# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=578

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 579

---

## [Azure Elastic Cloud - NEST Client - API call fails with Faulted](https://discuss.elastic.co/t/azure-elastic-cloud-nest-client-api-call-fails-with-faulted/329558)

<div class="topic-metadata">

**Author:** [@rahul-reveation](https://discuss.elastic.co/u/rahul-reveation)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 9:56pm UTC](https://discuss.elastic.co/t/azure-elastic-cloud-nest-client-api-call-fails-with-faulted/329558 "2023-04-06T21:56:28Z")

</div>

On Azure, we have a.Net Core App that connects to ES Cloud. The app makes use of the NEST client. We've recently noticed intermittent issues where the client call to ES would fail at random. Azure Insight reports that it…

---

## [Max limit for number of search results](https://discuss.elastic.co/t/max-limit-for-number-of-search-results/329544)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 7:29pm UTC](https://discuss.elastic.co/t/max-limit-for-number-of-search-results/329544 "2023-04-06T19:29:08Z")

</div>

What is the limit on number of search results by Elasticsearch? Is it 10,000? Which config parameter drives this count? Is it possible to export documents in terms of millions?

---

## [Desired Balance Allocator stuck - preventing assignment of new shards](https://discuss.elastic.co/t/desired-balance-allocator-stuck-preventing-assignment-of-new-shards/328633)

<div class="topic-metadata">

**Author:** [@itizir](https://discuss.elastic.co/u/itizir)\
**Replies:** 15\
**Last updated:** [April 6, 2023, 7:17pm UTC](https://discuss.elastic.co/t/desired-balance-allocator-stuck-preventing-assignment-of-new-shards/328633 "2023-04-06T19:17:54Z")

</div>

Hello, On one of our larger stacks, we have recently seen (twice last week) a problem seemingly related to the new 'desired balance allocator'. The documentation seems to imply this is purely a background operation so t…

---

## [Update to 8.7.0](https://discuss.elastic.co/t/update-to-8-7-0/329525)

<div class="topic-metadata">

**Author:** [@adis3421](https://discuss.elastic.co/u/adis3421)\
**Replies:** 4\
**Last updated:** [April 6, 2023, 6:18pm UTC](https://discuss.elastic.co/t/update-to-8-7-0/329525 "2023-04-06T18:18:39Z")

</div>

Hi, I have problem with kibana Analitycs \> Discover after update to version 8.7.0 from 8.6.1 on Oracle Linux 8.7 many options working without error

---

## [I need help creating a Kibana visualization](https://discuss.elastic.co/t/i-need-help-creating-a-kibana-visualization/329535)

<div class="topic-metadata">

**Author:** [@em817m](https://discuss.elastic.co/u/em817m)\
**Replies:** 2\
**Last updated:** [April 6, 2023, 4:30pm UTC](https://discuss.elastic.co/t/i-need-help-creating-a-kibana-visualization/329535 "2023-04-06T16:30:16Z")

</div>

I am new to Kibana and need to create a visualization for some performance data that I have collected. I am running Kibana 6.3.0. The data is extracted from a CSV file and looks like this in Kibana Discover window: W…

---

## [Effects of changing ILM policy](https://discuss.elastic.co/t/effects-of-changing-ilm-policy/329516)

<div class="topic-metadata">

**Author:** [@india](https://discuss.elastic.co/u/india)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 3:54pm UTC](https://discuss.elastic.co/t/effects-of-changing-ilm-policy/329516 "2023-04-06T15:54:04Z")

</div>

I am using Elasticsearch 7.17.0. I have configured ILM policy in following way: "post\_policy" : { "version" : 1, "modified\_date" : "2021-07-26T19:20:56.981Z", "policy" : { "phases" : { "hot…

---

## [Express.js not sending compressed files to front-end after compression enabled](https://discuss.elastic.co/t/express-js-not-sending-compressed-files-to-front-end-after-compression-enabled/329532)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 3:49pm UTC](https://discuss.elastic.co/t/express-js-not-sending-compressed-files-to-front-end-after-compression-enabled/329532 "2023-04-06T15:49:47Z")

</div>

I have an express.js server that's pulling data from Elasticsearch and serving it to the browser. I was under the impression that all I needed to do for the express app to send compressed responses was activating compres…

---

## [Ingest Pipeline - Date Processor Timezone](https://discuss.elastic.co/t/ingest-pipeline-date-processor-timezone/329457)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 7\
**Last updated:** [April 6, 2023, 3:48pm UTC](https://discuss.elastic.co/t/ingest-pipeline-date-processor-timezone/329457 "2023-04-06T15:48:39Z")

</div>

Hello, I'm trying to configure an ingest pipeline using Kibana. I'm ingesting data into Elasticsearch using filebeat and this pipeline. Among other fields, I'm ingesting the document's timestamp. To "parse" the date fro…

---

## [Parse log file line by line](https://discuss.elastic.co/t/parse-log-file-line-by-line/329518)

<div class="topic-metadata">

**Author:** [@pen120](https://discuss.elastic.co/u/pen120)\
**Replies:** 3\
**Last updated:** [April 6, 2023, 1:58pm UTC](https://discuss.elastic.co/t/parse-log-file-line-by-line/329518 "2023-04-06T13:58:53Z")

</div>

I have a log file with output repetitive below, I want to parse this log line by line in fields to extract the value for each line 10:31:07 2022/10/16 ZBXTRAP 192.168.23.2 PDU INFO: messageid 0 …

---

## [Elastic licences](https://discuss.elastic.co/t/elastic-licences/329174)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves](https://discuss.elastic.co/u/Joel_Goncalves)\
**Replies:** 21\
**Last updated:** [April 6, 2023, 1:17pm UTC](https://discuss.elastic.co/t/elastic-licences/329174 "2023-04-06T13:17:42Z")

</div>

Hello, I have a cluster with 1 master and 2 nodes, if I install the enterpise license on a node, will it move to the other node or to the master?

---

## [Unable to authenticate user \[logstash\_internal\] for REST request \[/bulk\]](https://discuss.elastic.co/t/unable-to-authenticate-user-logstash-internal-for-rest-request-bulk/329473)

<div class="topic-metadata">

**Author:** [@oscardoudou](https://discuss.elastic.co/u/oscardoudou)\
**Replies:** 3\
**Last updated:** [April 6, 2023, 12:59pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-logstash-internal-for-rest-request-bulk/329473 "2023-04-06T12:59:33Z")

</div>

logstash 7.17.9 \[2023-04-05T22:50:02,837\]\[ERROR\]\[logstash.outputs.elasticsearch\]\[main\] Encountered a retryable error (will retry with exponential backoff) {:code=\>401, :url=\>"http://server:9200/\_bulk", :content\_length=\>…

---

## [Docker cluster](https://discuss.elastic.co/t/docker-cluster/329511)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 12:53pm UTC](https://discuss.elastic.co/t/docker-cluster/329511 "2023-04-06T12:53:21Z")

</div>

hi how to check the logs at /usr/share/elasticsearch/logs/docker-cluster.log

---

## [How can be use the alerting for a data query](https://discuss.elastic.co/t/how-can-be-use-the-alerting-for-a-data-query/327671)

<div class="topic-metadata">

**Author:** [@allaboutopensource](https://discuss.elastic.co/u/allaboutopensource)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 12:32pm UTC](https://discuss.elastic.co/t/how-can-be-use-the-alerting-for-a-data-query/327671 "2023-04-06T12:32:50Z")

</div>

we have to setup an alert for all the windows event logs which are under the "error" types. I was able to create the dashboard for the windows event logs which eventually shows me the count of the event logs which has "e…

---

## [Logstash snmp OID](https://discuss.elastic.co/t/logstash-snmp-oid/327677)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 2\
**Last updated:** [April 6, 2023, 12:30pm UTC](https://discuss.elastic.co/t/logstash-snmp-oid/327677 "2023-04-06T12:30:20Z")

</div>

Hi all. In logstash, I use the snmp module to poll the OIDs. It partially works, I get the required values. I have many OIDs and hosts to poll. The problem is that on some of the equipment certain oids do not work or …

---

## [Elastic Fleet Vault Integration](https://discuss.elastic.co/t/elastic-fleet-vault-integration/329330)

<div class="topic-metadata">

**Author:** [@adis3421](https://discuss.elastic.co/u/adis3421)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 11:12am UTC](https://discuss.elastic.co/t/elastic-fleet-vault-integration/329330 "2023-04-06T11:12:05Z")

</div>

Hi, I add vault integration in elastic agent after instalation I have in my vault: on fleet server port 9007/tcp is open but not listen on tcp but only tcp6

---

## [Post-installation warning message](https://discuss.elastic.co/t/post-installation-warning-message/329218)

<div class="topic-metadata">

**Author:** [@Ghepardo](https://discuss.elastic.co/u/Ghepardo)\
**Replies:** 7\
**Last updated:** [April 6, 2023, 10:02am UTC](https://discuss.elastic.co/t/post-installation-warning-message/329218 "2023-04-06T10:02:57Z")

</div>

I have installed Elasticsearch on an Ubuntu 22.04 system. When I start the service, I get a warning message like the following in the Elasticsearch log: \[2023-04-03T14:07:41,411\]\[WARN \]\[stderr \] \[\<\<ho…

---

## [SOLR collection to Elasticsearch Indices data migration](https://discuss.elastic.co/t/solr-collection-to-elasticsearch-indices-data-migration/329364)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 5\
**Last updated:** [April 6, 2023, 9:25am UTC](https://discuss.elastic.co/t/solr-collection-to-elasticsearch-indices-data-migration/329364 "2023-04-06T09:25:06Z")

</div>

Is it possible to migrate the indexed data (collections) in SOLR to Elasticsearch (Indices)? Data volume will be around 100 million to 1 billion. If yes. What should be the approach? Is there any migration tool availabl…

---

## [Logstash bulk requests growing after some time](https://discuss.elastic.co/t/logstash-bulk-requests-growing-after-some-time/328486)

<div class="topic-metadata">

**Author:** [@zerzn](https://discuss.elastic.co/u/zerzn)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 9:15am UTC](https://discuss.elastic.co/t/logstash-bulk-requests-growing-after-some-time/328486 "2023-04-06T09:15:47Z")

</div>

hi, I have a strange situation with logstash with elasticsearch and maybe someone can help me out. My logstash bulk requests to elasticsearch are growing after some hours. (2-24h) There are arround 1000 winlogbeat age…

---

## [Type of Long not valid in time series dimension](https://discuss.elastic.co/t/type-of-long-not-valid-in-time-series-dimension/329464)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 4\
**Last updated:** [April 6, 2023, 8:52am UTC](https://discuss.elastic.co/t/type-of-long-not-valid-in-time-series-dimension/329464 "2023-04-06T08:52:18Z")

</div>

Hi Is this a bug? I can't use a type long field for a time\_series\_dimension. this is a simple example: PUT /temperature01 { "settings": { "index": { "mode": "time\_series", "time\_seri…

---

## [In Operator Behaves Unexpectedly When Used in a Filter](https://discuss.elastic.co/t/in-operator-behaves-unexpectedly-when-used-in-a-filter/329449)

<div class="topic-metadata">

**Author:** [@foxfire-auspex](https://discuss.elastic.co/u/foxfire-auspex)\
**Replies:** 2\
**Last updated:** [April 6, 2023, 8:42am UTC](https://discuss.elastic.co/t/in-operator-behaves-unexpectedly-when-used-in-a-filter/329449 "2023-04-06T08:42:59Z")

</div>

Hello, I just had a very strange experience debugging one of our Logstash filters and would like to know whether we could have anticipated this or encountered a known quirk or bug (we run Logstash v7.17). Please see be…

---

## [How to count documents in Elasticsearch with exclusive name-value attribute filters of nested type?](https://discuss.elastic.co/t/how-to-count-documents-in-elasticsearch-with-exclusive-name-value-attribute-filters-of-nested-type/329491)

<div class="topic-metadata">

**Author:** [@AKSHAY\_AGARWAL1](https://discuss.elastic.co/u/AKSHAY_AGARWAL1)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 8:05am UTC](https://discuss.elastic.co/t/how-to-count-documents-in-elasticsearch-with-exclusive-name-value-attribute-filters-of-nested-type/329491 "2023-04-06T08:05:12Z")

</div>

\`Require a solution to count the number of documents in Elasticsearch that match a given set of exclusive name-value attribute pairs, where the attribute field is of nested type. The output should show the count of docum…

---

## [Can I use Packetbeat and the ELK stack for network logs generated by a website button](https://discuss.elastic.co/t/can-i-use-packetbeat-and-the-elk-stack-for-network-logs-generated-by-a-website-button/329489)

<div class="topic-metadata">

**Author:** [@Jana\_Urmi](https://discuss.elastic.co/u/Jana_Urmi)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 7:43am UTC](https://discuss.elastic.co/t/can-i-use-packetbeat-and-the-elk-stack-for-network-logs-generated-by-a-website-button/329489 "2023-04-06T07:43:42Z")

</div>

I wrote a Python script to extract the network logs generated by clicking a button on a website using Selenium and store them in a file. I now want to use the ELK stack to visualize the logs. I'm confused whether Packet…

---

## [Logstash s3 parsing issue](https://discuss.elastic.co/t/logstash-s3-parsing-issue/329484)

<div class="topic-metadata">

**Author:** [@Rushikesh](https://discuss.elastic.co/u/Rushikesh)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 6:12am UTC](https://discuss.elastic.co/t/logstash-s3-parsing-issue/329484 "2023-04-06T06:12:30Z")

</div>

output { s3 { access\_key\_id =\> "test" secret\_access\_key =\> "test" bucket =\> "logstorage" region =\> "us-west-1" codec =\> "json\_lines" prefix =\> "%{+YYYY}/%{+MM}/%{+dd}/example.log" } } So I h…

---

## [Logstash Output Issue](https://discuss.elastic.co/t/logstash-output-issue/329319)

<div class="topic-metadata">

**Author:** [@Rushikesh](https://discuss.elastic.co/u/Rushikesh)\
**Replies:** 2\
**Last updated:** [April 6, 2023, 5:10am UTC](https://discuss.elastic.co/t/logstash-output-issue/329319 "2023-04-06T05:10:29Z")

</div>

Below is my logstash configuration file. input { beats { port =\> 5044 } } filter { json { source =\> "message" } } output { stdout { codec =\> json } } filter { mutate { add\_field =\> { …

---

## [Logstash query against elastic returning unwanted field](https://discuss.elastic.co/t/logstash-query-against-elastic-returning-unwanted-field/329418)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 5:05am UTC](https://discuss.elastic.co/t/logstash-query-against-elastic-returning-unwanted-field/329418 "2023-04-06T05:05:45Z")

</div>

I am exporting the metricbeat index from elastic using logstash. I would like to exclude the service.type term docker from the output. I am using the following query: query =\> '{ "query": { …

---

## [Can we use Scann for vector similarity in elasticsearch?](https://discuss.elastic.co/t/can-we-use-scann-for-vector-similarity-in-elasticsearch/328682)

<div class="topic-metadata">

**Author:** [@prakritidev](https://discuss.elastic.co/u/prakritidev)\
**Replies:** 2\
**Last updated:** [April 6, 2023, 4:58am UTC](https://discuss.elastic.co/t/can-we-use-scann-for-vector-similarity-in-elasticsearch/328682 "2023-04-06T04:58:34Z")

</div>

Hi, I am using es 7.14 and the cosine similairty function is not optimal as compare to other technologies. Can I use ScaNN somehow instead ? How will i integrate that library is thats possible. Thanks.

---

## [Silent setup](https://discuss.elastic.co/t/silent-setup/328972)

<div class="topic-metadata">

**Author:** [@geb](https://discuss.elastic.co/u/geb)\
**Replies:** 3\
**Last updated:** [April 6, 2023, 4:48am UTC](https://discuss.elastic.co/t/silent-setup/328972 "2023-04-06T04:48:57Z")

</div>

Is it possible to issue the command /usr/share/elasticsearch/bin/elasticsearch-certutil http in unattended mode? I automated the whole certificate generation stuff but couldnt solve this task.

---

## [Filebeat stops sending logs after kubernetes deployment.Hence logs loosing happens](https://discuss.elastic.co/t/filebeat-stops-sending-logs-after-kubernetes-deployment-hence-logs-loosing-happens/329480)

<div class="topic-metadata">

**Author:** [@Perwaiz\_Alam](https://discuss.elastic.co/u/Perwaiz_Alam)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 4:45am UTC](https://discuss.elastic.co/t/filebeat-stops-sending-logs-after-kubernetes-deployment-hence-logs-loosing-happens/329480 "2023-04-06T04:45:14Z")

</div>

Filebeat stops sending logs after kubernetes deployment.Hence logs loosing happens

---

## [I have a question need great god help to have a look, a data into the es and run for a period of time will appear stuck, here are some information](https://discuss.elastic.co/t/i-have-a-question-need-great-god-help-to-have-a-look-a-data-into-the-es-and-run-for-a-period-of-time-will-appear-stuck-here-are-some-information/329184)

<div class="topic-metadata">

**Author:** [@northestface](https://discuss.elastic.co/u/northestface)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 3:14am UTC](https://discuss.elastic.co/t/i-have-a-question-need-great-god-help-to-have-a-look-a-data-into-the-es-and-run-for-a-period-of-time-will-appear-stuck-here-are-some-information/329184 "2023-04-06T03:14:40Z")

</div>

this is jstash information 2023-04-03 16:34:24 Full thread dump OpenJDK 64-Bit Server VM (17.0.6+10 mixed mode, sharing): Threads class SMR info: \_java\_thread\_list=0x00007f24d0004620, length=41, elements={ 0x00007f251c…

---

## [Elastic hide/remove some unwanted fields](https://discuss.elastic.co/t/elastic-hide-remove-some-unwanted-fields/329433)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 1\
**Last updated:** [April 6, 2023, 1:02am UTC](https://discuss.elastic.co/t/elastic-hide-remove-some-unwanted-fields/329433 "2023-04-06T01:02:20Z")

</div>

I have elastic basic free license can I hide some fields to a specific user ? or can I remove certain fields from appearing in kibana by unwanted fields, I meant these fields "@version", "\_id", "\_index", "\_score", "\_t…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=577)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=579)
