# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=635

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 636

---

## [Elasticsearch Memory Optimization?](https://discuss.elastic.co/t/elasticsearch-memory-optimization/325335)

<div class="topic-metadata">

**Author:** [@Sheharyar\_Khalid](https://discuss.elastic.co/u/Sheharyar_Khalid)\
**Replies:** 5\
**Last updated:** [February 13, 2023, 4:23pm UTC](https://discuss.elastic.co/t/elasticsearch-memory-optimization/325335 "2023-02-13T16:23:13Z")

</div>

Hello, I have 64GB of RAM on my machine. I am trying to optimize the elasticsearch's performance by utilizing maximum possible hardware. I noticed that the elasticsearch is not utilizing as much RAM as allocated to it …

---

## [Logstash error: Failed to publish events](https://discuss.elastic.co/t/logstash-error-failed-to-publish-events/325400)

<div class="topic-metadata">

**Author:** [@Zack\_09](https://discuss.elastic.co/u/Zack_09)\
**Replies:** 3\
**Last updated:** [February 13, 2023, 4:11pm UTC](https://discuss.elastic.co/t/logstash-error-failed-to-publish-events/325400 "2023-02-13T16:11:57Z")

</div>

Hello all ,im new in elastic when I run logstash i get the following error Error: Cannot assign requested address desktop-logstash-1 | Exception: Java::JavaNet::BindException desktop-logstash-1 | Stack: sun…

---

## [Logstash to Elastic Multiple Connections](https://discuss.elastic.co/t/logstash-to-elastic-multiple-connections/325382)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 3:01pm UTC](https://discuss.elastic.co/t/logstash-to-elastic-multiple-connections/325382 "2023-02-13T15:01:36Z")

</div>

Hello everyone, I was wandering if you can help in this particular matter: the actual situation is that we maintain a large Elastic Stack (15+ nodes) with an ingestion workflow composed by two Logstash server on VMs, wi…

---

## [Enroll elastic agent on machine that doesn't directly reach the Elastic Cloud instance](https://discuss.elastic.co/t/enroll-elastic-agent-on-machine-that-doesnt-directly-reach-the-elastic-cloud-instance/324405)

<div class="topic-metadata">

**Author:** [@gab](https://discuss.elastic.co/u/gab)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 3:03pm UTC](https://discuss.elastic.co/t/enroll-elastic-agent-on-machine-that-doesnt-directly-reach-the-elastic-cloud-instance/324405 "2023-02-13T15:03:23Z")

</div>

Hi. I have an Elastic Cloud 8.4 instance and I have to install an elastic-agent on a protected machine A that doesn't directly reach the internet but reaches another machine B that does. So I have something like: A -\> B…

---

## [Filter documents using aggregation in Discover](https://discuss.elastic.co/t/filter-documents-using-aggregation-in-discover/325401)

<div class="topic-metadata">

**Author:** [@Suresh\_Subramaniyan](https://discuss.elastic.co/u/Suresh_Subramaniyan)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 2:54pm UTC](https://discuss.elastic.co/t/filter-documents-using-aggregation-in-discover/325401 "2023-02-13T14:54:59Z")

</div>

Need to filter the documents based on aggregated results in kibana discover . { "aggs": { "match\_id": { "terms": { "field": "MATCH\_ID", "size": 10000 }, "aggs": { "count\_i…

---

## [APM through fleet deployment not starting correctly](https://discuss.elastic.co/t/apm-through-fleet-deployment-not-starting-correctly/323451)

<div class="topic-metadata">

**Author:** [@bigdamhero](https://discuss.elastic.co/u/bigdamhero)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 2:51pm UTC](https://discuss.elastic.co/t/apm-through-fleet-deployment-not-starting-correctly/323451 "2023-02-13T14:51:42Z")

</div>

I tried checking the github but I am not finding anything like this. Where is the config stored for the APM Server when its deployed via policy through fleet? I think if I could look at that I might be able to determi…

---

## [Scroll vs search after](https://discuss.elastic.co/t/scroll-vs-search-after/325396)

<div class="topic-metadata">

**Author:** [@Prabu\_P](https://discuss.elastic.co/u/Prabu_P)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 2:40pm UTC](https://discuss.elastic.co/t/scroll-vs-search-after/325396 "2023-02-13T14:40:27Z")

</div>

in this thread it discussed about the performance issue of search after , is this issue still present in newer versions of ES ?

---

## [Filebeat cannot connect to kafka with SASL\_PLAIN authentication enabled?](https://discuss.elastic.co/t/filebeat-cannot-connect-to-kafka-with-sasl-plain-authentication-enabled/325391)

<div class="topic-metadata">

**Author:** [@GuiSong01](https://discuss.elastic.co/u/GuiSong01)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 2:31pm UTC](https://discuss.elastic.co/t/filebeat-cannot-connect-to-kafka-with-sasl-plain-authentication-enabled/325391 "2023-02-13T14:31:02Z")

</div>

My filebeat cannot connect to kafka with SASL\_PLAIN authentication enabled,and error massage is: 2023-02-10T11:59:56.014+0800 ERROR \[kafka\] kafka/client.go:317 Kafka (topic=test-logs): kafka: client has run out of avail…

---

## [Logstash JMS Input version 3.1.2](https://discuss.elastic.co/t/logstash-jms-input-version-3-1-2/325355)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 2:11pm UTC](https://discuss.elastic.co/t/logstash-jms-input-version-3-1-2/325355 "2023-02-13T14:11:38Z")

</div>

Hello, I want to know what JMS version is compatible with Logstash JMS Input version 3.1.2 and can you share with me some references? Thank you,

---

## [Filebeat high availability, avoiding duplicated results](https://discuss.elastic.co/t/filebeat-high-availability-avoiding-duplicated-results/324615)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 6\
**Last updated:** [February 13, 2023, 2:00pm UTC](https://discuss.elastic.co/t/filebeat-high-availability-avoiding-duplicated-results/324615 "2023-02-13T14:00:09Z")

</div>

Dear Elastic Community, I am looking for a solution to retrieve logs from multiple servers and I have considered using Filebeat for this purpose. My main concern is to ensure high availability, avoiding duplicated resu…

---

## [Monitoring cluster shows no data](https://discuss.elastic.co/t/monitoring-cluster-shows-no-data/325387)

<div class="topic-metadata">

**Author:** [@Fangy](https://discuss.elastic.co/u/Fangy)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 1:52pm UTC](https://discuss.elastic.co/t/monitoring-cluster-shows-no-data/325387 "2023-02-13T13:52:48Z")

</div>

Hello, I have a question about monitoring, my monitoring cluster shows no data. "No monitoring data found". The installation in a few nodes production cluster and one node monitoring cluster (both are 8.6.1 now). Monito…

---

## [How to find a term (title: req.query\['q\]) with geo\_distance with elasticsearch 8.6](https://discuss.elastic.co/t/how-to-find-a-term-title-req-query-q-with-geo-distance-with-elasticsearch-8-6/325330)

<div class="topic-metadata">

**Author:** [@teoman\_kirac](https://discuss.elastic.co/u/teoman_kirac)\
**Replies:** 20\
**Last updated:** [February 13, 2023, 1:48pm UTC](https://discuss.elastic.co/t/how-to-find-a-term-title-req-query-q-with-geo-distance-with-elasticsearch-8-6/325330 "2023-02-13T13:48:39Z")

</div>

Years ago I had this working with elasticsearch 16.x.x. It looked like this: let body = { size: 200, from: 0, query: { bool: { must: { term: { title : req.query\['q'\] } }, …

---

## [Removing Data Without Deleting Index While Using Filebeat on Elasticsearch](https://discuss.elastic.co/t/removing-data-without-deleting-index-while-using-filebeat-on-elasticsearch/324761)

<div class="topic-metadata">

**Author:** [@SFD13](https://discuss.elastic.co/u/SFD13)\
**Replies:** 11\
**Last updated:** [February 13, 2023, 10:49am UTC](https://discuss.elastic.co/t/removing-data-without-deleting-index-while-using-filebeat-on-elasticsearch/324761 "2023-02-13T10:49:18Z")

</div>

Hi everyone, I am using filebeat-\* index with some fields on Elasticsearch. I want to remove all data on the elasticsearch which I used but that index remains. It means that without deleting index name and contents (ava…

---

## ["Rejected execution of coordinating operation" exception after upgrade from 8.2.2 to 8.6.0?](https://discuss.elastic.co/t/rejected-execution-of-coordinating-operation-exception-after-upgrade-from-8-2-2-to-8-6-0/323430)

<div class="topic-metadata">

**Author:** [@mbooh](https://discuss.elastic.co/u/mbooh)\
**Replies:** 7\
**Last updated:** [February 13, 2023, 1:11pm UTC](https://discuss.elastic.co/t/rejected-execution-of-coordinating-operation-exception-after-upgrade-from-8-2-2-to-8-6-0/323430 "2023-02-13T13:11:15Z")

</div>

Hi! We just upgraded from 8.2.2 to 8.6.0 and suddenly our bulk inserts fails with this exception: es\_rejected\_execution\_exception Reason: "rejected execution of coordinating operation \[coordinating\_and\_primary\_bytes=20…

---

## [\[ES 6.7\] Multiple field terms aggregation using scripts](https://discuss.elastic.co/t/es-6-7-multiple-field-terms-aggregation-using-scripts/325383)

<div class="topic-metadata">

**Author:** [@Hi\_Jonk](https://discuss.elastic.co/u/Hi_Jonk)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 12:44pm UTC](https://discuss.elastic.co/t/es-6-7-multiple-field-terms-aggregation-using-scripts/325383 "2023-02-13T12:44:46Z")

</div>

In the 6.7 documentation for Terms aggregation, the section on multi field aggregation says that 6.7 does not support multiple field aggregation, and to use scripts instead: Terms Aggregation | Elasticsearch Guide \[6.7\] …

---

## [ECK 2.6.1 node shutdown for invoice optimization](https://discuss.elastic.co/t/eck-2-6-1-node-shutdown-for-invoice-optimization/325374)

<div class="topic-metadata">

**Author:** [@screwyy](https://discuss.elastic.co/u/screwyy)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 12:33pm UTC](https://discuss.elastic.co/t/eck-2-6-1-node-shutdown-for-invoice-optimization/325374 "2023-02-13T12:33:43Z")

</div>

Hello, I'm running an ECK 2.6.1 elastic cluster in a non-prod k8s cluster which has a Horizontal Node Autoscale rule based on CPU+RAM metrics. Is it possible to shutdown elastic nodes on Friday night and start them bac…

---

## [Index not getting deleted as per ILM](https://discuss.elastic.co/t/index-not-getting-deleted-as-per-ilm/324700)

<div class="topic-metadata">

**Author:** [@RahulWagh](https://discuss.elastic.co/u/RahulWagh)\
**Replies:** 4\
**Last updated:** [February 13, 2023, 11:50am UTC](https://discuss.elastic.co/t/index-not-getting-deleted-as-per-ilm/324700 "2023-02-13T11:50:33Z")

</div>

Hi, We are using Elastic cloud version 7.17. We have created one index template and one ILM policy to delete indexes after 90 days. In th ILM we are not using rollover. Assigned this policy to index template. We hav…

---

## [If the file is deleted, delete from the ElasticSearch index](https://discuss.elastic.co/t/if-the-file-is-deleted-delete-from-the-elasticsearch-index/325314)

<div class="topic-metadata">

**Author:** [@SplendX](https://discuss.elastic.co/u/SplendX)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 11:43am UTC](https://discuss.elastic.co/t/if-the-file-is-deleted-delete-from-the-elasticsearch-index/325314 "2023-02-13T11:43:52Z")

</div>

I'm trying to make a piece of code that will be responsible for deleting an indexed file from the elasticsearch index, I pass with the indexed file md5(file name), to the id value. It is necessary to make sure that when …

---

## [Error 503 filebeat can not connect to elasticsearch](https://discuss.elastic.co/t/error-503-filebeat-can-not-connect-to-elasticsearch/325375)

<div class="topic-metadata">

**Author:** [@jomaguca](https://discuss.elastic.co/u/jomaguca)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 10:56am UTC](https://discuss.elastic.co/t/error-503-filebeat-can-not-connect-to-elasticsearch/325375 "2023-02-13T10:56:18Z")

</div>

Hi everyone I have up my ELK server working, and I put a filebeat in another machine with filebeat installed but filebeat can not send inputs to elasticsearch, the error says "Exiting: couldn't connect to any of the con…

---

## [Change @Timestamp to date from API response](https://discuss.elastic.co/t/change-timestamp-to-date-from-api-response/325369)

<div class="topic-metadata">

**Author:** [@Renat](https://discuss.elastic.co/u/Renat)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 9:46am UTC](https://discuss.elastic.co/t/change-timestamp-to-date-from-api-response/325369 "2023-02-13T09:46:14Z")

</div>

Hello everyone, first of all i'm sorry if this common issue, but i really tried to solve it by myself. but searching in web didn't help me, may be because i never used Logstash. So i got request to receive "slowQuer…

---

## [Display live image data (base64 jpeg) in Kibana](https://discuss.elastic.co/t/display-live-image-data-base64-jpeg-in-kibana/324871)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 21\
**Last updated:** [February 13, 2023, 8:42am UTC](https://discuss.elastic.co/t/display-live-image-data-base64-jpeg-in-kibana/324871 "2023-02-13T08:42:59Z")

</div>

I have Base64 encoded jpeg image data stored in ES which I want to display in a dashboard. I'm able to to that with a static image from a specific path using the markdown visualization. But how can I do that with data …

---

## [Elastic Agent capability over logstash](https://discuss.elastic.co/t/elastic-agent-capability-over-logstash/325364)

<div class="topic-metadata">

**Author:** [@ranju](https://discuss.elastic.co/u/ranju)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 7:59am UTC](https://discuss.elastic.co/t/elastic-agent-capability-over-logstash/325364 "2023-02-13T07:59:31Z")

</div>

Hi Team Currently, we are using Logstash to process our logs from Kafka and filebeat sources. We Observed some capability of the beat agent to send the logs to the Elasticsearch directly. In Logstash we are mainly foc…

---

## [Active alert from deleted rule](https://discuss.elastic.co/t/active-alert-from-deleted-rule/325270)

<div class="topic-metadata">

**Author:** [@Mistral](https://discuss.elastic.co/u/Mistral)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 7:53am UTC](https://discuss.elastic.co/t/active-alert-from-deleted-rule/325270 "2023-02-13T07:53:49Z")

</div>

Hi ! Using Elastic & kibana 8.6.1 with Elastic Agent. I'm trying to configure alerts and tried a few. I've been creating and deleting a dozen of alerts. Since two days, I'm still having an active alert from a deleted r…

---

## [Help! workpad on website not showing fullwidth](https://discuss.elastic.co/t/help-workpad-on-website-not-showing-fullwidth/323590)

<div class="topic-metadata">

**Author:** [@rens](https://discuss.elastic.co/u/rens)\
**Replies:** 2\
**Last updated:** [February 13, 2023, 7:44am UTC](https://discuss.elastic.co/t/help-workpad-on-website-not-showing-fullwidth/323590 "2023-02-13T07:44:18Z")

</div>

Hi, I am new to this forum and to elastic. And I have a question. If I share a canvas workpad in static website I cannot get it to show fullwidth. On different monitors the result is either overflowing or to small. I …

---

## [Configure Filebeat to not delete AWS SQS message if the message does not match the file\_selectors](https://discuss.elastic.co/t/configure-filebeat-to-not-delete-aws-sqs-message-if-the-message-does-not-match-the-file-selectors/325299)

<div class="topic-metadata">

**Author:** [@b2ron](https://discuss.elastic.co/u/b2ron)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 7:29am UTC](https://discuss.elastic.co/t/configure-filebeat-to-not-delete-aws-sqs-message-if-the-message-does-not-match-the-file-selectors/325299 "2023-02-13T07:29:37Z")

</div>

AWS S3 is configured to send event notification to SQS queue Filebeat is using aws-s3 to pull logs from S3 through the SQS queue filebeat.inputs: - type: aws-s3 queue\_url: https://sqs.us-east-2.amazonaws.com/aws-…

---

## [Elasticsearch + Java - Can you further optimize this query?](https://discuss.elastic.co/t/elasticsearch-java-can-you-further-optimize-this-query/325357)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 7:15am UTC](https://discuss.elastic.co/t/elasticsearch-java-can-you-further-optimize-this-query/325357 "2023-02-13T07:15:28Z")

</div>

We have an elasticsearch that contains millions of records and we are using it for a global searching. However, our query takes 2-4 seconds to return result. Can somebody help or advice how to further optimize the follow…

---

## [Receiving an empty attachment with watcher email notification](https://discuss.elastic.co/t/receiving-an-empty-attachment-with-watcher-email-notification/325354)

<div class="topic-metadata">

**Author:** [@VenkatAnudeep](https://discuss.elastic.co/u/VenkatAnudeep)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 6:23am UTC](https://discuss.elastic.co/t/receiving-an-empty-attachment-with-watcher-email-notification/325354 "2023-02-13T06:23:18Z")

</div>

Hello, We have an email action configure in watcher which will send a result of Reporting URL. "email": { "profile": "standard", "attachments": { "KafkaReport.csv": { "reporting": …

---

## [How to redirect Dashboard's legacy URL alias using resolve API?](https://discuss.elastic.co/t/how-to-redirect-dashboards-legacy-url-alias-using-resolve-api/325349)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 5:17am UTC](https://discuss.elastic.co/t/how-to-redirect-dashboards-legacy-url-alias-using-resolve-api/325349 "2023-02-13T05:17:41Z")

</div>

I'm planning to upgrade Elastic Cloud v.7.17.0 to v.8.6.1. I know that there is a change to the saved object IDs from v.8 and my existing object IDs will be changed to a new UUID. To avoid changing the old dashboard UR…

---

## [How to filter by the nested values in the "message" field?](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277)

<div class="topic-metadata">

**Author:** [@Shiva\_Subramaniyan](https://discuss.elastic.co/u/Shiva_Subramaniyan)\
**Replies:** 6\
**Last updated:** [February 12, 2023, 7:57pm UTC](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277 "2023-02-12T19:57:11Z")

</div>

Hi, I have a "message" field in my "filebeat\*" index. This "message" field, particularly has nested fields like "httpRequest" and a "country" field in it. The value of this "country" field is 'US' I want to use a quer…

---

## [Error code 429,Too Many Requests](https://discuss.elastic.co/t/error-code-429-too-many-requests/325332)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [February 12, 2023, 4:37pm UTC](https://discuss.elastic.co/t/error-code-429-too-many-requests/325332 "2023-02-12T16:37:31Z")

</div>

Hi, What does error code 429,Too Many Requests actually means? Is the coordinator is fully loaded or the cluster is fully loaded? Thanks...

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=634)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=636)
