# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=379

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 380

---

## [Please help](https://discuss.elastic.co/t/please-help/333433)

<div class="topic-metadata">

**Author:** [@Bojan\_Dokic](https://discuss.elastic.co/u/Bojan_Dokic)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 5:20pm UTC](https://discuss.elastic.co/t/please-help/333433 "2023-05-15T17:20:18Z")

</div>

I am experiencing following error when trying to install elastic agent on linux macine: Error: fail to enroll: fail to execute request to fleet-server: lookup fleet: Temporary failure in name resolution Error: enroll c…

---

## [Parsing error in date format](https://discuss.elastic.co/t/parsing-error-in-date-format/333466)

<div class="topic-metadata">

**Author:** [@Sachchan](https://discuss.elastic.co/u/Sachchan)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 4:47pm UTC](https://discuss.elastic.co/t/parsing-error-in-date-format/333466 "2023-05-15T16:47:28Z")

</div>

Hi Team getting below error in parsing the date in logstash. Kindly suggest how this can be resolved. "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field \[ResponseTime\] of type \[date\] in docu…

---

## [Unable to open index after config change while closed](https://discuss.elastic.co/t/unable-to-open-index-after-config-change-while-closed/333325)

<div class="topic-metadata">

**Author:** [@matt-monacelli](https://discuss.elastic.co/u/matt-monacelli)\
**Replies:** 5\
**Last updated:** [May 15, 2023, 2:26pm UTC](https://discuss.elastic.co/t/unable-to-open-index-after-config-change-while-closed/333325 "2023-05-15T14:26:13Z")

</div>

ES version: 7.10.2 (running in AWS) I mistakenly added a configuration that had been deprecated and is now preventing me from opening the index. To reproduce, close an index, set the index.mpper.dynamic setting to fals…

---

## [Springboot maven project - RUM & APM Traces are not having same trace id](https://discuss.elastic.co/t/springboot-maven-project-rum-apm-traces-are-not-having-same-trace-id/332924)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 1:23pm UTC](https://discuss.elastic.co/t/springboot-maven-project-rum-apm-traces-are-not-having-same-trace-id/332924 "2023-05-15T13:23:56Z")

</div>

hello team, I came across the issue whee i am not getting same trace id for RUM & APM transaction. E.g. i initiate the transaction "login" and i get the transaction detail in APM (service - springboot-consumer) & RUM (…

---

## [Count distinct groups when using collapse](https://discuss.elastic.co/t/count-distinct-groups-when-using-collapse/333463)

<div class="topic-metadata">

**Author:** [@dorian-marchal](https://discuss.elastic.co/u/dorian-marchal)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 1:11pm UTC](https://discuss.elastic.co/t/count-distinct-groups-when-using-collapse/333463 "2023-05-15T13:11:29Z")

</div>

When collapsing results, the total number of hits (using track\_total\_hits) doesn't take collapsing into account, i.e. the total number of documents is returned, not the number of collapsed groups. E.g. if I index 150854…

---

## [High ram usage](https://discuss.elastic.co/t/high-ram-usage/333270)

<div class="topic-metadata">

**Author:** [@fnitz](https://discuss.elastic.co/u/fnitz)\
**Replies:** 6\
**Last updated:** [May 15, 2023, 12:55pm UTC](https://discuss.elastic.co/t/high-ram-usage/333270 "2023-05-15T12:55:41Z")

</div>

Hello, after some posts and good answers we optimize our Elasticsearch. Actually we use: 6 x hot nodes a 32 gb ram / heap space a 16 gb 22 x cold nodes a 16 gb / 8 gb space We reduce 8 primaries shards to 6 shards A…

---

## [Index data level security](https://discuss.elastic.co/t/index-data-level-security/332843)

<div class="topic-metadata">

**Author:** [@Msacs](https://discuss.elastic.co/u/Msacs)\
**Replies:** 3\
**Last updated:** [May 15, 2023, 12:38pm UTC](https://discuss.elastic.co/t/index-data-level-security/332843 "2023-05-15T12:38:44Z")

</div>

Wanted some guidance on how to setup data level security . I have a index with a field plant\_id and I have user list that I intend to map users to the corresponding plant id and when users searches ES or access Kibana da…

---

## [Pipeline not working in logstash / very strange work of logstash](https://discuss.elastic.co/t/pipeline-not-working-in-logstash-very-strange-work-of-logstash/332818)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 12:26pm UTC](https://discuss.elastic.co/t/pipeline-not-working-in-logstash-very-strange-work-of-logstash/332818 "2023-05-15T12:26:10Z")

</div>

I've encountered strange behavior of Lostash. I have a configuration that reads files locally on the server, then analyzes them and then poisons them into elastic. When I test the config everything works for me /usr/sha…

---

## [Problem with Kubernetes agent status showing as offline](https://discuss.elastic.co/t/problem-with-kubernetes-agent-status-showing-as-offline/333351)

<div class="topic-metadata">

**Author:** [@dbstjdghks25](https://discuss.elastic.co/u/dbstjdghks25)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 10:56am UTC](https://discuss.elastic.co/t/problem-with-kubernetes-agent-status-showing-as-offline/333351 "2023-05-15T10:56:32Z")

</div>

I checked the health of a specific pod in Kubernetes by accessing it, and the fleet appears to be healthy, but the logs are not being sent to the agents and they appear as offline. However, when I check the Elasticsearch…

---

## [Can someone explain how to use "Intervals query"?](https://discuss.elastic.co/t/can-someone-explain-how-to-use-intervals-query/333045)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 9:57am UTC](https://discuss.elastic.co/t/can-someone-explain-how-to-use-intervals-query/333045 "2023-05-15T09:57:51Z")

</div>

How to use them? What is the difference with query\_string and what are the benefits of using "Intervals query"? The documentation is really unclear and hard to understand.

---

## [Delete By query On Fields of type Text](https://discuss.elastic.co/t/delete-by-query-on-fields-of-type-text/333427)

<div class="topic-metadata">

**Author:** [@Martim\_Mourao](https://discuss.elastic.co/u/Martim_Mourao)\
**Replies:** 4\
**Last updated:** [May 15, 2023, 9:47am UTC](https://discuss.elastic.co/t/delete-by-query-on-fields-of-type-text/333427 "2023-05-15T09:47:55Z")

</div>

Elasticsearch Version: 8.7.1 We needed to do some deletes by Query using: Delete by query API | Elasticsearch Guide \[8.7\] | Elastic Our Request using dev tools on Kibana: POST /INDEX/\_delete\_by\_query { "query": { …

---

## [The length \[1133164\] of field \[code\] in doc\[8927\]/index\[ovaledge\_prasanthi4567890\_oequery\] exceeds the \[index.highlight.max\_analyzed\_offset\] limit \[1000000\]. To avoid this error, set the query parameter \[max\_analyzed\_offset\] to a value less than index set](https://discuss.elastic.co/t/the-length-1133164-of-field-code-in-doc-8927-index-ovaledge-prasanthi4567890-oequery-exceeds-the-index-highlight-max-analyzed-offset-limit-1000000-to-avoid-this-error-set-the-query-parameter-max-analyzed-offset-to-a-value-less-than-index-set/333412)

<div class="topic-metadata">

**Author:** [@g\_prashanth](https://discuss.elastic.co/u/g_prashanth)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 8:55am UTC](https://discuss.elastic.co/t/the-length-1133164-of-field-code-in-doc-8927-index-ovaledge-prasanthi4567890-oequery-exceeds-the-index-highlight-max-analyzed-offset-limit-1000000-to-avoid-this-error-set-the-query-parameter-max-analyzed-offset-to-a-value-less-than-index-set/333412 "2023-05-15T08:55:49Z")

</div>

Every time increase index.highlight.max\_analyzed\_offset is not correct right, suppose if the field string having 100 match take first match and ignore remaining matches in the highlight.

---

## [Identifying the cause of an unresponsive ES Cluster](https://discuss.elastic.co/t/identifying-the-cause-of-an-unresponsive-es-cluster/331050)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 23\
**Last updated:** [May 15, 2023, 8:38am UTC](https://discuss.elastic.co/t/identifying-the-cause-of-an-unresponsive-es-cluster/331050 "2023-05-15T08:38:58Z")

</div>

We are running a 3 node cluster to index logs from a firewall. The nodes are VMs (8 Core CPUs, 8GB RAM). The host runs on Intel i7, and has SSD storage. We have Kibana running on one of the nodes. The interface becomes…

---

## [Fleet server is offline](https://discuss.elastic.co/t/fleet-server-is-offline/333419)

<div class="topic-metadata">

**Author:** [@samiujan](https://discuss.elastic.co/u/samiujan)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 8:04am UTC](https://discuss.elastic.co/t/fleet-server-is-offline/333419 "2023-05-15T08:04:19Z")

</div>

Hi I am trying to set up APM using Fleet on an on-prem EC2 instance After much back and forth, I got the agent installed and it's running on an unsecured endpoint I want to move it to a secure endpoint and have added …

---

## [Getting Could not find the data view error on kibana dashboard](https://discuss.elastic.co/t/getting-could-not-find-the-data-view-error-on-kibana-dashboard/332792)

<div class="topic-metadata">

**Author:** [@Sachchan](https://discuss.elastic.co/u/Sachchan)\
**Replies:** 26\
**Last updated:** [May 15, 2023, 7:59am UTC](https://discuss.elastic.co/t/getting-could-not-find-the-data-view-error-on-kibana-dashboard/332792 "2023-05-15T07:59:25Z")

</div>

Hi All, I am using kibana dashboards to visualize the data. but i am getting "Could not find the data view" error very frequently and when i refresh again, this error doesn't come. Please help in resolving this error. T…

---

## [While helm upgrade getting error elasticsearch 7.17.5](https://discuss.elastic.co/t/while-helm-upgrade-getting-error-elasticsearch-7-17-5/333417)

<div class="topic-metadata">

**Author:** [@shivaji\_laxmi](https://discuss.elastic.co/u/shivaji_laxmi)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 7:57am UTC](https://discuss.elastic.co/t/while-helm-upgrade-getting-error-elasticsearch-7-17-5/333417 "2023-05-15T07:57:56Z")

</div>

I upgraded the kubernetes cluster from 1.24 to 1.25. When I try to add additional node in elasticsearch cluster. I am getting following error. $ helm upgrade esdata . -f esdata\_prod.yml -n dea-elk --debug --dry-run up…

---

## [Logstash/Kibana : time field incorrect](https://discuss.elastic.co/t/logstash-kibana-time-field-incorrect/333303)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 7:51am UTC](https://discuss.elastic.co/t/logstash-kibana-time-field-incorrect/333303 "2023-05-15T07:51:30Z")

</div>

I've been stuck for 4 days on this problem. The logs that appear in Kibana have their field time changed (+2 hours) + the logs that appear in kibana are logs from two hours ago. It's currently 14h10, here is my last lo…

---

## [Autodetect\_column\_names is not working as expected in csv filter plugin](https://discuss.elastic.co/t/autodetect-column-names-is-not-working-as-expected-in-csv-filter-plugin/333269)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 6:39am UTC](https://discuss.elastic.co/t/autodetect-column-names-is-not-working-as-expected-in-csv-filter-plugin/333269 "2023-05-15T06:39:13Z")

</div>

Hi, I have this logstash .conf file: input { file { path =\> "/eee/\*.csv" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" } } filter { csv { autodetect\_column\_names =\> true } } And multi…

---

## [Data enrichment using logstash with translate plugin](https://discuss.elastic.co/t/data-enrichment-using-logstash-with-translate-plugin/333403)

<div class="topic-metadata">

**Author:** [@gpandey7](https://discuss.elastic.co/u/gpandey7)\
**Replies:** 0\
**Last updated:** [May 15, 2023, 6:37am UTC](https://discuss.elastic.co/t/data-enrichment-using-logstash-with-translate-plugin/333403 "2023-05-15T06:37:29Z")

</div>

I am trying to enrich the data before it gets indexed, I have tried the below methods but both are currently not working Using the elasticsearch plugin in filter input { kafka { bootstrap\_servers =\> "x…

---

## [What are alternatives for query string to implement slope between phrases?](https://discuss.elastic.co/t/what-are-alternatives-for-query-string-to-implement-slope-between-phrases/333158)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 11:36pm UTC](https://discuss.elastic.co/t/what-are-alternatives-for-query-string-to-implement-slope-between-phrases/333158 "2023-05-14T23:36:29Z")

</div>

What are alternatives for query string to implement slope between phrases?

---

## [About configuring the ELK Stack in centos7 server](https://discuss.elastic.co/t/about-configuring-the-elk-stack-in-centos7-server/333208)

<div class="topic-metadata">

**Author:** [@Anil\_Sai\_Pinnelli](https://discuss.elastic.co/u/Anil_Sai_Pinnelli)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 11:34pm UTC](https://discuss.elastic.co/t/about-configuring-the-elk-stack-in-centos7-server/333208 "2023-05-14T23:34:32Z")

</div>

We are trying to Install ELK Stack in Centos7 server in order to pull the MySql data from the same centos7 server. Could You pls give us in detail instructions how to configure the Elasticsearch, Kibana and Logstash and …

---

## [Virtuel Deshboard](https://discuss.elastic.co/t/virtuel-deshboard/333308)

<div class="topic-metadata">

**Author:** [@Ali\_Trache](https://discuss.elastic.co/u/Ali_Trache)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 1:20pm UTC](https://discuss.elastic.co/t/virtuel-deshboard/333308 "2023-05-12T13:20:03Z")

</div>

hello community, I installed and configured elastic then I configured logstach and I shouted an index afterwards I configured a VMware virtual machine to send and analyzed ESXI logs with Kibana how can I shout a virtual …

---

## [Uptime Monitors](https://discuss.elastic.co/t/uptime-monitors/333320)

<div class="topic-metadata">

**Author:** [@LeonardoCord](https://discuss.elastic.co/u/LeonardoCord)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 3:21pm UTC](https://discuss.elastic.co/t/uptime-monitors/333320 "2023-05-12T15:21:27Z")

</div>

Me esta arrojando este error. Error: Batch request failed with status 503 \</\> at search\_interceptor\_SearchInterceptor.handleSearchError (https://172.16.101.71:5601/59020/bundles/plugin/data/kibana/data.plugin.js:1:38…

---

## [SnakeYAML vulnerability with latest Logstash version](https://discuss.elastic.co/t/snakeyaml-vulnerability-with-latest-logstash-version/333332)

<div class="topic-metadata">

**Author:** [@Nikhil\_Khurana](https://discuss.elastic.co/u/Nikhil_Khurana)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 11:29pm UTC](https://discuss.elastic.co/t/snakeyaml-vulnerability-with-latest-logstash-version/333332 "2023-05-14T23:29:26Z")

</div>

Hi, In the latest version of Logstash, SnakeYAML dependency was bumped to 1.33 but it seems that is vulnerable as well. The vulnerability CVE-2022-1471 is a critical one with score of 9.8. Are there plans to bump it to…

---

## [How to increase output efficiency in logstash to elastic search?](https://discuss.elastic.co/t/how-to-increase-output-efficiency-in-logstash-to-elastic-search/333291)

<div class="topic-metadata">

**Author:** [@Arjav](https://discuss.elastic.co/u/Arjav)\
**Replies:** 3\
**Last updated:** [May 14, 2023, 6:51pm UTC](https://discuss.elastic.co/t/how-to-increase-output-efficiency-in-logstash-to-elastic-search/333291 "2023-05-14T18:51:07Z")

</div>

I have a logstash configuration that has input for postgres database table that has 14 lakh records and an output to elasticsearch database that in setup on ec2 machine c5 x large, when i see documents formation for that…

---

## [Getting An unknown error occurred sending a bulk request to Elasticsearch](https://discuss.elastic.co/t/getting-an-unknown-error-occurred-sending-a-bulk-request-to-elasticsearch/333378)

<div class="topic-metadata">

**Author:** [@Manjiri](https://discuss.elastic.co/u/Manjiri)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 5:33pm UTC](https://discuss.elastic.co/t/getting-an-unknown-error-occurred-sending-a-bulk-request-to-elasticsearch/333378 "2023-05-14T17:33:42Z")

</div>

After Starting the logstash the logs are fetching for 5 mins after that in logstash facing below error : An unknown error occurred sending a bulk request to Elasticsearch (will retry indefinitely) {:message=\> "incompati…

---

## [Prioritized a master node in ES cluster](https://discuss.elastic.co/t/prioritized-a-master-node-in-es-cluster/333350)

<div class="topic-metadata">

**Author:** [@ahmed.emad](https://discuss.elastic.co/u/ahmed.emad)\
**Replies:** 13\
**Last updated:** [May 14, 2023, 2:25pm UTC](https://discuss.elastic.co/t/prioritized-a-master-node-in-es-cluster/333350 "2023-05-14T14:25:22Z")

</div>

Hello, My ES Cluster contains 3 Master nodes (node-1, node-2, node-3), and nodes have a priority (99,98,97) in order so when node-1 goes down it elects node-2 as the new master node this is good till now, but when node-…

---

## [Best practice for data model of geo data - less objects with nested vs. more objects with duplication](https://discuss.elastic.co/t/best-practice-for-data-model-of-geo-data-less-objects-with-nested-vs-more-objects-with-duplication/333376)

<div class="topic-metadata">

**Author:** [@gmmorris](https://discuss.elastic.co/u/gmmorris)\
**Replies:** 0\
**Last updated:** [May 14, 2023, 11:48am UTC](https://discuss.elastic.co/t/best-practice-for-data-model-of-geo-data-less-objects-with-nested-vs-more-objects-with-duplication/333376 "2023-05-14T11:48:47Z")

</div>

Hello, my dear Elasticians, I miss you dearly. :wave: On my new adventure, I encountered a data modelling dilemma and thought I'd ask the experts what they think. We're ingesting large data sets of geospatial data and …

---

## [Logstash: Logevent when shutting down but not when starting up](https://discuss.elastic.co/t/logstash-logevent-when-shutting-down-but-not-when-starting-up/333146)

<div class="topic-metadata">

**Author:** [@bitnapper](https://discuss.elastic.co/u/bitnapper)\
**Replies:** 5\
**Last updated:** [May 14, 2023, 10:54am UTC](https://discuss.elastic.co/t/logstash-logevent-when-shutting-down-but-not-when-starting-up/333146 "2023-05-14T10:54:50Z")

</div>

Hi, simple question. Logstash produces a log-event when shutting down but not when starting up. Can I make it do that without activating the whol debug log? Regards

---

## [How to construct geo\_point field from separate fields of latitude and longitude from Kafka?](https://discuss.elastic.co/t/how-to-construct-geo-point-field-from-separate-fields-of-latitude-and-longitude-from-kafka/333370)

<div class="topic-metadata">

**Author:** [@Jagath\_Prasanga](https://discuss.elastic.co/u/Jagath_Prasanga)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 10:29am UTC](https://discuss.elastic.co/t/how-to-construct-geo-point-field-from-separate-fields-of-latitude-and-longitude-from-kafka/333370 "2023-05-14T10:29:17Z")

</div>

How to construct geo\_point field in logstash from Kafka input? This is my logstash config file. But Kibana not recognizing as a geo\_point field. input { kafka { bootstrap\_servers =\> "localhost:9095" top…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=378)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=380)
