# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=601

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 602

---

## [FATAL Error: Unable to complete saved object migrations for the \[.kibana-7.17.1-ssl\] index: Unable to complete the UPDATE\_TARGET\_MAPPINGS\_WAIT\_FOR\_TASK step after 15 attempts, terminating](https://discuss.elastic.co/t/fatal-error-unable-to-complete-saved-object-migrations-for-the-kibana-7-17-1-ssl-index-unable-to-complete-the-update-target-mappings-wait-for-task-step-after-15-attempts-terminating/308076)

<div class="topic-metadata">

**Author:** [@nghia\_huynh](https://discuss.elastic.co/u/nghia_huynh)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 5:24am UTC](https://discuss.elastic.co/t/fatal-error-unable-to-complete-saved-object-migrations-for-the-kibana-7-17-1-ssl-index-unable-to-complete-the-update-target-mappings-wait-for-task-step-after-15-attempts-terminating/308076 "2022-06-24T05:24:31Z")

</div>

Dear Team, I have an issue relative to restarting Kibana. Every time I have this issue, I have to delete the .kibana\* index and start again, but I don't want to delete the .kibana\* index because of data loss. Also, I d…

---

## [Fixed interval in date histogram error](https://discuss.elastic.co/t/fixed-interval-in-date-histogram-error/308071)

<div class="topic-metadata">

**Author:** [@yeylatte](https://discuss.elastic.co/u/yeylatte)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 3:21am UTC](https://discuss.elastic.co/t/fixed-interval-in-date-histogram-error/308071 "2022-06-24T03:21:51Z")

</div>

Elasticsearch Version 7.17.4 Java Version 1.8.0 OS Version Linux Problem Description I use date\_histogram aggregation from Elasticsearch with fixed\_interval of 7d in time range from 2022-06-18 to 2022-07-01(14days…

---

## [Slow speed of ANN dense vector search using \_knn\_search](https://discuss.elastic.co/t/slow-speed-of-ann-dense-vector-search-using-knn-search/307448)

<div class="topic-metadata">

**Author:** [@jalustig](https://discuss.elastic.co/u/jalustig)\
**Replies:** 7\
**Last updated:** [June 24, 2022, 2:40am UTC](https://discuss.elastic.co/t/slow-speed-of-ann-dense-vector-search-using-knn-search/307448 "2022-06-24T02:40:03Z")

</div>

I'm building out a vector search application with 384 dimensional vectors. So far I have about 3 million documents in my Elasticsearch database using with a dense\_vector field. There are currently 8 shards (I am expectin…

---

## [Installing ece 2.13 1](https://discuss.elastic.co/t/installing-ece-2-13-1/308010)

<div class="topic-metadata">

**Author:** [@lcarr](https://discuss.elastic.co/u/lcarr)\
**Replies:** 3\
**Last updated:** [June 24, 2022, 1:58am UTC](https://discuss.elastic.co/t/installing-ece-2-13-1/308010 "2022-06-24T01:58:44Z")

</div>

Need to determine the required version of the srack for the standards deployments. Logging and Metrics etc

---

## [How to ship logs from filebeat to elasticsearch](https://discuss.elastic.co/t/how-to-ship-logs-from-filebeat-to-elasticsearch/308039)

<div class="topic-metadata">

**Author:** [@gisellecarballo](https://discuss.elastic.co/u/gisellecarballo)\
**Replies:** 2\
**Last updated:** [June 24, 2022, 12:10am UTC](https://discuss.elastic.co/t/how-to-ship-logs-from-filebeat-to-elasticsearch/308039 "2022-06-24T00:10:26Z")

</div>

Hi Everyone, I am trying to form a setup where my cisco devices syslog to be sent to filebeat and then filebeat will send it to elasticsearch so that it can be viewed on kibana. Problem: Filebeat error is The requested…

---

## [Struggling to replace a string in a syslog message with sub](https://discuss.elastic.co/t/struggling-to-replace-a-string-in-a-syslog-message-with-sub/307809)

<div class="topic-metadata">

**Author:** [@ddaloia](https://discuss.elastic.co/u/ddaloia)\
**Replies:** 4\
**Last updated:** [June 23, 2022, 10:36pm UTC](https://discuss.elastic.co/t/struggling-to-replace-a-string-in-a-syslog-message-with-sub/307809 "2022-06-23T22:36:45Z")

</div>

Hi Friends. I am taking in cef syslog messages from an application called Secret Server. The messages are not parsing correctly because some of the fields usernames have a slash in the username. The format is domain\\user…

---

## [How to find events that match for every string expression on Kibana?](https://discuss.elastic.co/t/how-to-find-events-that-match-for-every-string-expression-on-kibana/307543)

<div class="topic-metadata">

**Author:** [@gabrsar](https://discuss.elastic.co/u/gabrsar)\
**Replies:** 2\
**Last updated:** [June 23, 2022, 9:26pm UTC](https://discuss.elastic.co/t/how-to-find-events-that-match-for-every-string-expression-on-kibana/307543 "2022-06-23T21:26:05Z")

</div>

Hi. In Kibana -\> Discovery. How can I make a search for all logs that contain all the phrases I want, in or out of order? For example, Logs that contain "Operation complete", "total amount" and "success", without logs …

---

## [Elasticsearch index settings locked due to unsupported setting](https://discuss.elastic.co/t/elasticsearch-index-settings-locked-due-to-unsupported-setting/308053)

<div class="topic-metadata">

**Author:** [@bren\_x](https://discuss.elastic.co/u/bren_x)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 7:19pm UTC](https://discuss.elastic.co/t/elasticsearch-index-settings-locked-due-to-unsupported-setting/308053 "2022-06-23T19:19:33Z")

</div>

Hi, We are trying to upgrade our elasticsearch cluster from version 6.1 to version 6.8. While upgrading, we noticed that the index settings seem to be locked. Any command to change any index setting results in: { "er…

---

## [How can I create new field inside an array of obejcts?](https://discuss.elastic.co/t/how-can-i-create-new-field-inside-an-array-of-obejcts/308036)

<div class="topic-metadata">

**Author:** [@jvinacio](https://discuss.elastic.co/u/jvinacio)\
**Replies:** 2\
**Last updated:** [June 23, 2022, 5:42pm UTC](https://discuss.elastic.co/t/how-can-i-create-new-field-inside-an-array-of-obejcts/308036 "2022-06-23T17:42:28Z")

</div>

Hello! I have the following array: { "tempoTotalDayEvents" : \[ { "tempo7" : 25.0 }, { "tempo8" : 0.0 }, { "tempo11" : 0.0 }, { "tempo12" : 6.0 }, { "tempo13" : 0.0 }, { "tempo14" : 3.0 }, { "tempo1…

---

## [Cannot view single document however index exists](https://discuss.elastic.co/t/cannot-view-single-document-however-index-exists/308043)

<div class="topic-metadata">

**Author:** [@GloomOff](https://discuss.elastic.co/u/GloomOff)\
**Replies:** 2\
**Last updated:** [June 23, 2022, 4:49pm UTC](https://discuss.elastic.co/t/cannot-view-single-document-however-index-exists/308043 "2022-06-23T16:49:42Z")

</div>

Hello. I receive nginx logs from filebeat. Search works well. But in kibana in the expanded view, click View single document I get error: Cannot run search filebeat-7.9.2-2022.06.23-001859 is missing. \[Please ensure …

---

## [What is "Query Length"?](https://discuss.elastic.co/t/what-is-query-length/307835)

<div class="topic-metadata">

**Author:** [@minzeycat](https://discuss.elastic.co/u/minzeycat)\
**Replies:** 9\
**Last updated:** [June 23, 2022, 4:18pm UTC](https://discuss.elastic.co/t/what-is-query-length/307835 "2022-06-23T16:18:22Z")

</div>

Hi all, I'm wondering what query length is referring to in this limit guide (it is set to 128)? Limits | Elastic App Search Documentation \[8.2\] | Elastic I am having a hard time understanding what part of the query is l…

---

## [Elastic Stack Architecture and Requirements](https://discuss.elastic.co/t/elastic-stack-architecture-and-requirements/307930)

<div class="topic-metadata">

**Author:** [@Analyst](https://discuss.elastic.co/u/Analyst)\
**Replies:** 2\
**Last updated:** [June 23, 2022, 3:34pm UTC](https://discuss.elastic.co/t/elastic-stack-architecture-and-requirements/307930 "2022-06-23T15:34:23Z")

</div>

Hi Guys, I need to create an ELK architecture but I don't know how many servers and requirements (CPU, RAM,Disk space) I will need for large organization deployment. I will need to send syslog and logfiles from 7000 se…

---

## [Codec in gelf input plugin not working](https://discuss.elastic.co/t/codec-in-gelf-input-plugin-not-working/308017)

<div class="topic-metadata">

**Author:** [@smtp\_server](https://discuss.elastic.co/u/smtp_server)\
**Replies:** 5\
**Last updated:** [June 23, 2022, 3:37pm UTC](https://discuss.elastic.co/t/codec-in-gelf-input-plugin-not-working/308017 "2022-06-23T15:37:03Z")

</div>

I'm trying to use codec for logs coming from gelf driver of another container to aggregate multiline logs but they are turning into events for each line in message, So multiline is not working at all. input{ gelf{ …

---

## [Logstash http\_poller input body](https://discuss.elastic.co/t/logstash-http-poller-input-body/308034)

<div class="topic-metadata">

**Author:** [@mfrg85](https://discuss.elastic.co/u/mfrg85)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 3:15pm UTC](https://discuss.elastic.co/t/logstash-http-poller-input-body/308034 "2022-06-23T15:15:15Z")

</div>

I'm trying to POST to an external API that requires authorization headers and a query. Here is the configuration that I have so far and the error that I am receiving. I'm not sure if the body portion of the config is for…

---

## [How to Improve ELK Performance](https://discuss.elastic.co/t/how-to-improve-elk-performance/307092)

<div class="topic-metadata">

**Author:** [@truptir](https://discuss.elastic.co/u/truptir)\
**Replies:** 8\
**Last updated:** [June 23, 2022, 3:07pm UTC](https://discuss.elastic.co/t/how-to-improve-elk-performance/307092 "2022-06-23T15:07:44Z")

</div>

Hi Team, My flow is, JSON Logs files will be processed from FileBeat \> Logstash \> Elasticsearch. But it skips some data. In thread\_pool It shows below many rejected write requests. node-1 write 0 0 0 …

---

## [Missing documents during bulk insert](https://discuss.elastic.co/t/missing-documents-during-bulk-insert/307802)

<div class="topic-metadata">

**Author:** [@EsraKahraman](https://discuss.elastic.co/u/EsraKahraman)\
**Replies:** 4\
**Last updated:** [June 23, 2022, 2:02pm UTC](https://discuss.elastic.co/t/missing-documents-during-bulk-insert/307802 "2022-06-23T14:02:29Z")

</div>

Hi there, I am using bulk API to load data in Elasticsearch. I need to load millions of documents to an elastic index; my ETL job breaks the whole set down to 10K record chunks. And then, it splits each chunk into the JS…

---

## [Deprecation.logstash.codecs.plain](https://discuss.elastic.co/t/deprecation-logstash-codecs-plain/308005)

<div class="topic-metadata">

**Author:** [@Stevenpoot](https://discuss.elastic.co/u/Stevenpoot)\
**Replies:** 1\
**Last updated:** [June 23, 2022, 1:59pm UTC](https://discuss.elastic.co/t/deprecation-logstash-codecs-plain/308005 "2022-06-23T13:59:23Z")

</div>

How do I solve this. Logstash is working but the message is repeating all the time \[deprecation.logstash.codecs.plain\] Relying on default value of pipeline.ecs\_compatibility, which may change in a future maj or release …

---

## [NOT Queries documents returning no highlight fragment](https://discuss.elastic.co/t/not-queries-documents-returning-no-highlight-fragment/308016)

<div class="topic-metadata">

**Author:** [@jcmiron](https://discuss.elastic.co/u/jcmiron)\
**Replies:** 4\
**Last updated:** [June 23, 2022, 1:46pm UTC](https://discuss.elastic.co/t/not-queries-documents-returning-no-highlight-fragment/308016 "2022-06-23T13:46:58Z")

</div>

If I do a query like "NOT (CANADA)" or something like that it'll return the documents that don't include that word in it, but not return any highlight fragment. Is this the default behavior for a query like that?

---

## [Logstash parse multiline logging](https://discuss.elastic.co/t/logstash-parse-multiline-logging/307995)

<div class="topic-metadata">

**Author:** [@Ceesz](https://discuss.elastic.co/u/Ceesz)\
**Replies:** 1\
**Last updated:** [June 23, 2022, 12:36pm UTC](https://discuss.elastic.co/t/logstash-parse-multiline-logging/307995 "2022-06-23T12:36:43Z")

</div>

Hi all, I am trying to parse the following log file with multi-log lines: Benutzerkennung: test1 Uhrzeit: 20:53:54 14.05.2022 Version: Microsoft Dynamics AX 6.2 (Erstellungsnummer 3000.5768) Datenbank: Microsoft SQL Se…

---

## [Multiple Entity Type Indexing and Search](https://discuss.elastic.co/t/multiple-entity-type-indexing-and-search/306718)

<div class="topic-metadata">

**Author:** [@Gerardo\_Zenobi](https://discuss.elastic.co/u/Gerardo_Zenobi)\
**Replies:** 4\
**Last updated:** [June 23, 2022, 12:35pm UTC](https://discuss.elastic.co/t/multiple-entity-type-indexing-and-search/306718 "2022-06-23T12:35:04Z")

</div>

Hi there :wave: Let's say I have an application where I need to index multiple different types of entities: users, courses, programs, etc. Each of these entities will have a specific schema of their own, and different s…

---

## [Received an event that has a different character encoding from DLP software](https://discuss.elastic.co/t/received-an-event-that-has-a-different-character-encoding-from-dlp-software/308004)

<div class="topic-metadata">

**Author:** [@Stevenpoot](https://discuss.elastic.co/u/Stevenpoot)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 12:11pm UTC](https://discuss.elastic.co/t/received-an-event-that-has-a-different-character-encoding-from-dlp-software/308004 "2022-06-23T12:11:08Z")

</div>

{:text=\>"\\u0000\\x FF\\u0001\\u0000\\u0000$\\u0000\\r\\u0000 \\u0000\\u001E\\u0006\\u0001\\u0006\\ u0002\\u0006\\u0003\\u0005\\u0001\\u0005\\u0002\\u0005\\u0003\\u0004\\u0001\\u0 004\\u0002\\u0004\\u0003\\u0003\\u0001\\u0003\\u0002\\u0003\\u0003\\u0002\\u…

---

## [Complex Proximity/Nested/exact-match Queries in Elasticsearch](https://discuss.elastic.co/t/complex-proximity-nested-exact-match-queries-in-elasticsearch/307998)

<div class="topic-metadata">

**Author:** [@jaivikram](https://discuss.elastic.co/u/jaivikram)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 11:33am UTC](https://discuss.elastic.co/t/complex-proximity-nested-exact-match-queries-in-elasticsearch/307998 "2022-06-23T11:33:34Z")

</div>

I am looking for proximity (and nested proximity as well) between multiple hetrogeneous groups By hetrogeneous I mean the token in the groups can be: term and term term and phrase phrase and phrase term and wildcard p…

---

## [Collapse, Term Aggregation, Grouping](https://discuss.elastic.co/t/collapse-term-aggregation-grouping/307993)

<div class="topic-metadata">

**Author:** [@dev\_test](https://discuss.elastic.co/u/dev_test)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 11:01am UTC](https://discuss.elastic.co/t/collapse-term-aggregation-grouping/307993 "2022-06-23T11:01:33Z")

</div>

Hi there, I am using elasticsearch 7.17 and trying to group result on some field Here is the query which i am trying to run GET content-data/\_search { "\_source": false, "query": { "bool": { "should": \[ …

---

## [Elasticsearch not starting](https://discuss.elastic.co/t/elasticsearch-not-starting/307984)

<div class="topic-metadata">

**Author:** [@Ram3](https://discuss.elastic.co/u/Ram3)\
**Replies:** 2\
**Last updated:** [June 23, 2022, 10:59am UTC](https://discuss.elastic.co/t/elasticsearch-not-starting/307984 "2022-06-23T10:59:02Z")

</div>

Hello Everyone so I am very new to elasticsearch and I don't know How it work I had installed it and was working but suddenly today the clients told me that it is not working. I have made sure all the ownership is good …

---

## [Elasticsearch and NestJs multi cluster](https://discuss.elastic.co/t/elasticsearch-and-nestjs-multi-cluster/307989)

<div class="topic-metadata">

**Author:** [@meyer1](https://discuss.elastic.co/u/meyer1)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 10:23am UTC](https://discuss.elastic.co/t/elasticsearch-and-nestjs-multi-cluster/307989 "2022-06-23T10:23:41Z")

</div>

Hello everyone, I have a small problem I want to produce an elasticsearch via an app NestJs. I have 3 hosts but I don't know how to configure my "search.module" "search.providers" and "search.service". Should I do someth…

---

## [Nodes getting removed often from the cluster](https://discuss.elastic.co/t/nodes-getting-removed-often-from-the-cluster/307956)

<div class="topic-metadata">

**Author:** [@Giuliano\_Drago](https://discuss.elastic.co/u/Giuliano_Drago)\
**Replies:** 4\
**Last updated:** [June 23, 2022, 9:39am UTC](https://discuss.elastic.co/t/nodes-getting-removed-often-from-the-cluster/307956 "2022-06-23T09:39:13Z")

</div>

hello, I have a couple of clusters running: es 6.8.21 es 5.6.16 the machines are Ubuntu VMs and are continuously showing these error in the logs: \[2022-06-23T09:08:46,082\]\[INFO \]\[o.e.c.s.ClusterApplierService\] \[serve…

---

## [Rally 2.5.0](https://discuss.elastic.co/t/rally-2-5-0/307970)

<div class="topic-metadata">

**Author:** [@Quentin\_Pradet](https://discuss.elastic.co/u/Quentin_Pradet)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 9:05am UTC](https://discuss.elastic.co/t/rally-2-5-0/307970 "2022-06-23T09:05:42Z")

</div>

We have just released Rally 2.5.0. Highlights: We introduced the field-caps operation type We fully support the ZGC garbage collector We fixed an issue for Python 3.10 with use\_ssl: True that many users were hitting F…

---

## [Bug? "Could not communicate with the node... from the enrollment token."](https://discuss.elastic.co/t/bug-could-not-communicate-with-the-node-from-the-enrollment-token/306189)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 7\
**Last updated:** [June 23, 2022, 8:57am UTC](https://discuss.elastic.co/t/bug-could-not-communicate-with-the-node-from-the-enrollment-token/306189 "2022-06-23T08:57:01Z")

</div>

Hi there, I am making my first steps in Elasticsearch 8.x coming from 7.x. On 2 local virtual box nodes I would like to test / to understand the procedure of how I can let join a second Elasticsearch node to an already…

---

## [Aggregate on field value](https://discuss.elastic.co/t/aggregate-on-field-value/307968)

<div class="topic-metadata">

**Author:** [@zoriax](https://discuss.elastic.co/u/zoriax)\
**Replies:** 0\
**Last updated:** [June 23, 2022, 8:56am UTC](https://discuss.elastic.co/t/aggregate-on-field-value/307968 "2022-06-23T08:56:28Z")

</div>

Hello, I'm new on this forum and I need your help :slight\_smile: I'm looking for a we to "aggregate" values on a field. Let me explain what I'm looking for : I have documents with this kind of fields : { "\_id" : "1…

---

## [Tokens offset issue](https://discuss.elastic.co/t/tokens-offset-issue/307737)

<div class="topic-metadata">

**Author:** [@itaydvir](https://discuss.elastic.co/u/itaydvir)\
**Replies:** 1\
**Last updated:** [June 23, 2022, 8:50am UTC](https://discuss.elastic.co/t/tokens-offset-issue/307737 "2022-06-23T08:50:34Z")

</div>

Hello, I'm upgrading from Elastic 6.8.1 to 7.8.1 (tested on 8.2.3 as well) and getting the following error: startOffset must be non-negative, and endOffset must be \>= startOffset, and offsets must not go backwards I…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=600)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=602)
