# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=594

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 595

---

## [\[Logstash\] SSL TCP input certificate issue](https://discuss.elastic.co/t/logstash-ssl-tcp-input-certificate-issue/328220)

<div class="topic-metadata">

**Author:** [@perezdev](https://discuss.elastic.co/u/perezdev)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:00pm UTC](https://discuss.elastic.co/t/logstash-ssl-tcp-input-certificate-issue/328220 "2023-03-23T15:00:44Z")

</div>

Hello, I'm trying to setup an SSL TCP input config file in Logstash to receive logs from other syslog server over TLS 1.2. For the certificates I have created the following files using openssl: openssl req -x509 -nodes…

---

## [Filebeat is not pushing the documents to kibana (through elasticsearch)](https://discuss.elastic.co/t/filebeat-is-not-pushing-the-documents-to-kibana-through-elasticsearch/328358)

<div class="topic-metadata">

**Author:** [@Maneesh545](https://discuss.elastic.co/u/Maneesh545)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 2:56pm UTC](https://discuss.elastic.co/t/filebeat-is-not-pushing-the-documents-to-kibana-through-elasticsearch/328358 "2023-03-23T14:56:04Z")

</div>

I am using the below configuration in filebeat.yml to push the logs into kibana to visualize. Initially documents used to flow into kibana but since last couple of days the documents are not flowing through elasticsear…

---

## [KNN search speed](https://discuss.elastic.co/t/knn-search-speed/326961)

<div class="topic-metadata">

**Author:** [@dendog1](https://discuss.elastic.co/u/dendog1)\
**Replies:** 11\
**Last updated:** [March 23, 2023, 2:38pm UTC](https://discuss.elastic.co/t/knn-search-speed/326961 "2023-03-23T14:38:07Z")

</div>

Hi! Today we are using ES mainly as a key / value store where most of our reads are just get by key. We have recently started to use KNN, where we have: Around 10MM docs. 384 dim vectors. Using cosine sim as the metr…

---

## [Slow aKNN search](https://discuss.elastic.co/t/slow-aknn-search/326915)

<div class="topic-metadata">

**Author:** [@ruslaniv](https://discuss.elastic.co/u/ruslaniv)\
**Replies:** 6\
**Last updated:** [March 23, 2023, 2:30pm UTC](https://discuss.elastic.co/t/slow-aknn-search/326915 "2023-03-23T14:30:50Z")

</div>

We have implemented vector similarity search using ES dense\_vector field and KNN option in the search API. We are using 1024 dimension embeddings and our index size is about 60 Gb for approx 11\_000\_000 documents. So our…

---

## [Can't join elastic to microsoft active directory ldap](https://discuss.elastic.co/t/cant-join-elastic-to-microsoft-active-directory-ldap/326514)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 16\
**Last updated:** [March 23, 2023, 2:05pm UTC](https://discuss.elastic.co/t/cant-join-elastic-to-microsoft-active-directory-ldap/326514 "2023-03-23T14:05:36Z")

</div>

Hi ldap users can't login on kibana: here is the log when user attempt to login: Feb 26 11:55:21 logdev kibana\[1784685\]: \[2023-02-26T11:55:21.243+03:30\]\[INFO \]\[plugins.security.routes\] Logging in with provider "bas…

---

## [Logstash MultiPipeline](https://discuss.elastic.co/t/logstash-multipipeline/328341)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 1:39pm UTC](https://discuss.elastic.co/t/logstash-multipipeline/328341 "2023-03-23T13:39:59Z")

</div>

Hello , I want to use several pipeline . I had put them in the logstash directory conf.d . I named the files like this 01\_Input 02\_Filter 03\_Output Must I do anything else for work with the pipelines ? Does it wo…

---

## [Elasticsearch NoShardAvailableActionException](https://discuss.elastic.co/t/elasticsearch-noshardavailableactionexception/328279)

<div class="topic-metadata">

**Author:** [@Lohanna\_Sarah](https://discuss.elastic.co/u/Lohanna_Sarah)\
**Replies:** 4\
**Last updated:** [March 23, 2023, 1:35pm UTC](https://discuss.elastic.co/t/elasticsearch-noshardavailableactionexception/328279 "2023-03-23T13:35:51Z")

</div>

Suppose a cluster is composed of three data nodes. If one of the nodes throws the exception "NoShardAvailableActionException", what is the impact on the cluster and how is the request handled? Specifically, is the reques…

---

## [How do I use Elastic Agent to send log data to Logstash?](https://discuss.elastic.co/t/how-do-i-use-elastic-agent-to-send-log-data-to-logstash/328269)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 7\
**Last updated:** [March 23, 2023, 12:57pm UTC](https://discuss.elastic.co/t/how-do-i-use-elastic-agent-to-send-log-data-to-logstash/328269 "2023-03-23T12:57:14Z")

</div>

Hello. Based on the documentation (Beats and Elastic Agent capabilities | Fleet and Elastic Agent Guide \[8.6\] | Elastic) I am under the impression that the Elastic Agent can send log data to Logstash. However, the only b…

---

## [How to search a piece of URI](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 8\
**Last updated:** [March 23, 2023, 12:36pm UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342 "2023-03-23T12:36:28Z")

</div>

I want to search a piece of URL. I am using the sample weblogs in elasticsearch. If I analyze the field: GET /\_analyze { "analyzer" : "standard", "text" : \["http://nytimes.com/success/kevin-Kregel"\] } I get: { "…

---

## [Regex lookahead in painless](https://discuss.elastic.co/t/regex-lookahead-in-painless/328268)

<div class="topic-metadata">

**Author:** [@HansPeterSloot](https://discuss.elastic.co/u/HansPeterSloot)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 12:17pm UTC](https://discuss.elastic.co/t/regex-lookahead-in-painless/328268 "2023-03-23T12:17:25Z")

</div>

Is it possible to use regex with lookahead in Painless? I want to match a pattern in a string starting with a certain expression and ending before a certain expression.

---

## [Kibana login Issue due to space full](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153)

<div class="topic-metadata">

**Author:** [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Replies:** 11\
**Last updated:** [March 23, 2023, 12:15pm UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153 "2023-03-23T12:15:27Z")

</div>

Hello Expert, We have created the Kibana and Elasticsearch with filebeat. Below are the details. Kibana version: 7.14.1. running in Kubernetes. Issue: Not able to login to Kibana as Elasticsearch space is full. but …

---

## [Kibana dashboard issue - i have created a disk usage dashboard , it doesnot show up a straight line --but with dotted lines](https://discuss.elastic.co/t/kibana-dashboard-issue-i-have-created-a-disk-usage-dashboard-it-doesnot-show-up-a-straight-line-but-with-dotted-lines/328346)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 12:05pm UTC](https://discuss.elastic.co/t/kibana-dashboard-issue-i-have-created-a-disk-usage-dashboard-it-doesnot-show-up-a-straight-line-but-with-dotted-lines/328346 "2023-03-23T12:05:25Z")

</div>

ELK - 7.17.3 , KIBANA 7.17.3 I have a 3 node cluster and two logstash server and one kibana server I have created disk usage dashboard , but it shows the data in dotted line for 15 minutes or 30 minutes.. while for 1 h…

---

## [Cluster en elastic search; error: main process exited, failed with result 'exit-code'](https://discuss.elastic.co/t/cluster-en-elastic-search-error-main-process-exited-failed-with-result-exit-code/328337)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 11:37am UTC](https://discuss.elastic.co/t/cluster-en-elastic-search-error-main-process-exited-failed-with-result-exit-code/328337 "2023-03-23T11:37:24Z")

</div>

I am trying to create a cluster with two machines and I am trying to configure the /etc/elasticsearch/elasticsearch.yml file but I get an error. I am attaching code captures. The attached screenshot is from the ma…

---

## [How to add an inner field as a source field in ML inference pipeline?](https://discuss.elastic.co/t/how-to-add-an-inner-field-as-a-source-field-in-ml-inference-pipeline/328323)

<div class="topic-metadata">

**Author:** [@848bb15cf6e891bef7ba](https://discuss.elastic.co/u/848bb15cf6e891bef7ba)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-to-add-an-inner-field-as-a-source-field-in-ml-inference-pipeline/328323 "2023-03-23T11:21:18Z")

</div>

Hi, I am trying out vector search. While creating a Machine Learning Inference Pipeline, I see that some fields in the index are not recognised. Only the top level fields are shown. Consider the below example with fiel…

---

## [Kibana Server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/328232)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 9:17am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/328232 "2023-03-23T09:17:18Z")

</div>

Hi, I am not able to connect kibana with elasticsearch, if someone could offer me some help. Thank you.

---

## [Building Kibana from source code got "operation not permitted, rename" ERROR](https://discuss.elastic.co/t/building-kibana-from-source-code-got-operation-not-permitted-rename-error/328317)

<div class="topic-metadata">

**Author:** [@gnehcnij](https://discuss.elastic.co/u/gnehcnij)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 9:28am UTC](https://discuss.elastic.co/t/building-kibana-from-source-code-got-operation-not-permitted-rename-error/328317 "2023-03-23T09:28:50Z")

</div>

When I run yarn build --skip-os-packages, it got error below: ERROR Error: EPERM: operation not permitted, rename........

---

## [ElasticSearch - Java layered search BoolQueryBuilder](https://discuss.elastic.co/t/elasticsearch-java-layered-search-boolquerybuilder/328256)

<div class="topic-metadata">

**Author:** [@Sachin\_Sharma](https://discuss.elastic.co/u/Sachin_Sharma)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 9:21am UTC](https://discuss.elastic.co/t/elasticsearch-java-layered-search-boolquerybuilder/328256 "2023-03-23T09:21:50Z")

</div>

I have data in Elastic. Elastic data is as below. Name Parties Parties is array of objects that contains partyCode and displayCode { "query": { "bool": { "should": \[ { "bool": { "must": \[ …

---

## [Dashboard performance help](https://discuss.elastic.co/t/dashboard-performance-help/327582)

<div class="topic-metadata">

**Author:** [@tommycahir](https://discuss.elastic.co/u/tommycahir)\
**Replies:** 9\
**Last updated:** [March 23, 2023, 8:56am UTC](https://discuss.elastic.co/t/dashboard-performance-help/327582 "2023-03-23T08:56:57Z")

</div>

Hi All I am looking for some help in understanding how I can debug/find slow performance issues and then resolve them. We have a dashboard that is presenting some visualisations on an index with 29,369,877 documents an…

---

## [APM-Server /intake/v2/events http 404 page not found](https://discuss.elastic.co/t/apm-server-intake-v2-events-http-404-page-not-found/328244)

<div class="topic-metadata">

**Author:** [@niemimik](https://discuss.elastic.co/u/niemimik)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 8:40am UTC](https://discuss.elastic.co/t/apm-server-intake-v2-events-http-404-page-not-found/328244 "2023-03-23T08:40:13Z")

</div>

I'm running 7.17 APM server with Fleet and APM agent installed. APM server is responsing healthy status but intake/v2/events not found. I cannot see any errors in log files. Please, could you give some ideas how can I d…

---

## [co.elastic.clients.elasticsearch.\_types.ElasticsearchException: \[es/indices.create\] failed: \[resource\_already\_exists\_exception\] index \[\[test1111/OvwpReOdTNa-44HKedMUrw\]\]already exists](https://discuss.elastic.co/t/co-elastic-clients-elasticsearch-types-elasticsearchexception-es-indices-create-failed-resource-already-exists-exception-index-test1111-ovwpreodtna-44hkedmurw-already-exists/328321)

<div class="topic-metadata">

**Author:** [@chinaman](https://discuss.elastic.co/u/chinaman)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 8:25am UTC](https://discuss.elastic.co/t/co-elastic-clients-elasticsearch-types-elasticsearchexception-es-indices-create-failed-resource-already-exists-exception-index-test1111-ovwpreodtna-44hkedmurw-already-exists/328321 "2023-03-23T08:25:57Z")

</div>

Create index use elasticsearchClient.indices() , Executed Exception:co.elastic.clients.elasticsearch.\_types.ElasticsearchException: \[es/indices.create\] failed:\[resource\_already\_exists\_exception\] index \[test12345/OvwpReOd…

---

## [Snapshot Repository integration with GitHub](https://discuss.elastic.co/t/snapshot-repository-integration-with-github/328307)

<div class="topic-metadata">

**Author:** [@dadiasish](https://discuss.elastic.co/u/dadiasish)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 8:17am UTC](https://discuss.elastic.co/t/snapshot-repository-integration-with-github/328307 "2023-03-23T08:17:12Z")

</div>

Hi, We've currently enabled Snapshots in our cluster with Amazon S3 buckets and everything it going great. I'm just exploring on new repository connections which can be applied with Elasticsearch Snapshots enablement. …

---

## [Logstash error -"Could not load '.aprc' from ENV\['HOME'\]: couldn't find HOME environment -- expanding \`~"](https://discuss.elastic.co/t/logstash-error-could-not-load-aprc-from-env-home-couldnt-find-home-environment-expanding/328318)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 7:36am UTC](https://discuss.elastic.co/t/logstash-error-could-not-load-aprc-from-env-home-couldnt-find-home-environment-expanding/328318 "2023-03-23T07:36:38Z")

</div>

Hi Folks, I have a log file that logstash(8.6.2) is successfully parse, but has this error . i'm not sure whats causing it ? Could have a look ? , the data doesnt appear in kibana either Could not load '.aprc' from EN…

---

## [Filebeat processors](https://discuss.elastic.co/t/filebeat-processors/328275)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 7:34am UTC](https://discuss.elastic.co/t/filebeat-processors/328275 "2023-03-23T07:34:13Z")

</div>

Hi everyone, I have a question about the filebeat processors (extract\_array, drop\_event, drop\_fields). My filebeat agent collects about 2500 logs lines a second. Do you think that using these processors can lead to hug…

---

## [Split nested docs into a separate docs](https://discuss.elastic.co/t/split-nested-docs-into-a-separate-docs/328265)

<div class="topic-metadata">

**Author:** [@silverjoe](https://discuss.elastic.co/u/silverjoe)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 3:02pm UTC](https://discuss.elastic.co/t/split-nested-docs-into-a-separate-docs/328265 "2023-03-22T15:02:21Z")

</div>

Hi, I have a simple Logstash pipeline that reads all docs from an ES index using an ES input plugin, then I have a filter that splits one doc into several, and finally the output plugin to index docs in the ES. My probl…

---

## [Too much network data out in 8.4.3 elasticsearch](https://discuss.elastic.co/t/too-much-network-data-out-in-8-4-3-elasticsearch/328182)

<div class="topic-metadata">

**Author:** [@Dharampal\_Singh](https://discuss.elastic.co/u/Dharampal_Singh)\
**Replies:** 9\
**Last updated:** [March 23, 2023, 5:43am UTC](https://discuss.elastic.co/t/too-much-network-data-out-in-8-4-3-elasticsearch/328182 "2023-03-23T05:43:09Z")

</div>

HI We have migrated from elasticsearch 6.2.3 to 8.4.3 and seeing huge network data transfer cost.is anyone else also facing this issue or its suppose to be happen. in my configuration only 3 node cluster all are mater …

---

## [Two seprate log files to put in separate index](https://discuss.elastic.co/t/two-seprate-log-files-to-put-in-separate-index/327626)

<div class="topic-metadata">

**Author:** [@abhishek1111](https://discuss.elastic.co/u/abhishek1111)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 4:36am UTC](https://discuss.elastic.co/t/two-seprate-log-files-to-put-in-separate-index/327626 "2023-03-23T04:36:12Z")

</div>

Hello Experts :slight\_smile: Need your assistance on below use case of mine where filebeat is running as kubernetes daemon set. I have two log files under same folder in which i want to parse and push data to separate …

---

## [Why is the length of keyword array always 1?](https://discuss.elastic.co/t/why-is-the-length-of-keyword-array-always-1/328164)

<div class="topic-metadata">

**Author:** [@lyq2333](https://discuss.elastic.co/u/lyq2333)\
**Replies:** 6\
**Last updated:** [March 23, 2023, 12:56am UTC](https://discuss.elastic.co/t/why-is-the-length-of-keyword-array-always-1/328164 "2023-03-23T00:56:28Z")

</div>

I create an index by PUT my-index-000002 { "mappings": { "properties": { "content":{ "type": "keyword", "index\_options": "freqs" }, "id":{ "type": "integer" } } …

---

## [ORing a text field with a unique identifier keyword field leading to increased next\_doc count and poor performance](https://discuss.elastic.co/t/oring-a-text-field-with-a-unique-identifier-keyword-field-leading-to-increased-next-doc-count-and-poor-performance/328283)

<div class="topic-metadata">

**Author:** [@helderdias](https://discuss.elastic.co/u/helderdias)\
**Replies:** 8\
**Last updated:** [March 22, 2023, 11:24pm UTC](https://discuss.elastic.co/t/oring-a-text-field-with-a-unique-identifier-keyword-field-leading-to-increased-next-doc-count-and-poor-performance/328283 "2023-03-22T23:24:18Z")

</div>

TL;DR: I want to find documents that match a certain query (e.g. "my search") OR match the unique ID of a document. When I search for the text field alone, the search is super fast. However, when I or the text field wit…

---

## [K8s multiple replicas pq](https://discuss.elastic.co/t/k8s-multiple-replicas-pq/327887)

<div class="topic-metadata">

**Author:** [@liel\_bondy](https://discuss.elastic.co/u/liel_bondy)\
**Replies:** 3\
**Last updated:** [March 19, 2023, 1:10pm UTC](https://discuss.elastic.co/t/k8s-multiple-replicas-pq/327887 "2023-03-19T13:10:15Z")

</div>

Hey, quick question. If I want to scale my logstash (with PQ) horizontally in k8s, I would just increase the replica amount. Now that I have multiple nodes, I would like to understand how the PQ manages race conditions.…

---

## [Logstash TCP input pipeline performance issues](https://discuss.elastic.co/t/logstash-tcp-input-pipeline-performance-issues/328006)

<div class="topic-metadata">

**Author:** [@mread830](https://discuss.elastic.co/u/mread830)\
**Replies:** 9\
**Last updated:** [March 22, 2023, 9:44pm UTC](https://discuss.elastic.co/t/logstash-tcp-input-pipeline-performance-issues/328006 "2023-03-22T21:44:22Z")

</div>

I’m having an issue when a particular pipeline and i’m not sure how to track it down or trouble shoot it further.. First, I have multiple cloud environments, configured the same, sending to the same endpoints. 2 of the…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=593)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=595)
