# Latest

**URL:** https://discuss.elastic.co/latest.md?page=472

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 473

---

## [Run Rally races against an ES cluster built on OpenShift](https://discuss.elastic.co/t/run-rally-races-against-an-es-cluster-built-on-openshift/348028)

<div class="topic-metadata">

**Author:** [@benelastic](https://discuss.elastic.co/u/benelastic)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 9:18am UTC](https://discuss.elastic.co/t/run-rally-races-against-an-es-cluster-built-on-openshift/348028 "2023-11-27T09:18:37Z")

</div>

Here is how I do benchmarking with my existing ES cluster: I have an existing ES cluster built on OpenShift environment The cluster has 5 nodes and each is having exactly same resources The ES cluster is being exposed …

---

## [Does Filebeat support cgroupV2](https://discuss.elastic.co/t/does-filebeat-support-cgroupv2/348017)

<div class="topic-metadata">

**Author:** [@Thiruvikraman](https://discuss.elastic.co/u/Thiruvikraman)\
**Replies:** 0\
**Last updated:** [November 27, 2023, 7:54am UTC](https://discuss.elastic.co/t/does-filebeat-support-cgroupv2/348017 "2023-11-27T07:54:10Z")

</div>

There are no indication in filebeat document that cgroupV2 is supported by beats or not, Is there any page or pointers to look for that details

---

## [Custom index not getting created in Kibana](https://discuss.elastic.co/t/custom-index-not-getting-created-in-kibana/347970)

<div class="topic-metadata">

**Author:** [@sunil\_s](https://discuss.elastic.co/u/sunil_s)\
**Replies:** 5\
**Last updated:** [November 27, 2023, 5:21am UTC](https://discuss.elastic.co/t/custom-index-not-getting-created-in-kibana/347970 "2023-11-27T05:21:12Z")

</div>

Unable to create new index in ES. Please find below Filebeat configuration filebeat.inputs: - type: log enabled: true paths: - xxx.log processors: - add\_cloud\_metadata: ~ - add\_docker\_metadata: ~ - add\_k…

---

## [Logstash filter to create a subfield based on specific text in a log message](https://discuss.elastic.co/t/logstash-filter-to-create-a-subfield-based-on-specific-text-in-a-log-message/347978)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 7:39pm UTC](https://discuss.elastic.co/t/logstash-filter-to-create-a-subfield-based-on-specific-text-in-a-log-message/347978 "2023-11-26T19:39:20Z")

</div>

I've been working on a Logstash configuration where I'm trying to create a subfield within the 'message1' field based on a specific text pattern ('Started'). Here's a snippet of my current Logstash filter: filter { gr…

---

## [NVMe storage with bitnami helm chart](https://discuss.elastic.co/t/nvme-storage-with-bitnami-helm-chart/347952)

<div class="topic-metadata">

**Author:** [@O\_K](https://discuss.elastic.co/u/O_K)\
**Replies:** 2\
**Last updated:** [November 26, 2023, 6:01pm UTC](https://discuss.elastic.co/t/nvme-storage-with-bitnami-helm-chart/347952 "2023-11-26T18:01:14Z")

</div>

Does bitnami helm chart support NVMe storage?

---

## [Slow elasticsearch search performance](https://discuss.elastic.co/t/slow-elasticsearch-search-performance/347902)

<div class="topic-metadata">

**Author:** [@habibkka1234](https://discuss.elastic.co/u/habibkka1234)\
**Replies:** 4\
**Last updated:** [November 26, 2023, 4:37pm UTC](https://discuss.elastic.co/t/slow-elasticsearch-search-performance/347902 "2023-11-26T16:37:02Z")

</div>

i have a eck operator based Elasticsearch cluster with 4 nodes - each with 6 cpu cores and 16 gb ram configured on eck operator. Note: Configured ILM with alias, and have 3 index already created when max size is great…

---

## [Filebeat 7.10.2: connection reset by peer Error flooding in filebeat log](https://discuss.elastic.co/t/filebeat-7-10-2-connection-reset-by-peer-error-flooding-in-filebeat-log/347826)

<div class="topic-metadata">

**Author:** [@epadmav](https://discuss.elastic.co/u/epadmav)\
**Replies:** 2\
**Last updated:** [November 26, 2023, 4:31pm UTC](https://discuss.elastic.co/t/filebeat-7-10-2-connection-reset-by-peer-error-flooding-in-filebeat-log/347826 "2023-11-26T16:31:18Z")

</div>

Hi, We have a cluster in which we're inconsistently observing the below errors filbeat.log within time periods of 5mins/10mins/15mins so on, when using filebeat to send logs to logstash. 2023-11-23T04:40:07.524+0100 …

---

## [\[APM\] Using custom tags and labels for Latency and Error correlations](https://discuss.elastic.co/t/apm-using-custom-tags-and-labels-for-latency-and-error-correlations/347995)

<div class="topic-metadata">

**Author:** [@Jakub\_Zilinek](https://discuss.elastic.co/u/Jakub_Zilinek)\
**Replies:** 0\
**Last updated:** [November 26, 2023, 2:38pm UTC](https://discuss.elastic.co/t/apm-using-custom-tags-and-labels-for-latency-and-error-correlations/347995 "2023-11-26T14:38:14Z")

</div>

Hello, We are using Java/Kotlin OpenTelemetry SDK on our spring micro services. We would like to use new feature to analyse error and latency correlations more here - Find transaction latency and failure correlations | …

---

## [Kibana SSO authentication configuration requirement](https://discuss.elastic.co/t/kibana-sso-authentication-configuration-requirement/347988)

<div class="topic-metadata">

**Author:** [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 2:03pm UTC](https://discuss.elastic.co/t/kibana-sso-authentication-configuration-requirement/347988 "2023-11-26T14:03:59Z")

</div>

Hello All, Thanks, in advance. We have an AWS hosted Elasticsearch and Kibana (8.10 version). Logstash is configured on AWS RHEL7 server. For Kibana I need to enable the AD based SSO authentication. Could anyone pleas…

---

## [/etc/default/logstash](https://discuss.elastic.co/t/etc-default-logstash/347994)

<div class="topic-metadata">

**Author:** [@Tal\_Blat](https://discuss.elastic.co/u/Tal_Blat)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 1:57pm UTC](https://discuss.elastic.co/t/etc-default-logstash/347994 "2023-11-26T13:57:46Z")

</div>

Hi How do i add to logstash env file "/etc/default/logstash" a line with the following format: ELK\_SERVERS="host1:9200","host2:9200","host3:9200","host4:9200" Thanks

---

## [7.2 Rollover Command Fails](https://discuss.elastic.co/t/7-2-rollover-command-fails/347981)

<div class="topic-metadata">

**Author:** [@Matt\_Clairmont](https://discuss.elastic.co/u/Matt_Clairmont)\
**Replies:** 3\
**Last updated:** [November 26, 2023, 12:31pm UTC](https://discuss.elastic.co/t/7-2-rollover-command-fails/347981 "2023-11-26T12:31:47Z")

</div>

Course: Certified Elasticsearch Engineer Version: 8.1 Hi, in module 7.2, at the rollover step to refrewsh component template, the rollover solution fails due to missing items in the payload. POST my\_metrics-service.st…

---

## [An internal error while attempting to create policy](https://discuss.elastic.co/t/an-internal-error-while-attempting-to-create-policy/347991)

<div class="topic-metadata">

**Author:** [@amarnath](https://discuss.elastic.co/u/amarnath)\
**Replies:** 0\
**Last updated:** [November 26, 2023, 11:42am UTC](https://discuss.elastic.co/t/an-internal-error-while-attempting-to-create-policy/347991 "2023-11-26T11:42:08Z")

</div>

{"service":{"node":{"roles":\["background\_tasks","ui"\]}},"ecs":{"version":"8.6.1"},"@timestamp":"2023-11-26T11:27:03.939+00:00","message":"Cannot read properties of undefined (reading 'split')","error":{"message":"Cannot …

---

## [How to calculate how much data a single data node in an elasticsearch cluster can store?](https://discuss.elastic.co/t/how-to-calculate-how-much-data-a-single-data-node-in-an-elasticsearch-cluster-can-store/347916)

<div class="topic-metadata">

**Author:** [@qq\_123456](https://discuss.elastic.co/u/qq_123456)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 10:05am UTC](https://discuss.elastic.co/t/how-to-calculate-how-much-data-a-single-data-node-in-an-elasticsearch-cluster-can-store/347916 "2023-11-26T10:05:52Z")

</div>

I now want to install an elasticsearch cluster. How to evaluate the cluster size and resources? How to calculate how much data a single data node in an elasticsearch cluster can store? How to determine the ratio of memor…

---

## [Best practis for agents enrollment with fleet on ECK](https://discuss.elastic.co/t/best-practis-for-agents-enrollment-with-fleet-on-eck/347986)

<div class="topic-metadata">

**Author:** [@khaled\_belgacem](https://discuss.elastic.co/u/khaled_belgacem)\
**Replies:** 0\
**Last updated:** [November 26, 2023, 8:33am UTC](https://discuss.elastic.co/t/best-practis-for-agents-enrollment-with-fleet-on-eck/347986 "2023-11-26T08:33:58Z")

</div>

Hello everyone, i'm currently using ECK for my elastic stack, i installed agents on some laptops and they enrolled successfully with fleet ( they go by the public network, both elasticsearch and fleet are exposed ), but…

---

## [Increase in shard count vs increase in shard size - Performance comparison](https://discuss.elastic.co/t/increase-in-shard-count-vs-increase-in-shard-size-performance-comparison/347984)

<div class="topic-metadata">

**Author:** [@sriapr98](https://discuss.elastic.co/u/sriapr98)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 7:34am UTC](https://discuss.elastic.co/t/increase-in-shard-count-vs-increase-in-shard-size-performance-comparison/347984 "2023-11-26T07:34:08Z")

</div>

Currently we are creating an index which will take space of around 900GB. We are not able to use ILM because there are updates possible to any older data as well. So the only option left to us is sharding optimization w…

---

## [Hostname not extracted when i run logstash as a service on rhel](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 6\
**Last updated:** [November 26, 2023, 2:30am UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977 "2023-11-26T02:30:37Z")

</div>

Hi When i run logstash normally like this: ./logstash -f logstash.cfg It extract hostname. But when i run as service not extract hostname. Any idea? Thanks

---

## [Dealing with high number of deleted documents](https://discuss.elastic.co/t/dealing-with-high-number-of-deleted-documents/347973)

<div class="topic-metadata">

**Author:** [@Dishant\_18](https://discuss.elastic.co/u/Dishant_18)\
**Replies:** 8\
**Last updated:** [November 25, 2023, 6:15pm UTC](https://discuss.elastic.co/t/dealing-with-high-number-of-deleted-documents/347973 "2023-11-25T18:15:55Z")

</div>

Hello everyone! We have an elasticsearch index with 40 shards and 1 replica. We index live email data in this ES index - so the volume of deletes is also high! We have 2 data nodes and 3 master nodes in our cluster. For…

---

## [Disable auto configuring Kibana](https://discuss.elastic.co/t/disable-auto-configuring-kibana/347972)

<div class="topic-metadata">

**Author:** [@habajol675](https://discuss.elastic.co/u/habajol675)\
**Replies:** 2\
**Last updated:** [November 25, 2023, 4:04pm UTC](https://discuss.elastic.co/t/disable-auto-configuring-kibana/347972 "2023-11-25T16:04:38Z")

</div>

I want to just launch services in docker compos but without automatic configuration from the Kibana side. Can you please tell me if I can turn this off? I see that initially it started correctly and waited for me to con…

---

## [No verify ssl input elasticsearch](https://discuss.elastic.co/t/no-verify-ssl-input-elasticsearch/347860)

<div class="topic-metadata">

**Author:** [@lstoneir](https://discuss.elastic.co/u/lstoneir)\
**Replies:** 3\
**Last updated:** [November 25, 2023, 1:11pm UTC](https://discuss.elastic.co/t/no-verify-ssl-input-elasticsearch/347860 "2023-11-25T13:11:46Z")

</div>

Hi Dears Is there any way to not verify ssl in input elasticsearch plugin? logstash 7.17 I can not do this! please help

---

## [Search template in elastic 8.10](https://discuss.elastic.co/t/search-template-in-elastic-8-10/347969)

<div class="topic-metadata">

**Author:** [@ashish9333](https://discuss.elastic.co/u/ashish9333)\
**Replies:** 0\
**Last updated:** [November 25, 2023, 9:13am UTC](https://discuss.elastic.co/t/search-template-in-elastic-8-10/347969 "2023-11-25T09:13:41Z")

</div>

Greetings to all I have an issue with my search template in ES 8.11, It appears that there is data on the docName parameter, but there is no data when I search using the fulltext parameter and the docName parameter. I…

---

## [Aws managed elastic search](https://discuss.elastic.co/t/aws-managed-elastic-search/347812)

<div class="topic-metadata">

**Author:** [@Hariharan\_Raj](https://discuss.elastic.co/u/Hariharan_Raj)\
**Replies:** 8\
**Last updated:** [November 25, 2023, 6:31am UTC](https://discuss.elastic.co/t/aws-managed-elastic-search/347812 "2023-11-25T06:31:28Z")

</div>

Hi, I am trying to create a 2 node aws managed elasticsearch. I am having trouble creating it. I am running my backend services inside a VPC. the filter service has all the elasticsearch codes and resides in a private …

---

## [Synonym Graph giving incorrect results](https://discuss.elastic.co/t/synonym-graph-giving-incorrect-results/347966)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 0\
**Last updated:** [November 25, 2023, 6:10am UTC](https://discuss.elastic.co/t/synonym-graph-giving-incorrect-results/347966 "2023-11-25T06:10:45Z")

</div>

I am trying to implement Multi-Word Synonyms This is the index setting { "settings": { "analysis": { "filter": { "synonym\_filter": { "type": "synonym\_graph", "synonyms": \[ …

---

## [Acces to Elastic error "Username or password is incorrect. Please try again."](https://discuss.elastic.co/t/acces-to-elastic-error-username-or-password-is-incorrect-please-try-again/347963)

<div class="topic-metadata">

**Author:** [@Antonio\_Sanchez](https://discuss.elastic.co/u/Antonio_Sanchez)\
**Replies:** 1\
**Last updated:** [November 25, 2023, 1:44am UTC](https://discuss.elastic.co/t/acces-to-elastic-error-username-or-password-is-incorrect-please-try-again/347963 "2023-11-25T01:44:11Z")

</div>

Hello everyone I start in this app(elasticsearch,logstash and kibana) on Ubuntu 20.04, I finish all the process to intaller I add a other user but when I put my new user and my password I recibet the error "Username or…

---

## [The span does not contain setUserContext!](https://discuss.elastic.co/t/the-span-does-not-contain-setusercontext/347964)

<div class="topic-metadata">

**Author:** [@thiagobr](https://discuss.elastic.co/u/thiagobr)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 9:46pm UTC](https://discuss.elastic.co/t/the-span-does-not-contain-setusercontext/347964 "2023-11-24T21:46:37Z")

</div>

According to the logs, the transactions are with the userContext, but the spans are without them and I need them to create the dashboard and do a FROM/TO with the user ids.

---

## [Kibana with elastic form docker compose setup problem](https://discuss.elastic.co/t/kibana-with-elastic-form-docker-compose-setup-problem/347951)

<div class="topic-metadata">

**Author:** [@habajol675](https://discuss.elastic.co/u/habajol675)\
**Replies:** 5\
**Last updated:** [November 24, 2023, 7:51pm UTC](https://discuss.elastic.co/t/kibana-with-elastic-form-docker-compose-setup-problem/347951 "2023-11-24T19:51:30Z")

</div>

Hello everyone, I have been trying to deploy elasticsearch and kibana for several days now. I'm using docker compos and having a lot of problems. I have provided an example of the file below, but there is this error with…

---

## [Docker Plesk - ERROR: Elasticsearch exited unexpectedly](https://discuss.elastic.co/t/docker-plesk-error-elasticsearch-exited-unexpectedly/347954)

<div class="topic-metadata">

**Author:** [@appuni](https://discuss.elastic.co/u/appuni)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 7:00pm UTC](https://discuss.elastic.co/t/docker-plesk-error-elasticsearch-exited-unexpectedly/347954 "2023-11-24T19:00:53Z")

</div>

Good afternoon Community, When launching the Elasticsearch image I am receiving the error message: ERROR: Elasticsearch exited unexpectedly I configured it in Docker Plesk for unlimited memory usage, but it didn't sol…

---

## [Use specific subsets of data for visualization layers](https://discuss.elastic.co/t/use-specific-subsets-of-data-for-visualization-layers/347945)

<div class="topic-metadata">

**Author:** [@greendrake](https://discuss.elastic.co/u/greendrake)\
**Replies:** 1\
**Last updated:** [November 24, 2023, 5:56pm UTC](https://discuss.elastic.co/t/use-specific-subsets-of-data-for-visualization-layers/347945 "2023-11-24T17:56:22Z")

</div>

There is a nice feature in Kibana (I am using v 8.6.2) which allows to add multiple layers to visualizations: I have the following kind of data in the index: { utc: "\<datetime\>", source: "foo", value: 5 }…

---

## [How to access an index created by APM in Kibana's custom visualization?](https://discuss.elastic.co/t/how-to-access-an-index-created-by-apm-in-kibanas-custom-visualization/347949)

<div class="topic-metadata">

**Author:** [@thiagobr](https://discuss.elastic.co/u/thiagobr)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 5:33pm UTC](https://discuss.elastic.co/t/how-to-access-an-index-created-by-apm-in-kibanas-custom-visualization/347949 "2023-11-24T17:33:53Z")

</div>

I need to access some custom labels sent from the front in the Dashboard --\> Custom Visualization area, I'm trying to do the following code but I don't seem to get anything. In addition, I am getting a specific index fro…

---

## [Logstash 8.1 multiple patterns](https://discuss.elastic.co/t/logstash-8-1-multiple-patterns/347943)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 1\
**Last updated:** [November 24, 2023, 4:33pm UTC](https://discuss.elastic.co/t/logstash-8-1-multiple-patterns/347943 "2023-11-24T16:33:36Z")

</div>

According to the doc of logstash " \`\`\` filter { grok { match =\> \[ "message", "PATTERN1", "PATTERN2" \] } } I wrote my filter as : filter { grok { match =\> { "message" =\> \[ "%{TIMESTAMP\_ISO860…

---

## [Mustache toJSON tag issue](https://discuss.elastic.co/t/mustache-tojson-tag-issue/347944)

<div class="topic-metadata">

**Author:** [@pszemesy](https://discuss.elastic.co/u/pszemesy)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 4:27pm UTC](https://discuss.elastic.co/t/mustache-tojson-tag-issue/347944 "2023-11-24T16:27:54Z")

</div>

Hi All, I'm trying to create a search template: { "script": { "lang": "mustache", "source": """{ "query": { "bool": { "must": \[ {{#docyear}}{ "terms": { …

[Previous page](https://discuss.elastic.co/latest.md?page=471)

[Next page](https://discuss.elastic.co/latest.md?page=473)
