# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=437

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 438

---

## [Logstash to Elastic Multiple Connections](https://discuss.elastic.co/t/logstash-to-elastic-multiple-connections/325382)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 3:01pm UTC](https://discuss.elastic.co/t/logstash-to-elastic-multiple-connections/325382 "2023-02-13T15:01:36Z")

</div>

Hello everyone, I was wandering if you can help in this particular matter: the actual situation is that we maintain a large Elastic Stack (15+ nodes) with an ingestion workflow composed by two Logstash server on VMs, wi…

---

## [Filter documents using aggregation in Discover](https://discuss.elastic.co/t/filter-documents-using-aggregation-in-discover/325401)

<div class="topic-metadata">

**Author:** [@Suresh\_Subramaniyan](https://discuss.elastic.co/u/Suresh_Subramaniyan)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 2:54pm UTC](https://discuss.elastic.co/t/filter-documents-using-aggregation-in-discover/325401 "2023-02-13T14:54:59Z")

</div>

Need to filter the documents based on aggregated results in kibana discover . { "aggs": { "match\_id": { "terms": { "field": "MATCH\_ID", "size": 10000 }, "aggs": { "count\_i…

---

## [Scroll vs search after](https://discuss.elastic.co/t/scroll-vs-search-after/325396)

<div class="topic-metadata">

**Author:** [@Prabu\_P](https://discuss.elastic.co/u/Prabu_P)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 2:40pm UTC](https://discuss.elastic.co/t/scroll-vs-search-after/325396 "2023-02-13T14:40:27Z")

</div>

in this thread it discussed about the performance issue of search after , is this issue still present in newer versions of ES ?

---

## [Logstash JMS Input version 3.1.2](https://discuss.elastic.co/t/logstash-jms-input-version-3-1-2/325355)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 2:11pm UTC](https://discuss.elastic.co/t/logstash-jms-input-version-3-1-2/325355 "2023-02-13T14:11:38Z")

</div>

Hello, I want to know what JMS version is compatible with Logstash JMS Input version 3.1.2 and can you share with me some references? Thank you,

---

## [How to find a term (title: req.query\['q\]) with geo\_distance with elasticsearch 8.6](https://discuss.elastic.co/t/how-to-find-a-term-title-req-query-q-with-geo-distance-with-elasticsearch-8-6/325330)

<div class="topic-metadata">

**Author:** [@teoman\_kirac](https://discuss.elastic.co/u/teoman_kirac)\
**Replies:** 20\
**Last updated:** [February 13, 2023, 1:48pm UTC](https://discuss.elastic.co/t/how-to-find-a-term-title-req-query-q-with-geo-distance-with-elasticsearch-8-6/325330 "2023-02-13T13:48:39Z")

</div>

Years ago I had this working with elasticsearch 16.x.x. It looked like this: let body = { size: 200, from: 0, query: { bool: { must: { term: { title : req.query\['q'\] } }, …

---

## ["Rejected execution of coordinating operation" exception after upgrade from 8.2.2 to 8.6.0?](https://discuss.elastic.co/t/rejected-execution-of-coordinating-operation-exception-after-upgrade-from-8-2-2-to-8-6-0/323430)

<div class="topic-metadata">

**Author:** [@mbooh](https://discuss.elastic.co/u/mbooh)\
**Replies:** 7\
**Last updated:** [February 13, 2023, 1:11pm UTC](https://discuss.elastic.co/t/rejected-execution-of-coordinating-operation-exception-after-upgrade-from-8-2-2-to-8-6-0/323430 "2023-02-13T13:11:15Z")

</div>

Hi! We just upgraded from 8.2.2 to 8.6.0 and suddenly our bulk inserts fails with this exception: es\_rejected\_execution\_exception Reason: "rejected execution of coordinating operation \[coordinating\_and\_primary\_bytes=20…

---

## [\[ES 6.7\] Multiple field terms aggregation using scripts](https://discuss.elastic.co/t/es-6-7-multiple-field-terms-aggregation-using-scripts/325383)

<div class="topic-metadata">

**Author:** [@Hi\_Jonk](https://discuss.elastic.co/u/Hi_Jonk)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 12:44pm UTC](https://discuss.elastic.co/t/es-6-7-multiple-field-terms-aggregation-using-scripts/325383 "2023-02-13T12:44:46Z")

</div>

In the 6.7 documentation for Terms aggregation, the section on multi field aggregation says that 6.7 does not support multiple field aggregation, and to use scripts instead: Terms Aggregation | Elasticsearch Guide \[6.7\] …

---

## [If the file is deleted, delete from the ElasticSearch index](https://discuss.elastic.co/t/if-the-file-is-deleted-delete-from-the-elasticsearch-index/325314)

<div class="topic-metadata">

**Author:** [@SplendX](https://discuss.elastic.co/u/SplendX)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 11:43am UTC](https://discuss.elastic.co/t/if-the-file-is-deleted-delete-from-the-elasticsearch-index/325314 "2023-02-13T11:43:52Z")

</div>

I'm trying to make a piece of code that will be responsible for deleting an indexed file from the elasticsearch index, I pass with the indexed file md5(file name), to the id value. It is necessary to make sure that when …

---

## [Error 503 filebeat can not connect to elasticsearch](https://discuss.elastic.co/t/error-503-filebeat-can-not-connect-to-elasticsearch/325375)

<div class="topic-metadata">

**Author:** [@jomaguca](https://discuss.elastic.co/u/jomaguca)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 10:56am UTC](https://discuss.elastic.co/t/error-503-filebeat-can-not-connect-to-elasticsearch/325375 "2023-02-13T10:56:18Z")

</div>

Hi everyone I have up my ELK server working, and I put a filebeat in another machine with filebeat installed but filebeat can not send inputs to elasticsearch, the error says "Exiting: couldn't connect to any of the con…

---

## [Change @Timestamp to date from API response](https://discuss.elastic.co/t/change-timestamp-to-date-from-api-response/325369)

<div class="topic-metadata">

**Author:** [@Renat](https://discuss.elastic.co/u/Renat)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 9:46am UTC](https://discuss.elastic.co/t/change-timestamp-to-date-from-api-response/325369 "2023-02-13T09:46:14Z")

</div>

Hello everyone, first of all i'm sorry if this common issue, but i really tried to solve it by myself. but searching in web didn't help me, may be because i never used Logstash. So i got request to receive "slowQuer…

---

## [Display live image data (base64 jpeg) in Kibana](https://discuss.elastic.co/t/display-live-image-data-base64-jpeg-in-kibana/324871)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 21\
**Last updated:** [February 13, 2023, 8:42am UTC](https://discuss.elastic.co/t/display-live-image-data-base64-jpeg-in-kibana/324871 "2023-02-13T08:42:59Z")

</div>

I have Base64 encoded jpeg image data stored in ES which I want to display in a dashboard. I'm able to to that with a static image from a specific path using the markdown visualization. But how can I do that with data …

---

## [Elastic Agent capability over logstash](https://discuss.elastic.co/t/elastic-agent-capability-over-logstash/325364)

<div class="topic-metadata">

**Author:** [@ranju](https://discuss.elastic.co/u/ranju)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 7:59am UTC](https://discuss.elastic.co/t/elastic-agent-capability-over-logstash/325364 "2023-02-13T07:59:31Z")

</div>

Hi Team Currently, we are using Logstash to process our logs from Kafka and filebeat sources. We Observed some capability of the beat agent to send the logs to the Elasticsearch directly. In Logstash we are mainly foc…

---

## [Help! workpad on website not showing fullwidth](https://discuss.elastic.co/t/help-workpad-on-website-not-showing-fullwidth/323590)

<div class="topic-metadata">

**Author:** [@rens](https://discuss.elastic.co/u/rens)\
**Replies:** 2\
**Last updated:** [February 13, 2023, 7:44am UTC](https://discuss.elastic.co/t/help-workpad-on-website-not-showing-fullwidth/323590 "2023-02-13T07:44:18Z")

</div>

Hi, I am new to this forum and to elastic. And I have a question. If I share a canvas workpad in static website I cannot get it to show fullwidth. On different monitors the result is either overflowing or to small. I …

---

## [Elasticsearch + Java - Can you further optimize this query?](https://discuss.elastic.co/t/elasticsearch-java-can-you-further-optimize-this-query/325357)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 7:15am UTC](https://discuss.elastic.co/t/elasticsearch-java-can-you-further-optimize-this-query/325357 "2023-02-13T07:15:28Z")

</div>

We have an elasticsearch that contains millions of records and we are using it for a global searching. However, our query takes 2-4 seconds to return result. Can somebody help or advice how to further optimize the follow…

---

## [Custom values are not reflected during ECK helm chart install](https://discuss.elastic.co/t/custom-values-are-not-reflected-during-eck-helm-chart-install/325341)

<div class="topic-metadata">

**Author:** [@techavidity](https://discuss.elastic.co/u/techavidity)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 3:46am UTC](https://discuss.elastic.co/t/custom-values-are-not-reflected-during-eck-helm-chart-install/325341 "2023-02-13T03:46:05Z")

</div>

I am trying to setup multi node Elasticsearch cluster, whatever the value i am passing in it's not getting reflected. This will loop finally and throws errors about PV or storageclass is not set. Steps followed: Creat…

---

## [Adding traces-apm.rum@custom pipeline breaks RUM traces](https://discuss.elastic.co/t/adding-traces-apm-rum-custom-pipeline-breaks-rum-traces/325201)

<div class="topic-metadata">

**Author:** [@jrhut](https://discuss.elastic.co/u/jrhut)\
**Replies:** 8\
**Last updated:** [February 13, 2023, 2:21am UTC](https://discuss.elastic.co/t/adding-traces-apm-rum-custom-pipeline-breaks-rum-traces/325201 "2023-02-13T02:21:25Z")

</div>

Hi there, RUM traces work fine in the UI until I create a traces-apm.rum@custom pipeline with a pipeline processor. The presence of the pipeline processor breaks RUM transaction traces creating a perpetual loading anima…

---

## [How to filter by the nested values in the "message" field?](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277)

<div class="topic-metadata">

**Author:** [@Shiva\_Subramaniyan](https://discuss.elastic.co/u/Shiva_Subramaniyan)\
**Replies:** 6\
**Last updated:** [February 12, 2023, 7:57pm UTC](https://discuss.elastic.co/t/how-to-filter-by-the-nested-values-in-the-message-field/325277 "2023-02-12T19:57:11Z")

</div>

Hi, I have a "message" field in my "filebeat\*" index. This "message" field, particularly has nested fields like "httpRequest" and a "country" field in it. The value of this "country" field is 'US' I want to use a quer…

---

## [Error code 429,Too Many Requests](https://discuss.elastic.co/t/error-code-429-too-many-requests/325332)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [February 12, 2023, 4:37pm UTC](https://discuss.elastic.co/t/error-code-429-too-many-requests/325332 "2023-02-12T16:37:31Z")

</div>

Hi, What does error code 429,Too Many Requests actually means? Is the coordinator is fully loaded or the cluster is fully loaded? Thanks...

---

## [Failed to parse date field](https://discuss.elastic.co/t/failed-to-parse-date-field/325324)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 5\
**Last updated:** [February 12, 2023, 3:31am UTC](https://discuss.elastic.co/t/failed-to-parse-date-field/325324 "2023-02-12T03:31:45Z")

</div>

I currently have a problem with an error message that is appearing that refers to a date field but is not detecting it as such. \[2023-02-11T15:16:39,111\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Could not index even…

---

## [Kafka input - resync missing items from topic](https://discuss.elastic.co/t/kafka-input-resync-missing-items-from-topic/325294)

<div class="topic-metadata">

**Author:** [@Chris\_Denneen](https://discuss.elastic.co/u/Chris_Denneen)\
**Replies:** 7\
**Last updated:** [February 12, 2023, 2:04am UTC](https://discuss.elastic.co/t/kafka-input-resync-missing-items-from-topic/325294 "2023-02-12T02:04:14Z")

</div>

Ran into issue where we have logstash input reading kafka topics for log events. Last night the ES index rolled over and the write alias was lost (not on the new index... so nothing with is\_write\_index = true) therefore…

---

## [Elasticsearch throwing invalid attributes in log](https://discuss.elastic.co/t/elasticsearch-throwing-invalid-attributes-in-log/323355)

<div class="topic-metadata">

**Author:** [@Ramesh\_Perumal](https://discuss.elastic.co/u/Ramesh_Perumal)\
**Replies:** 1\
**Last updated:** [February 12, 2023, 1:55am UTC](https://discuss.elastic.co/t/elasticsearch-throwing-invalid-attributes-in-log/323355 "2023-02-12T01:55:50Z")

</div>

Hi, Elasticsearch log is been written as below: 2023-01-16 19:02:31,790 main ERROR Filters contains invalid attributes "onMatch", "onMismatch" In our log4j2.properties, we have included onMatch and onMismatch, what is…

---

## [Import objects from v8.x to v7.x](https://discuss.elastic.co/t/import-objects-from-v8-x-to-v7-x/323801)

<div class="topic-metadata">

**Author:** [@wedkarz014](https://discuss.elastic.co/u/wedkarz014)\
**Replies:** 1\
**Last updated:** [February 12, 2023, 1:35am UTC](https://discuss.elastic.co/t/import-objects-from-v8-x-to-v7-x/323801 "2023-02-12T01:35:53Z")

</div>

Hi, is it possible to import to kibana v7.16.2 dashboards which were created in kibana version 8.2.3? when i try to import objects i have an error: Best

---

## [Cache mechanism and log when transfer fails](https://discuss.elastic.co/t/cache-mechanism-and-log-when-transfer-fails/325230)

<div class="topic-metadata">

**Author:** [@YasuhiroOkumura](https://discuss.elastic.co/u/YasuhiroOkumura)\
**Replies:** 1\
**Last updated:** [February 12, 2023, 1:26am UTC](https://discuss.elastic.co/t/cache-mechanism-and-log-when-transfer-fails/325230 "2023-02-12T01:26:05Z")

</div>

1.When transferring messages from logstash(8.6) to pagerduty using pagerduty output plugin, if the transfer fails, is it possible to cache and resend? 2.When using the pagerduty output plugin to transfer messages from l…

---

## [Help. My filebeat stops working after I installed my wazuh server after 30 minutes](https://discuss.elastic.co/t/help-my-filebeat-stops-working-after-i-installed-my-wazuh-server-after-30-minutes/324536)

<div class="topic-metadata">

**Author:** [@Joshua\_John\_Consulta](https://discuss.elastic.co/u/Joshua_John_Consulta)\
**Replies:** 1\
**Last updated:** [February 12, 2023, 1:20am UTC](https://discuss.elastic.co/t/help-my-filebeat-stops-working-after-i-installed-my-wazuh-server-after-30-minutes/324536 "2023-02-12T01:20:01Z")

</div>

Here's the error: × filebeat.service - Filebeat sends log files to Logstash or directly to Elasti\> Loaded: loaded (/lib/systemd/system/filebeat.service; enabled; preset: ena\> Active: failed (Result: exit-code) since T…

---

## [Logstash heartbeat input error](https://discuss.elastic.co/t/logstash-heartbeat-input-error/325315)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 2\
**Last updated:** [February 11, 2023, 8:34pm UTC](https://discuss.elastic.co/t/logstash-heartbeat-input-error/325315 "2023-02-11T20:34:40Z")

</div>

Hello All, I am using heartbeat input to perform a specific job periodically. However, on my local windows machine, I occasionally keep getting this error message \[2023-02-09T02:35:37,209\]\[ERROR\]\[logstash.javapipeline…

---

## [Wildcard matches are not highlighted in complex query containing field\_masking\_span](https://discuss.elastic.co/t/wildcard-matches-are-not-highlighted-in-complex-query-containing-field-masking-span/325301)

<div class="topic-metadata">

**Author:** [@claudinoac](https://discuss.elastic.co/u/claudinoac)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 9:42pm UTC](https://discuss.elastic.co/t/wildcard-matches-are-not-highlighted-in-complex-query-containing-field-masking-span/325301 "2023-02-10T21:42:05Z")

</div>

I'm applying the unified highlighter to the query below and the matched terms are being correctly highlighted, except by the ones matched by the wildcard term. That happens only when there is a field\_masking\_span term i…

---

## [Failed to determine the health of the cluster](https://discuss.elastic.co/t/failed-to-determine-the-health-of-the-cluster/325290)

<div class="topic-metadata">

**Author:** [@goodeejay](https://discuss.elastic.co/u/goodeejay)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 8:56pm UTC](https://discuss.elastic.co/t/failed-to-determine-the-health-of-the-cluster/325290 "2023-02-10T20:56:57Z")

</div>

Hello, I've been trying to generate enrollment token for kibana with: sudo /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s "kibana" But I'm getting an error, the last line says: ERROR: Failed to …

---

## [Error split was expecting field to be an array](https://discuss.elastic.co/t/error-split-was-expecting-field-to-be-an-array/325285)

<div class="topic-metadata">

**Author:** [@fabien9402](https://discuss.elastic.co/u/fabien9402)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 5:09pm UTC](https://discuss.elastic.co/t/error-split-was-expecting-field-to-be-an-array/325285 "2023-02-10T17:09:45Z")

</div>

Hello, We have an error in one of our elastic-agent. This returns the error below: Feb 7, 2023 15:01:20.773 elastic\_agent.filebeat \[elastic\_agent.filebeat\]\[error\] error processing response: split was expecting field t…

---

## [Curl'ing Kibana Dashboards exported into NDJSON](https://discuss.elastic.co/t/curling-kibana-dashboards-exported-into-ndjson/325012)

<div class="topic-metadata">

**Author:** [@plissken](https://discuss.elastic.co/u/plissken)\
**Replies:** 8\
**Last updated:** [February 10, 2023, 4:55pm UTC](https://discuss.elastic.co/t/curling-kibana-dashboards-exported-into-ndjson/325012 "2023-02-10T16:55:49Z")

</div>

I'm having considerable difficulty in understanding the documentation on the Kibana API's. There's so much out of date information on the web that I could literally spend months doing syntax jenga. I have a set of dash…

---

## [Why I am getting two fields (label & metrics) for Prometheus data in Elasticsearch](https://discuss.elastic.co/t/why-i-am-getting-two-fields-label-metrics-for-prometheus-data-in-elasticsearch/325280)

<div class="topic-metadata">

**Author:** [@Maruthappan\_Muthu](https://discuss.elastic.co/u/Maruthappan_Muthu)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 3:41pm UTC](https://discuss.elastic.co/t/why-i-am-getting-two-fields-label-metrics-for-prometheus-data-in-elasticsearch/325280 "2023-02-10T15:41:00Z")

</div>

I am sending the Prometheus scraped data to Elasticsearch through Metricbeat on 'remote write' option. However I am getting two fields as prometheus.labels.\* and prometheus.metrics.\* for every different fields. Is my con…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=436)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=438)
