# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=584

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 585

---

## [Es restore \[parent\] data too large](https://discuss.elastic.co/t/es-restore-parent-data-too-large/329016)

<div class="topic-metadata">

**Author:** [@huang1](https://discuss.elastic.co/u/huang1)\
**Replies:** 7\
**Last updated:** [March 31, 2023, 12:34pm UTC](https://discuss.elastic.co/t/es-restore-parent-data-too-large/329016 "2023-03-31T12:34:37Z")

</div>

The total data size of es is less than 1G. Perform a regular restore. After running for a period of time, throw the \[parent\] data too large. The node executing the restore has a high xmx and a high CPU utilization rate\_ …

---

## [Trying to export data reports using Kibana discover but could not be able to export large no. of data](https://discuss.elastic.co/t/trying-to-export-data-reports-using-kibana-discover-but-could-not-be-able-to-export-large-no-of-data/329018)

<div class="topic-metadata">

**Author:** [@Mangesh\_Mathe](https://discuss.elastic.co/u/Mangesh_Mathe)\
**Replies:** 6\
**Last updated:** [March 31, 2023, 12:28pm UTC](https://discuss.elastic.co/t/trying-to-export-data-reports-using-kibana-discover-but-could-not-be-able-to-export-large-no-of-data/329018 "2023-03-31T12:28:37Z")

</div>

Hello Team, I'm trying to download discover search data with some of my filters. However, When I download I see that document limit in CSV is at 10,000 documents. Any way or setting to increase document download limit…

---

## [Version\_conflict\_engine\_exception errors with status 409](https://discuss.elastic.co/t/version-conflict-engine-exception-errors-with-status-409/328855)

<div class="topic-metadata">

**Author:** [@Fernando\_Oliveira](https://discuss.elastic.co/u/Fernando_Oliveira)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 12:13pm UTC](https://discuss.elastic.co/t/version-conflict-engine-exception-errors-with-status-409/328855 "2023-03-31T12:13:14Z")

</div>

Hello, I clean my indexes in the elastic with the script below: POST /aplicacao/\_delete\_by\_query { "query": { "range": { "timeLog": { "lte": "now-5M" } } } } "aplicacao " is the name of the index, I leave …

---

## [Can't log in Kibana when a specific elasticsearch node is not running](https://discuss.elastic.co/t/cant-log-in-kibana-when-a-specific-elasticsearch-node-is-not-running/328914)

<div class="topic-metadata">

**Author:** [@jgl75](https://discuss.elastic.co/u/jgl75)\
**Replies:** 5\
**Last updated:** [March 31, 2023, 11:52am UTC](https://discuss.elastic.co/t/cant-log-in-kibana-when-a-specific-elasticsearch-node-is-not-running/328914 "2023-03-31T11:52:03Z")

</div>

Hi everyone, First time poster here. I'm working with ELK since a few weeks, learning new things every day :slight\_smile: I've solved all my problems except one. I have a 3 nodes elasticsearch cluster and a separate …

---

## [Passing dynamic values to range query](https://discuss.elastic.co/t/passing-dynamic-values-to-range-query/329037)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 9:48am UTC](https://discuss.elastic.co/t/passing-dynamic-values-to-range-query/329037 "2023-03-31T09:48:24Z")

</div>

In kibana discover, with Elasticsearch Query DSL, I want to search for a range of timestamp dynamically here is the range I used: { "range": { "@timestamp": { "gte": "2023-03-03T15:0…

---

## [Function score weight rounding score If value is high](https://discuss.elastic.co/t/function-score-weight-rounding-score-if-value-is-high/329043)

<div class="topic-metadata">

**Author:** [@eerkisi](https://discuss.elastic.co/u/eerkisi)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 11:10am UTC](https://discuss.elastic.co/t/function-score-weight-rounding-score-if-value-is-high/329043 "2023-03-31T11:10:22Z")

</div>

Hello, We have function scores and functions which manipulate scores by some filters etc. We set one of the function score weight as high numbers because of the our business. Also we need fraction of the value to be abl…

---

## [Tried to build package registry image but no content](https://discuss.elastic.co/t/tried-to-build-package-registry-image-but-no-content/329039)

<div class="topic-metadata">

**Author:** [@Mudboyzh](https://discuss.elastic.co/u/Mudboyzh)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 10:24am UTC](https://discuss.elastic.co/t/tried-to-build-package-registry-image-but-no-content/329039 "2023-03-31T10:24:55Z")

</div>

Hi I have already deployed ELK / Elastic Agent / Package registry with official images. They work well. Because of our company's standard, images have to fix vulnerability before deploy on k8s(air-gapped), I have to f…

---

## [Fleet giving error | unable to initialize fleet](https://discuss.elastic.co/t/fleet-giving-error-unable-to-initialize-fleet/326337)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 10\
**Last updated:** [March 31, 2023, 9:48am UTC](https://discuss.elastic.co/t/fleet-giving-error-unable-to-initialize-fleet/326337 "2023-03-31T09:48:00Z")

</div>

getting this error sometimes in FLEET resource\_already\_exists\_exception: \[resource\_already\_exists\_exception\] reason: task with id {endpoint.metadata\_current-default-8.6.1} already exist

---

## [Creating customised reference values based on lagged information](https://discuss.elastic.co/t/creating-customised-reference-values-based-on-lagged-information/329036)

<div class="topic-metadata">

**Author:** [@NiklasHBB](https://discuss.elastic.co/u/NiklasHBB)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 9:38am UTC](https://discuss.elastic.co/t/creating-customised-reference-values-based-on-lagged-information/329036 "2023-03-31T09:38:29Z")

</div>

What is the best way to create reference values which are based on past information in Elasticsearch? My current use case involves detailling in Kibana how the values for a day, week or month relate to past developments…

---

## [How to hide rows in table without affecting search criteria](https://discuss.elastic.co/t/how-to-hide-rows-in-table-without-affecting-search-criteria/329033)

<div class="topic-metadata">

**Author:** [@abhardwaj](https://discuss.elastic.co/u/abhardwaj)\
**Replies:** 4\
**Last updated:** [March 31, 2023, 9:35am UTC](https://discuss.elastic.co/t/how-to-hide-rows-in-table-without-affecting-search-criteria/329033 "2023-03-31T09:35:36Z")

</div>

Hello, I am creating a kibana visualization table based on few test run results in my elasticsearch index. Following is the composition of value hits. Following is the output table having the results captured T…

---

## [Curl command to delete cluster settings](https://discuss.elastic.co/t/curl-command-to-delete-cluster-settings/329019)

<div class="topic-metadata">

**Author:** [@devarajsit](https://discuss.elastic.co/u/devarajsit)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 9:15am UTC](https://discuss.elastic.co/t/curl-command-to-delete-cluster-settings/329019 "2023-03-31T09:15:54Z")

</div>

Hi Team, Is there any API where i can utilize to delete the cluster settings? I have configured the cluster settings to use sniff mode but when i tried to change that to proxy mode, i am getting error that its already …

---

## [Configure Username and password](https://discuss.elastic.co/t/configure-username-and-password/328913)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 6\
**Last updated:** [March 31, 2023, 9:11am UTC](https://discuss.elastic.co/t/configure-username-and-password/328913 "2023-03-31T09:11:47Z")

</div>

How to configure the username and password while running elasticsearch in Docker without docker-compose.

---

## [Date range not working as expected between Elasticsearch 7.17 and Elasticsearch 8.6](https://discuss.elastic.co/t/date-range-not-working-as-expected-between-elasticsearch-7-17-and-elasticsearch-8-6/328825)

<div class="topic-metadata">

**Author:** [@MarynaCherniavska](https://discuss.elastic.co/u/MarynaCherniavska)\
**Replies:** 3\
**Last updated:** [March 31, 2023, 8:50am UTC](https://discuss.elastic.co/t/date-range-not-working-as-expected-between-elasticsearch-7-17-and-elasticsearch-8-6/328825 "2023-03-31T08:50:08Z")

</div>

We're exploring a move from (self-managed) Elasticsearch 7.17 to Elasticsearch 8.6. Some of the tests on the application fail if we switch. We traced the failure to an inconsistency between the results on the range using…

---

## [Elasticsearch installation using helm chart ..Used nfs-storageclass](https://discuss.elastic.co/t/elasticsearch-installation-using-helm-chart-used-nfs-storageclass/329025)

<div class="topic-metadata">

**Author:** [@thirumoorthy](https://discuss.elastic.co/u/thirumoorthy)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 8:40am UTC](https://discuss.elastic.co/t/elasticsearch-installation-using-helm-chart-used-nfs-storageclass/329025 "2023-03-31T08:40:44Z")

</div>

ERROR: {"@timestamp":"2023-03-31T08:10:14.942Z", "log.level":"ERROR", "message":"uncaught exception in thread \[process reaper (pid 228)\]", "ecs.version": "1.2.0","service.name":"ES\_ECS","event.dataset":"elasticsearch.se…

---

## [CloudWatch input plugin not working with EC2 namespace](https://discuss.elastic.co/t/cloudwatch-input-plugin-not-working-with-ec2-namespace/329026)

<div class="topic-metadata">

**Author:** [@kanny](https://discuss.elastic.co/u/kanny)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 8:19am UTC](https://discuss.elastic.co/t/cloudwatch-input-plugin-not-working-with-ec2-namespace/329026 "2023-03-31T08:19:16Z")

</div>

Hello, When I ran Logstash 8.6.2 version to collect EC2 CloudWatch metrics, the process returned "Exception: NameError". As far as I know by testing, this exception happends only for AWS/EC2 namespace, and setting for …

---

## [What should the bucket path be with a top hits](https://discuss.elastic.co/t/what-should-the-bucket-path-be-with-a-top-hits/329024)

<div class="topic-metadata">

**Author:** [@m.a.tanaka](https://discuss.elastic.co/u/m.a.tanaka)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 8:16am UTC](https://discuss.elastic.co/t/what-should-the-bucket-path-be-with-a-top-hits/329024 "2023-03-31T08:16:17Z")

</div>

I am trying to create a query in elasticsearch, which is able to retrieve the documents for each group, which is the latest document within each group and meet a specific criteria. But I have not been able to solve this …

---

## [Logstash can't talk to Elasticsearch but I can access from the browser](https://discuss.elastic.co/t/logstash-cant-talk-to-elasticsearch-but-i-can-access-from-the-browser/328970)

<div class="topic-metadata">

**Author:** [@crimson\_med](https://discuss.elastic.co/u/crimson_med)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 6:18pm UTC](https://discuss.elastic.co/t/logstash-cant-talk-to-elasticsearch-but-i-can-access-from-the-browser/328970 "2023-03-30T18:18:52Z")

</div>

I have been trying to configure the ELK stack to use our wildcard certificate however this has been impossible until now. Logstash and kibana are unable to talk to elasticsearch however i can curl with no issues. Resul…

---

## [Autocompletion by most popular phrases in the text](https://discuss.elastic.co/t/autocompletion-by-most-popular-phrases-in-the-text/329012)

<div class="topic-metadata">

**Author:** [@Quaerere](https://discuss.elastic.co/u/Quaerere)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 6:52am UTC](https://discuss.elastic.co/t/autocompletion-by-most-popular-phrases-in-the-text/329012 "2023-03-31T06:52:59Z")

</div>

Let's say I have many text fields indexed: { "body": "The quick brown fox jumps over the lazy dog" } { "body": "There was a quick brown fox in a forest" } { "body": "Forest was a most fun place for a lazy dog to…

---

## ["Internal Server error" while pulling the data from elastic search](https://discuss.elastic.co/t/internal-server-error-while-pulling-the-data-from-elastic-search/328898)

<div class="topic-metadata">

**Author:** [@zameer712](https://discuss.elastic.co/u/zameer712)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 6:46am UTC](https://discuss.elastic.co/t/internal-server-error-while-pulling-the-data-from-elastic-search/328898 "2023-03-31T06:46:28Z")

</div>

Hello team, we are using Elastic cloud on Azure and all the versions of kibana, filebeat , Elasticsearch is 8.6.2 right now. Facing an issue respect to one of our API please help by checking below error { "id": "c70b…

---

## [Why mutate will influence different pipelines?](https://discuss.elastic.co/t/why-mutate-will-influence-different-pipelines/328210)

<div class="topic-metadata">

**Author:** [@AlanChan](https://discuss.elastic.co/u/AlanChan)\
**Replies:** 9\
**Last updated:** [March 31, 2023, 6:44am UTC](https://discuss.elastic.co/t/why-mutate-will-influence-different-pipelines/328210 "2023-03-31T06:44:11Z")

</div>

Hi I'd like to process the same input data in different ways to get different results, so I'm trying to do with multiple pipelines. However, I notice that using mutate will influence other pipelines. Does anyone know ho…

---

## [Error parsing json but data still thrown to elastic](https://discuss.elastic.co/t/error-parsing-json-but-data-still-thrown-to-elastic/328922)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [March 31, 2023, 4:03am UTC](https://discuss.elastic.co/t/error-parsing-json-but-data-still-thrown-to-elastic/328922 "2023-03-31T04:03:40Z")

</div>

Hi there, i want to ask about this error. anyone know what this error is trying to tell ? exception=\>java.lang.ClassCastException: class org.jruby.RubyHash cannot be cast to class org.jruby.RubyIO (org.jruby.RubyHash a…

---

## [API: Exporting the data into CSV file](https://discuss.elastic.co/t/api-exporting-the-data-into-csv-file/328967)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 4\
**Last updated:** [March 31, 2023, 6:05am UTC](https://discuss.elastic.co/t/api-exporting-the-data-into-csv-file/328967 "2023-03-31T06:05:09Z")

</div>

Is there any API which supports the exports of data in CSV format from elasticsearch?

---

## [Issue connecting to Elastic from Metricbeat](https://discuss.elastic.co/t/issue-connecting-to-elastic-from-metricbeat/327833)

<div class="topic-metadata">

**Author:** [@SANTHOSH\_R](https://discuss.elastic.co/u/SANTHOSH_R)\
**Replies:** 5\
**Last updated:** [March 31, 2023, 5:32am UTC](https://discuss.elastic.co/t/issue-connecting-to-elastic-from-metricbeat/327833 "2023-03-31T05:32:09Z")

</div>

I am getting following error , when i tried to connect to elastic (which is in another server) from metricbeat server. What could be the issue ? Can you guys help on it . Thanks in Advance PS C:\\ELK\_PROD\\Metricbeat\> .\\m…

---

## [Recommended settings with close\_removed and clean\_removed false](https://discuss.elastic.co/t/recommended-settings-with-close-removed-and-clean-removed-false/327226)

<div class="topic-metadata">

**Author:** [@running\_banana](https://discuss.elastic.co/u/running_banana)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 5:26am UTC](https://discuss.elastic.co/t/recommended-settings-with-close-removed-and-clean-removed-false/327226 "2023-03-31T05:26:23Z")

</div>

Hi, We were looking to tune our filebeat.autodiscover settings to better handle scraping of ephemeral docker containers. The main issue we have is that when the container is stopped and removed, its log file also gets r…

---

## [Unable to start logstash on Amazon EC2 with Windows Server 2022](https://discuss.elastic.co/t/unable-to-start-logstash-on-amazon-ec2-with-windows-server-2022/328986)

<div class="topic-metadata">

**Author:** [@xavier76](https://discuss.elastic.co/u/xavier76)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 5:01am UTC](https://discuss.elastic.co/t/unable-to-start-logstash-on-amazon-ec2-with-windows-server-2022/328986 "2023-03-31T05:01:58Z")

</div>

The erorr I'm getting is below. \[2023-03-30T23:40:36,465\]\[INFO \]\[logstash.runner \] Starting Logstash {"logstash.version"=\>"8.6.2", "jruby.version"=\>"jruby 9.3.10.0 (2.6.8) 2023-02-01 107b2e6697 OpenJDK 64-Bit S…

---

## [Elastic Agents infinitely revisioning, stops sending data to Elasticsearch](https://discuss.elastic.co/t/elastic-agents-infinitely-revisioning-stops-sending-data-to-elasticsearch/328996)

<div class="topic-metadata">

**Author:** [@johnkim](https://discuss.elastic.co/u/johnkim)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 4:50am UTC](https://discuss.elastic.co/t/elastic-agents-infinitely-revisioning-stops-sending-data-to-elasticsearch/328996 "2023-03-31T04:50:34Z")

</div>

I have a combination of problem symptoms that may be caused by multiple issues, but since I don't know for sure what is the cause I'm compiling my issues into one thread. First, my ECK is self-managed. There are two thi…

---

## [How to get creation timestamp of input file](https://discuss.elastic.co/t/how-to-get-creation-timestamp-of-input-file/328533)

<div class="topic-metadata">

**Author:** [@Zak1](https://discuss.elastic.co/u/Zak1)\
**Replies:** 4\
**Last updated:** [March 31, 2023, 4:54am UTC](https://discuss.elastic.co/t/how-to-get-creation-timestamp-of-input-file/328533 "2023-03-31T04:54:48Z")

</div>

Am using logstash to parse an input logfile and subsequently sends data to elasticsearch. I would like to capture the creation date/timestamp of the input logfile as a field on the event. How best to go about this? Fyi, …

---

## [Kibana URL template dynamic url generation](https://discuss.elastic.co/t/kibana-url-template-dynamic-url-generation/328951)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 2:50pm UTC](https://discuss.elastic.co/t/kibana-url-template-dynamic-url-generation/328951 "2023-03-30T14:50:20Z")

</div>

Hello All, I've a requrirement where in When I create index pattern under which I'd like to create url template that would dynamically update the host and port. ex: http://abc:8089/web-ui/#/login I'd like to know a w…

---

## [Elasticsearch 5.5.1 version not reflecting after installation on debian based system](https://discuss.elastic.co/t/elasticsearch-5-5-1-version-not-reflecting-after-installation-on-debian-based-system/328831)

<div class="topic-metadata">

**Author:** [@beju](https://discuss.elastic.co/u/beju)\
**Replies:** 5\
**Last updated:** [March 31, 2023, 4:36am UTC](https://discuss.elastic.co/t/elasticsearch-5-5-1-version-not-reflecting-after-installation-on-debian-based-system/328831 "2023-03-31T04:36:05Z")

</div>

wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-5.5.1.deb sha1sum elasticsearch-5.5.1.deb sudo dpkg -i elasticsearch-5.5.1.deb n# curl -XGET 'http://localhost:9200' { "name" : "advance365", …

---

## [Will legacy index template work after version 8 upgrade?](https://discuss.elastic.co/t/will-legacy-index-template-work-after-version-8-upgrade/327908)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 8\
**Last updated:** [March 31, 2023, 3:26am UTC](https://discuss.elastic.co/t/will-legacy-index-template-work-after-version-8-upgrade/327908 "2023-03-31T03:26:29Z")

</div>

Hello team, I currently working on cluster with version 7.17.7 and now I am thinking of upgrading it to version 8.x. I received an API deprecation log that Legacy index templates are deprecated in favor of composable te…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=583)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=585)
