# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=565

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 566

---

## [Unable to bringup up 3 node, 300gb elasticsearch setup from docker volume](https://discuss.elastic.co/t/unable-to-bringup-up-3-node-300gb-elasticsearch-setup-from-docker-volume/329852)

<div class="topic-metadata">

**Author:** [@coldcoder8502](https://discuss.elastic.co/u/coldcoder8502)\
**Replies:** 5\
**Last updated:** [April 20, 2023, 12:47pm UTC](https://discuss.elastic.co/t/unable-to-bringup-up-3-node-300gb-elasticsearch-setup-from-docker-volume/329852 "2023-04-20T12:47:03Z")

</div>

Hi all, Iam trying to bringup elasticsearch 3 node setup with default settings which has 300gb data on a single index, I copied data volume of elasticsearch names =\> es01,es02,es03 from 1 machine to another machine and …

---

## [Datastream behavior in filebeat?](https://discuss.elastic.co/t/datastream-behavior-in-filebeat/330325)

<div class="topic-metadata">

**Author:** [@matheuscirillo](https://discuss.elastic.co/u/matheuscirillo)\
**Replies:** 4\
**Last updated:** [April 20, 2023, 11:32am UTC](https://discuss.elastic.co/t/datastream-behavior-in-filebeat/330325 "2023-04-20T11:32:11Z")

</div>

A very simple filebeat.yml configuration: filebeat: inputs: - type: filestream id: vouchers-logs-stream paths: - /path/to/logs/\*.log json: keys\_under\_root: true add\_error\_key: true …

---

## [Istio annotation not working](https://discuss.elastic.co/t/istio-annotation-not-working/330385)

<div class="topic-metadata">

**Author:** [@arun\_udaiyar](https://discuss.elastic.co/u/arun_udaiyar)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 10:46am UTC](https://discuss.elastic.co/t/istio-annotation-not-working/330385 "2023-04-20T10:46:19Z")

</div>

Hi All, I am trying to deploy Elasticsearch(8.5) and Kibana using helm chart. Elasticsearch works fine with (3 master, 2 data), but when i deploy Kibana its keep on failing, Finally found that Istio is the culprit. So…

---

## [GeoIP Manual Database Updating](https://discuss.elastic.co/t/geoip-manual-database-updating/330253)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 10:33am UTC](https://discuss.elastic.co/t/geoip-manual-database-updating/330253 "2023-04-20T10:33:48Z")

</div>

I am manually updating the GeoIP databases, but don't have the ability to host the updated DBs on a web server somewhere. Is it possible to utilize a Elasticsearch, Kibana, or Logstash to host the files? For instance, …

---

## [Search latency comparison of using \_seq\_no vs a keyword field in random\_score function](https://discuss.elastic.co/t/search-latency-comparison-of-using-seq-no-vs-a-keyword-field-in-random-score-function/330381)

<div class="topic-metadata">

**Author:** [@shekimod](https://discuss.elastic.co/u/shekimod)\
**Replies:** 0\
**Last updated:** [April 20, 2023, 10:31am UTC](https://discuss.elastic.co/t/search-latency-comparison-of-using-seq-no-vs-a-keyword-field-in-random-score-function/330381 "2023-04-20T10:31:59Z")

</div>

Hi all, We are using random\_score function with seed as System.nanoTime() and field as one of the keyword fields in the index for a use-case of returning random results from the index with pagination support. We are obs…

---

## [Journald input cannot read read zstd compressed journal](https://discuss.elastic.co/t/journald-input-cannot-read-read-zstd-compressed-journal/330379)

<div class="topic-metadata">

**Author:** [@ederst](https://discuss.elastic.co/u/ederst)\
**Replies:** 0\
**Last updated:** [April 20, 2023, 9:58am UTC](https://discuss.elastic.co/t/journald-input-cannot-read-read-zstd-compressed-journal/330379 "2023-04-20T09:58:07Z")

</div>

Currently, the container Image of filebeat ships with Ubuntu 20.04 ("focal") as OS which uses libsystemd0 version 245. However, this is incompatible with newer Host OS versions, as most of them use a systemd version \>=2…

---

## [Error in one alert rule object crashes the rule list](https://discuss.elastic.co/t/error-in-one-alert-rule-object-crashes-the-rule-list/329533)

<div class="topic-metadata">

**Author:** [@upcfrost](https://discuss.elastic.co/u/upcfrost)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 9:38am UTC](https://discuss.elastic.co/t/error-in-one-alert-rule-object-crashes-the-rule-list/329533 "2023-04-20T09:38:23Z")

</div>

Hi, After playing around with alerting and browser monitors in uptime, my alert rules page got completely broken. On every request it raises an error similar to: Could not find reference for kibanaSavedObjectMeta.searc…

---

## [XOR on vector parameters](https://discuss.elastic.co/t/xor-on-vector-parameters/330368)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 9:29am UTC](https://discuss.elastic.co/t/xor-on-vector-parameters/330368 "2023-04-20T09:29:32Z")

</div>

Hi, I want to do an xor on vectors in a painless scoring script. ATM I'm iterating over one vector and xoring each entry with the corresponding entry in the query vector. Is there a way I can do it in a single command…

---

## [Want to use Elasticsearch as a base image](https://discuss.elastic.co/t/want-to-use-elasticsearch-as-a-base-image/330295)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 7\
**Last updated:** [April 20, 2023, 9:23am UTC](https://discuss.elastic.co/t/want-to-use-elasticsearch-as-a-base-image/330295 "2023-04-20T09:23:30Z")

</div>

I want to use elasticsearch app as a base image and load a json file while booting up the ES instance. Can I do this? What will be the Entrypoint to start the container?

---

## [Elasticsearch wildcard keyword \* not working](https://discuss.elastic.co/t/elasticsearch-wildcard-keyword-not-working/330361)

<div class="topic-metadata">

**Author:** [@jiankunking](https://discuss.elastic.co/u/jiankunking)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 9:00am UTC](https://discuss.elastic.co/t/elasticsearch-wildcard-keyword-not-working/330361 "2023-04-20T09:00:11Z")

</div>

mapping { "jiankunking-dev": { "mappings": { "dynamic\_templates": \[ { "strings": { "match\_mapping\_type": "string", "mapping": { "type": "keyword" } } } \], "properti…

---

## [Schema optimization/alternative for nested objects](https://discuss.elastic.co/t/schema-optimization-alternative-for-nested-objects/329901)

<div class="topic-metadata">

**Author:** [@cbp698](https://discuss.elastic.co/u/cbp698)\
**Replies:** 5\
**Last updated:** [April 20, 2023, 8:56am UTC](https://discuss.elastic.co/t/schema-optimization-alternative-for-nested-objects/329901 "2023-04-20T08:56:06Z")

</div>

Hi, We are using Elastic search for storing product catalog in e-commerce domain. We have different prices in different regions for a given product. Every product belongs to certain category. Our query pattern is we s…

---

## [Does master node update cluster state document for upserts?](https://discuss.elastic.co/t/does-master-node-update-cluster-state-document-for-upserts/330365)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 8:24am UTC](https://discuss.elastic.co/t/does-master-node-update-cluster-state-document-for-upserts/330365 "2023-04-20T08:24:24Z")

</div>

So, I understand the master nodes updates cluster state documents when I create or delete an index. What if I just have one index ( I am not going to create or delete any other indices). and I constantly add data to this…

---

## [Nest.Time Casting Error](https://discuss.elastic.co/t/nest-time-casting-error/330364)

<div class="topic-metadata">

**Author:** [@LhamoDev](https://discuss.elastic.co/u/LhamoDev)\
**Replies:** 0\
**Last updated:** [April 20, 2023, 8:21am UTC](https://discuss.elastic.co/t/nest-time-casting-error/330364 "2023-04-20T08:21:59Z")

</div>

Hi With the new Nest upgrade to 7.17, I'm getting this error Scroll = {"Unable to cast object of type 'System.TimeSpan' to type 'Nest.Time' On Client.Scrollall\<T\>(new ScrollAllRequest(\_halfminute, 5) {Search = query…

---

## [Licence check is making the auditbeat connection fail with AWS elasticsearch](https://discuss.elastic.co/t/licence-check-is-making-the-auditbeat-connection-fail-with-aws-elasticsearch/330338)

<div class="topic-metadata">

**Author:** [@Rajnish\_Robin](https://discuss.elastic.co/u/Rajnish_Robin)\
**Replies:** 6\
**Last updated:** [April 20, 2023, 8:05am UTC](https://discuss.elastic.co/t/licence-check-is-making-the-auditbeat-connection-fail-with-aws-elasticsearch/330338 "2023-04-20T08:05:27Z")

</div>

I am using auditbeat version 7.5.2 and AWS opensearch based elasticsearch engine version 7.10.2 The connection to the elasticsearch is breaking with the following error: connection marked as failed because the onConne…

---

## [Ingest logs from a web API that require auth in a separate request](https://discuss.elastic.co/t/ingest-logs-from-a-web-api-that-require-auth-in-a-separate-request/330113)

<div class="topic-metadata">

**Author:** [@Miguel\_Azorin](https://discuss.elastic.co/u/Miguel_Azorin)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 7:46am UTC](https://discuss.elastic.co/t/ingest-logs-from-a-web-api-that-require-auth-in-a-separate-request/330113 "2023-04-20T07:46:09Z")

</div>

Hi! We are currently facing a situation in which we need to request the logs to an external API. Our initial idea was to do this using Filebeat's httpjson plugin, but now we are uncertain that this can be achieved, give…

---

## [Limit index memory](https://discuss.elastic.co/t/limit-index-memory/330319)

<div class="topic-metadata">

**Author:** [@pabloochoa](https://discuss.elastic.co/u/pabloochoa)\
**Replies:** 3\
**Last updated:** [April 20, 2023, 7:35am UTC](https://discuss.elastic.co/t/limit-index-memory/330319 "2023-04-20T07:35:46Z")

</div>

Don't know if this has already been asked, but I haven't been able to find either any question or documentation related to this issue. The thing is that I would like to limit the size of all the indeces of my Elastic, a…

---

## [Is there a way to find P95 search latency in elasticsearch?](https://discuss.elastic.co/t/is-there-a-way-to-find-p95-search-latency-in-elasticsearch/330356)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 3\
**Last updated:** [April 20, 2023, 6:44am UTC](https://discuss.elastic.co/t/is-there-a-way-to-find-p95-search-latency-in-elasticsearch/330356 "2023-04-20T06:44:17Z")

</div>

is there a way to find P95 latency in elasticsearch? If so, could you please share how I could do that?

---

## [To know about the compression logs](https://discuss.elastic.co/t/to-know-about-the-compression-logs/329808)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 6:37am UTC](https://discuss.elastic.co/t/to-know-about-the-compression-logs/329808 "2023-04-20T06:37:50Z")

</div>

Hi Team, We would like to know about the compression logs. These compression logs are generated when we increase the compression level in filebeat.yml. We are processing the logs from filebeat -\> kafka -\> Logstash -\> …

---

## [Integration of a dashboard to custom application](https://discuss.elastic.co/t/integration-of-a-dashboard-to-custom-application/330355)

<div class="topic-metadata">

**Author:** [@Sugunakar](https://discuss.elastic.co/u/Sugunakar)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 6:36am UTC](https://discuss.elastic.co/t/integration-of-a-dashboard-to-custom-application/330355 "2023-04-20T06:36:37Z")

</div>

Hi, I want to integrate a dashboard or a visual to a custom application. The data source is of any database. If the data in the database got updated like any new data is added or deleted the visual in the application mu…

---

## [Handshake... ERROR x509: certificate signed by unknown authorityhandshake](https://discuss.elastic.co/t/handshake-error-x509-certificate-signed-by-unknown-authorityhandshake/329741)

<div class="topic-metadata">

**Author:** [@songhe](https://discuss.elastic.co/u/songhe)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 6:06am UTC](https://discuss.elastic.co/t/handshake-error-x509-certificate-signed-by-unknown-authorityhandshake/329741 "2023-04-20T06:06:34Z")

</div>

version:7.17.9 filebeat command：filebeat test output elasticsearch: https://10.202.250.243:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: 10.202.250.243 dial up... OK TLS... …

---

## [Confirm force merging the index is running](https://discuss.elastic.co/t/confirm-force-merging-the-index-is-running/330189)

<div class="topic-metadata">

**Author:** [@ruslaniv](https://discuss.elastic.co/u/ruslaniv)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 5:09am UTC](https://discuss.elastic.co/t/confirm-force-merging-the-index-is-running/330189 "2023-04-20T05:09:18Z")

</div>

We are using a dense\_vector field for semantic search. Due to very slow performance on our index and based on several conversations here I decided to force\_merge the index to 1 segment. So it's been running asynchronous…

---

## [Customize Elastic Agent modules/integrations just like what we did with Metricbeat using Golang](https://discuss.elastic.co/t/customize-elastic-agent-modules-integrations-just-like-what-we-did-with-metricbeat-using-golang/329283)

<div class="topic-metadata">

**Author:** [@jtrongkhoa](https://discuss.elastic.co/u/jtrongkhoa)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 4:33am UTC](https://discuss.elastic.co/t/customize-elastic-agent-modules-integrations-just-like-what-we-did-with-metricbeat-using-golang/329283 "2023-04-20T04:33:41Z")

</div>

Hi all, Our company is considering using Elastic Agent instead of Beats (Metricbeat). But I am curious whether Elastic agent could be customized/extended to collect the metrics that has not been supported yet by the cur…

---

## [INstall filebeat on windows](https://discuss.elastic.co/t/install-filebeat-on-windows/330343)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 4:12am UTC](https://discuss.elastic.co/t/install-filebeat-on-windows/330343 "2023-04-20T04:12:19Z")

</div>

Hi, I am following the steps mentioned in the document elastic.co Filebeat quick start: installation and configuration | Filebeat Reference... to install filebeat on windows. but when i run the following command .\\…

---

## [Query String with Wildcard not giving exact matches in the result set first](https://discuss.elastic.co/t/query-string-with-wildcard-not-giving-exact-matches-in-the-result-set-first/330106)

<div class="topic-metadata">

**Author:** [@Avin\_Pereira](https://discuss.elastic.co/u/Avin_Pereira)\
**Replies:** 7\
**Last updated:** [April 20, 2023, 4:02am UTC](https://discuss.elastic.co/t/query-string-with-wildcard-not-giving-exact-matches-in-the-result-set-first/330106 "2023-04-20T04:02:49Z")

</div>

If a Query is fired to Elastic Search as shown below GET purchase\_order/\_search { "query": { "query\_string": { "query": "\*HEAVENLUXE-SG23FEB2022\*", "fields": \[ "purchaseOrderNumber^4" \] …

---

## [Decrease score when field has additional values](https://discuss.elastic.co/t/decrease-score-when-field-has-additional-values/330341)

<div class="topic-metadata">

**Author:** [@MattG1](https://discuss.elastic.co/u/MattG1)\
**Replies:** 0\
**Last updated:** [April 20, 2023, 3:38am UTC](https://discuss.elastic.co/t/decrease-score-when-field-has-additional-values/330341 "2023-04-20T03:38:52Z")

</div>

Hey, is it possible to decrease a score when a field has more values than is being matched for? const documents = \[ { id: 1, tags: \['a', 'b'\], }, { id: 2, tags: \['a'\], }, \]; const query = { bo…

---

## [Install filebeat on windows](https://discuss.elastic.co/t/install-filebeat-on-windows/330279)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 8:58am UTC](https://discuss.elastic.co/t/install-filebeat-on-windows/330279 "2023-04-19T08:58:06Z")

</div>

Hi, I am following the steps mentioned in the document to install filebeat on windows. but when i run the following command .\\install-service-filebeat.ps1 or PowerShell.exe -ExecutionPolicy UnRestricted -File .\\ins…

---

## [Merge tokens (terms) after the tokenisation](https://discuss.elastic.co/t/merge-tokens-terms-after-the-tokenisation/330316)

<div class="topic-metadata">

**Author:** [@Ranjana](https://discuss.elastic.co/u/Ranjana)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 11:52pm UTC](https://discuss.elastic.co/t/merge-tokens-terms-after-the-tokenisation/330316 "2023-04-19T23:52:40Z")

</div>

Hi there, I am trying to find a solution to combine all tokens (terms) after tokenisation. for example - This analyser(my-analyser) produce n tokens after applying "custom\_stop" filter. Is there any way to combine all …

---

## [Getting compile error trying to access a field that include hyphens](https://discuss.elastic.co/t/getting-compile-error-trying-to-access-a-field-that-include-hyphens/330305)

<div class="topic-metadata">

**Author:** [@rorii](https://discuss.elastic.co/u/rorii)\
**Replies:** 2\
**Last updated:** [April 19, 2023, 10:27pm UTC](https://discuss.elastic.co/t/getting-compile-error-trying-to-access-a-field-that-include-hyphens/330305 "2023-04-19T22:27:34Z")

</div>

I have a painless script that I use in my watcher and I need to access a nested element but for some reason I am getting a compile error. I access the element in this way: hits.hits\[0\].\_source.getSomething.the-problema…

---

## [EuiTable and In memory table doesn't have scroll](https://discuss.elastic.co/t/euitable-and-in-memory-table-doesnt-have-scroll/329622)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 11\
**Last updated:** [April 19, 2023, 9:59pm UTC](https://discuss.elastic.co/t/euitable-and-in-memory-table-doesnt-have-scroll/329622 "2023-04-19T21:59:56Z")

</div>

Hi, I am using both EuiTable and in-memory tables Is there a scroll functionally for the same? I couldn't find any. When the no of columns is like 10-15, the table just keeps getting compressed, rather than having a h…

---

## [Alerting API for v7.10](https://discuss.elastic.co/t/alerting-api-for-v7-10/330294)

<div class="topic-metadata">

**Author:** [@Ewen\_Field](https://discuss.elastic.co/u/Ewen_Field)\
**Replies:** 3\
**Last updated:** [April 19, 2023, 9:56pm UTC](https://discuss.elastic.co/t/alerting-api-for-v7-10/330294 "2023-04-19T21:56:43Z")

</div>

Hey! Is there a way to collect Alert Rules and a history of Alerts via the API from ELK version 7.10 ? In the documentation the Alerting API is available only since the 7.13 version. Is there a way to get this data on t…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=564)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=566)
