# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=639

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 640

---

## [Lower latency by using more shards (with routing)](https://discuss.elastic.co/t/lower-latency-by-using-more-shards-with-routing/325117)

<div class="topic-metadata">

**Author:** [@frankkoornstra](https://discuss.elastic.co/u/frankkoornstra)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 9:32am UTC](https://discuss.elastic.co/t/lower-latency-by-using-more-shards-with-routing/325117 "2023-02-09T09:32:56Z")

</div>

Hey, I'm trying to lower the search latency for an index which has routing enabled (and we consistently use it for all queries) and I was wondering if increasing the amount of shards would do the trick? We're deployed o…

---

## [Understanding Metrics ( Cumulative indexing time of primary shards )](https://discuss.elastic.co/t/understanding-metrics-cumulative-indexing-time-of-primary-shards/324986)

<div class="topic-metadata">

**Author:** [@Sriram\_Kumar](https://discuss.elastic.co/u/Sriram_Kumar)\
**Replies:** 3\
**Last updated:** [February 9, 2023, 8:29am UTC](https://discuss.elastic.co/t/understanding-metrics-cumulative-indexing-time-of-primary-shards/324986 "2023-02-09T08:29:12Z")

</div>

Hi , I have a corpus of 100k ( 1 lakh products ) in json , I am bulk indexing to one of the cluster with bulk\_size of 10k . GET product\_\_v99/\_stats { "indexing": { "index\_total": 100000, "index\_t…

---

## [Is there document count limitation for aggregations?](https://discuss.elastic.co/t/is-there-document-count-limitation-for-aggregations/325108)

<div class="topic-metadata">

**Author:** [@ysj6987](https://discuss.elastic.co/u/ysj6987)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 7:52am UTC](https://discuss.elastic.co/t/is-there-document-count-limitation-for-aggregations/325108 "2023-02-09T07:52:02Z")

</div>

Hello, I'm trying to get percentiles aggregation from rather big document size count ( over 400,000 ) I know that query size limitation of documents is10000 as default. I wonder it applies to aggregation so that it res…

---

## [Vega: Set a text for empty data set](https://discuss.elastic.co/t/vega-set-a-text-for-empty-data-set/325099)

<div class="topic-metadata">

**Author:** [@Irwan\_Kurniawan](https://discuss.elastic.co/u/Irwan_Kurniawan)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 7:09am UTC](https://discuss.elastic.co/t/vega-set-a-text-for-empty-data-set/325099 "2023-02-09T07:09:29Z")

</div>

Actually my condition same with this thread but when I try, it doesn't work for me. I did the filter transform and when there's no rows that shown after the transform, I want to make a static text to inform that.

---

## [Kibana dashboard map layer tooltip shows array instead of individual field](https://discuss.elastic.co/t/kibana-dashboard-map-layer-tooltip-shows-array-instead-of-individual-field/324478)

<div class="topic-metadata">

**Author:** [@dro](https://discuss.elastic.co/u/dro)\
**Replies:** 3\
**Last updated:** [February 9, 2023, 7:08am UTC](https://discuss.elastic.co/t/kibana-dashboard-map-layer-tooltip-shows-array-instead-of-individual-field/324478 "2023-02-09T07:08:21Z")

</div>

Good afternoon all, I've checked the forums to see if there was a similar issue to this, but was not able to find any besides this regarding supporting nested field in maps Mapping { "mappings": { "properties": …

---

## [\[Filebeat\] panic: runtime error: makeslice: len out of range](https://discuss.elastic.co/t/filebeat-panic-runtime-error-makeslice-len-out-of-range/325096)

<div class="topic-metadata">

**Author:** [@g00221501](https://discuss.elastic.co/u/g00221501)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 7:00am UTC](https://discuss.elastic.co/t/filebeat-panic-runtime-error-makeslice-len-out-of-range/325096 "2023-02-09T07:00:03Z")

</div>

I have a k8s node with a label of “1235679543222322113” as the key. Getting a panic when starting filebeat for collector the node info. Version: 7.13 Operating System: Linux Steps to Reproduce: k8s node with a label o…

---

## [Saml Connection in Elastic cloud](https://discuss.elastic.co/t/saml-connection-in-elastic-cloud/325047)

<div class="topic-metadata">

**Author:** [@Jenil\_Gupta](https://discuss.elastic.co/u/Jenil_Gupta)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 6:07am UTC](https://discuss.elastic.co/t/saml-connection-in-elastic-cloud/325047 "2023-02-09T06:07:23Z")

</div>

Hi team, We are getting some error " You do not have permission to access the requested page Either go back to the previous page or log in as a different user." . I have attached the screenshot below. Please kindly he…

---

## [Filebeat x509 certificate signed by unknown authority when calling api endpoint](https://discuss.elastic.co/t/filebeat-x509-certificate-signed-by-unknown-authority-when-calling-api-endpoint/325086)

<div class="topic-metadata">

**Author:** [@tom\_morgan](https://discuss.elastic.co/u/tom_morgan)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 5:16am UTC](https://discuss.elastic.co/t/filebeat-x509-certificate-signed-by-unknown-authority-when-calling-api-endpoint/325086 "2023-02-09T05:16:27Z")

</div>

I am getting this error from filebeat: 2023-02-07 07:14:47 2023-02-07T15:14:47.204Z ERROR \[input.httpjson-stateless\] v2/input.go:129 Error while processing http request: failed to execute http client.Do: fail…

---

## [How to use PagerDuty plugin to insert data into pagerduty payload](https://discuss.elastic.co/t/how-to-use-pagerduty-plugin-to-insert-data-into-pagerduty-payload/324524)

<div class="topic-metadata">

**Author:** [@YasuhiroOkumura](https://discuss.elastic.co/u/YasuhiroOkumura)\
**Replies:** 3\
**Last updated:** [February 9, 2023, 5:15am UTC](https://discuss.elastic.co/t/how-to-use-pagerduty-plugin-to-insert-data-into-pagerduty-payload/324524 "2023-02-09T05:15:48Z")

</div>

I am trying to send data to PageDuty side using PagerDuty plugin in Logstash output plugin. I want to insert data into the "payload" field of PagerDuty, but when I use the PagerDuty plugin, the data goes into the "detai…

---

## [Data Nodes disconnected randomly](https://discuss.elastic.co/t/data-nodes-disconnected-randomly/325071)

<div class="topic-metadata">

**Author:** [@ignaciood](https://discuss.elastic.co/u/ignaciood)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 5:05am UTC](https://discuss.elastic.co/t/data-nodes-disconnected-randomly/325071 "2023-02-09T05:05:43Z")

</div>

Hi everyone, I have an Elasticsearch (7.10.2) cluster with 11 cluster nodes (3 master, 8 data). Randomly there are data nodes that start to disconnect from the cluster. The node is healthy but offline, it comes back on…

---

## [I am getting Mapping\_parsing error in logtsah](https://discuss.elastic.co/t/i-am-getting-mapping-parsing-error-in-logtsah/325083)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 4:52am UTC](https://discuss.elastic.co/t/i-am-getting-mapping-parsing-error-in-logtsah/325083 "2023-02-09T04:52:35Z")

</div>

Hi, We can see there are different values for "partition" for the "XYZ" operation logs (logtype also same). loglines are: (1). 2023-01-05T20:46:21.36348538Z stdout F 2023-01-05 20:46:21.363 \[INFO\] - {"logtype":"ABC"…

---

## [How to make Kibana trust in my proxy server certificate?](https://discuss.elastic.co/t/how-to-make-kibana-trust-in-my-proxy-server-certificate/325079)

<div class="topic-metadata">

**Author:** [@Leonardo\_Henrique](https://discuss.elastic.co/u/Leonardo_Henrique)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 4:29am UTC](https://discuss.elastic.co/t/how-to-make-kibana-trust-in-my-proxy-server-certificate/325079 "2023-02-09T04:29:18Z")

</div>

Hey everyone. I have a Kibana running behind my proxy (with self signed certificate). So far, I can not reach the EPR and I am getting the "Self signed certificate in the chain" error when enabling the proxy. How can I…

---

## [Unable to install Elasticsearch using Helm chart](https://discuss.elastic.co/t/unable-to-install-elasticsearch-using-helm-chart/325078)

<div class="topic-metadata">

**Author:** [@techavidity](https://discuss.elastic.co/u/techavidity)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 4:15am UTC](https://discuss.elastic.co/t/unable-to-install-elasticsearch-using-helm-chart/325078 "2023-02-09T04:15:35Z")

</div>

I am trying to setup Elasticsearch on multi node Kubernetes cluster. I did create the storage class, after that i installed the Elasticsearch using Helm. helm repo add elastic https://helm.elastic.co helm repo update …

---

## [Query multiple conditions of an array property](https://discuss.elastic.co/t/query-multiple-conditions-of-an-array-property/325068)

<div class="topic-metadata">

**Author:** [@thomas.schroeder](https://discuss.elastic.co/u/thomas.schroeder)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 10:40pm UTC](https://discuss.elastic.co/t/query-multiple-conditions-of-an-array-property/325068 "2023-02-08T22:40:42Z")

</div>

Hey everyone, I have a document which describes when an entry was/is valid. The entry can be valid for multiple time periods but these can never overlap. Now I want to query only documents which have been changed it's a…

---

## [Connector error](https://discuss.elastic.co/t/connector-error/325062)

<div class="topic-metadata">

**Author:** [@Cosmin\_Ciobanu1](https://discuss.elastic.co/u/Cosmin_Ciobanu1)\
**Replies:** 2\
**Last updated:** [February 8, 2023, 9:52pm UTC](https://discuss.elastic.co/t/connector-error/325062 "2023-02-08T21:52:31Z")

</div>

Hi! I get this error: "\[DEPTH\_ZERO\_SELF\_SIGNED\_CERT\] self signed certificate" on local Elastic Stack infrastructure when I want to use a connector with "https" address. Any help, please?

---

## [Changed field in filebeat but not working in logstash](https://discuss.elastic.co/t/changed-field-in-filebeat-but-not-working-in-logstash/324925)

<div class="topic-metadata">

**Author:** [@yc99](https://discuss.elastic.co/u/yc99)\
**Replies:** 1\
**Last updated:** [February 8, 2023, 9:16pm UTC](https://discuss.elastic.co/t/changed-field-in-filebeat-but-not-working-in-logstash/324925 "2023-02-08T21:16:42Z")

</div>

I changed the source from access to admin and restarted the filebeat service, when I use grok to filter only the admin source, it is empty, but if using grok to filter only the access, it working. It should be source adm…

---

## [ELK Migartion to 8x](https://discuss.elastic.co/t/elk-migartion-to-8x/324539)

<div class="topic-metadata">

**Author:** [@p\_vimal](https://discuss.elastic.co/u/p_vimal)\
**Replies:** 1\
**Last updated:** [February 8, 2023, 8:26pm UTC](https://discuss.elastic.co/t/elk-migartion-to-8x/324539 "2023-02-08T20:26:48Z")

</div>

Hello, Current ELK stack version details: Elasticsearch: 7.17.8 Kibana: 7.17.8 Logstash: 7.17.8 Could you please help me out with the steps for upgrading ELK stack into multi-tier architecture cluster when we upgra…

---

## [Can't Add Terms Query to a Search Template](https://discuss.elastic.co/t/cant-add-terms-query-to-a-search-template/325038)

<div class="topic-metadata">

**Author:** [@krmathieu](https://discuss.elastic.co/u/krmathieu)\
**Replies:** 3\
**Last updated:** [February 8, 2023, 8:37pm UTC](https://discuss.elastic.co/t/cant-add-terms-query-to-a-search-template/325038 "2023-02-08T20:37:31Z")

</div>

I have started work on a search template and hit a snag when trying to add a terms query to the template. Here is the template definition: POST \_scripts/establishments\_search { "script": { "lang": "mustache", …

---

## [Redis Module Connection By using Different User rather than redis default user](https://discuss.elastic.co/t/redis-module-connection-by-using-different-user-rather-than-redis-default-user/323410)

<div class="topic-metadata">

**Author:** [@Gopal\_Nipane](https://discuss.elastic.co/u/Gopal_Nipane)\
**Replies:** 1\
**Last updated:** [February 8, 2023, 8:06pm UTC](https://discuss.elastic.co/t/redis-module-connection-by-using-different-user-rather-than-redis-default-user/323410 "2023-02-08T20:06:16Z")

</div>

Can we mention username in metricbeat redis module ie. /etc/metricbeat/modules.d/redis.yml? I tried two approches to add username in module.hosts field: hosts: \["redis://username:password@localhost:6379"\] in modu…

---

## [Append elements to array avoiding duplicates](https://discuss.elastic.co/t/append-elements-to-array-avoiding-duplicates/325059)

<div class="topic-metadata">

**Author:** [@Sergio\_Serra](https://discuss.elastic.co/u/Sergio_Serra)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 7:35pm UTC](https://discuss.elastic.co/t/append-elements-to-array-avoiding-duplicates/325059 "2023-02-08T19:35:55Z")

</div>

Hello everyone, Is there a performant way to append elements to an array avoiding duplicates basically making it work like a Set instead of a List ? This is the script i'm using, but this will duplicate entries in the …

---

## [JDBC Pipeline Log data question](https://discuss.elastic.co/t/jdbc-pipeline-log-data-question/325058)

<div class="topic-metadata">

**Author:** [@nbrenke](https://discuss.elastic.co/u/nbrenke)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 7:34pm UTC](https://discuss.elastic.co/t/jdbc-pipeline-log-data-question/325058 "2023-02-08T19:34:56Z")

</div>

I have several pipelines that run on a timed basis. They are all JDBC pipelines that ingest data from a SQL database. I am looking to see if it's possible to have the output to the logs state the time the ingest starte…

---

## [There are two types of Flattened Field Types, is that correct?](https://discuss.elastic.co/t/there-are-two-types-of-flattened-field-types-is-that-correct/325057)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 7:34pm UTC](https://discuss.elastic.co/t/there-are-two-types-of-flattened-field-types-is-that-correct/325057 "2023-02-08T19:34:33Z")

</div>

I am learning about Flattened Field Types for index mappings. Can someone confirm if my findings are correct? There are two types of flattened field types. 1. Explicitly Flattened Field Types - This documentation is a…

---

## [How to fetch out the array values](https://discuss.elastic.co/t/how-to-fetch-out-the-array-values/325001)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 6\
**Last updated:** [February 8, 2023, 6:01pm UTC](https://discuss.elastic.co/t/how-to-fetch-out-the-array-values/325001 "2023-02-08T18:01:49Z")

</div>

Hi, I have below sample data { "logtype":"demo" ,"operation":"demoStatus", "Stats":\[ { "apiName":"a", "failedCount":0, "successCount":0 }, { "apiName":"b", "failedCount":0, "…

---

## [Question for Logging Cluster - is 3master, 2data node is good?](https://discuss.elastic.co/t/question-for-logging-cluster-is-3master-2data-node-is-good/324445)

<div class="topic-metadata">

**Author:** [@ggalihpp-jubelio](https://discuss.elastic.co/u/ggalihpp-jubelio)\
**Replies:** 5\
**Last updated:** [February 8, 2023, 5:15pm UTC](https://discuss.elastic.co/t/question-for-logging-cluster-is-3master-2data-node-is-good/324445 "2023-02-08T17:15:17Z")

</div>

Hi everyone, So we tried to move to ECK, and want to execute it perfectly or at least the right way... My use case is for logging and APM, Indexing around 7000ish/s Search rate 50-100/s Now we have an ECK cluster co…

---

## [Elasticsearch 8.5.1 Won't Build. Failed to Apply SpotlessPlugin](https://discuss.elastic.co/t/elasticsearch-8-5-1-wont-build-failed-to-apply-spotlessplugin/324476)

<div class="topic-metadata">

**Author:** [@alxdaly](https://discuss.elastic.co/u/alxdaly)\
**Replies:** 2\
**Last updated:** [February 8, 2023, 5:07pm UTC](https://discuss.elastic.co/t/elasticsearch-8-5-1-wont-build-failed-to-apply-spotlessplugin/324476 "2023-02-08T17:07:27Z")

</div>

I am trying to build an instance of elasticsearch 8.5.1 in a linux environment. I have had to modify the gradle files to point to my company's artifact repositories. When I try to run any ./gradlew commands, I get the er…

---

## [How to only get the highest score of a token graphs multiple sub-queries](https://discuss.elastic.co/t/how-to-only-get-the-highest-score-of-a-token-graphs-multiple-sub-queries/325046)

<div class="topic-metadata">

**Author:** [@Nicolas\_Labrot](https://discuss.elastic.co/u/Nicolas_Labrot)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 4:47pm UTC](https://discuss.elastic.co/t/how-to-only-get-the-highest-score-of-a-token-graphs-multiple-sub-queries/325046 "2023-02-08T16:47:30Z")

</div>

Hello, For example, is indexed "european union" with an hunspell english filter. The filter generates the following tokens token: european / position: 0 token: union / position: 1 token: ion / position: 1 If I do a …

---

## [Is there is alternative for HTTP plugin in ECK version?](https://discuss.elastic.co/t/is-there-is-alternative-for-http-plugin-in-eck-version/325045)

<div class="topic-metadata">

**Author:** [@kinkkong](https://discuss.elastic.co/u/kinkkong)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 4:28pm UTC](https://discuss.elastic.co/t/is-there-is-alternative-for-http-plugin-in-eck-version/325045 "2023-02-08T16:28:06Z")

</div>

We are migrating our platform to Kubernetes, one of the features that we currently use in ELK is the logstash HTTP plugin. Unfortunately, this will be no the case in Kubernetes. Is there an alternative plugin, or ingest …

---

## [Azure Function's log streams from Azure Event Hub can't be consumed by Filebeat](https://discuss.elastic.co/t/azure-functions-log-streams-from-azure-event-hub-cant-be-consumed-by-filebeat/325044)

<div class="topic-metadata">

**Author:** [@dfgh012316](https://discuss.elastic.co/u/dfgh012316)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 4:25pm UTC](https://discuss.elastic.co/t/azure-functions-log-streams-from-azure-event-hub-cant-be-consumed-by-filebeat/325044 "2023-02-08T16:25:19Z")

</div>

I enable azure module to streams azure platformlog to Elasticsearch. When I collected the logs of azure postgreSQL and aks, everything worked fine, but when I used the same method to collect the logs of azure function, …

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/325023)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 3\
**Last updated:** [February 8, 2023, 3:58pm UTC](https://discuss.elastic.co/t/elasticsearch/325023 "2023-02-08T15:58:42Z")

</div>

Hi Team, Is there any major changes and Features in the elasticsearch V7.14 to 8.5.3 Thanks&Regards, SM

---

## [Add description to my logstas index based on another csv field](https://discuss.elastic.co/t/add-description-to-my-logstas-index-based-on-another-csv-field/325002)

<div class="topic-metadata">

**Author:** [@Miriam](https://discuss.elastic.co/u/Miriam)\
**Replies:** 3\
**Last updated:** [February 8, 2023, 3:58pm UTC](https://discuss.elastic.co/t/add-description-to-my-logstas-index-based-on-another-csv-field/325002 "2023-02-08T15:58:21Z")

</div>

I have my index created using logstah config file. Reading from log file following information: id, iduser,datetimInit, dateTimeends 0001 210 2023-02-03 04:45:16.78 2023-02-03 04:46:16.78 0002 1003 2023-02-03 08:45:16.7…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=638)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=640)
