# Latest

**URL:** https://discuss.elastic.co/latest.md?page=551

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 552

---

## [Query cache is getting cleared under heavy query load](https://discuss.elastic.co/t/query-cache-is-getting-cleared-under-heavy-query-load/341704)

<div class="topic-metadata">

**Author:** [@mahesh44](https://discuss.elastic.co/u/mahesh44)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 2:38pm UTC](https://discuss.elastic.co/t/query-cache-is-getting-cleared-under-heavy-query-load/341704 "2023-09-05T14:38:15Z")

</div>

We are seeing exact same issue mentioned in the below post after upgrading to ES 7.17.8. This issue still exists even in the ES 8.8.0. Can someone please help with the solution for this. ES 7.17 | Exponentially growing …

---

## [ELK monog module printing null value in event.original](https://discuss.elastic.co/t/elk-monog-module-printing-null-value-in-event-original/342349)

<div class="topic-metadata">

**Author:** [@Shubham\_Singh](https://discuss.elastic.co/u/Shubham_Singh)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 2:10pm UTC](https://discuss.elastic.co/t/elk-monog-module-printing-null-value-in-event-original/342349 "2023-09-05T14:10:55Z")

</div>

We are exporting the mongo logs using mongodb filebeat module but few values in event.original comes as blank value but when we switch to json i can see the field has a value in it. Can somebody help in identifying the i…

---

## [Filtered alias not working](https://discuss.elastic.co/t/filtered-alias-not-working/342139)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 2:01pm UTC](https://discuss.elastic.co/t/filtered-alias-not-working/342139 "2023-09-05T14:01:27Z")

</div>

Hi , I'm trying to create an alias filtered based on existing field but it seems not working Does anyone have any idea about this issue? POST /\_aliases { "actions" : \[ { "add" : { "index" : "myIndex", "alias" : …

---

## [How to filtering the data in api level while offloading in eastic search](https://discuss.elastic.co/t/how-to-filtering-the-data-in-api-level-while-offloading-in-eastic-search/342315)

<div class="topic-metadata">

**Author:** [@sahithi](https://discuss.elastic.co/u/sahithi)\
**Replies:** 6\
**Last updated:** [September 5, 2023, 2:00pm UTC](https://discuss.elastic.co/t/how-to-filtering-the-data-in-api-level-while-offloading-in-eastic-search/342315 "2023-09-05T14:00:39Z")

</div>

How to filtering the data in api level while offloading the data in eastic search ? Can any one help me here plz?

---

## [How to create a simple CPU usage graph?](https://discuss.elastic.co/t/how-to-create-a-simple-cpu-usage-graph/342036)

<div class="topic-metadata">

**Author:** [@gornication](https://discuss.elastic.co/u/gornication)\
**Replies:** 9\
**Last updated:** [September 5, 2023, 1:39pm UTC](https://discuss.elastic.co/t/how-to-create-a-simple-cpu-usage-graph/342036 "2023-09-05T13:39:40Z")

</div>

Hi! How to create a simple CPU usage graph? I have incoming records with CPU metrics. Using the cpu\_p field, I want to plot the load percentage versus time. Why do I need Break down by? (this is a required paramete…

---

## [Problems with Number of replicas and UNASSIGNED errors](https://discuss.elastic.co/t/problems-with-number-of-replicas-and-unassigned-errors/342138)

<div class="topic-metadata">

**Author:** [@Ednei\_Rodrigues](https://discuss.elastic.co/u/Ednei_Rodrigues)\
**Replies:** 9\
**Last updated:** [September 5, 2023, 1:32pm UTC](https://discuss.elastic.co/t/problems-with-number-of-replicas-and-unassigned-errors/342138 "2023-09-05T13:32:54Z")

</div>

Hello, how are you doing ? So, I have a standalone ELK Stack and I am suffering with the error messages "UNASSIGNED" replicas. I know, to not use replica, I need to set 'number\_of\_replicas': 0 to the index. As I am usin…

---

## [Elasticsearch Index is exist or not](https://discuss.elastic.co/t/elasticsearch-index-is-exist-or-not/342224)

<div class="topic-metadata">

**Author:** [@hld942614](https://discuss.elastic.co/u/hld942614)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 1:28pm UTC](https://discuss.elastic.co/t/elasticsearch-index-is-exist-or-not/342224 "2023-09-05T13:28:23Z")

</div>

How can I know if an index is exist or not? I am using co.elastic.clients 8.6.2 in Java below is my code String index = "test"+ date; try { ElasticsearchClient client = elasticsearchConfig.getClient(); SearchR…

---

## [Where the KNN index is stored?](https://discuss.elastic.co/t/where-the-knn-index-is-stored/342157)

<div class="topic-metadata">

**Author:** [@panivan99pl](https://discuss.elastic.co/u/panivan99pl)\
**Replies:** 3\
**Last updated:** [September 5, 2023, 1:18pm UTC](https://discuss.elastic.co/t/where-the-knn-index-is-stored/342157 "2023-09-05T13:18:04Z")

</div>

Where is the KNN index stored, in RAM or disk memory ? I came across that I used to use ChromaDB to store vectors, I had about 1 million vectors and it stores them all in RAM, it took about 24gb. That's too much, and I'…

---

## [How to create Alerts for cluster health (green/yellow/red) and Circuit Breaker errors?](https://discuss.elastic.co/t/how-to-create-alerts-for-cluster-health-green-yellow-red-and-circuit-breaker-errors/341842)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 1:12pm UTC](https://discuss.elastic.co/t/how-to-create-alerts-for-cluster-health-green-yellow-red-and-circuit-breaker-errors/341842 "2023-09-05T13:12:59Z")

</div>

In Kibana 8.9.0, I managed to successfully create an alert for Cluster Health, so that if cluster health transitions from green to yellow or red, I receive an alert. I did the following: Go to Stack Monitoring In th…

---

## [Offload apic analytics to elastic search, while offloading exclude one of the api](https://discuss.elastic.co/t/offload-apic-analytics-to-elastic-search-while-offloading-exclude-one-of-the-api/342339)

<div class="topic-metadata">

**Author:** [@sahithi](https://discuss.elastic.co/u/sahithi)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 12:38pm UTC](https://discuss.elastic.co/t/offload-apic-analytics-to-elastic-search-while-offloading-exclude-one-of-the-api/342339 "2023-09-05T12:38:53Z")

</div>

we implemented the Elasticsearch and kibana, and we are able to see analytics data and all for all APIs which are running . But now i want to exclude ( remove) one api analytics from the index . How can we achieve this t…

---

## [Calculating time interval manually in Vega](https://discuss.elastic.co/t/calculating-time-interval-manually-in-vega/341837)

<div class="topic-metadata">

**Author:** [@Tankut\_Koray](https://discuss.elastic.co/u/Tankut_Koray)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 10:57am UTC](https://discuss.elastic.co/t/calculating-time-interval-manually-in-vega/341837 "2023-09-05T10:57:18Z")

</div>

Hi, I have a Vega chart where I want to specify my own time intervals according to min-max time differences. auto\_interval is not given me what I want, so I want to calculate it manually and give to aggr query. Is it po…

---

## [Enabling null values on expanded document in Kibana Discover](https://discuss.elastic.co/t/enabling-null-values-on-expanded-document-in-kibana-discover/341052)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 10:54am UTC](https://discuss.elastic.co/t/enabling-null-values-on-expanded-document-in-kibana-discover/341052 "2023-09-05T10:54:40Z")

</div>

Hi. I am using version 8.5.3. I created a Data View under Stack Management. Displayed an index with multiple fields successfully If we filter results and click the diagonal button on document, expanded document comes …

---

## [Filebeat now working on Kubernetes 1.24](https://discuss.elastic.co/t/filebeat-now-working-on-kubernetes-1-24/342334)

<div class="topic-metadata">

**Author:** [@Marco\_Lagalla](https://discuss.elastic.co/u/Marco_Lagalla)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 10:34am UTC](https://discuss.elastic.co/t/filebeat-now-working-on-kubernetes-1-24/342334 "2023-09-05T10:34:13Z")

</div>

Hi, I have a cluster running Kubernetes version 1.24, hosted on AWS EKS. Into the cluster there are multiple workloads segregated by namespace. Filebeat is installed to run as a DaemonSet, and should be able to collec…

---

## [Query latency spike when a node joins the cluster](https://discuss.elastic.co/t/query-latency-spike-when-a-node-joins-the-cluster/342213)

<div class="topic-metadata">

**Author:** [@marinko](https://discuss.elastic.co/u/marinko)\
**Replies:** 6\
**Last updated:** [September 5, 2023, 10:30am UTC](https://discuss.elastic.co/t/query-latency-spike-when-a-node-joins-the-cluster/342213 "2023-09-05T10:30:11Z")

</div>

Hi, We have Elasticsearch 8.6.0 with ltr plugin running on AWS EC2. Each time a new instance (data node) joins the cluster, we see a short (\< 1 min) spike in latency. The maximum latency can rise to 4-5 seconds. This h…

---

## [Does synonym\_graph work on Percolator Query?](https://discuss.elastic.co/t/does-synonym-graph-work-on-percolator-query/342331)

<div class="topic-metadata">

**Author:** [@jspark9812](https://discuss.elastic.co/u/jspark9812)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 10:16am UTC](https://discuss.elastic.co/t/does-synonym-graph-work-on-percolator-query/342331 "2023-09-05T10:16:15Z")

</div>

Hello. There was a question from the percolator query, so I wrote it like this. The link below is a description of token-graphs. The description states that the positionLength of synonym\_graph is ignored in index time. …

---

## [Authentication failed for an OpenID integration(oidc)](https://discuss.elastic.co/t/authentication-failed-for-an-openid-integration-oidc/342330)

<div class="topic-metadata">

**Author:** [@EdricStrongshield](https://discuss.elastic.co/u/EdricStrongshield)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 10:15am UTC](https://discuss.elastic.co/t/authentication-failed-for-an-openid-integration-oidc/342330 "2023-09-05T10:15:28Z")

</div>

Hello,I have a question about authentication that I need your help with. My software version is 8.5 Error: \[o.e.x.s.a.RealmsAuthenticator\] \[node-1\] Authentication to realm oidc1 failed - Failed to authenticate user wit…

---

## [Namespaced Synthetic monitors are missing after upgrade](https://discuss.elastic.co/t/namespaced-synthetic-monitors-are-missing-after-upgrade/342286)

<div class="topic-metadata">

**Author:** [@Marko\_Todoric](https://discuss.elastic.co/u/Marko_Todoric)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 10:04am UTC](https://discuss.elastic.co/t/namespaced-synthetic-monitors-are-missing-after-upgrade/342286 "2023-09-05T10:04:51Z")

</div>

Hello everyone, after upgrading from 8.7.1 to 8.9.1 - I'm no longer able to see any of my monitored hosts but one from heartbeat in Kibana. I can confirm the data is there by looking at the discover but no hosts are sho…

---

## [logstash can no longer write to elasticsearch](https://discuss.elastic.co/t/logstash-can-no-longer-write-to-elasticsearch/342260)

<div class="topic-metadata">

**Author:** [@TaF](https://discuss.elastic.co/u/TaF)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 9:51am UTC](https://discuss.elastic.co/t/logstash-can-no-longer-write-to-elasticsearch/342260 "2023-09-05T09:51:40Z")

</div>

Hello, I'm new to this platform and I need your help for my ELK stack Indeed logstash has not been able to write to elasticsearch for a while below is my logstash/conf.d flow management configuration \< input { tcp …

---

## [Configuring LDAP](https://discuss.elastic.co/t/configuring-ldap/342312)

<div class="topic-metadata">

**Author:** [@elk\_beginner](https://discuss.elastic.co/u/elk_beginner)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 9:06am UTC](https://discuss.elastic.co/t/configuring-ldap/342312 "2023-09-05T09:06:06Z")

</div>

Hi, I am trying to configure LDAP authentication, but I have some trouble. I have this logs. P.S. I just begin to work with ELK, so I don’t know much \[node-1\] license \[...\] mode \[basic\] - valid \[node-1\] license mode i…

---

## [How trigger page with asking for built-in rules and conncectors?](https://discuss.elastic.co/t/how-trigger-page-with-asking-for-built-in-rules-and-conncectors/342304)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 7:47am UTC](https://discuss.elastic.co/t/how-trigger-page-with-asking-for-built-in-rules-and-conncectors/342304 "2023-09-05T07:47:12Z")

</div>

Hi there, I am running 7.17.4 and would like to see the pop-up coming up in monitoring asking me if I want to install the the standard rules & connectors for Kibana alerting. No such page is showing up in the standard …

---

## [Aggregate filter plugin - aggregation exception](https://discuss.elastic.co/t/aggregate-filter-plugin-aggregation-exception/342314)

<div class="topic-metadata">

**Author:** [@Anca\_Linca](https://discuss.elastic.co/u/Anca_Linca)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 8:15am UTC](https://discuss.elastic.co/t/aggregate-filter-plugin-aggregation-exception/342314 "2023-09-05T08:15:44Z")

</div>

Hello, Logstash version: 7.17 Aggregate filter plugin: v2.10.0 I have the following input of logs: {"@timestamp": "2023-07-27T08:40:27.849Z", "message": "Activity Stream update entry for job", "host": "tower-host", "…

---

## [Elastic Agent fleet-managed advanced filebeat configuration](https://discuss.elastic.co/t/elastic-agent-fleet-managed-advanced-filebeat-configuration/342310)

<div class="topic-metadata">

**Author:** [@martcus](https://discuss.elastic.co/u/martcus)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 7:23am UTC](https://discuss.elastic.co/t/elastic-agent-fleet-managed-advanced-filebeat-configuration/342310 "2023-09-05T07:23:54Z")

</div>

Hi! We use the elastic agent fleet-managed solution extensively, especially with the custom logs integration for monitoring application logs. We need to set the filebeat close\_\*, scan\_frequency and ignore\_older paramet…

---

## [Color coding on different value](https://discuss.elastic.co/t/color-coding-on-different-value/342226)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 4\
**Last updated:** [September 5, 2023, 7:23am UTC](https://discuss.elastic.co/t/color-coding-on-different-value/342226 "2023-09-05T07:23:31Z")

</div>

In my document I have 3 fields, first is timestamp, second is absolute\_value and third is percentage\_value. I want show this data in Table type visualization . So in rows I am show timestamp and in metrics i want displa…

---

## [Logstash in k8s - parsing nested json from MongoDB and get every nested json as separated field](https://discuss.elastic.co/t/logstash-in-k8s-parsing-nested-json-from-mongodb-and-get-every-nested-json-as-separated-field/341755)

<div class="topic-metadata">

**Author:** [@Denis\_Lezgin](https://discuss.elastic.co/u/Denis_Lezgin)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 7:11am UTC](https://discuss.elastic.co/t/logstash-in-k8s-parsing-nested-json-from-mongodb-and-get-every-nested-json-as-separated-field/341755 "2023-09-05T07:11:15Z")

</div>

Hi there, I'm using Logstash to take documents from specific MongoDB collection, and save it to Elasticsearch. Nested fields are being saved to "log\_entry" as one JSON, starting with "BSON" or "ID", depends on manipul…

---

## [Bulk inserts more documents than given](https://discuss.elastic.co/t/bulk-inserts-more-documents-than-given/342280)

<div class="topic-metadata">

**Author:** [@Kostyantyn\_Dobriohlo](https://discuss.elastic.co/u/Kostyantyn_Dobriohlo)\
**Replies:** 3\
**Last updated:** [September 5, 2023, 6:30am UTC](https://discuss.elastic.co/t/bulk-inserts-more-documents-than-given/342280 "2023-09-05T06:30:29Z")

</div>

Elasticsearched configured in single-node mode, I have ~1 million elements, but after bulk insert operation I see 10 million elements. I use this python code: def generate\_docs(data): for item in data: doc =…

---

## [Bulk API hangs forever python cloud function](https://discuss.elastic.co/t/bulk-api-hangs-forever-python-cloud-function/342221)

<div class="topic-metadata">

**Author:** [@Thani\_Ath\_Nain\_Khurs](https://discuss.elastic.co/u/Thani_Ath_Nain_Khurs)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 6:25am UTC](https://discuss.elastic.co/t/bulk-api-hangs-forever-python-cloud-function/342221 "2023-09-05T06:25:50Z")

</div>

I am new to Elasticsearch and this issue is driving me crazy. My use case involves getting all documents in elastic-search, min-max normalising some fields and then updating documents in bulk but my bulk call just hangs …

---

## [Key value searching](https://discuss.elastic.co/t/key-value-searching/342279)

<div class="topic-metadata">

**Author:** [@Katya](https://discuss.elastic.co/u/Katya)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 6:12am UTC](https://discuss.elastic.co/t/key-value-searching/342279 "2023-09-05T06:12:18Z")

</div>

Hello everyone. I'm trying to find logs in Kibana which contain the key and value in the table's key, but don't know which syntax is correct for this search. Example: The table contains the key "body". "body" is a JS…

---

## [Elastic.Clients.Elasticsearch .NET client - calling Vector tile search API](https://discuss.elastic.co/t/elastic-clients-elasticsearch-net-client-calling-vector-tile-search-api/341422)

<div class="topic-metadata">

**Author:** [@Jarrod](https://discuss.elastic.co/u/Jarrod)\
**Replies:** 5\
**Last updated:** [September 5, 2023, 5:10am UTC](https://discuss.elastic.co/t/elastic-clients-elasticsearch-net-client-calling-vector-tile-search-api/341422 "2023-09-05T05:10:55Z")

</div>

I am trying to call the Vector tile search API using the new v8 .NET client but receiving an exception. Specifically 8.9.2 as of writing. I understand it doesn't have official support in the client, but it appears I sho…

---

## [What does it mean a shard executing a search locally?](https://discuss.elastic.co/t/what-does-it-mean-a-shard-executing-a-search-locally/342298)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 4:31am UTC](https://discuss.elastic.co/t/what-does-it-mean-a-shard-executing-a-search-locally/342298 "2023-09-05T04:31:17Z")

</div>

Hi Folks, I need some help understanding Query phase of distributed search in ES better, step 2 specifically. Node 3 forwards the search request to a primary or replica copy of every shard in the index. Each shard ex…

---

## [New Control Panel widget not working in Kibana](https://discuss.elastic.co/t/new-control-panel-widget-not-working-in-kibana/340255)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 4:25am UTC](https://discuss.elastic.co/t/new-control-panel-widget-not-working-in-kibana/340255 "2023-09-05T04:25:07Z")

</div>

Hi Team, in 8.x version, Elastic has introduced controls option in kibana dashboard itself. however, in below case, it is not depicting the expected result. if i use control via visualization, it is working as expected…

[Previous page](https://discuss.elastic.co/latest.md?page=550)

[Next page](https://discuss.elastic.co/latest.md?page=552)
