# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=570

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 571

---

## [Logstash throws java.lang.OutOfMemoryError: Java heap space no matter the heap size](https://discuss.elastic.co/t/logstash-throws-java-lang-outofmemoryerror-java-heap-space-no-matter-the-heap-size/330089)

<div class="topic-metadata">

**Author:** [@ste1](https://discuss.elastic.co/u/ste1)\
**Replies:** 6\
**Last updated:** [April 17, 2023, 10:57am UTC](https://discuss.elastic.co/t/logstash-throws-java-lang-outofmemoryerror-java-heap-space-no-matter-the-heap-size/330089 "2023-04-17T10:57:36Z")

</div>

Im attempting to parse a huge (few million lines) csv file with logstash and output it to elasticsearch. \[FATAL\] 2023-04-16 19:00:19.011 \[LogStash::Runner\] Logstash - java.lang.OutOfMemoryError: Java heap space …

---

## [Elasticsearch Transform API - Trying to Script a Moving Average](https://discuss.elastic.co/t/elasticsearch-transform-api-trying-to-script-a-moving-average/330115)

<div class="topic-metadata">

**Author:** [@Silver137](https://discuss.elastic.co/u/Silver137)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 10:43am UTC](https://discuss.elastic.co/t/elasticsearch-transform-api-trying-to-script-a-moving-average/330115 "2023-04-17T10:43:09Z")

</div>

My use case requieres keeping the moving average over hours withing a windows of the last 12 hours, every time the transofrm is executed. It's possible to use the "pivot" "group by" to program a transform that keeps tra…

---

## [Is it possible to have a variable scripted field which changes based on Kibana Dashboard selection?](https://discuss.elastic.co/t/is-it-possible-to-have-a-variable-scripted-field-which-changes-based-on-kibana-dashboard-selection/329908)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 10:15am UTC](https://discuss.elastic.co/t/is-it-possible-to-have-a-variable-scripted-field-which-changes-based-on-kibana-dashboard-selection/329908 "2023-04-17T10:15:46Z")

</div>

Hi, Is it possible to have a variable scripted field which changes based on Kibana Dashboard selection? I want a scripted field which changes to true of false based on kibana lens selection on the dashboard.

---

## [Block installation of bundled Npcap via Network Packet Capture integration?](https://discuss.elastic.co/t/block-installation-of-bundled-npcap-via-network-packet-capture-integration/329748)

<div class="topic-metadata">

**Author:** [@jaegerschnitzel](https://discuss.elastic.co/u/jaegerschnitzel)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 9:01am UTC](https://discuss.elastic.co/t/block-installation-of-bundled-npcap-via-network-packet-capture-integration/329748 "2023-04-17T09:01:28Z")

</div>

My old thread is closed so I'm creating a new one. We updated our Elastic Agent to v8.7.0 in order to use the new feature to block installation of the bundled Npcap library. Unfortunately this option is not available in…

---

## [Kibana helmchart throws error](https://discuss.elastic.co/t/kibana-helmchart-throws-error/330101)

<div class="topic-metadata">

**Author:** [@arun\_udaiyar](https://discuss.elastic.co/u/arun_udaiyar)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 8:40am UTC](https://discuss.elastic.co/t/kibana-helmchart-throws-error/330101 "2023-04-17T08:40:19Z")

</div>

Hi Team, I have used helmchart to deploy the stack and i have created own self-signed using openssl as per the documentation. seems fine for master, data and client communication. root@N81111:/mnt/d/elasticsearch# kub…

---

## [Alerts in a Cluster](https://discuss.elastic.co/t/alerts-in-a-cluster/330003)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves1](https://discuss.elastic.co/u/Joel_Goncalves1)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 8:27am UTC](https://discuss.elastic.co/t/alerts-in-a-cluster/330003 "2023-04-17T08:27:08Z")

</div>

Is it possible to create a cluster and each node configure rules and when an alert is heard in a node, this alert is replicated to a master node? But I didn't want alerts from other nodes or master's alerts to be replica…

---

## [Multiple lines Canva Kibana](https://discuss.elastic.co/t/multiple-lines-canva-kibana/329926)

<div class="topic-metadata">

**Author:** [@Julie\_Gils](https://discuss.elastic.co/u/Julie_Gils)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 7:45am UTC](https://discuss.elastic.co/t/multiple-lines-canva-kibana/329926 "2023-04-17T07:45:33Z")

</div>

Hi, I have several data that are calculated like this: I just wanna have the number of process by step. Data used (with aggregation) look like : And I want the chart looks like : but with canva line chart. At …

---

## [Elastic cloud with Okta SSO](https://discuss.elastic.co/t/elastic-cloud-with-okta-sso/329561)

<div class="topic-metadata">

**Author:** [@joshuskarki](https://discuss.elastic.co/u/joshuskarki)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 5:46am UTC](https://discuss.elastic.co/t/elastic-cloud-with-okta-sso/329561 "2023-04-17T05:46:12Z")

</div>

I am trying to get the Kibana with Okta SAML working, but after successfully signing in, I get {"statusCode":404,"error":"Not Found","message":"Not Found"} Has anybody come across this and know how to fix it?

---

## [Document size, weight and performance in an automatic mapping and improve it afterwards manually](https://discuss.elastic.co/t/document-size-weight-and-performance-in-an-automatic-mapping-and-improve-it-afterwards-manually/330085)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 3\
**Last updated:** [April 17, 2023, 5:13am UTC](https://discuss.elastic.co/t/document-size-weight-and-performance-in-an-automatic-mapping-and-improve-it-afterwards-manually/330085 "2023-04-17T05:13:21Z")

</div>

Is it possible to know the weight of a document in terms of bytes, to know the impact index in terms of indexing? All this in order to better optimize, to know how to configure a mapping of fields in such and such a way…

---

## [Docker-compose issue with elasticsearch and kibana docker image](https://discuss.elastic.co/t/docker-compose-issue-with-elasticsearch-and-kibana-docker-image/330067)

<div class="topic-metadata">

**Author:** [@toki0709](https://discuss.elastic.co/u/toki0709)\
**Replies:** 3\
**Last updated:** [April 16, 2023, 3:49pm UTC](https://discuss.elastic.co/t/docker-compose-issue-with-elasticsearch-and-kibana-docker-image/330067 "2023-04-16T15:49:51Z")

</div>

I am trying to create a docker-compose file with the latest image version of Elasticsearch and Kibana. Even after mentioning the version name in docker-compose.yml, I am noticing that the image version is 7.11.1 for both…

---

## [Frequently occurring "should have been dropped, but couldn't as state is not finished"](https://discuss.elastic.co/t/frequently-occurring-should-have-been-dropped-but-couldnt-as-state-is-not-finished/330082)

<div class="topic-metadata">

**Author:** [@micmeow](https://discuss.elastic.co/u/micmeow)\
**Replies:** 1\
**Last updated:** [April 16, 2023, 8:32am UTC](https://discuss.elastic.co/t/frequently-occurring-should-have-been-dropped-but-couldnt-as-state-is-not-finished/330082 "2023-04-16T08:32:13Z")

</div>

Hello. If you know how fix that, lend me your wisdom. I use filebeat to transfer logs to Logstash to Opensearch. When I checked the filebeat log, I found that the same log file transfer errors were occurring frequently…

---

## [Send logs from filebeat to elastic search](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elastic-search/330078)

<div class="topic-metadata">

**Author:** [@Abdolah\_Said](https://discuss.elastic.co/u/Abdolah_Said)\
**Replies:** 0\
**Last updated:** [April 16, 2023, 6:53am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elastic-search/330078 "2023-04-16T06:53:10Z")

</div>

i'm using winlogbeat to send log to logstash and i store logs in file path \[ /var/log/file.log \] and i have file beat in this server who send logs from the path to elasticsearch the problem is the elasticsearch show logs…

---

## [One saved Discover search without "Time"](https://discuss.elastic.co/t/one-saved-discover-search-without-time/328258)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 3\
**Last updated:** [April 15, 2023, 5:41pm UTC](https://discuss.elastic.co/t/one-saved-discover-search-without-time/328258 "2023-04-15T17:41:02Z")

</div>

Hello, In a dashboard, I need to display a table with 2 fields, with text as it is in Discover. I found it was possible with a saved search in Discover, and then in the dashboard: Add from library the saved search. …

---

## [Query questions (autocomplete)](https://discuss.elastic.co/t/query-questions-autocomplete/330047)

<div class="topic-metadata">

**Author:** [@tallboy](https://discuss.elastic.co/u/tallboy)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 10:02pm UTC](https://discuss.elastic.co/t/query-questions-autocomplete/330047 "2023-04-14T22:02:17Z")

</div>

Hello, I am trying to craft a query which will allow a realtime search dropdown: My search data has 3 columns: name (text) alternate\_names (array of text) description (text) The only column which shows in the dro…

---

## [Reduce load time of Kibana-8.6.2](https://discuss.elastic.co/t/reduce-load-time-of-kibana-8-6-2/330065)

<div class="topic-metadata">

**Author:** [@akansha.agarwal1](https://discuss.elastic.co/u/akansha.agarwal1)\
**Replies:** 0\
**Last updated:** [April 15, 2023, 12:51pm UTC](https://discuss.elastic.co/t/reduce-load-time-of-kibana-8-6-2/330065 "2023-04-15T12:51:34Z")

</div>

hi I am using Elastic stack 8.6.2 Average time to load dashboard is close to 13sec with a single user. Please note that visualizations consists of a mix of Kibana lens & Vega lite. Most of the time is consumed in load…

---

## [How can I get several search results on a huge document? (like a book or a big article)](https://discuss.elastic.co/t/how-can-i-get-several-search-results-on-a-huge-document-like-a-book-or-a-big-article/329885)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 3\
**Last updated:** [April 15, 2023, 9:47am UTC](https://discuss.elastic.co/t/how-can-i-get-several-search-results-on-a-huge-document-like-a-book-or-a-big-article/329885 "2023-04-15T09:47:35Z")

</div>

Is it possible to use elasticsearch to get several search results when preforming search on big documents? Like a book or huge articles.. So I get not only the article itself but also all the positions of relevant data…

---

## [Error - circuit\_breaking\_exception, \[parent\] Data too large](https://discuss.elastic.co/t/error-circuit-breaking-exception-parent-data-too-large/330055)

<div class="topic-metadata">

**Author:** [@Bugsbee](https://discuss.elastic.co/u/Bugsbee)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 7:39am UTC](https://discuss.elastic.co/t/error-circuit-breaking-exception-parent-data-too-large/330055 "2023-04-15T07:39:39Z")

</div>

Hi Community Whenever i try to search in dashboard i keep on getting this error. any idea how to fix this? I confirm my storage is fine . how to fix this polease Request error: circuit\_breaking\_exception, \[parent\] D…

---

## [Elasticsearch - search by two fields. And how to use one text with Text type and custom analyzer](https://discuss.elastic.co/t/elasticsearch-search-by-two-fields-and-how-to-use-one-text-with-text-type-and-custom-analyzer/330054)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 0\
**Last updated:** [April 15, 2023, 6:04am UTC](https://discuss.elastic.co/t/elasticsearch-search-by-two-fields-and-how-to-use-one-text-with-text-type-and-custom-analyzer/330054 "2023-04-15T06:04:49Z")

</div>

There is a set of data that I want to fit into Elasticsearch. Product description - a few paragraphs. I have a lot of them - about 250mln. At the same time I want to remove stop words, hunspell and a couple of other thi…

---

## [Loading Kibana dashboards using Metricbeat through HELM charts](https://discuss.elastic.co/t/loading-kibana-dashboards-using-metricbeat-through-helm-charts/329414)

<div class="topic-metadata">

**Author:** [@RoshRagh](https://discuss.elastic.co/u/RoshRagh)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 10:33am UTC](https://discuss.elastic.co/t/loading-kibana-dashboards-using-metricbeat-through-helm-charts/329414 "2023-04-05T10:33:10Z")

</div>

Hi, I am looking to load the default dashboards that come pre-built in Kibana by setting up a Kibana endpoint in metricbeat configuration. The "setup.kibana" option is not really available in the official metricbeat hel…

---

## [How to create proper alert for multiple hits?](https://discuss.elastic.co/t/how-to-create-proper-alert-for-multiple-hits/329432)

<div class="topic-metadata">

**Author:** [@jackshan](https://discuss.elastic.co/u/jackshan)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 5:10am UTC](https://discuss.elastic.co/t/how-to-create-proper-alert-for-multiple-hits/329432 "2023-04-15T05:10:41Z")

</div>

I have a scenario where i am matching two metadata along with "level" = "error". I am setting the time to last 15 minutes for running the query. The monitor does capture what i want, but when there are multiple hits in …

---

## [Metricbeat - INDEX LIFECYCLE ERROR](https://discuss.elastic.co/t/metricbeat-index-lifecycle-error/328149)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 5:07am UTC](https://discuss.elastic.co/t/metricbeat-index-lifecycle-error/328149 "2023-04-15T05:07:41Z")

</div>

Hi i have an indices which the ILM get an error. Could you please help me here ? "lifecycle": { "name": "metricbeat", "rollover\_alias": "metricbeat" }, If more information is needed ple…

---

## [Kibana Alerts USAGE](https://discuss.elastic.co/t/kibana-alerts-usage/329467)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 5:04am UTC](https://discuss.elastic.co/t/kibana-alerts-usage/329467 "2023-04-15T05:04:40Z")

</div>

Hi, I am looking a way to know which is the usage of every alert in my cluster. Elastic has any predefine dashboard for this? or there is an index that has this information? Thanks,

---

## [Remove Processor return an illegal\_argument\_exception error](https://discuss.elastic.co/t/remove-processor-return-an-illegal-argument-exception-error/329470)

<div class="topic-metadata">

**Author:** [@Anh\_Nguyen](https://discuss.elastic.co/u/Anh_Nguyen)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 2:47am UTC](https://discuss.elastic.co/t/remove-processor-return-an-illegal-argument-exception-error/329470 "2023-04-06T02:47:37Z")

</div>

I want to remove some duplicated fileds' value by using remove processor in ingest pipeline. I using Elastic Agent to collect log. The problem is I always got an error in output is: "field \[field\_name\] not present as par…

---

## [Difference of timing](https://discuss.elastic.co/t/difference-of-timing/329493)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 5:02am UTC](https://discuss.elastic.co/t/difference-of-timing/329493 "2023-04-15T05:02:04Z")

</div>

Hello, I faced an issue that when I send the data from the data source to logstash and elastic the data reach Kibana with a specific time but when Kibana display the records the time on it is delayed for 7 minutes as be…

---

## [\_id field not aggregatable after Elastic migration to 8.6.2](https://discuss.elastic.co/t/id-field-not-aggregatable-after-elastic-migration-to-8-6-2/329490)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:59am UTC](https://discuss.elastic.co/t/id-field-not-aggregatable-after-elastic-migration-to-8-6-2/329490 "2023-04-15T04:59:53Z")

</div>

Hi all, I migrated my Elastic & kibana versions from 7.9 to 7.17 to 8.6.2. I continued to use same dashboards and data. But in new ES version, I'm getting below issue for \_id field. I noticed that in old version, …

---

## [Watcher's transform adds smaller number of the values](https://discuss.elastic.co/t/watchers-transform-adds-smaller-number-of-the-values/329497)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 9:07am UTC](https://discuss.elastic.co/t/watchers-transform-adds-smaller-number-of-the-values/329497 "2023-04-06T09:07:48Z")

</div>

Hi, I'd like to make watcher which will write to a certain index unique values of the particular field. A part of my query is { "query" : { "bool": { "must": \[ { "wildcard": { "field": { "value"…

---

## [Kibana Dashboards in MS Teams](https://discuss.elastic.co/t/kibana-dashboards-in-ms-teams/329530)

<div class="topic-metadata">

**Author:** [@htunahan](https://discuss.elastic.co/u/htunahan)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:57am UTC](https://discuss.elastic.co/t/kibana-dashboards-in-ms-teams/329530 "2023-04-15T04:57:29Z")

</div>

Hi Guys, I have already prepared some dashboard with Kibana and now I would like to show them in MS Teams if it is possible. I have tried to add a website to my Teams channel and put my dashboard URL but it didn't work.…

---

## [KIbana automatic-reports post url changes](https://discuss.elastic.co/t/kibana-automatic-reports-post-url-changes/329667)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:46am UTC](https://discuss.elastic.co/t/kibana-automatic-reports-post-url-changes/329667 "2023-04-15T04:46:31Z")

</div>

Hi, in older version of kibana 7.x the post url for reporting was very long, but you could manipulate the string to filter de data, so you put the names of the hosts in an array and iterate trouhg it and use one dashboa…

---

## [Saved visualisation on kibana pods](https://discuss.elastic.co/t/saved-visualisation-on-kibana-pods/329690)

<div class="topic-metadata">

**Author:** [@Sibasish\_Behera](https://discuss.elastic.co/u/Sibasish_Behera)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:45am UTC](https://discuss.elastic.co/t/saved-visualisation-on-kibana-pods/329690 "2023-04-15T04:45:14Z")

</div>

Is there any way to save predefined visualisation for kibana running as a kubernetes pod for eg i can make make a metric visualisation on number of request to my service but i want it to be a default visualisation when…

---

## [How to filter a different field when a value is selected in another field in Kibana?](https://discuss.elastic.co/t/how-to-filter-a-different-field-when-a-value-is-selected-in-another-field-in-kibana/329762)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:33am UTC](https://discuss.elastic.co/t/how-to-filter-a-different-field-when-a-value-is-selected-in-another-field-in-kibana/329762 "2023-04-15T04:33:18Z")

</div>

hi, Lets says I have the below index PUT /testindex/ { "mappings": { "properties": { "field1": { "type": "keyword" }, "Data": { "type": "keyword" } } } } POST /testindex/\_…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=569)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=571)
