# Latest

**URL:** https://discuss.elastic.co/latest.md?page=577

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 578

---

## [Elasticdump is getting failed for uploading the index into elastic](https://discuss.elastic.co/t/elasticdump-is-getting-failed-for-uploading-the-index-into-elastic/340501)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:38am UTC](https://discuss.elastic.co/t/elasticdump-is-getting-failed-for-uploading-the-index-into-elastic/340501 "2023-08-10T01:38:09Z")

</div>

hello all, i am trying to upload the index dump which i have taken using the elasticdump while uploading i am facing issue, as below - Tue, 08 Aug 2023 10:21:37 GMT | sent 10000 objects to destination elasticsearch, wr…

---

## [Difference in filebeat + ES performance](https://discuss.elastic.co/t/difference-in-filebeat-es-performance/340500)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:10am UTC](https://discuss.elastic.co/t/difference-in-filebeat-es-performance/340500 "2023-08-10T01:10:10Z")

</div>

Hi, I currently have 2 setups: Filebeat v8.3.3 + ES v8.3.3 different physical servers connected to the same subnet 3-node ES (each configured as master + data) Total of 90GB JVM heap Total of 18TB hard disk space (ru…

---

## [Fortigate alerts](https://discuss.elastic.co/t/fortigate-alerts/340499)

<div class="topic-metadata">

**Author:** [@Mbrezzy](https://discuss.elastic.co/u/Mbrezzy)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 12:34am UTC](https://discuss.elastic.co/t/fortigate-alerts/340499 "2023-08-10T00:34:08Z")

</div>

Hello , i would like to set up alerts on fortinet field for example alert if a host sent or receive a large data . Hope you understand what im trying to say thanks

---

## [Documentation - get index api- why there is no info about what api is returning](https://discuss.elastic.co/t/documentation-get-index-api-why-there-is-no-info-about-what-api-is-returning/340495)

<div class="topic-metadata">

**Author:** [@Krzysztof\_Lempicki](https://discuss.elastic.co/u/Krzysztof_Lempicki)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 9:16pm UTC](https://discuss.elastic.co/t/documentation-get-index-api-why-there-is-no-info-about-what-api-is-returning/340495 "2023-08-09T21:16:42Z")

</div>

In doc: Get index information | Elasticsearch API documentation there is no info about what is returned. Is this in purpose? If yes why? For example: From console I see that keys of returned map are index names. With…

---

## [Petclinic Lab Metrics Internal Server Error 500](https://discuss.elastic.co/t/petclinic-lab-metrics-internal-server-error-500/340487)

<div class="topic-metadata">

**Author:** [@lucasyuki](https://discuss.elastic.co/u/lucasyuki)\
**Replies:** 2\
**Last updated:** [August 9, 2023, 8:35pm UTC](https://discuss.elastic.co/t/petclinic-lab-metrics-internal-server-error-500/340487 "2023-08-09T20:35:49Z")

</div>

Course: \<Petclinic Lab 4t?\> I had done the lab until I arrived at the 4th module but as soon as I realized I went to Metrics and I was giving this error (Internal Server Error 500, before it was working

---

## [Kibana RAM usage allocation | ELK running too slow](https://discuss.elastic.co/t/kibana-ram-usage-allocation-elk-running-too-slow/340445)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 8:08pm UTC](https://discuss.elastic.co/t/kibana-ram-usage-allocation-elk-running-too-slow/340445 "2023-08-09T20:08:54Z")

</div>

ELK running too slow and in kibana stack monitoring section this is what kibana memory shows my doubt is why it shows 4 gb for kibana when server ram is 64 gb

---

## [Snapshot/restore repository-s3 --\> Using IAM roles for Kubernetes service accounts for authentication is not working](https://discuss.elastic.co/t/snapshot-restore-repository-s3-using-iam-roles-for-kubernetes-service-accounts-for-authentication-is-not-working/340125)

<div class="topic-metadata">

**Author:** [@Celal\_SAHIN](https://discuss.elastic.co/u/Celal_SAHIN)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 7:15pm UTC](https://discuss.elastic.co/t/snapshot-restore-repository-s3-using-iam-roles-for-kubernetes-service-accounts-for-authentication-is-not-working/340125 "2023-08-09T19:15:43Z")

</div>

Hi, Currently we are following the guide here\[1\]. We can successfully assign proper service account(hence AWS iam role) to the es pods. If relevant here\[2\] you can see our redacted elasticsearch CRD file. This correctl…

---

## [Download Transactions Data to excel sheet in Elastic APM](https://discuss.elastic.co/t/download-transactions-data-to-excel-sheet-in-elastic-apm/339957)

<div class="topic-metadata">

**Author:** [@Dixit](https://discuss.elastic.co/u/Dixit)\
**Replies:** 7\
**Last updated:** [August 9, 2023, 6:20pm UTC](https://discuss.elastic.co/t/download-transactions-data-to-excel-sheet-in-elastic-apm/339957 "2023-08-09T18:20:13Z")

</div>

hi @basepi , Is there any way can download the TRANSACTIONAL DATA to an excel sheet.

---

## [Parse the values from aggregation results in watcher transform painless script](https://discuss.elastic.co/t/parse-the-values-from-aggregation-results-in-watcher-transform-painless-script/340485)

<div class="topic-metadata">

**Author:** [@Pavani\_Reddy](https://discuss.elastic.co/u/Pavani_Reddy)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 5:51pm UTC](https://discuss.elastic.co/t/parse-the-values-from-aggregation-results-in-watcher-transform-painless-script/340485 "2023-08-09T17:51:14Z")

</div>

Hello @Badger , @magnusbaeck Please help on painless script for parsing the timestamp and compare with now-1h. ''' "aggs": { "by\_index": { "terms": { "field": "\_index" }, "aggs": { "by\_timestamp": { "max": { "…

---

## [Custom integration for a KVM](https://discuss.elastic.co/t/custom-integration-for-a-kvm/340483)

<div class="topic-metadata">

**Author:** [@divygobi](https://discuss.elastic.co/u/divygobi)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 5:30pm UTC](https://discuss.elastic.co/t/custom-integration-for-a-kvm/340483 "2023-08-09T17:30:14Z")

</div>

If I want to monitor user info(through ecs and kibana) from a KVM instance without installing anything on the KVM, would making a custom integration be the right way to do it? If so, how would we get started on that?

---

## [Separate result by category](https://discuss.elastic.co/t/separate-result-by-category/340479)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 5:05pm UTC](https://discuss.elastic.co/t/separate-result-by-category/340479 "2023-08-09T17:05:07Z")

</div>

Hello , I have nested filed . And I want to bring the result separated by broker , something like this - \[ "broker\_one" =\> \[ result \], "broker\_two" =\> \[ result \] I know that I can aggregate the result , and co…

---

## [Cannot start enterprise search - pre-flight check to Kibana timed out](https://discuss.elastic.co/t/cannot-start-enterprise-search-pre-flight-check-to-kibana-timed-out/340360)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 3\
**Last updated:** [August 9, 2023, 4:21pm UTC](https://discuss.elastic.co/t/cannot-start-enterprise-search-pre-flight-check-to-kibana-timed-out/340360 "2023-08-09T16:21:21Z")

</div>

Hi, I am using Elasticsearch 8.8.1 with Kibana (dev mode) 8.8.1. I installed EnterpriseSearch 8.8.1 (Enterprise Search 8.8.1 | Elastic) and installed the same. Made the following configurations in /usr/share/enterpris…

---

## [Elasticsearch node stats api showing high cpu when nodes are idle](https://discuss.elastic.co/t/elasticsearch-node-stats-api-showing-high-cpu-when-nodes-are-idle/340455)

<div class="topic-metadata">

**Author:** [@Pradeep\_B1](https://discuss.elastic.co/u/Pradeep_B1)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 3:21pm UTC](https://discuss.elastic.co/t/elasticsearch-node-stats-api-showing-high-cpu-when-nodes-are-idle/340455 "2023-08-09T15:21:51Z")

</div>

We are observing high CPU usage in elastic cluster master node even when cluster is Idle. We are using elasticsearch version 7.12 We are using cluster with 3 master nodes and 5 data nodes . All data nodes are having 36…

---

## [Filebeat output.kafka with SASL oauthbearer mecanism](https://discuss.elastic.co/t/filebeat-output-kafka-with-sasl-oauthbearer-mecanism/340474)

<div class="topic-metadata">

**Author:** [@chatim](https://discuss.elastic.co/u/chatim)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 3:09pm UTC](https://discuss.elastic.co/t/filebeat-output-kafka-with-sasl-oauthbearer-mecanism/340474 "2023-08-09T15:09:35Z")

</div>

Hello, i have a kafka cluster that use authentication with sasl oauthbearer mecanism (keycloak), i would like to know if filebeat support sasl/oauthbearer. I already found that it supports sasl/plain & sasl/scram, what…

---

## [Can Elastic Stack replace tools like zabbix?](https://discuss.elastic.co/t/can-elastic-stack-replace-tools-like-zabbix/340357)

<div class="topic-metadata">

**Author:** [@musialny](https://discuss.elastic.co/u/musialny)\
**Replies:** 3\
**Last updated:** [August 9, 2023, 2:57pm UTC](https://discuss.elastic.co/t/can-elastic-stack-replace-tools-like-zabbix/340357 "2023-08-09T14:57:42Z")

</div>

Is Elasticsearch stack capable of distribute network monitoring?

---

## [Filter and search through python](https://discuss.elastic.co/t/filter-and-search-through-python/340386)

<div class="topic-metadata">

**Author:** [@IamExperimenting\_Now](https://discuss.elastic.co/u/IamExperimenting_Now)\
**Replies:** 3\
**Last updated:** [August 9, 2023, 2:51pm UTC](https://discuss.elastic.co/t/filter-and-search-through-python/340386 "2023-08-09T14:51:49Z")

</div>

Hi, I'm new to elasticsearch, I'm using elasticsearch for semantic search. I have pushed 5pdf files after converting into vector. when I do search i'm not getting right index value. so, I thought I would do the filter …

---

## [Synthetics Agent Options - Playwright Configuration](https://discuss.elastic.co/t/synthetics-agent-options-playwright-configuration/340428)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 2:40pm UTC](https://discuss.elastic.co/t/synthetics-agent-options-playwright-configuration/340428 "2023-08-09T14:40:31Z")

</div>

Hello Elastic, I would like to set the timeout to 2 minutes = 120000 ms and do the word checking for Synthetic. This is for a Single Page Browser Test, I would like to do checking if there is a word 'DOWN' appeared in …

---

## [Which version of Kibana do we find "Formula" tab for Metrics visualization?](https://discuss.elastic.co/t/which-version-of-kibana-do-we-find-formula-tab-for-metrics-visualization/340355)

<div class="topic-metadata">

**Author:** [@Prathamesh\_S\_Pai](https://discuss.elastic.co/u/Prathamesh_S_Pai)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 2:09pm UTC](https://discuss.elastic.co/t/which-version-of-kibana-do-we-find-formula-tab-for-metrics-visualization/340355 "2023-08-09T14:09:33Z")

</div>

---

## [Event correlation (with EQL)](https://discuss.elastic.co/t/event-correlation-with-eql/339077)

<div class="topic-metadata">

**Author:** [@Adamsb01](https://discuss.elastic.co/u/Adamsb01)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 1:48pm UTC](https://discuss.elastic.co/t/event-correlation-with-eql/339077 "2023-08-09T13:48:03Z")

</div>

Hello everyone, I am currently deploying a Elastic, Kibana, Fleet & agents stack for a project. Details: Elastic (three nodes), in a cluster, version 8.6 Kibana (one node), version 8.6 Fleet servers (on each node) El…

---

## [Elasticsearch failed Search rejected due to missing shards \[\[.kibana\_task\_manager\_7.17.7\_001\]\[0\]\]](https://discuss.elastic.co/t/elasticsearch-failed-search-rejected-due-to-missing-shards-kibana-task-manager-7-17-7-001-0/340192)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 7\
**Last updated:** [August 9, 2023, 1:42pm UTC](https://discuss.elastic.co/t/elasticsearch-failed-search-rejected-due-to-missing-shards-kibana-task-manager-7-17-7-001-0/340192 "2023-08-09T13:42:03Z")

</div>

Hello, Current Conf - Version - Elasticsearch| Kibana - 7.17.3 2 Node Cluster Recently i am facing lot of trouble to keep the cluster in healthy state. The error which i am facing is - Caused by: org.elasticsearch…

---

## [Elasticsearch started by Windows Service needs keystore password](https://discuss.elastic.co/t/elasticsearch-started-by-windows-service-needs-keystore-password/340463)

<div class="topic-metadata">

**Author:** [@stephencoffman](https://discuss.elastic.co/u/stephencoffman)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 1:22pm UTC](https://discuss.elastic.co/t/elasticsearch-started-by-windows-service-needs-keystore-password/340463 "2023-08-09T13:22:15Z")

</div>

We are using VM’s in Azure to host Elasticsearch in a FedRAMP High (FIPS enabled) environment. The VM’s have their own disk space. We are currently using the “zip” distribution type for Windows. We install a Windows S…

---

## [EsHadoopRemoteException: illegal\_argument\_exception: only write ops with an op\_type of create are allowed in data streams?](https://discuss.elastic.co/t/eshadoopremoteexception-illegal-argument-exception-only-write-ops-with-an-op-type-of-create-are-allowed-in-data-streams/340267)

<div class="topic-metadata">

**Author:** [@Zephery\_Wen](https://discuss.elastic.co/u/Zephery_Wen)\
**Replies:** 4\
**Last updated:** [August 9, 2023, 1:07pm UTC](https://discuss.elastic.co/t/eshadoopremoteexception-illegal-argument-exception-only-write-ops-with-an-op-type-of-create-are-allowed-in-data-streams/340267 "2023-08-09T13:07:05Z")

</div>

I want to use Spark to save data to a data stream. JavaEsSparkSQL.saveToEs(result, dataStream, map); It seems like 'saveToEs' only allows index. EsHadoopRemoteException: illegal\_argument\_exception: only write ops with…

---

## [How can i update the data in index when i have multiple docementId](https://discuss.elastic.co/t/how-can-i-update-the-data-in-index-when-i-have-multiple-docementid/340167)

<div class="topic-metadata">

**Author:** [@Mohit\_Rajput](https://discuss.elastic.co/u/Mohit_Rajput)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 1:06pm UTC](https://discuss.elastic.co/t/how-can-i-update-the-data-in-index-when-i-have-multiple-docementid/340167 "2023-08-09T13:06:34Z")

</div>

How can i update the data in index when i have multiple docementtId?

---

## [Populate a dense vector field for only a subset of the documents](https://discuss.elastic.co/t/populate-a-dense-vector-field-for-only-a-subset-of-the-documents/340326)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 4\
**Last updated:** [August 9, 2023, 12:56pm UTC](https://discuss.elastic.co/t/populate-a-dense-vector-field-for-only-a-subset-of-the-documents/340326 "2023-08-09T12:56:58Z")

</div>

I have an index of over 10 million documents. On those documents, I want to store an openai (or similar) embedding vector using an indexed dense vector field. I will be using cosine similarity to search through those vec…

---

## [Metricbeat not working on Docker desktop for windows](https://discuss.elastic.co/t/metricbeat-not-working-on-docker-desktop-for-windows/340459)

<div class="topic-metadata">

**Author:** [@BEIIKS](https://discuss.elastic.co/u/BEIIKS)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 12:56pm UTC](https://discuss.elastic.co/t/metricbeat-not-working-on-docker-desktop-for-windows/340459 "2023-08-09T12:56:09Z")

</div>

Hi there, my first issue here :smiley: Im a rookie in ELK, and today I try to use metricbeat to monitor my cpu, ram and etc... ofc that I work with docker desktop as its in development stage so, therefore I understand …

---

## [Upgrade Elastic Stack 7.15.1 to 7.17.10](https://discuss.elastic.co/t/upgrade-elastic-stack-7-15-1-to-7-17-10/339706)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 24\
**Last updated:** [August 9, 2023, 12:50pm UTC](https://discuss.elastic.co/t/upgrade-elastic-stack-7-15-1-to-7-17-10/339706 "2023-08-09T12:50:14Z")

</div>

Hello Team, After Upgrade ELK from 7.15.1 to 7.17.10 : logstash-kibana-filebeat-Elastic search , i can't receive log IIS in KIBANA. when i check log logstash i get this error : " LogStash::PipelineAction::Create/pipel…

---

## [JVM for logstash](https://discuss.elastic.co/t/jvm-for-logstash/340424)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [August 9, 2023, 12:48pm UTC](https://discuss.elastic.co/t/jvm-for-logstash/340424 "2023-08-09T12:48:48Z")

</div>

Hi there, just want to confirm, is there any limit for JVM for logstash? if the JVM limit for elastic is 30 - 32 GB, does it also apply for logstash? Thanks

---

## [\[App Search\] Search and join across multiple engines](https://discuss.elastic.co/t/app-search-search-and-join-across-multiple-engines/337333)

<div class="topic-metadata">

**Author:** [@ismaelalt](https://discuss.elastic.co/u/ismaelalt)\
**Replies:** 2\
**Last updated:** [August 9, 2023, 12:26pm UTC](https://discuss.elastic.co/t/app-search-search-and-join-across-multiple-engines/337333 "2023-08-09T12:26:14Z")

</div>

I'm using App Search. Is it possible to search and join results across two engines? For instance, let's consider 2 indices: exam { ... } exam\_completion { exam\_id: ... user\_id: ... } Use case: I want to r…

---

## [Elasticsearch v2.3 disk throughput Throttle](https://discuss.elastic.co/t/elasticsearch-v2-3-disk-throughput-throttle/340453)

<div class="topic-metadata">

**Author:** [@ram\_222](https://discuss.elastic.co/u/ram_222)\
**Replies:** 3\
**Last updated:** [August 9, 2023, 11:58am UTC](https://discuss.elastic.co/t/elasticsearch-v2-3-disk-throughput-throttle/340453 "2023-08-09T11:58:02Z")

</div>

we are currently using Elasticsearch v2.3 Cluster configuration Details: 3 master Nodes ( t2.medium.search ) and 9 Data Nodes ( r4.xlarge.search ) EBS changed from gp2 to Provision IOPS Storage is 250 Gib/Node CPU Ut…

---

## [Trace Apache Webserver to Python application](https://discuss.elastic.co/t/trace-apache-webserver-to-python-application/337757)

<div class="topic-metadata">

**Author:** [@Dixit](https://discuss.elastic.co/u/Dixit)\
**Replies:** 7\
**Last updated:** [August 9, 2023, 9:41am UTC](https://discuss.elastic.co/t/trace-apache-webserver-to-python-application/337757 "2023-08-09T09:41:17Z")

</div>

hi Team, There is a need to trace the Request from Apache WebServer to Python Backend (Zope). How can we utilize Elastic APM to trace the request from Apache Webserver (entry point), already ZOPE (python backend) we ha…

[Previous page](https://discuss.elastic.co/latest.md?page=576)

[Next page](https://discuss.elastic.co/latest.md?page=578)
