticsearch cluster on Kubernetes cluster. The passwords I have generated for build-in-users like kibana\_system and elastic are changed after restart of the elasticsearch node. I am trying to find a wa…

---

## [Upgrade Elasticsearch from 6.8 to 7](https://discuss.elastic.co/t/upgrade-elasticsearch-from-6-8-to-7/332767)

<div class="topic-metadata">

**Author:** [@Chirag\_Poddar](https://discuss.elastic.co/u/Chirag_Poddar)\
**Replies:** 1\
**Last updated:** [May 7, 2023, 7:16pm UTC](https://discuss.elastic.co/t/upgrade-elasticsearch-from-6-8-to-7/332767 "2023-05-07T19:16:26Z")

</div>

We have 7 ES clusters (each having 3 nodes) running in production on the 6.8 version. We are planning to upgrade them to 7 and then eventually to 8. We have 2 options Upgrade versions on node one by one (rolling upgrad…

---

## [org.elasticsearch.client.ResponseException while creating index](https://discuss.elastic.co/t/org-elasticsearch-client-responseexception-while-creating-index/332706)

<div class="topic-metadata">

**Author:** [@Keerthy\_Ar](https://discuss.elastic.co/u/Keerthy_Ar)\
**Replies:** 5\
**Last updated:** [May 7, 2023, 6:45pm UTC](https://discuss.elastic.co/t/org-elasticsearch-client-responseexception-while-creating-index/332706 "2023-05-07T18:45:43Z")

</div>

I am trying to create index with High Rest Client, version 7.17.10 String mappingSource = "{"mappings":{"properties":{"name":{"type":"text"},"age":{"type":"integer"}}}}"; CreateIndexRequest request = new CreateIndexReq…

---

## [Java virtuale machine error while starting elasticsearch service](https://discuss.elastic.co/t/java-virtuale-machine-error-while-starting-elasticsearch-service/332769)

<div class="topic-metadata">

**Author:** [@khadija70](https://discuss.elastic.co/u/khadija70)\
**Replies:** 1\
**Last updated:** [May 7, 2023, 6:43pm UTC](https://discuss.elastic.co/t/java-virtuale-machine-error-while-starting-elasticsearch-service/332769 "2023-05-07T18:43:58Z")

</div>

Hi , We have an error related to starting Elasticsearch service on one of elasticsearch data servers related to creation of java vertuel machie , the error is attached . Could you please provide helps

---

## [UNABLE\_TO\_INSTALL\_ELK\_STACK\_WINDOWS](https://discuss.elastic.co/t/unable-to-install-elk-stack-windows/332697)

<div class="topic-metadata">

**Author:** [@naman\_marria](https://discuss.elastic.co/u/naman_marria)\
**Replies:** 6\
**Last updated:** [May 6, 2023, 4:07pm UTC](https://discuss.elastic.co/t/unable-to-install-elk-stack-windows/332697 "2023-05-06T16:07:00Z")

</div>

Unable to access Elasticsearch on WINDOWS : My Elasticsearch successfully installs and generates enrollment id along with rest of the credentials but it is not accessible on port 9200 or 9300. I have not edited the yml f…

---

## [How to do Composite Aggregation with Multiple Term Aggregation in new Java Client](https://discuss.elastic.co/t/how-to-do-composite-aggregation-with-multiple-term-aggregation-in-new-java-client/332696)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 0\
**Last updated:** [May 6, 2023, 6:56am UTC](https://discuss.elastic.co/t/how-to-do-composite-aggregation-with-multiple-term-aggregation-in-new-java-client/332696 "2023-05-06T06:56:05Z")

</div>

I am getting error when giving multiple term aggregation in composite aggregation sources \[es/search\] failed: \[x\_content\_parse\_exception\] \[1:177\] \[composite\] failed to parse field \[sources\] my code as below …

---

## [Datehistogram Composite Agg Sort Error in new Java Client](https://discuss.elastic.co/t/datehistogram-composite-agg-sort-error-in-new-java-client/332695)

<div class="topic-metadata">

**Author:** [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Replies:** 0\
**Last updated:** [May 6, 2023, 6:27am UTC](https://discuss.elastic.co/t/datehistogram-composite-agg-sort-error-in-new-java-client/332695 "2023-05-06T06:27:19Z")

</div>

I am getting error when giving sort in Datehistogram composite agg \[es/search\] failed: \[x\_content\_parse\_exception\] \[1:186\] \[composite\] failed to parse field \[sources\] my code as below Map\<String, CompositeAggregationS…

---

## [Create autocomplete query](https://discuss.elastic.co/t/create-autocomplete-query/332693)

<div class="topic-metadata">

**Author:** [@Khaled\_Omara](https://discuss.elastic.co/u/Khaled_Omara)\
**Replies:** 0\
**Last updated:** [May 6, 2023, 5:22am UTC](https://discuss.elastic.co/t/create-autocomplete-query/332693 "2023-05-06T05:22:52Z")

</div>

Here is my indices mapping: { "mappings": { "properties": { "categories": { "type": "text", "analyzer": "standard" }, "color": { "type": "text", "analyzer": "stand…

---

## [Reset similarity on an index](https://discuss.elastic.co/t/reset-similarity-on-an-index/332652)

<div class="topic-metadata">

**Author:** [@slayer](https://discuss.elastic.co/u/slayer)\
**Replies:** 2\
**Last updated:** [May 6, 2023, 3:53am UTC](https://discuss.elastic.co/t/reset-similarity-on-an-index/332652 "2023-05-06T03:53:49Z")

</div>

Hi all, I have changed the default similarity from BM25 to scripted similarity on one of my indices. Now If I try to change it back to BM25, I am facing an error: Unknown settings for similarity of type \[BM25\]: \[scri…

---

## [\[Packetbeat\] bpf\_filter setting does not work in packetbeat 8.x.](https://discuss.elastic.co/t/packetbeat-bpf-filter-setting-does-not-work-in-packetbeat-8-x/332622)

<div class="topic-metadata">

**Author:** [@md-irohas](https://discuss.elastic.co/u/md-irohas)\
**Replies:** 2\
**Last updated:** [May 6, 2023, 2:08am UTC](https://discuss.elastic.co/t/packetbeat-bpf-filter-setting-does-not-work-in-packetbeat-8-x/332622 "2023-05-06T02:08:17Z")

</div>

I am using packetbeat (v8.7.0) in my home network and find that the packetbeat.interfaces.bpf\_filter setting in packetbeat.yml does not work. I read the source code and find that the bpf\_filter value is not addressed co…

---

## [Problem with the size of the circles in Map](https://discuss.elastic.co/t/problem-with-the-size-of-the-circles-in-map/332570)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 6\
**Last updated:** [May 5, 2023, 11:06pm UTC](https://discuss.elastic.co/t/problem-with-the-size-of-the-circles-in-map/332570 "2023-05-05T23:06:21Z")

</div>

I don't understand how Kibana manages the size of proportional circles in Map. For example I want to map data with a proportional circle linked to a variable (fatalities) so I know that the maximum value is 136. My prob…

---

## [What is the replacment for HighLevelRestClient SearchHit.getSortValues() in the Java API Client?](https://discuss.elastic.co/t/what-is-the-replacment-for-highlevelrestclient-searchhit-getsortvalues-in-the-java-api-client/332676)

<div class="topic-metadata">

**Author:** [@kayld](https://discuss.elastic.co/u/kayld)\
**Replies:** 1\
**Last updated:** [May 5, 2023, 7:43pm UTC](https://discuss.elastic.co/t/what-is-the-replacment-for-highlevelrestclient-searchhit-getsortvalues-in-the-java-api-client/332676 "2023-05-05T19:43:09Z")

</div>

The HighLevelRestClient has a method in SearchHit class called getSortValues(). In converting to the Java API Client I cannot find a replacement or way to get the same information. How would I go about getting the sor…

---

## [IndexSettings SettingsSimilarity api spec wrong?](https://discuss.elastic.co/t/indexsettings-settingssimilarity-api-spec-wrong/332673)

<div class="topic-metadata">

**Author:** [@selckin1](https://discuss.elastic.co/u/selckin1)\
**Replies:** 0\
**Last updated:** [May 5, 2023, 5:32pm UTC](https://discuss.elastic.co/t/indexsettings-settingssimilarity-api-spec-wrong/332673 "2023-05-05T17:32:11Z")

</div>

In the documentation here you can specify an id/name for the similarity such as 'my\_similarity' But this seems to not be possible in the java api client or in the api spec Am i missing something, or is the api wrong?

---

## [Integrations Development and \`elastic-package\` Question](https://discuss.elastic.co/t/integrations-development-and-elastic-package-question/330868)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 3\
**Last updated:** [May 5, 2023, 2:38pm UTC](https://discuss.elastic.co/t/integrations-development-and-elastic-package-question/330868 "2023-05-05T14:38:08Z")

</div>

I have been contributing a few PR's for enhancements and bug fixes to Integrations lately, and some of the bigger things I have been attempting require testing the package before submitting a PR. I have gotten my environ…

---

## [Formatting markdown alert email (new line)](https://discuss.elastic.co/t/formatting-markdown-alert-email-new-line/332297)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 1\
**Last updated:** [May 5, 2023, 2:15pm UTC](https://discuss.elastic.co/t/formatting-markdown-alert-email-new-line/332297 "2023-05-05T14:15:46Z")

</div>

Hi, In "Rules and Connectors", I created an alert generating an email. In this email, I want to display values of a fields, that contain NewLines In Discover, we can see these NewLines. In the email, there is no more…

---

## [Query to fetch data for current month](https://discuss.elastic.co/t/query-to-fetch-data-for-current-month/331034)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 7\
**Last updated:** [May 5, 2023, 1:33pm UTC](https://discuss.elastic.co/t/query-to-fetch-data-for-current-month/331034 "2023-05-05T13:33:04Z")

</div>

Hi all, I'm trying to fetch data only for current month of april 2023. For example, I have a query filter condition in my search bar in my kibana data table as configuredDate \> now-30d which gives me data for past 1…

---

## [Multiple patterns for dissect processor in the pipeline](https://discuss.elastic.co/t/multiple-patterns-for-dissect-processor-in-the-pipeline/332420)

<div class="topic-metadata">

**Author:** [@mmartinez](https://discuss.elastic.co/u/mmartinez)\
**Replies:** 4\
**Last updated:** [May 5, 2023, 1:22pm UTC](https://discuss.elastic.co/t/multiple-patterns-for-dissect-processor-in-the-pipeline/332420 "2023-05-05T13:22:55Z")

</div>

Hello, We have logs with similar but different log formats and we would like to use the pipeline dissect processor with multiple patterns to dissect the different formats. We have already tried with grok but the ingesti…

---

## [Metricbeat, MSSQL module, TLS Handshake failed unsupported protocol version 301](https://discuss.elastic.co/t/metricbeat-mssql-module-tls-handshake-failed-unsupported-protocol-version-301/332651)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [May 5, 2023, 1:11pm UTC](https://discuss.elastic.co/t/metricbeat-mssql-module-tls-handshake-failed-unsupported-protocol-version-301/332651 "2023-05-05T13:11:21Z")

</div>

Hi, Im getting this error when remotly monitoring a MSSQL database: ERROR instance/beat.go:1014 Exiting: 2 errors: could not create connection to db: error doing ping to db: TLS Handshake failed: tls: server select…

---

## [Creating a new beat but can't see proper output](https://discuss.elastic.co/t/creating-a-new-beat-but-cant-see-proper-output/332645)

<div class="topic-metadata">

**Author:** [@zeynepyz](https://discuss.elastic.co/u/zeynepyz)\
**Replies:** 0\
**Last updated:** [May 5, 2023, 12:00pm UTC](https://discuss.elastic.co/t/creating-a-new-beat-but-cant-see-proper-output/332645 "2023-05-05T12:00:35Z")

</div>

Hello i'm new here so if i say something wrong please let me know. I was trying to make a new beat that collects k6 metrics via rest api and then send them into Elasticsearch. I follow the 7.17 Dev Guide " Creating a Bea…

---

## [KQL Query or Elastic query to fetch data for current month](https://discuss.elastic.co/t/kql-query-or-elastic-query-to-fetch-data-for-current-month/331045)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 4\
**Last updated:** [May 5, 2023, 11:12am UTC](https://discuss.elastic.co/t/kql-query-or-elastic-query-to-fetch-data-for-current-month/331045 "2023-05-05T11:12:35Z")

</div>

Hi all, I'm trying to fetch data only for current month of april 2023. For example, I have a query filter condition in my search bar in my kibana data table as configuredDate \> now-30d which gives me data for past 1…

---

## [Script for version 7.3.2](https://discuss.elastic.co/t/script-for-version-7-3-2/332633)

<div class="topic-metadata">

**Author:** [@spino17](https://discuss.elastic.co/u/spino17)\
**Replies:** 4\
**Last updated:** [May 5, 2023, 10:16am UTC](https://discuss.elastic.co/t/script-for-version-7-3-2/332633 "2023-05-05T10:16:06Z")

</div>

I want to get an example for using script for custom scoring for 7.3.2 version of ES.

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=550)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=552)
