# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=581

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 582

---

## [Mongodb/logstash connect error](https://discuss.elastic.co/t/mongodb-logstash-connect-error/328799)

<div class="topic-metadata">

**Author:** [@jskang](https://discuss.elastic.co/u/jskang)\
**Replies:** 18\
**Last updated:** [April 4, 2023, 9:57am UTC](https://discuss.elastic.co/t/mongodb-logstash-connect-error/328799 "2023-04-04T09:57:48Z")

</div>

This is an error message when running logstash. error message: Using bundled JDK: /home/admin/lg-862/jdk Sending Logstash logs to /home/admin/lg-862/logs which is now configured via log4j2.properties \[2023-03-29T18:2…

---

## [Need help to push pm2 logs into ELK server](https://discuss.elastic.co/t/need-help-to-push-pm2-logs-into-elk-server/329176)

<div class="topic-metadata">

**Author:** [@SUNA](https://discuss.elastic.co/u/SUNA)\
**Replies:** 7\
**Last updated:** [April 4, 2023, 9:16am UTC](https://discuss.elastic.co/t/need-help-to-push-pm2-logs-into-elk-server/329176 "2023-04-04T09:16:55Z")

</div>

Hi Team, Could you please help to push pm2 service logs for nodejs application into ELK server.

---

## [Old question but at a loss http\_request which is larger than the limit of \[\*\*\*\*\*/4.1gb\]](https://discuss.elastic.co/t/old-question-but-at-a-loss-http-request-which-is-larger-than-the-limit-of-4-1gb/329295)

<div class="topic-metadata">

**Author:** [@uschellh](https://discuss.elastic.co/u/uschellh)\
**Replies:** 2\
**Last updated:** [April 4, 2023, 8:54am UTC](https://discuss.elastic.co/t/old-question-but-at-a-loss-http-request-which-is-larger-than-the-limit-of-4-1gb/329295 "2023-04-04T08:54:54Z")

</div>

Hello, i already increased Java Heap sizes for graylog-server which is 4.3.13 and elasticsearch . According to the nodes overview, my settings for graylog of 8/12 gb are not filled. Elasticsearch can do searches (someti…

---

## [\[WARN \]\[o.e.c.c.ClusterFormationFailureHelper\] \[node1\] master not discovered yet, this node has not previously joined a bootstrapped cluster](https://discuss.elastic.co/t/warn-o-e-c-c-clusterformationfailurehelper-node1-master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-cluster/329267)

<div class="topic-metadata">

**Author:** [@Raghulvishal](https://discuss.elastic.co/u/Raghulvishal)\
**Replies:** 9\
**Last updated:** [April 4, 2023, 7:56am UTC](https://discuss.elastic.co/t/warn-o-e-c-c-clusterformationfailurehelper-node1-master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-cluster/329267 "2023-04-04T07:56:16Z")

</div>

Hi Team, I am using ES 8.6 version and configured 3 nodes,while starting the node i'am getting master not discovered yet exception. This is my elastic .yml given below. cluster.name: es-8\_6 node.name: node1 path.dat…

---

## [Best method for calculating text embedding for a KNN search?](https://discuss.elastic.co/t/best-method-for-calculating-text-embedding-for-a-knn-search/329258)

<div class="topic-metadata">

**Author:** [@scott\_root](https://discuss.elastic.co/u/scott_root)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 7:50am UTC](https://discuss.elastic.co/t/best-method-for-calculating-text-embedding-for-a-knn-search/329258 "2023-04-04T07:50:15Z")

</div>

Hello, I am using Elastic Cloud and am using pre-trained ML models for text/semantic search and for image search. Currently, in order to do a text KNN search I have to make two API calls to ES, first to get the text em…

---

## [Failed to enable unit](https://discuss.elastic.co/t/failed-to-enable-unit/329289)

<div class="topic-metadata">

**Author:** [@bhargav.burugupalli](https://discuss.elastic.co/u/bhargav.burugupalli)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 7:45am UTC](https://discuss.elastic.co/t/failed-to-enable-unit/329289 "2023-04-04T07:45:37Z")

</div>

Hello everyone, Good day ! I was trying to setup Elastic search on a RHEL machine in our office network. And following through this link.Install Elasticsearch with RPM | Elasticsearch Guide \[8.7\] | Elastic When I am t…

---

## [Delay in logs in filebeat for only one index](https://discuss.elastic.co/t/delay-in-logs-in-filebeat-for-only-one-index/329282)

<div class="topic-metadata">

**Author:** [@ks-ak](https://discuss.elastic.co/u/ks-ak)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 7:24am UTC](https://discuss.elastic.co/t/delay-in-logs-in-filebeat-for-only-one-index/329282 "2023-04-04T07:24:08Z")

</div>

Hi! I have filebeat with multiple indexes and one particular index is causing the issue and other indexes are sending logs without delayi.e., Sending logs to Kibana is getting delayed by 6 hours for the particular index…

---

## [Shield Licensing in 2023](https://discuss.elastic.co/t/shield-licensing-in-2023/329272)

<div class="topic-metadata">

**Author:** [@ovidiutirsa-en](https://discuss.elastic.co/u/ovidiutirsa-en)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 7:09am UTC](https://discuss.elastic.co/t/shield-licensing-in-2023/329272 "2023-04-04T07:09:41Z")

</div>

Hello, We are currently self hosting a very old version of Elasticsearch (2.0) and are in need of extending our Shield plugin license. Is there a way to contact someone from ES for pricing? Querying on emails did not h…

---

## [Elastic agent fails to install on Centos 7](https://discuss.elastic.co/t/elastic-agent-fails-to-install-on-centos-7/329260)

<div class="topic-metadata">

**Author:** [@sblack](https://discuss.elastic.co/u/sblack)\
**Replies:** 10\
**Last updated:** [April 4, 2023, 4:21am UTC](https://discuss.elastic.co/t/elastic-agent-fails-to-install-on-centos-7/329260 "2023-04-04T04:21:19Z")

</div>

Hi, I am getting the following error message when attempting to install Fleet agent: Installed as a system package, installation will not be altered. Error: failed to execute enroll command: fork/exec /usr/bin/elastic-…

---

## [Setting up monitoring cluster](https://discuss.elastic.co/t/setting-up-monitoring-cluster/329106)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 4:11am UTC](https://discuss.elastic.co/t/setting-up-monitoring-cluster/329106 "2023-04-04T04:11:18Z")

</div>

I have cluster running 7.17 and want to setup monitoring cluster with 8.x version can I use metricbeat 8.x on elastic cluster running 7.17? they way I understand metricbeat is just going to pull data from cluster/node…

---

## [Would be a good idea to turn all data nodes into non-eligible masters?](https://discuss.elastic.co/t/would-be-a-good-idea-to-turn-all-data-nodes-into-non-eligible-masters/329261)

<div class="topic-metadata">

**Author:** [@Bruno\_Arruda](https://discuss.elastic.co/u/Bruno_Arruda)\
**Replies:** 2\
**Last updated:** [April 4, 2023, 3:57am UTC](https://discuss.elastic.co/t/would-be-a-good-idea-to-turn-all-data-nodes-into-non-eligible-masters/329261 "2023-04-04T03:57:08Z")

</div>

Hi, Actually I have a cluster with 4 master nodes and 10 data nodes on a Kubernetes Cluster. Basically, each node causes my cluster to scale new hosts because of the anti-affinity default behavior, so my k8s got 14 node…

---

## [Determine a document's origin](https://discuss.elastic.co/t/determine-a-documents-origin/329253)

<div class="topic-metadata">

**Author:** [@etnachtman](https://discuss.elastic.co/u/etnachtman)\
**Replies:** 3\
**Last updated:** [April 4, 2023, 2:39am UTC](https://discuss.elastic.co/t/determine-a-documents-origin/329253 "2023-04-04T02:39:33Z")

</div>

Is there a way to glean additional information on what generated a document in elasticsearch? I'm working with an inherited reporting architecture and found some visualizations that are using an index pattern I'm not fa…

---

## [Filter Vector Points by Class (Maps)](https://discuss.elastic.co/t/filter-vector-points-by-class-maps/329234)

<div class="topic-metadata">

**Author:** [@m.hanna](https://discuss.elastic.co/u/m.hanna)\
**Replies:** 4\
**Last updated:** [April 4, 2023, 1:51am UTC](https://discuss.elastic.co/t/filter-vector-points-by-class-maps/329234 "2023-04-04T01:51:54Z")

</div>

We have a map server on a disconnected network that is serving vector tiles only (tileserver-gl-light). I can create a basemap in the Elastic Maps, but would like to be able to filter the points by class. For example, "p…

---

## [How to set timezone when use python sdk?](https://discuss.elastic.co/t/how-to-set-timezone-when-use-python-sdk/329011)

<div class="topic-metadata">

**Author:** [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 1:49am UTC](https://discuss.elastic.co/t/how-to-set-timezone-when-use-python-sdk/329011 "2023-04-04T01:49:09Z")

</div>

{ "\_index": "mysql\_backup\_stat", "\_type": "\_doc", "\_id": "addb-m15-2023-03-31T02:31:22.920268+08:00", "\_version": 1, "\_score": null, "\_source": { "timestamp": "2023-03-31T02:31:22.920268+08:00", "host…

---

## [Kafka 0 partition metadata cannot be read in logstash6.8, other partitions can. Sample configuration:](https://discuss.elastic.co/t/kafka-0-partition-metadata-cannot-be-read-in-logstash6-8-other-partitions-can-sample-configuration/329055)

<div class="topic-metadata">

**Author:** [@angus](https://discuss.elastic.co/u/angus)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 1:45am UTC](https://discuss.elastic.co/t/kafka-0-partition-metadata-cannot-be-read-in-logstash6-8-other-partitions-can-sample-configuration/329055 "2023-04-04T01:45:44Z")

</div>

kafka 0 partition metadata cannot be read in logstash6.8, other partitions can. Sample configuration: input { kafka { client\_id =\> "ycUsrRdNews" consumer\_threads =\> 4 bootstrap\_servers =\> "${KAFKA\_BOOTSTRAP\_SERVE…

---

## [Elasticsearch - getting Circuit breaker exception with sudden spike in Heap usage](https://discuss.elastic.co/t/elasticsearch-getting-circuit-breaker-exception-with-sudden-spike-in-heap-usage/329231)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 1:33am UTC](https://discuss.elastic.co/t/elasticsearch-getting-circuit-breaker-exception-with-sudden-spike-in-heap-usage/329231 "2023-04-04T01:33:07Z")

</div>

We are having ES 7.3.2 in production and we are getting circuit breaker exception when the heap usage increases suddenly, we have also tested for the same in es 7.17 and 8.x in local but is there any improvement in lates…

---

## [S3 Access Denied error while verifying repository for snapshot and restore](https://discuss.elastic.co/t/s3-access-denied-error-while-verifying-repository-for-snapshot-and-restore/329263)

<div class="topic-metadata">

**Author:** [@shawnmin](https://discuss.elastic.co/u/shawnmin)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 1:17am UTC](https://discuss.elastic.co/t/s3-access-denied-error-while-verifying-repository-for-snapshot-and-restore/329263 "2023-04-04T01:17:27Z")

</div>

Hi, I am working on Snapshot and Restore to ensure that my Elasticsearch indices are securely backed-up and stored. I've set up an EFK stack on my AWS EKS cluster. I've deployed the stack using Helm in Bitnami chart. I a…

---

## [ILM policy for a index which only delets 30 days data without deleting the index please check the below policy is write or wrong?](https://discuss.elastic.co/t/ilm-policy-for-a-index-which-only-delets-30-days-data-without-deleting-the-index-please-check-the-below-policy-is-write-or-wrong/329022)

<div class="topic-metadata">

**Author:** [@Bibhudutta\_Mohanty](https://discuss.elastic.co/u/Bibhudutta_Mohanty)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 9:51pm UTC](https://discuss.elastic.co/t/ilm-policy-for-a-index-which-only-delets-30-days-data-without-deleting-the-index-please-check-the-below-policy-is-write-or-wrong/329022 "2023-04-03T21:51:46Z")

</div>

please any one can check the code is write according to this situation PUT \_ilm/policy/my\_policy { "policy": { "phases": { "hot": { "actions": { "rollover": { "max\_age": "30d" } } }, "delete": { "min\_age": "…

---

## [Fluentd configuration is not creating indexes in elasticsearch](https://discuss.elastic.co/t/fluentd-configuration-is-not-creating-indexes-in-elasticsearch/328876)

<div class="topic-metadata">

**Author:** [@sc9501](https://discuss.elastic.co/u/sc9501)\
**Replies:** 12\
**Last updated:** [April 3, 2023, 9:50pm UTC](https://discuss.elastic.co/t/fluentd-configuration-is-not-creating-indexes-in-elasticsearch/328876 "2023-04-03T21:50:33Z")

</div>

Hello everyone, I need some help with the EFK stack. I've already installed Elasticsearch, Kibana and Fluentd with their respective Helm charts in a k8s environment. Every pod is running fine but I'm my Fluentd configu…

---

## [Reference one dashboard from another?](https://discuss.elastic.co/t/reference-one-dashboard-from-another/327623)

<div class="topic-metadata">

**Author:** [@smchamberlin](https://discuss.elastic.co/u/smchamberlin)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 9:11pm UTC](https://discuss.elastic.co/t/reference-one-dashboard-from-another/327623 "2023-04-03T21:11:25Z")

</div>

Hello, We have various dashboards that are interconnected, some provide more details like a "drill down". Instead of going out to the top-level view and selecting a new dashboard, is there any way to load or reference …

---

## [How do I enable data collection in the elastic agent of my fleet server?](https://discuss.elastic.co/t/how-do-i-enable-data-collection-in-the-elastic-agent-of-my-fleet-server/329251)

<div class="topic-metadata">

**Author:** [@WowSuchLogs](https://discuss.elastic.co/u/WowSuchLogs)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 9:08pm UTC](https://discuss.elastic.co/t/how-do-i-enable-data-collection-in-the-elastic-agent-of-my-fleet-server/329251 "2023-04-03T21:08:43Z")

</div>

Hello, I'm learning ES in a home lab consisting in a server running a cluster of ES/Kibana docker nodes and I installed the fleet server on the docker host itself. I'd like to monitor Docker through the agent of the fl…

---

## [Issues with snapshots](https://discuss.elastic.co/t/issues-with-snapshots/329142)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 7:30pm UTC](https://discuss.elastic.co/t/issues-with-snapshots/329142 "2023-04-03T19:30:06Z")

</div>

I am struggling to understand how one is expected to use the snapshot system to provide a reliable back up. I understand that individual snapshots are incremental, but presumably only within repositories? I have set up…

---

## [Streaming API to local folder using logstash](https://discuss.elastic.co/t/streaming-api-to-local-folder-using-logstash/329248)

<div class="topic-metadata">

**Author:** [@Reloef\_Khoza](https://discuss.elastic.co/u/Reloef_Khoza)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 7:26pm UTC](https://discuss.elastic.co/t/streaming-api-to-local-folder-using-logstash/329248 "2023-04-03T19:26:54Z")

</div>

Any example of how to stream multiple API from a website into a local folder

---

## [How to exclude attachment content and still searching inside it?](https://discuss.elastic.co/t/how-to-exclude-attachment-content-and-still-searching-inside-it/329191)

<div class="topic-metadata">

**Author:** [@aabdo](https://discuss.elastic.co/u/aabdo)\
**Replies:** 7\
**Last updated:** [April 3, 2023, 5:35pm UTC](https://discuss.elastic.co/t/how-to-exclude-attachment-content-and-still-searching-inside-it/329191 "2023-04-03T17:35:58Z")

</div>

hello, to optimize my disk space, i'm excluding my attachment content in the mapping of my index. but i can't no longer search inside it . i don't know what am i messing !! . is there any solution for this issue ??

---

## [Elasticsearch 7.17 with G1GC and Java 17](https://discuss.elastic.co/t/elasticsearch-7-17-with-g1gc-and-java-17/329230)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 5:14pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-with-g1gc-and-java-17/329230 "2023-04-03T17:14:39Z")

</div>

Is it good to go with G1GC in Elasticsearch 7.17 With Java 17 and is there any drawback of having this config in production

---

## [If IP results in \_geoip\_lookup\_failure is it possible to fill geoip-related vields with a custom value?](https://discuss.elastic.co/t/if-ip-results-in-geoip-lookup-failure-is-it-possible-to-fill-geoip-related-vields-with-a-custom-value/329144)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 4:57pm UTC](https://discuss.elastic.co/t/if-ip-results-in-geoip-lookup-failure-is-it-possible-to-fill-geoip-related-vields-with-a-custom-value/329144 "2023-04-03T16:57:54Z")

</div>

Basically if the IP cannot be found in the database, I want to fill the geoip.city\_name, geoip.region\_name, and geoip.country\_name with a custom value like "PRIVATE ADDRESS" or "IP NOT IN DATABASE" or something similar..…

---

## [Median Forumla Question](https://discuss.elastic.co/t/median-forumla-question/329238)

<div class="topic-metadata">

**Author:** [@Joshua\_Boyd](https://discuss.elastic.co/u/Joshua_Boyd)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 4:51pm UTC](https://discuss.elastic.co/t/median-forumla-question/329238 "2023-04-03T16:51:40Z")

</div>

Hello, wondering if anyone could give advice on the following: i have a table of incidents, with column of account name and the incident id incident1, account1 incident2, account1 incident3, account2 .... I want to…

---

## [Operations over indexed documents](https://discuss.elastic.co/t/operations-over-indexed-documents/329068)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 4:27pm UTC](https://discuss.elastic.co/t/operations-over-indexed-documents/329068 "2023-04-03T16:27:41Z")

</div>

Hi, Is it possible to compute variables taking the documents from an index as input? I will describe my current situation and my objective. I have data indexed on an Elasticsearch cluster. My data contains a timestamp …

---

## [Using Lens Table to Keep Track of Days of the Month](https://discuss.elastic.co/t/using-lens-table-to-keep-track-of-days-of-the-month/327597)

<div class="topic-metadata">

**Author:** [@Goishin](https://discuss.elastic.co/u/Goishin)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 9:11pm UTC](https://discuss.elastic.co/t/using-lens-table-to-keep-track-of-days-of-the-month/327597 "2023-03-13T21:11:08Z")

</div>

I use a Kibana dashboard to keep track of a number of things on my team. We all look at this dashboard to see the team's current status of stuff. But our team also has regular things that happen on specific days of the m…

---

## [Grant read privileges to specific documentss](https://discuss.elastic.co/t/grant-read-privileges-to-specific-documentss/329098)

<div class="topic-metadata">

**Author:** [@hiba](https://discuss.elastic.co/u/hiba)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 4:12pm UTC](https://discuss.elastic.co/t/grant-read-privileges-to-specific-documentss/329098 "2023-04-03T16:12:07Z")

</div>

Hi, I want to create a role that can read only specific documents. For example: User A can only read documents where professional\_id = 49 Now I want to display a default currency for each user For example, user A …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=580)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=582)
