# Latest

**URL:** https://discuss.elastic.co/latest.md?page=594

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 595

---

## [Pagination + Sorted Aggregations: Efficiently Retrieve Sorted List of Values?](https://discuss.elastic.co/t/pagination-sorted-aggregations-efficiently-retrieve-sorted-list-of-values/339325)

<div class="topic-metadata">

**Author:** [@openelasticsearch](https://discuss.elastic.co/u/openelasticsearch)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 3:15pm UTC](https://discuss.elastic.co/t/pagination-sorted-aggregations-efficiently-retrieve-sorted-list-of-values/339325 "2023-07-26T15:15:05Z")

</div>

Hi, I'm looking for some advice on the best way to implement an aggregation query that supports pagination and sorting. Quick Overview of My Documents & Desired Use Case: I have indexes that contain documents with a nu…

---

## [Error logstash \[logstash.outputs.elasticsearch\] Encountered a retryable error code=\>503](https://discuss.elastic.co/t/error-logstash-logstash-outputs-elasticsearch-encountered-a-retryable-error-code-503/328331)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 13\
**Last updated:** [July 26, 2023, 2:56pm UTC](https://discuss.elastic.co/t/error-logstash-logstash-outputs-elasticsearch-encountered-a-retryable-error-code-503/328331 "2023-07-26T14:56:45Z")

</div>

Hi all. I'm a beginner at this. When setting up another pipelayer, after starting it, the following errors started to appear in the log for all other pipelines: logstash\[363391\]: \[2023-03-23T08:05:49,424\]\[ERROR\]\[logsta…

---

## [Installing Elasticsearch as an external service at OpenShift](https://discuss.elastic.co/t/installing-elasticsearch-as-an-external-service-at-openshift/338845)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 2:38pm UTC](https://discuss.elastic.co/t/installing-elasticsearch-as-an-external-service-at-openshift/338845 "2023-07-26T14:38:21Z")

</div>

We have OpenShift cluster and we want to install elasticsearch at ocp to serve both internal and external audit shipment. our design should be something like this: FileBeat (outside ocp) --\> Logstash (inside ocp) --\> El…

---

## [Which is the most stable version of elastic search in 8.x?](https://discuss.elastic.co/t/which-is-the-most-stable-version-of-elastic-search-in-8-x/339314)

<div class="topic-metadata">

**Author:** [@Pankaj\_Goyal](https://discuss.elastic.co/u/Pankaj_Goyal)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 1:57pm UTC](https://discuss.elastic.co/t/which-is-the-most-stable-version-of-elastic-search-in-8-x/339314 "2023-07-26T13:57:34Z")

</div>

We are working on a use case where we have to most rely on vector matching searched. Please suggest most stable version for elastic 8.x.

---

## [Log Retention Issue - Only 10 Days of Logs Kept, Need Assistance](https://discuss.elastic.co/t/log-retention-issue-only-10-days-of-logs-kept-need-assistance/339307)

<div class="topic-metadata">

**Author:** [@7a6b6f](https://discuss.elastic.co/u/7a6b6f)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 1:16pm UTC](https://discuss.elastic.co/t/log-retention-issue-only-10-days-of-logs-kept-need-assistance/339307 "2023-07-26T13:16:23Z")

</div>

Hi everyone, I am facing an issue with log retention in my Elastic Stack setup and could use some help in troubleshooting it. Currently, my system is only retaining logs for 10 days, and after that, the logs are being d…

---

## [\[filebeat ASA Module\] outbound traffic log is parsed in reverse for the source and destination IP](https://discuss.elastic.co/t/filebeat-asa-module-outbound-traffic-log-is-parsed-in-reverse-for-the-source-and-destination-ip/339269)

<div class="topic-metadata">

**Author:** [@Keunwoo\_Lee](https://discuss.elastic.co/u/Keunwoo_Lee)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 12:54pm UTC](https://discuss.elastic.co/t/filebeat-asa-module-outbound-traffic-log-is-parsed-in-reverse-for-the-source-and-destination-ip/339269 "2023-07-26T12:54:04Z")

</div>

Hi. I am collecting logs using the cisco asa module, and the outbound traffic log is parsed in reverse for the source and destination IP. eg) DNS query traffic elasticsearch 8.8.1 kibana 8.8.1 filebeat 8.8.2 /mo…

---

## [🎉 Elastic Stack 8.9 released](https://discuss.elastic.co/t/elastic-stack-8-9-released/339298)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 11:23am UTC](https://discuss.elastic.co/t/elastic-stack-8-9-released/339298 "2023-07-26T11:23:42Z")

</div>

:tada: What’s new in Elastic 8.9 This release provides faster search performance and increased SIEM capabilities along with a tech preview of Reciprocal Rank Fusion for hybrid search. Importantly, the beta release of the…

---

## [Multiline Filter : How to group error logs with stacktrace to elastic search using logstash?](https://discuss.elastic.co/t/multiline-filter-how-to-group-error-logs-with-stacktrace-to-elastic-search-using-logstash/338952)

<div class="topic-metadata">

**Author:** [@karthi.charles](https://discuss.elastic.co/u/karthi.charles)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 11:57am UTC](https://discuss.elastic.co/t/multiline-filter-how-to-group-error-logs-with-stacktrace-to-elastic-search-using-logstash/338952 "2023-07-26T11:57:45Z")

</div>

I am trying to group Error logs which having stacktrace information using multiline filter. Not sure how to set pattern correctly. Kindly help me to config the correct pattern. This is my logging pattern, INFO | 2023-…

---

## [Install elasticsearch 8.8](https://discuss.elastic.co/t/install-elasticsearch-8-8/339304)

<div class="topic-metadata">

**Author:** [@abntkpi](https://discuss.elastic.co/u/abntkpi)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 11:54am UTC](https://discuss.elastic.co/t/install-elasticsearch-8-8/339304 "2023-07-26T11:54:44Z")

</div>

Hello, I intend to install Elasticsearch 8.8 on an Ubuntu 22.04 server following the link below: Install Elasticsearch with Debian Package | Elasticsearch Guide \[8.9\] | Elastic The server has internet access, and the a…

---

## [Why comments field not being displayed](https://discuss.elastic.co/t/why-comments-field-not-being-displayed/338228)

<div class="topic-metadata">

**Author:** [@Dana\_Pavaday](https://discuss.elastic.co/u/Dana_Pavaday)\
**Replies:** 8\
**Last updated:** [July 26, 2023, 11:16am UTC](https://discuss.elastic.co/t/why-comments-field-not-being-displayed/338228 "2023-07-26T11:16:40Z")

</div>

Why is the comment field not being displayed for some Affected Services field values (Memory, CPU) in the Dashboard when they are already being displayed in Discover? Is this an issue with the logstash? What should be d…

---

## [Incorrect links in Kibana plugin documentation](https://discuss.elastic.co/t/incorrect-links-in-kibana-plugin-documentation/339097)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 3\
**Last updated:** [July 26, 2023, 10:28am UTC](https://discuss.elastic.co/t/incorrect-links-in-kibana-plugin-documentation/339097 "2023-07-26T10:28:02Z")

</div>

Hi, Please update documentation for plugin development. There is very little/vague documentation, out of which most of them contains incorrect links to examples and github. This is just an example(Elasticsearch servic…

---

## [when bumped up beats version from 7.16 to 8.6.2, indices are not created](https://discuss.elastic.co/t/when-bumped-up-beats-version-from-7-16-to-8-6-2-indices-are-not-created/339282)

<div class="topic-metadata">

**Author:** [@skumarya](https://discuss.elastic.co/u/skumarya)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 9:20am UTC](https://discuss.elastic.co/t/when-bumped-up-beats-version-from-7-16-to-8-6-2-indices-are-not-created/339282 "2023-07-26T09:20:05Z")

</div>

we were using Elasticsearch version 7.16 earlier since we have bumped up the version to 8.6.2 for elasticsearch, kibana and filebeat indices are not created. we are using Helm version 3.12.2 Kubernetes version 1.25.4/1…

---

## [Charts plugin or @elastic/charts](https://discuss.elastic.co/t/charts-plugin-or-elastic-charts/339033)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 6\
**Last updated:** [July 26, 2023, 8:16am UTC](https://discuss.elastic.co/t/charts-plugin-or-elastic-charts/339033 "2023-07-26T08:16:11Z")

</div>

Hi, I am creating an external plugin in Kibana 8.8.1 using React. I want to create charts inside my plugin. I expect them to be clickable and also just like in Kibana, when I click on a particular chart item (like bar …

---

## [How to see audit log in for my deployment in elastic cloud](https://discuss.elastic.co/t/how-to-see-audit-log-in-for-my-deployment-in-elastic-cloud/339257)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 7:17am UTC](https://discuss.elastic.co/t/how-to-see-audit-log-in-for-my-deployment-in-elastic-cloud/339257 "2023-07-26T07:17:42Z")

</div>

I have run the insert the data in Elasticsearch through rest call and once I went to Log and metrics inside the elastic cloud GUI ,I am unable to find audit logs , only I am getting server log, Please guide me regarding…

---

## [Date Filter](https://discuss.elastic.co/t/date-filter/337023)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 3\
**Last updated:** [July 26, 2023, 7:11am UTC](https://discuss.elastic.co/t/date-filter/337023 "2023-07-26T07:11:23Z")

</div>

I am trying to see how many count of items named from the data index has expiry date less than 30 days from now and also the count of items having expiry date till the next 30 days. I have tried a lot in TSVB with three …

---

## [Process logs of different formats to JSON](https://discuss.elastic.co/t/process-logs-of-different-formats-to-json/339258)

<div class="topic-metadata">

**Author:** [@Chel\_Db](https://discuss.elastic.co/u/Chel_Db)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 6:45am UTC](https://discuss.elastic.co/t/process-logs-of-different-formats-to-json/339258 "2023-07-26T06:45:43Z")

</div>

I'm pretty new to ELK and I'm trying to push few of our service's logs to ES. Log funneling flow is --\> \` Fluentd --\> Logstash --\> ES --\> Kibana. \` A thing to note is that, each service has its own log format. Attach…

---

## [Write data to Elasticsearch through plugin](https://discuss.elastic.co/t/write-data-to-elasticsearch-through-plugin/339260)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 6:55am UTC](https://discuss.elastic.co/t/write-data-to-elasticsearch-through-plugin/339260 "2023-07-26T06:55:28Z")

</div>

Hi, I am creating an external plugin in Kibana 8.8.1 using React. I want to write data to an Elasticsearch index on a button click inside the plugin. I presume I will have to use the Elasticsearch service provided by …

---

## [I don't know , how to solve this errorr.. , while try to reset the passcode in terminul](https://discuss.elastic.co/t/i-dont-know-how-to-solve-this-errorr-while-try-to-reset-the-passcode-in-terminul/339242)

<div class="topic-metadata">

**Author:** [@hari\_prabhu](https://discuss.elastic.co/u/hari_prabhu)\
**Replies:** 4\
**Last updated:** [July 26, 2023, 5:07am UTC](https://discuss.elastic.co/t/i-dont-know-how-to-solve-this-errorr-while-try-to-reset-the-passcode-in-terminul/339242 "2023-07-26T05:07:17Z")

</div>

./elasticsearch-env: line 86: cd: /etc/elasticsearch: Permission denied \`\`\` 86th line : \`\`\` ES\_PATH\_CONF = "cd" "$ES\_PATH\_CONF" ; \`pwd\` \`\`\`

---

## [When using the index settings with auto\_expand\_replicas set to "0-all," an issue arises where primary shards are concentrated on specific nodes](https://discuss.elastic.co/t/when-using-the-index-settings-with-auto-expand-replicas-set-to-0-all-an-issue-arises-where-primary-shards-are-concentrated-on-specific-nodes/339185)

<div class="topic-metadata">

**Author:** [@wedul\_chul](https://discuss.elastic.co/u/wedul_chul)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 4:31am UTC](https://discuss.elastic.co/t/when-using-the-index-settings-with-auto-expand-replicas-set-to-0-all-an-issue-arises-where-primary-shards-are-concentrated-on-specific-nodes/339185 "2023-07-26T04:31:01Z")

</div>

Due to the service requirements, the setting "auto\_expand\_replicas" is configured as "0-all," enabling replica shards to be present on all nodes. However, there is an issue where primary shards are concentrated on a spec…

---

## [Heartbeat auto reload configuration file](https://discuss.elastic.co/t/heartbeat-auto-reload-configuration-file/339163)

<div class="topic-metadata">

**Author:** [@michael31](https://discuss.elastic.co/u/michael31)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 4:25am UTC](https://discuss.elastic.co/t/heartbeat-auto-reload-configuration-file/339163 "2023-07-26T04:25:41Z")

</div>

Hello, I am setting up heartbeat with auto reload configuration files under the monitor.d path. It works fine and loads new config files but the problem is that it loads only for new files, if I edit an existing file an…

---

## [Search error rate 100](https://discuss.elastic.co/t/search-error-rate-100/339235)

<div class="topic-metadata">

**Author:** [@maximiliano\_carrasco](https://discuss.elastic.co/u/maximiliano_carrasco)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 12:41am UTC](https://discuss.elastic.co/t/search-error-rate-100/339235 "2023-07-26T00:41:48Z")

</div>

I am trying to run a simple track with search operation but I keep getting 100 error rate, This is my track {% import "rally.helpers" as rally with context %} { "version": 2, "description": "Tracker-generated track…

---

## [Need advice on using Elasticsearch in a transaction processing application](https://discuss.elastic.co/t/need-advice-on-using-elasticsearch-in-a-transaction-processing-application/338265)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 11:13pm UTC](https://discuss.elastic.co/t/need-advice-on-using-elasticsearch-in-a-transaction-processing-application/338265 "2023-07-25T23:13:04Z")

</div>

We develop and maintain an ecommerce back-office fulfillment system. So, it has the transaction processing function to capture fulfillment requests from an ecommerce website, and the reporting, listing, and business fu…

---

## [How to overcome the two-billion limitation on the number of Elasticsearch records?](https://discuss.elastic.co/t/how-to-overcome-the-two-billion-limitation-on-the-number-of-elasticsearch-records/339232)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 11:01pm UTC](https://discuss.elastic.co/t/how-to-overcome-the-two-billion-limitation-on-the-number-of-elasticsearch-records/339232 "2023-07-25T23:01:55Z")

</div>

As explained in the below quoted post on StackOverflow, Elasticsearch has a limit of two billion documents. Yes there is limit to the number of docs per shard of 2 billion, which is a hard lucene limit. There is a max…

---

## [401 error when setting up filebeat google\_workspace integration](https://discuss.elastic.co/t/401-error-when-setting-up-filebeat-google-workspace-integration/338417)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 7\
**Last updated:** [July 25, 2023, 10:12pm UTC](https://discuss.elastic.co/t/401-error-when-setting-up-filebeat-google-workspace-integration/338417 "2023-07-25T22:12:52Z")

</div>

Hi All, I'm using filebeat (7.17.9) and trying to setup google workspace integration. I've followed all the steps in: I've got a json credential file: { "type": "service\_account", "project\_id": "gwm-168856537013…

---

## [Getting started - Kibana - ElasticSearch - logstash](https://discuss.elastic.co/t/getting-started-kibana-elasticsearch-logstash/339204)

<div class="topic-metadata">

**Author:** [@rajdevworks](https://discuss.elastic.co/u/rajdevworks)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 10:09pm UTC](https://discuss.elastic.co/t/getting-started-kibana-elasticsearch-logstash/339204 "2023-07-25T22:09:08Z")

</div>

Hello, I have different json files which I would like to visualize into Kibana after ingesting them to Elasticsearch. Where can I get started and do I need to define input/output filters?

---

## [We are seeing the issue on SonarQube with elasticsearch. Elastic search is not coming up preventing the sonarqube to be up and running](https://discuss.elastic.co/t/we-are-seeing-the-issue-on-sonarqube-with-elasticsearch-elastic-search-is-not-coming-up-preventing-the-sonarqube-to-be-up-and-running/339229)

<div class="topic-metadata">

**Author:** [@bipin23](https://discuss.elastic.co/u/bipin23)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 9:56pm UTC](https://discuss.elastic.co/t/we-are-seeing-the-issue-on-sonarqube-with-elasticsearch-elastic-search-is-not-coming-up-preventing-the-sonarqube-to-be-up-and-running/339229 "2023-07-25T21:56:47Z")

</div>

Sonarqube version - 10.0.0 OS : RHEL 8 Java - opendfk 17 Here are the logs: 2023.07.25 21:03:47 ERROR es\[o.e.b.Elasticsearch\] fatal exception while booting Elasticsearch java.lang.ExceptionInInitializerError: null …

---

## [AlmaLinux OS 9](https://discuss.elastic.co/t/almalinux-os-9/338910)

<div class="topic-metadata">

**Author:** [@Nirjonadda](https://discuss.elastic.co/u/Nirjonadda)\
**Replies:** 4\
**Last updated:** [July 25, 2023, 8:27pm UTC](https://discuss.elastic.co/t/almalinux-os-9/338910 "2023-07-25T20:27:12Z")

</div>

Do you have any plan add support for AlmaLinux OS 9? Can not install Elasticsearch in AlmaLinux OS 9 because RPM signing key is invalid. rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch warning: Signature…

---

## [Combine term and bucket range query](https://discuss.elastic.co/t/combine-term-and-bucket-range-query/339215)

<div class="topic-metadata">

**Author:** [@aelam](https://discuss.elastic.co/u/aelam)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 8:09pm UTC](https://discuss.elastic.co/t/combine-term-and-bucket-range-query/339215 "2023-07-25T20:09:43Z")

</div>

I'm attempting to extract records of http success/failure data per user using an elasticsearch aggregation. I'm looking at two fields, "user.name" and "http.response.status\_code". My goal is to use a keyed range bucket …

---

## [Enable xpack.security but not password authentication](https://discuss.elastic.co/t/enable-xpack-security-but-not-password-authentication/338917)

<div class="topic-metadata">

**Author:** [@darshanypatel](https://discuss.elastic.co/u/darshanypatel)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 8:00pm UTC](https://discuss.elastic.co/t/enable-xpack-security-but-not-password-authentication/338917 "2023-07-25T20:00:11Z")

</div>

I have an ES 7.16.2 cluster running with TLS set up. I haven't set the xpack.security.enabled setting in my elasticsearch.yml file. I'm using the BASIC license. So it should have used the default value of false for that …

---

## [Enterprise Search Error : "You do not have sufficient permissions."](https://discuss.elastic.co/t/enterprise-search-error-you-do-not-have-sufficient-permissions/338841)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 7:54pm UTC](https://discuss.elastic.co/t/enterprise-search-error-you-do-not-have-sufficient-permissions/338841 "2023-07-25T19:54:09Z")

</div>

Hello Elastic, I have a case where my user received an error when accessing to the Enterprise Search. The error looks like image below : And the server logs refer to : \[2023-07-20T06:15:16.907+08:00\]\[ERROR\]\[plugin…

[Previous page](https://discuss.elastic.co/latest.md?page=593)

[Next page](https://discuss.elastic.co/latest.md?page=595)
