# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=250

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 251

---

## [Elasticsearch query](https://discuss.elastic.co/t/elasticsearch-query/350260)

<div class="topic-metadata">

**Author:** [@Bibhudutta\_Mohanty](https://discuss.elastic.co/u/Bibhudutta_Mohanty)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 7:13pm UTC](https://discuss.elastic.co/t/elasticsearch-query/350260 "2024-01-02T19:13:54Z")

</div>

I have a field called @editors in my index . It has multiple values like , i would like only show the last editor name in last\_editors field . I want to write a query where i can only fetch the the last editor name in e…

---

## [Logstash-plugin command for preparing offline pack is not working on 8.11.3](https://discuss.elastic.co/t/logstash-plugin-command-for-preparing-offline-pack-is-not-working-on-8-11-3/349302)

<div class="topic-metadata">

**Author:** [@ebiibe82](https://discuss.elastic.co/u/ebiibe82)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 5:56pm UTC](https://discuss.elastic.co/t/logstash-plugin-command-for-preparing-offline-pack-is-not-working-on-8-11-3/349302 "2024-01-02T17:56:10Z")

</div>

Hello All, I am new to Elastic Stack. I have installed Logstash 8.11.3 using deb package on Ubuntu 22.04 Server. On top of it, I have installed logstash-output-syslog plugin. Till this point, it works fine. After this, …

---

## [ElasticSearch Nested Search Analyzer not working](https://discuss.elastic.co/t/elasticsearch-nested-search-analyzer-not-working/350256)

<div class="topic-metadata">

**Author:** [@pasupathi-raja](https://discuss.elastic.co/u/pasupathi-raja)\
**Replies:** 2\
**Last updated:** [January 2, 2024, 4:57pm UTC](https://discuss.elastic.co/t/elasticsearch-nested-search-analyzer-not-working/350256 "2024-01-02T16:57:25Z")

</div>

Index Creation I'm creating index with nested property and assigning analyzers to it both index and search time as follows. PUT /test\_index\_pasu { "settings": { "analysis": { "analyzer": { "keyword\_…

---

## [Elasticsearch cluster resiliency and availability](https://discuss.elastic.co/t/elasticsearch-cluster-resiliency-and-availability/350033)

<div class="topic-metadata">

**Author:** [@artechkey](https://discuss.elastic.co/u/artechkey)\
**Replies:** 12\
**Last updated:** [January 2, 2024, 3:56pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-resiliency-and-availability/350033 "2024-01-02T15:56:48Z")

</div>

Hi, We are currently running ES on a 4 node cluster where 2 nodes are in DC 1 & 2 in DC 2. We have a third node in DC 1 with master-voting-only role. The n/w latency b/w DC 1 & DC 2 is negligible. DC 1 - 2 nodes (all r…

---

## [Index not found in Logs](https://discuss.elastic.co/t/index-not-found-in-logs/349828)

<div class="topic-metadata">

**Author:** [@anoman](https://discuss.elastic.co/u/anoman)\
**Replies:** 2\
**Last updated:** [January 2, 2024, 3:27pm UTC](https://discuss.elastic.co/t/index-not-found-in-logs/349828 "2024-01-02T15:27:28Z")

</div>

I have installed Microsoft Defender Endpoint integration to collect logs. The agent was installed properly and the other configuration. But If I go to Elastic Search -\> Discover and try to create a new data view, I can'…

---

## [Kibana not accessible via Kubernetes Ingress](https://discuss.elastic.co/t/kibana-not-accessible-via-kubernetes-ingress/349162)

<div class="topic-metadata">

**Author:** [@patrick-94](https://discuss.elastic.co/u/patrick-94)\
**Replies:** 4\
**Last updated:** [January 2, 2024, 3:18pm UTC](https://discuss.elastic.co/t/kibana-not-accessible-via-kubernetes-ingress/349162 "2024-01-02T15:18:04Z")

</div>

Hey, i have the following Problem which I copy and paste it from Github, anyone here who can help me out with this? This is the Original Post to Github: Kibana not accessible via Ingress · Issue #172630 · elastic/kiban…

---

## [Visualization Lens bar display limit](https://discuss.elastic.co/t/visualization-lens-bar-display-limit/350212)

<div class="topic-metadata">

**Author:** [@Liam619](https://discuss.elastic.co/u/Liam619)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 3:17pm UTC](https://discuss.elastic.co/t/visualization-lens-bar-display-limit/350212 "2024-01-02T15:17:52Z")

</div>

Hi everyone and happy new year. I have a question regarding Visual Lens -\> Bar Chart. I'm trying to display more bars in my chart, during my testing stage, it found that the number of bar charts that can display with a…

---

## [Error: Limit of total fields \[1000\] has been exceeded but index limit is higher](https://discuss.elastic.co/t/error-limit-of-total-fields-1000-has-been-exceeded-but-index-limit-is-higher/350103)

<div class="topic-metadata">

**Author:** [@MColeman](https://discuss.elastic.co/u/MColeman)\
**Replies:** 7\
**Last updated:** [January 2, 2024, 3:00pm UTC](https://discuss.elastic.co/t/error-limit-of-total-fields-1000-has-been-exceeded-but-index-limit-is-higher/350103 "2024-01-02T15:00:37Z")

</div>

I'm re-indexing some data from our old cluster into a new one. I pre-created my index (logstash-2023.10.02) and changed the total field mappings to 4000, the same as the old index on the old host. If I look at the new i…

---

## [Elasticsearch performance testing](https://discuss.elastic.co/t/elasticsearch-performance-testing/350228)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 2:55pm UTC](https://discuss.elastic.co/t/elasticsearch-performance-testing/350228 "2024-01-02T14:55:29Z")

</div>

Hi all, We are trying to come up with performance tests, stress tests etc to calculate throughput and identify bottlenecks in our elasticsearch cluster. We are using elasticsearch exporter to export metrics from the clu…

---

## [How list index and size using python](https://discuss.elastic.co/t/how-list-index-and-size-using-python/350235)

<div class="topic-metadata">

**Author:** [@pratik\_jain163](https://discuss.elastic.co/u/pratik_jain163)\
**Replies:** 2\
**Last updated:** [January 2, 2024, 2:35pm UTC](https://discuss.elastic.co/t/how-list-index-and-size-using-python/350235 "2024-01-02T14:35:19Z")

</div>

i tried to write one Python code for get ES index and size but it gave me a huge json output and I was not able to find an exact result. how we can do this. es.indices.stats(index=index)

---

## [Elasticsearch\_exporter not listing all metrics](https://discuss.elastic.co/t/elasticsearch-exporter-not-listing-all-metrics/349940)

<div class="topic-metadata">

**Author:** [@Balachander\_Ramaling](https://discuss.elastic.co/u/Balachander_Ramaling)\
**Replies:** 0\
**Last updated:** [December 26, 2023, 10:16am UTC](https://discuss.elastic.co/t/elasticsearch-exporter-not-listing-all-metrics/349940 "2023-12-26T10:16:47Z")

</div>

Am trying to install elasticsearch\_exporter v1.5.0 from GitHub - prometheus-community/elasticsearch\_exporter: Elasticsearch stats exporter for Prometheus in k8 environment. Post installation, am not seeing many of the me…

---

## [Elasticagent - filebeat is still increasing memory](https://discuss.elastic.co/t/elasticagent-filebeat-is-still-increasing-memory/350211)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 2:07pm UTC](https://discuss.elastic.co/t/elasticagent-filebeat-is-still-increasing-memory/350211 "2024-01-02T14:07:33Z")

</div>

Hello, we are using ELK 8.11 and we have figured out that after installing elastic agent on windows and linux machines, they are 2 processes filebeat that are still increasing/allocation RAM more and more RAM. Even it …

---

## [Two Logstash nodes. Same config. Persistent queue filling only in one of them](https://discuss.elastic.co/t/two-logstash-nodes-same-config-persistent-queue-filling-only-in-one-of-them/350229)

<div class="topic-metadata">

**Author:** [@nahiko](https://discuss.elastic.co/u/nahiko)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 1:34pm UTC](https://discuss.elastic.co/t/two-logstash-nodes-same-config-persistent-queue-filling-only-in-one-of-them/350229 "2024-01-02T13:34:31Z")

</div>

Hello! I have a 3 node Elasticsearch cluster, 2 Logstash nodes and about 100 filebeats sending data to Logstash. Every piece is 7.17 Both Logstash nodes have the exact same configuration. There is a 16 GB persistent q…

---

## [Logstash inconsistency while reading csv data](https://discuss.elastic.co/t/logstash-inconsistency-while-reading-csv-data/348881)

<div class="topic-metadata">

**Author:** [@iko](https://discuss.elastic.co/u/iko)\
**Replies:** 8\
**Last updated:** [January 2, 2024, 1:15pm UTC](https://discuss.elastic.co/t/logstash-inconsistency-while-reading-csv-data/348881 "2024-01-02T13:15:05Z")

</div>

Hello, We are using Logstash for parsing csv data and load them into Postgresql and then after making proper transformation we move that data to Elasticsearch by using same Logstash . We don't have any problem about tra…

---

## [How much cpu power needed for elk consider security use case?](https://discuss.elastic.co/t/how-much-cpu-power-needed-for-elk-consider-security-use-case/350179)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 4\
**Last updated:** [January 2, 2024, 12:48pm UTC](https://discuss.elastic.co/t/how-much-cpu-power-needed-for-elk-consider-security-use-case/350179 "2024-01-02T12:48:27Z")

</div>

elk documentation say that for every 20 shard we need 1 gb ram what about cpu?

---

## [Elastic Engineer On-Demand Course Lab in Strigo has ended](https://discuss.elastic.co/t/elastic-engineer-on-demand-course-lab-in-strigo-has-ended/350183)

<div class="topic-metadata">

**Author:** [@Maor\_Shmul](https://discuss.elastic.co/u/Maor_Shmul)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 11:49am UTC](https://discuss.elastic.co/t/elastic-engineer-on-demand-course-lab-in-strigo-has-ended/350183 "2024-01-02T11:49:17Z")

</div>

Course: Version: Question: \<I enrolled in Elastic Engineer On-Demand 3 months ago and took a break for paternity leave. I resumed 2 weeks ago, but yesterday I got notified that Strigo lab ended. Can I get a new envir…

---

## [Playwright script is working while testing in synthetic recorder but its networking while configure it in the monitor](https://discuss.elastic.co/t/playwright-script-is-working-while-testing-in-synthetic-recorder-but-its-networking-while-configure-it-in-the-monitor/349859)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 5\
**Last updated:** [January 2, 2024, 11:13am UTC](https://discuss.elastic.co/t/playwright-script-is-working-while-testing-in-synthetic-recorder-but-its-networking-while-configure-it-in-the-monitor/349859 "2024-01-02T11:13:00Z")

</div>

Hi Team, I have recorded an activity on a website using synthetic recorder and while I am testing the script that is formed in synthetic recorder itself is working fine but when I configure the same in synthetic multipa…

---

## [Kibana v8(beat)和V7主题版本的区别](https://discuss.elastic.co/t/kibana-v8-beat-v7/350217)

<div class="topic-metadata">

**Author:** [@wq1357226](https://discuss.elastic.co/u/wq1357226)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 10:01am UTC](https://discuss.elastic.co/t/kibana-v8-beat-v7/350217 "2024-01-02T10:01:19Z")

</div>

kibana7.11.2提供V8（beat）和V7两种版本选择，有什么区别呢

---

## [Certificate pinning in Elasticsearch](https://discuss.elastic.co/t/certificate-pinning-in-elasticsearch/350214)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 9:55am UTC](https://discuss.elastic.co/t/certificate-pinning-in-elasticsearch/350214 "2024-01-02T09:55:54Z")

</div>

Hi, We are using Elasticsearch 7.17.0 and using azure storage blobs for snapshots. We recently received a general notification from azure about certificate pinning. I believe we do not have any such configuration tha…

---

## [Logstash upgrade issue - 8.11.3 version](https://discuss.elastic.co/t/logstash-upgrade-issue-8-11-3-version/350132)

<div class="topic-metadata">

**Author:** [@siva0030](https://discuss.elastic.co/u/siva0030)\
**Replies:** 7\
**Last updated:** [January 2, 2024, 9:23am UTC](https://discuss.elastic.co/t/logstash-upgrade-issue-8-11-3-version/350132 "2024-01-02T09:23:40Z")

</div>

Hello Team, Good evening! Today I have upgraded the Logstash from version 8.10.4 to 8.11.3 version. After the upgrade the Logstash is keep restarting and throwing below errors. This type of FATAL error is coming for a…

---

## [Esrally creat index error,class\_cast\_exception](https://discuss.elastic.co/t/esrally-creat-index-error-class-cast-exception/350215)

<div class="topic-metadata">

**Author:** [@zhouxuanxuan](https://discuss.elastic.co/u/zhouxuanxuan)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 9:19am UTC](https://discuss.elastic.co/t/esrally-creat-index-error-class-cast-exception/350215 "2024-01-02T09:19:44Z")

</div>

\[ERROR\] Cannot race. Error in load generator \[0\] Cannot run task \[create-index\]: Request returned an error. Error type: transport, Description: class\_cast\_exception ({'error': {'root\_cause': \[{'type': 'class\_cast\_except…

---

## [Encountered a retryable error (will retry with exponential backoff) {:code=\>413}](https://discuss.elastic.co/t/encountered-a-retryable-error-will-retry-with-exponential-backoff-code-413/349802)

<div class="topic-metadata">

**Author:** [@sathishkumarD](https://discuss.elastic.co/u/sathishkumarD)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 9:02am UTC](https://discuss.elastic.co/t/encountered-a-retryable-error-will-retry-with-exponential-backoff-code-413/349802 "2024-01-02T09:02:25Z")

</div>

Elastic search and Logstash version: 8.5.1 Getting below error from logstash when trying to transfer files to elasticsearch. Could someone help me to fix the issue. \[ERROR\]\[logstash.outputs.elasticsearch\]\[main\]\[532e27b…

---

## [Elasticsearch 7.16 shard recovery slow](https://discuss.elastic.co/t/elasticsearch-7-16-shard-recovery-slow/349952)

<div class="topic-metadata">

**Author:** [@wangxiangyu](https://discuss.elastic.co/u/wangxiangyu)\
**Replies:** 6\
**Last updated:** [January 2, 2024, 8:51am UTC](https://discuss.elastic.co/t/elasticsearch-7-16-shard-recovery-slow/349952 "2024-01-02T08:51:47Z")

</div>

hi, The elasticsearch cluster has 6 hot node and 4 cold node. One cold node is removed caused by hardware failure. So lots of missing replica shards( about 20TB) began to recover. But I found the recovery process was v…

---

## [Kibana\_error](https://discuss.elastic.co/t/kibana-error/349585)

<div class="topic-metadata">

**Author:** [@sossoulokoariel](https://discuss.elastic.co/u/sossoulokoariel)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 8:30am UTC](https://discuss.elastic.co/t/kibana-error/349585 "2024-01-02T08:30:48Z")

</div>

Hi community, hope you're well. I'm in the process of implementing the ELK stack as part of my dissertation project. For a few weeks I haven't logged in, but today I logged in, but the web interface puts Kibana is not re…

---

## [Kibana8.4.3 & nginx，nginx returns 502 bad gateway](https://discuss.elastic.co/t/kibana8-4-3-nginx-nginx-returns-502-bad-gateway/350197)

<div class="topic-metadata">

**Author:** [@gaygayGuys](https://discuss.elastic.co/u/gaygayGuys)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 7:29am UTC](https://discuss.elastic.co/t/kibana8-4-3-nginx-nginx-returns-502-bad-gateway/350197 "2024-01-02T07:29:19Z")

</div>

hello everyone ! i need help !!!! when i use nginx to proxy kibana ,i find a tricky problem. at the beginning ,everything is ok. but several minutes later, 502 bad gateway is starting to appear! i hava no idea to solve…

---

## [Elastic SIEM Fundamentals no longer available?](https://discuss.elastic.co/t/elastic-siem-fundamentals-no-longer-available/350195)

<div class="topic-metadata">

**Author:** [@coroso136](https://discuss.elastic.co/u/coroso136)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 7:16am UTC](https://discuss.elastic.co/t/elastic-siem-fundamentals-no-longer-available/350195 "2024-01-02T07:16:30Z")

</div>

Course: Elastic SIEM Fundamentals Question: Hey there, is the course no longer available? I can't enroll unfortunately.

---

## [Where if anywhere does ES documentation explain about metadata, specifically index creation datetimes?](https://discuss.elastic.co/t/where-if-anywhere-does-es-documentation-explain-about-metadata-specifically-index-creation-datetimes/350185)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 4\
**Last updated:** [January 1, 2024, 10:57pm UTC](https://discuss.elastic.co/t/where-if-anywhere-does-es-documentation-explain-about-metadata-specifically-index-creation-datetimes/350185 "2024-01-01T22:57:57Z")

</div>

This in an application context, not "human consumption". With a bit of searching I finally found this answer. The up-to-date (v. 8.11) documentation for this appears to be here, "cat indices API". But there it says "ca…

---

## [Invalid version of beats protocol: 69](https://discuss.elastic.co/t/invalid-version-of-beats-protocol-69/349830)

<div class="topic-metadata">

**Author:** [@e-ferrari](https://discuss.elastic.co/u/e-ferrari)\
**Replies:** 10\
**Last updated:** [January 1, 2024, 10:28pm UTC](https://discuss.elastic.co/t/invalid-version-of-beats-protocol-69/349830 "2024-01-01T22:28:56Z")

</div>

Hello, I'm completely new to ELK. I'm reading the doc and try to execute this: But i got an error from logstash: \[2023-12-21T23:21:37,978\]\[WARN \]\[io.netty.channel.DefaultChannelPipeline\]\[main\]\[c6b88577022f3da3a78380…

---

## [Date Column has some rows with NULL - strict\_date\_optional\_time causes Exception](https://discuss.elastic.co/t/date-column-has-some-rows-with-null-strict-date-optional-time-causes-exception/350164)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 23\
**Last updated:** [January 1, 2024, 5:11pm UTC](https://discuss.elastic.co/t/date-column-has-some-rows-with-null-strict-date-optional-time-causes-exception/350164 "2024-01-01T17:11:46Z")

</div>

All this time, I use \[strict\_date\_optional\_time||yyyy-MM-dd HH:mm:ss.SSS||yyyy-MM-dd HH:mm:ss.SS||yyyy-MM-dd HH:mm:ss||yyyy-MM-dd HH:mm:ss.S\] To parse in columns with dates. Now, I have a csv file whose columns have ro…

---

## [Sizing elk for SIEM(security) use case](https://discuss.elastic.co/t/sizing-elk-for-siem-security-use-case/350178)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 2\
**Last updated:** [January 1, 2024, 4:42pm UTC](https://discuss.elastic.co/t/sizing-elk-for-siem-security-use-case/350178 "2024-01-01T16:42:52Z")

</div>

Hello everyone, can you help me how to size my elk as SIEM? any thoughts or resources can help please give to me. Thanks in advance.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=249)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=251)
