# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=658

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 659

---

## [Illegal reflective access errors](https://discuss.elastic.co/t/illegal-reflective-access-errors/323020)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 6\
**Last updated:** [January 23, 2023, 9:58am UTC](https://discuss.elastic.co/t/illegal-reflective-access-errors/323020 "2023-01-23T09:58:24Z")

</div>

Getting Illegal reflective access errors along with these warnings: WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by org.jruby.ext.openssl.SecurityHelper (file:/{...}…

---

## [C# client 8.4 filter by date range](https://discuss.elastic.co/t/c-client-8-4-filter-by-date-range/323411)

<div class="topic-metadata">

**Author:** [@matres](https://discuss.elastic.co/u/matres)\
**Replies:** 3\
**Last updated:** [January 23, 2023, 9:12am UTC](https://discuss.elastic.co/t/c-client-8-4-filter-by-date-range/323411 "2023-01-23T09:12:31Z")

</div>

Hi. How can I filter results by date range using .net client v8.4? I can't find that option

---

## [Jupyter -\> Vega -\> Kibana Visualization Error](https://discuss.elastic.co/t/jupyter-vega-kibana-visualization-error/321264)

<div class="topic-metadata">

**Author:** [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Replies:** 4\
**Last updated:** [January 23, 2023, 9:09am UTC](https://discuss.elastic.co/t/jupyter-vega-kibana-visualization-error/321264 "2023-01-23T09:09:09Z")

</div>

Hi, I want to visualize data from jupyter to Vega to Kibana. I got a reference How to bring Jupyter Notebook visualizations to Kibana dashboards for data science | Elastic Blog and GitHub - walterra/jupyter2kibana: A…

---

## [ElasticSearch - logstash ( 8.2.0 )](https://discuss.elastic.co/t/elasticsearch-logstash-8-2-0/323710)

<div class="topic-metadata">

**Author:** [@Nalin\_Kumar](https://discuss.elastic.co/u/Nalin_Kumar)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 8:56am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-8-2-0/323710 "2023-01-23T08:56:49Z")

</div>

Hi, all. I'am new to Elasticsearch and finding the best way to store data in elastic-search engine using log stash. Reading tables from input JDBC and output to elastic-search. Currently i have create single index but…

---

## [Help to create new field from message](https://discuss.elastic.co/t/help-to-create-new-field-from-message/323698)

<div class="topic-metadata">

**Author:** [@Sam\_1995](https://discuss.elastic.co/u/Sam_1995)\
**Replies:** 1\
**Last updated:** [January 23, 2023, 8:27am UTC](https://discuss.elastic.co/t/help-to-create-new-field-from-message/323698 "2023-01-23T08:27:50Z")

</div>

Hello, I m looking for a way (maybe with grok), to create new field by extracting some specified pattern but with keeping the field message without modification after operation Example Pattern 2023-01-23 10:33:25 \[ALB…

---

## [Run multi-vectors kNN search](https://discuss.elastic.co/t/run-multi-vectors-knn-search/299958)

<div class="topic-metadata">

**Author:** [@rporcu](https://discuss.elastic.co/u/rporcu)\
**Replies:** 2\
**Last updated:** [January 23, 2023, 7:48am UTC](https://discuss.elastic.co/t/run-multi-vectors-knn-search/299958 "2023-01-23T07:48:05Z")

</div>

Hello everyone! I’m really interested by the new kNN search functionality of Elasticsearch v8. Is there any way to run an approximate kNN search on multiple dense\_vectors? I checked the docs but, as of version 8.1.0, …

---

## [How to take a snapshot using SSE-C](https://discuss.elastic.co/t/how-to-take-a-snapshot-using-sse-c/323704)

<div class="topic-metadata">

**Author:** [@iamraashokkumar](https://discuss.elastic.co/u/iamraashokkumar)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 6:32am UTC](https://discuss.elastic.co/t/how-to-take-a-snapshot-using-sse-c/323704 "2023-01-23T06:32:21Z")

</div>

Hi All, I’m able to encrypt the snapshot using SSE-S3(SSE managed by AWS) by adding the configuration “server-side-encryption: true” in the snapshot repository. However, I’m trying to encrypt the snapshot using SSE-C(Se…

---

## [How to execute exists query for a enabled false property fields](https://discuss.elastic.co/t/how-to-execute-exists-query-for-a-enabled-false-property-fields/323652)

<div class="topic-metadata">

**Author:** [@sriteja\_chebrolu](https://discuss.elastic.co/u/sriteja_chebrolu)\
**Replies:** 5\
**Last updated:** [January 23, 2023, 6:44am UTC](https://discuss.elastic.co/t/how-to-execute-exists-query-for-a-enabled-false-property-fields/323652 "2023-01-23T06:44:27Z")

</div>

How to execute exists query for a enabled false property fields

---

## [Paginantion in logstash](https://discuss.elastic.co/t/paginantion-in-logstash/323385)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 3\
**Last updated:** [January 23, 2023, 6:34am UTC](https://discuss.elastic.co/t/paginantion-in-logstash/323385 "2023-01-23T06:34:07Z")

</div>

Hello there ! I am fetching data from vRops api using http\_poller. Is there any way to achieve pagination in logstash ?

---

## [Having Issue with Data indexing](https://discuss.elastic.co/t/having-issue-with-data-indexing/323581)

<div class="topic-metadata">

**Author:** [@Danish\_Ibrar](https://discuss.elastic.co/u/Danish_Ibrar)\
**Replies:** 3\
**Last updated:** [January 23, 2023, 6:13am UTC](https://discuss.elastic.co/t/having-issue-with-data-indexing/323581 "2023-01-23T06:13:32Z")

</div>

I'm Having an issue I've just deployed the Custom decoders and rules they being triggered but data is not indexed to elastic default alerts are indexed but not for custom rules

---

## [ILM deleted indices before reaching min\_age](https://discuss.elastic.co/t/ilm-deleted-indices-before-reaching-min-age/323696)

<div class="topic-metadata">

**Author:** [@RapTvin](https://discuss.elastic.co/u/RapTvin)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 4:36am UTC](https://discuss.elastic.co/t/ilm-deleted-indices-before-reaching-min-age/323696 "2023-01-23T04:36:12Z")

</div>

Problem We have set the following index management policy for indices, which moves the index to delete phase after 32 days & then once the snapshot is completed the index will be deleted. { "policy": { "phases": {…

---

## [Filter data based on dates and days](https://discuss.elastic.co/t/filter-data-based-on-dates-and-days/323681)

<div class="topic-metadata">

**Author:** [@stella\_raj](https://discuss.elastic.co/u/stella_raj)\
**Replies:** 2\
**Last updated:** [January 23, 2023, 3:50am UTC](https://discuss.elastic.co/t/filter-data-based-on-dates-and-days/323681 "2023-01-23T03:50:31Z")

</div>

Hi, Need to filter data based on specific dates and days. Suggest any filter plugin that will fulfil my requirement. Thanks

---

## [Execute policy synchronously without a \`sleep\` in my bash scripts](https://discuss.elastic.co/t/execute-policy-synchronously-without-a-sleep-in-my-bash-scripts/323695)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 2:44am UTC](https://discuss.elastic.co/t/execute-policy-synchronously-without-a-sleep-in-my-bash-scripts/323695 "2023-01-23T02:44:41Z")

</div>

I've been following this guide to learn how to use enrich processor and ingestion pipelines: I've got most things working so I tried a more realistic workflow that goes something like this: #!/bin/bash /usr/share/l…

---

## [Nodejs (typescript) communication error with elastic](https://discuss.elastic.co/t/nodejs-typescript-communication-error-with-elastic/323687)

<div class="topic-metadata">

**Author:** [@David\_Robles](https://discuss.elastic.co/u/David_Robles)\
**Replies:** 0\
**Last updated:** [January 22, 2023, 5:00pm UTC](https://discuss.elastic.co/t/nodejs-typescript-communication-error-with-elastic/323687 "2023-01-22T17:00:13Z")

</div>

I have a problem connecting nodejs with elasticsearch, at this moment I have dockerized the version of Elasticsearch 8.6.0 as the documentation comes, the communication between kibana and elastic is correct since I have …

---

## [Shard Allocation](https://discuss.elastic.co/t/shard-allocation/323683)

<div class="topic-metadata">

**Author:** [@kajal\_sri](https://discuss.elastic.co/u/kajal_sri)\
**Replies:** 2\
**Last updated:** [January 22, 2023, 7:18pm UTC](https://discuss.elastic.co/t/shard-allocation/323683 "2023-01-22T19:18:11Z")

</div>

Getting Shard allocation issues. Able to see some partial indices as well and those are reported under UNASSIGNED shards. Any specific reason why am getting this issue and how to fix this?

---

## [As a result of my queries, only one result should be returned, but irrelevant results are coming](https://discuss.elastic.co/t/as-a-result-of-my-queries-only-one-result-should-be-returned-but-irrelevant-results-are-coming/323669)

<div class="topic-metadata">

**Author:** [@yasmin1991](https://discuss.elastic.co/u/yasmin1991)\
**Replies:** 8\
**Last updated:** [January 22, 2023, 6:54pm UTC](https://discuss.elastic.co/t/as-a-result-of-my-queries-only-one-result-should-be-returned-but-irrelevant-results-are-coming/323669 "2023-01-22T18:54:08Z")

</div>

Hello I have a question that I expect to return only one result. GET /cvlist/\_search { "query": { "match": { "cvID": "17411189" } } } As a result of the query, another result with a similar cvID is r…

---

## [403 on Discover Tab](https://discuss.elastic.co/t/403-on-discover-tab/323690)

<div class="topic-metadata">

**Author:** [@Akash\_Sethiya](https://discuss.elastic.co/u/Akash_Sethiya)\
**Replies:** 0\
**Last updated:** [January 22, 2023, 6:31pm UTC](https://discuss.elastic.co/t/403-on-discover-tab/323690 "2023-01-22T18:31:45Z")

</div>

Kibana version - 8.5.3 on k8s Elasticsearch version - 8.5.3 on VM On opening discover tab I keep getting Error: Batch request failed with status 403 at search\_interceptor\_SearchInterceptor.handleSearchError Look…

---

## [Remove monitoring for some specific URL in on application - Elastic APM](https://discuss.elastic.co/t/remove-monitoring-for-some-specific-url-in-on-application-elastic-apm/323685)

<div class="topic-metadata">

**Author:** [@Harhsa\_vardhan](https://discuss.elastic.co/u/Harhsa_vardhan)\
**Replies:** 1\
**Last updated:** [January 22, 2023, 4:48pm UTC](https://discuss.elastic.co/t/remove-monitoring-for-some-specific-url-in-on-application-elastic-apm/323685 "2023-01-22T16:48:33Z")

</div>

Trying to implement APM newly in one of my test cluster. My test application has some 6+ URL's which starts with same domain, I need to remove monitoring for some specific URL in on application. Is there any option to …

---

## [Use persian calendar in date\_histogram](https://discuss.elastic.co/t/use-persian-calendar-in-date-histogram/323678)

<div class="topic-metadata">

**Author:** [@masoud\_darvishi](https://discuss.elastic.co/u/masoud_darvishi)\
**Replies:** 0\
**Last updated:** [January 22, 2023, 2:08pm UTC](https://discuss.elastic.co/t/use-persian-calendar-in-date-histogram/323678 "2023-01-22T14:08:49Z")

</div>

hi i'm using date histogram with monthly interval aggregation "date\_histogram": { "field": "events.create", "calendar\_interval": "month", "format": "yyyy-MM-dd" } and this is the result { "key\_as\_…

---

## [Designing elasticsearch cluster for a SOC](https://discuss.elastic.co/t/designing-elasticsearch-cluster-for-a-soc/323647)

<div class="topic-metadata">

**Author:** [@TomSLV](https://discuss.elastic.co/u/TomSLV)\
**Replies:** 4\
**Last updated:** [January 22, 2023, 1:09pm UTC](https://discuss.elastic.co/t/designing-elasticsearch-cluster-for-a-soc/323647 "2023-01-22T13:09:13Z")

</div>

Hi everyone, I'm Tom, i'm a soc analyst since 4 years and i'm actually working for a company who want to put a SIEM. I've read many blog post on how to designing/sizing an elasticsearch cluster but i want to have your f…

---

## [Ruby Filter : difference between init option and path option in terms of performance](https://discuss.elastic.co/t/ruby-filter-difference-between-init-option-and-path-option-in-terms-of-performance/323677)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 0\
**Last updated:** [January 22, 2023, 1:27pm UTC](https://discuss.elastic.co/t/ruby-filter-difference-between-init-option-and-path-option-in-terms-of-performance/323677 "2023-01-22T13:27:07Z")

</div>

Hello All, while I am reading on Ruby filter plugin, I found that the "init" option is used to execute any code at startup time. so, is there any 'performance' difference between path option and init option used like t…

---

## [Replacing @timestamp with logs having custom timestamp](https://discuss.elastic.co/t/replacing-timestamp-with-logs-having-custom-timestamp/323656)

<div class="topic-metadata">

**Author:** [@sahoo35](https://discuss.elastic.co/u/sahoo35)\
**Replies:** 7\
**Last updated:** [January 22, 2023, 10:22am UTC](https://discuss.elastic.co/t/replacing-timestamp-with-logs-having-custom-timestamp/323656 "2023-01-22T10:22:39Z")

</div>

Hello Everyone, I am newbie in ELK stack and i am still learning the logstash, kibana and its further uses . Currently i am stuck at a point where i want to extract the time stamp from my logs and replace it with @times…

---

## [Adding new fields from timestamp nvarchar(max) with grok filter in logstash](https://discuss.elastic.co/t/adding-new-fields-from-timestamp-nvarchar-max-with-grok-filter-in-logstash/323645)

<div class="topic-metadata">

**Author:** [@Dor\_Steinberg](https://discuss.elastic.co/u/Dor_Steinberg)\
**Replies:** 12\
**Last updated:** [January 22, 2023, 9:57am UTC](https://discuss.elastic.co/t/adding-new-fields-from-timestamp-nvarchar-max-with-grok-filter-in-logstash/323645 "2023-01-22T09:57:40Z")

</div>

hey everyone, i want to create 2 new fields (as month, year) from an existing timestamp field that comes from a json filter (payload) when the timestamp field type is nvarchar(max) I tried going in several directions …

---

## [Does NFS Server (remote source) exported in ELK?](https://discuss.elastic.co/t/does-nfs-server-remote-source-exported-in-elk/323667)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [January 22, 2023, 8:43am UTC](https://discuss.elastic.co/t/does-nfs-server-remote-source-exported-in-elk/323667 "2023-01-22T08:43:52Z")

</div>

I have a remote source (NFS server) and I want to use the file systems to visualize the row data in elastic and use the search engine (kibana). is there supporting in elastic with NFS?

---

## [Logstash unable to write records to existing elasticsearch index](https://discuss.elastic.co/t/logstash-unable-to-write-records-to-existing-elasticsearch-index/323659)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [January 21, 2023, 9:46pm UTC](https://discuss.elastic.co/t/logstash-unable-to-write-records-to-existing-elasticsearch-index/323659 "2023-01-21T21:46:13Z")

</div>

I can successfully get logstash to write records to an elasticsearch index if the index doesn't exist in the first place. But I can't seem to get logstash to write records to an index if it already exists. For example,…

---

## [Add\_kubernetes\_metadata processor does not seem to work. Filebeat Data indexed to Elastic does not have any fields relevant to kubernetes](https://discuss.elastic.co/t/add-kubernetes-metadata-processor-does-not-seem-to-work-filebeat-data-indexed-to-elastic-does-not-have-any-fields-relevant-to-kubernetes/323596)

<div class="topic-metadata">

**Author:** [@sunil\_s](https://discuss.elastic.co/u/sunil_s)\
**Replies:** 2\
**Last updated:** [January 21, 2023, 9:10pm UTC](https://discuss.elastic.co/t/add-kubernetes-metadata-processor-does-not-seem-to-work-filebeat-data-indexed-to-elastic-does-not-have-any-fields-relevant-to-kubernetes/323596 "2023-01-21T21:10:29Z")

</div>

PFB filebeat.yaml filebeat.inputs: - type: container paths: - '/var/log/containers/\*.log' processors: - add\_kubernetes\_metadata: host: ${NODE\_NAME} matchers: - logs\_path: …

---

## [ELK Active Active Setup with Failure Recovery](https://discuss.elastic.co/t/elk-active-active-setup-with-failure-recovery/323621)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 2\
**Last updated:** [January 21, 2023, 6:34pm UTC](https://discuss.elastic.co/t/elk-active-active-setup-with-failure-recovery/323621 "2023-01-21T18:34:31Z")

</div>

Hello All The use case is that we want to setup Active Active architecture in ELK using two clusters in two different regions. We will index the event to both the local elasticsearch cluster and remote elasticsearch clu…

---

## [Unassigned missng shards after node failure](https://discuss.elastic.co/t/unassigned-missng-shards-after-node-failure/323649)

<div class="topic-metadata">

**Author:** [@EthanJ1999](https://discuss.elastic.co/u/EthanJ1999)\
**Replies:** 0\
**Last updated:** [January 21, 2023, 1:59pm UTC](https://discuss.elastic.co/t/unassigned-missng-shards-after-node-failure/323649 "2023-01-21T13:59:43Z")

</div>

Hi how's going every body. the proble is one of the shards of an specific index on a cluster is unassigned. the problem occures when a cluster node left, after rejoining to the cluster the shard reamain unassigned so we …

---

## [Divide two counts of the same index with different filters](https://discuss.elastic.co/t/divide-two-counts-of-the-same-index-with-different-filters/323631)

<div class="topic-metadata">

**Author:** [@TheFish](https://discuss.elastic.co/u/TheFish)\
**Replies:** 3\
**Last updated:** [January 21, 2023, 12:00pm UTC](https://discuss.elastic.co/t/divide-two-counts-of-the-same-index-with-different-filters/323631 "2023-01-21T12:00:32Z")

</div>

Hi, I'm trying to divide two counts in TSVB, and I've read the related answer at Divides two sum fields in kibana? but I have a twist, and I can't get it to work: I have one index with "death" events in a game. Each eve…

---

## [Segment size/ merge policy for large indices](https://discuss.elastic.co/t/segment-size-merge-policy-for-large-indices/323623)

<div class="topic-metadata">

**Author:** [@GregoryJC](https://discuss.elastic.co/u/GregoryJC)\
**Replies:** 7\
**Last updated:** [January 21, 2023, 6:44am UTC](https://discuss.elastic.co/t/segment-size-merge-policy-for-large-indices/323623 "2023-01-21T06:44:19Z")

</div>

I am new to Elastic, I started learning about it in depth a month ago as I moved into a position to take over the more or less unmanaged cloud install we had. We have quite a few indices with segment counts ranging from…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=657)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=659)
