# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=308

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 309

---

## [Painless syntax doc inconsistancy](https://discuss.elastic.co/t/painless-syntax-doc-inconsistancy/353190)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 0\
**Last updated:** [February 13, 2024, 4:00pm UTC](https://discuss.elastic.co/t/painless-syntax-doc-inconsistancy/353190 "2024-02-13T16:00:21Z")

</div>

It's probably my lack of understanding, but in the doc document fields are sometimes referenced (top of link, in the conditional) as: doc\[item\] and other times (bottom of the linked page) as ctx.\_source.item It s…

---

## [Can I avoid elasticsearch monitoring index from moving to my temporary nodes?](https://discuss.elastic.co/t/can-i-avoid-elasticsearch-monitoring-index-from-moving-to-my-temporary-nodes/353128)

<div class="topic-metadata">

**Author:** [@Churchill](https://discuss.elastic.co/u/Churchill)\
**Replies:** 10\
**Last updated:** [February 13, 2024, 3:47pm UTC](https://discuss.elastic.co/t/can-i-avoid-elasticsearch-monitoring-index-from-moving-to-my-temporary-nodes/353128 "2024-02-13T15:47:15Z")

</div>

Good day, I'm currently maintaining a cluster with 4 permanent nodes and 3 temporary nodes. How it works is, during work hours, our temporary nodes will be started automatically, and will be shutdown after work hours. T…

---

## [Elastic query when executed from dev tools gives top 1 record, when same through logstash gives many record in Index](https://discuss.elastic.co/t/elastic-query-when-executed-from-dev-tools-gives-top-1-record-when-same-through-logstash-gives-many-record-in-index/353067)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [February 13, 2024, 7:12am UTC](https://discuss.elastic.co/t/elastic-query-when-executed-from-dev-tools-gives-top-1-record-when-same-through-logstash-gives-many-record-in-index/353067 "2024-02-13T07:12:38Z")

</div>

Hello All, I am trying to send two fields from mis-monitoring-webserver to new index mis-monitoring-webui. Issue faced: This webserver index gets data every 10 seconds and from this my expectation is- I have written sp…

---

## [Timeout errors Elastic GitHub Workflow Runner](https://discuss.elastic.co/t/timeout-errors-elastic-github-workflow-runner/353064)

<div class="topic-metadata">

**Author:** [@christos-P](https://discuss.elastic.co/u/christos-P)\
**Replies:** 2\
**Last updated:** [February 13, 2024, 2:18pm UTC](https://discuss.elastic.co/t/timeout-errors-elastic-github-workflow-runner/353064 "2024-02-13T14:18:58Z")

</div>

Hi all, We have our code hosted in GitHub, and we utilize GitHub workflows for our CI/CD pipeline. On each push in a feature branch, based on a docker compose file , in which we describe two services, two services are s…

---

## [System Integration dashboard somehow broken](https://discuss.elastic.co/t/system-integration-dashboard-somehow-broken/353177)

<div class="topic-metadata">

**Author:** [@Alphayeeeet](https://discuss.elastic.co/u/Alphayeeeet)\
**Replies:** 1\
**Last updated:** [February 13, 2024, 2:15pm UTC](https://discuss.elastic.co/t/system-integration-dashboard-somehow-broken/353177 "2024-02-13T14:15:03Z")

</div>

I completely uninstalled and reinstalled the integration and it didnt help (as it is caused by the aggregation in the dashboard). My Dashbaord visualization is like this: There are some missing values (I do use the …

---

## [Logstash as a Statefulset in Kubernetes - File Input and duplicated logs](https://discuss.elastic.co/t/logstash-as-a-statefulset-in-kubernetes-file-input-and-duplicated-logs/353162)

<div class="topic-metadata">

**Author:** [@veramendi](https://discuss.elastic.co/u/veramendi)\
**Replies:** 6\
**Last updated:** [February 13, 2024, 1:52pm UTC](https://discuss.elastic.co/t/logstash-as-a-statefulset-in-kubernetes-file-input-and-duplicated-logs/353162 "2024-02-13T13:52:06Z")

</div>

Hello, I am trying to deploy a multiple pod logstash Statefulset on a kubernetes cluster using the Input File type. It looks like each pod is reading the same logs from the logfile placed on a PVC, and therefore we are…

---

## [Elasticsearch tuning](https://discuss.elastic.co/t/elasticsearch-tuning/353163)

<div class="topic-metadata">

**Author:** [@Mathews\_Ignatius](https://discuss.elastic.co/u/Mathews_Ignatius)\
**Replies:** 3\
**Last updated:** [February 13, 2024, 1:47pm UTC](https://discuss.elastic.co/t/elasticsearch-tuning/353163 "2024-02-13T13:47:59Z")

</div>

Hi, I am trying to reduce storage size of index. I tried customising the mapping, shrinking shards, compression algorithms and all but nothing seems to work the size is not getting reduced. Is there anything else that c…

---

## [Kibana deprecated settings](https://discuss.elastic.co/t/kibana-deprecated-settings/352747)

<div class="topic-metadata">

**Author:** [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Replies:** 10\
**Last updated:** [February 13, 2024, 1:31pm UTC](https://discuss.elastic.co/t/kibana-deprecated-settings/352747 "2024-02-13T13:31:19Z")

</div>

Hello, Can you help me, how to get of rid of this deprecated setting in KIbana GUI under Upgrade asistant? I Already removed these settings in my kibana.yml but it is still shwoing. How to fix Remove the "xpack.repor…

---

## [Data fs grows forever after full snapshot is taken](https://discuss.elastic.co/t/data-fs-grows-forever-after-full-snapshot-is-taken/353139)

<div class="topic-metadata">

**Author:** [@TinaMartiello](https://discuss.elastic.co/u/TinaMartiello)\
**Replies:** 4\
**Last updated:** [February 13, 2024, 1:10pm UTC](https://discuss.elastic.co/t/data-fs-grows-forever-after-full-snapshot-is-taken/353139 "2024-02-13T13:10:42Z")

</div>

Hi, we have 3 elasticsearch nodes, elasticsearch-8.11.1-1.x86\_64 and CentOS Linux release 7.3.1611 (Core) o.s. are installed on premis. We have very busy read/write systems. We are taking a full snapshot once a day, o…

---

## [Export/Import ES 7 to ES 8](https://discuss.elastic.co/t/export-import-es-7-to-es-8/353159)

<div class="topic-metadata">

**Author:** [@omegaziv](https://discuss.elastic.co/u/omegaziv)\
**Replies:** 1\
**Last updated:** [February 13, 2024, 1:03pm UTC](https://discuss.elastic.co/t/export-import-es-7-to-es-8/353159 "2024-02-13T13:03:12Z")

</div>

Hello. we have ES 7 with 3 GB of data. We will migrate to ES 8. and we are looking for the best way. is there an upgrade procedure without moving the data? we tried to export the data for later import - but it took o…

---

## [Downsampling policy](https://discuss.elastic.co/t/downsampling-policy/353106)

<div class="topic-metadata">

**Author:** [@noambe991](https://discuss.elastic.co/u/noambe991)\
**Replies:** 0\
**Last updated:** [February 12, 2024, 8:08pm UTC](https://discuss.elastic.co/t/downsampling-policy/353106 "2024-02-12T20:08:34Z")

</div>

Hello, I'm trying to define a policy for my time-series data stream as follows: "policy": { "phases": { "warm": { "min\_age": "0d", "actions": { "readonly": {}, …

---

## [Integration Oracle Cloud Kafka + Elastic-agent doesn't work](https://discuss.elastic.co/t/integration-oracle-cloud-kafka-elastic-agent-doesnt-work/353155)

<div class="topic-metadata">

**Author:** [@Death](https://discuss.elastic.co/u/Death)\
**Replies:** 0\
**Last updated:** [February 13, 2024, 10:57am UTC](https://discuss.elastic.co/t/integration-oracle-cloud-kafka-elastic-agent-doesnt-work/353155 "2024-02-13T10:57:20Z")

</div>

Good afternoon. At the moment, there was an attempt to connect to collect logs from Oracle cloud Audit logs via Kafka, and everything worked through logstash. Now when I try to use Custom Kafka Integration in elasticsear…

---

## [Script.painless.regex.enabled: true Is not enough to disable limits](https://discuss.elastic.co/t/script-painless-regex-enabled-true-is-not-enough-to-disable-limits/353153)

<div class="topic-metadata">

**Author:** [@Saief](https://discuss.elastic.co/u/Saief)\
**Replies:** 0\
**Last updated:** [February 13, 2024, 10:49am UTC](https://discuss.elastic.co/t/script-painless-regex-enabled-true-is-not-enough-to-disable-limits/353153 "2024-02-13T10:49:42Z")

</div>

Hello, ES vesion : 8.12.0 I want to use scripting when search documents. I activated "script.painless.regex.enabled: true" in purpose to avoid limiting chars, But in my cluster settings, I still see : "painless":{"re…

---

## [ELK configuration for OpenShift](https://discuss.elastic.co/t/elk-configuration-for-openshift/353149)

<div class="topic-metadata">

**Author:** [@ayoub\_souihel](https://discuss.elastic.co/u/ayoub_souihel)\
**Replies:** 0\
**Last updated:** [February 13, 2024, 10:27am UTC](https://discuss.elastic.co/t/elk-configuration-for-openshift/353149 "2024-02-13T10:27:00Z")

</div>

Hello , i am a very new to ELK , i have set up a single node cluster ( Elasticsearch , kibana , logstash ) , i have configured the logforwarder on openshift correctly ( i see elasticsearch logs showing logs recieved fro…

---

## [Performance problem because of read IOPS increase](https://discuss.elastic.co/t/performance-problem-because-of-read-iops-increase/353074)

<div class="topic-metadata">

**Author:** [@jnegredo](https://discuss.elastic.co/u/jnegredo)\
**Replies:** 4\
**Last updated:** [February 13, 2024, 9:28am UTC](https://discuss.elastic.co/t/performance-problem-because-of-read-iops-increase/353074 "2024-02-13T09:28:55Z")

</div>

Hi, I've a elasticsearch cluster with 3 nodes (version 6.8.0). It's deployed on 3 virtual machines with 16GB RAM and 4 cores, in Google Cloud. Usually we have a lot more wirting IOPS than reading (40-50 vs 0-5) without …

---

## [Useruuid,tracingId and correlationId field is not comming in logstash](https://discuss.elastic.co/t/useruuid-tracingid-and-correlationid-field-is-not-comming-in-logstash/351537)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 4\
**Last updated:** [February 13, 2024, 5:32am UTC](https://discuss.elastic.co/t/useruuid-tracingid-and-correlationid-field-is-not-comming-in-logstash/351537 "2024-02-13T05:32:15Z")

</div>

Not able to see Useruuid,tracingId and correlationId field in logs in logstash which is comming from mule but it is comming in message field in logstash.Below is my logstash.conf file and I have attached the screenshot a…

---

## [Filebeat: How to create multiple instances/pipelines on same VM](https://discuss.elastic.co/t/filebeat-how-to-create-multiple-instances-pipelines-on-same-vm/352999)

<div class="topic-metadata">

**Author:** [@albus](https://discuss.elastic.co/u/albus)\
**Replies:** 5\
**Last updated:** [February 12, 2024, 7:51pm UTC](https://discuss.elastic.co/t/filebeat-how-to-create-multiple-instances-pipelines-on-same-vm/352999 "2024-02-12T19:51:38Z")

</div>

Hello Elastic Community, I hope everybody is doing great. I am facing a problem and I cannot find any documentation or blog related to it. Problem statement is: Is there a possibility to run multiple instances of Fileb…

---

## [Primary shard not available](https://discuss.elastic.co/t/primary-shard-not-available/352938)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 3\
**Last updated:** [February 12, 2024, 7:41pm UTC](https://discuss.elastic.co/t/primary-shard-not-available/352938 "2024-02-12T19:41:34Z")

</div>

Hi after i've receive disk full i try to remove some indices from this path: elasticsearch/indices/ after the status of the cluster become red and give below errors: is there any way to fix it please?

---

## [Sorting of classes while getting top 10 classes by each category using aggregation](https://discuss.elastic.co/t/sorting-of-classes-while-getting-top-10-classes-by-each-category-using-aggregation/352620)

<div class="topic-metadata">

**Author:** [@Vaibhav\_Vidhate](https://discuss.elastic.co/u/Vaibhav_Vidhate)\
**Replies:** 1\
**Last updated:** [February 12, 2024, 7:10pm UTC](https://discuss.elastic.co/t/sorting-of-classes-while-getting-top-10-classes-by-each-category-using-aggregation/352620 "2024-02-12T19:10:50Z")

</div>

We are using Elasticsearch for searching classes and showing a list of featured classes. Each class can have many categories assigned. For each class, sort order is defined within each category assigned. We need to ret…

---

## [.net client (8.12) converts params data properties to camelCase but i use PascalCase](https://discuss.elastic.co/t/net-client-8-12-converts-params-data-properties-to-camelcase-but-i-use-pascalcase/353101)

<div class="topic-metadata">

**Author:** [@Nazim\_Kirma](https://discuss.elastic.co/u/Nazim_Kirma)\
**Replies:** 0\
**Last updated:** [February 12, 2024, 7:05pm UTC](https://discuss.elastic.co/t/net-client-8-12-converts-params-data-properties-to-camelcase-but-i-use-pascalcase/353101 "2024-02-12T19:05:13Z")

</div>

Hi all, I use .net client to index my documents. I use nested field to update arrays and add new objects. I use the PascalCase configuration for Properties. This is my configuration : var node = new SingleNodePool(new…

---

## [Moving shapshot between computers (again)](https://discuss.elastic.co/t/moving-shapshot-between-computers-again/352963)

<div class="topic-metadata">

**Author:** [@kwalcock](https://discuss.elastic.co/u/kwalcock)\
**Replies:** 7\
**Last updated:** [February 12, 2024, 6:43pm UTC](https://discuss.elastic.co/t/moving-shapshot-between-computers-again/352963 "2024-02-12T18:43:11Z")

</div>

I know things like this have been discussed here, but I do not find any complete answer that matches the situation or what I observe on the screen, so I have to ask again. If I make a snapshot of an index on one compute…

---

## [Massive index compression](https://discuss.elastic.co/t/massive-index-compression/352926)

<div class="topic-metadata">

**Author:** [@revelc33](https://discuss.elastic.co/u/revelc33)\
**Replies:** 10\
**Last updated:** [February 12, 2024, 5:47pm UTC](https://discuss.elastic.co/t/massive-index-compression/352926 "2024-02-12T17:47:29Z")

</div>

How can I easily compress 140 indices (some of which are up to 100 GB)? I have tried closing the indices, changing the codec to 'best\_compression,' and then executing a forcemerge on the index. The forcemerge task fi…

---

## [Get available fields in index](https://discuss.elastic.co/t/get-available-fields-in-index/353091)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 0\
**Last updated:** [February 12, 2024, 5:08pm UTC](https://discuss.elastic.co/t/get-available-fields-in-index/353091 "2024-02-12T17:08:29Z")

</div>

Hello, community, I want to get the available fields from an index, like taking the last 500 documents and returning a list of non-null fields. thanks.

---

## [Elastic Defend integration failed to upgrade](https://discuss.elastic.co/t/elastic-defend-integration-failed-to-upgrade/352583)

<div class="topic-metadata">

**Author:** [@Krishna\_Teja](https://discuss.elastic.co/u/Krishna_Teja)\
**Replies:** 4\
**Last updated:** [February 12, 2024, 5:05pm UTC](https://discuss.elastic.co/t/elastic-defend-integration-failed-to-upgrade/352583 "2024-02-12T17:05:33Z")

</div>

I upgraded elastic version to 8.12.0 recently. Today, when I tried to upgrade my agents, they are stuck in "unhealthy" state with a few errors stating Download failure and "No action taken" (screenshot attached). What c…

---

## [Oracle Data to ES using Logstash](https://discuss.elastic.co/t/oracle-data-to-es-using-logstash/352900)

<div class="topic-metadata">

**Author:** [@elkeng](https://discuss.elastic.co/u/elkeng)\
**Replies:** 4\
**Last updated:** [February 12, 2024, 2:19pm UTC](https://discuss.elastic.co/t/oracle-data-to-es-using-logstash/352900 "2024-02-12T14:19:25Z")

</div>

Hello everyone, I am trying to ingest Oracle data to ES using Logstash. But I got some errors in different conditions. Is there a procedure or best practice to do this? Thanks

---

## [New to Kibana: How to Remove Lingering Active Alerts? (Rules Deleted)](https://discuss.elastic.co/t/new-to-kibana-how-to-remove-lingering-active-alerts-rules-deleted/353072)

<div class="topic-metadata">

**Author:** [@skumarsingh](https://discuss.elastic.co/u/skumarsingh)\
**Replies:** 1\
**Last updated:** [February 12, 2024, 1:52pm UTC](https://discuss.elastic.co/t/new-to-kibana-how-to-remove-lingering-active-alerts-rules-deleted/353072 "2024-02-12T13:52:24Z")

</div>

Hi everyone, I'm relatively new to Kibana and I'm encountering some persistent active alerts that I'd like to remove. I've already deleted the rules associated with these alerts, but they're still showing up under "Acti…

---

## [Shape mapping, only return certain type(s) on a query](https://discuss.elastic.co/t/shape-mapping-only-return-certain-type-s-on-a-query/352552)

<div class="topic-metadata">

**Author:** [@paul5](https://discuss.elastic.co/u/paul5)\
**Replies:** 8\
**Last updated:** [February 12, 2024, 1:23pm UTC](https://discuss.elastic.co/t/shape-mapping-only-return-certain-type-s-on-a-query/352552 "2024-02-12T13:23:39Z")

</div>

I don't see a way for a query on mapping type shape to only return certain shapes. Something like this: POST /example/\_doc { "location" : { "type" : "point", "coordinates" : \[-377.03653, 389.897676\] }, "ret…

---

## [Update security certificates with a different CA](https://discuss.elastic.co/t/update-security-certificates-with-a-different-ca/352766)

<div class="topic-metadata">

**Author:** [@amitjadhav0384](https://discuss.elastic.co/u/amitjadhav0384)\
**Replies:** 5\
**Last updated:** [February 12, 2024, 1:00pm UTC](https://discuss.elastic.co/t/update-security-certificates-with-a-different-ca/352766 "2024-02-12T13:00:53Z")

</div>

I am trying to update new CA which are signed using trusted source given by our organization. ./bin/elasticsearch-certutil cert --ca-cert ca/ca.crt --ca-key ca/ca.key While trying to create new certificate using the ab…

---

## [Alerts to ServiceNow Generic Pipeline](https://discuss.elastic.co/t/alerts-to-servicenow-generic-pipeline/352631)

<div class="topic-metadata">

**Author:** [@sajmeister](https://discuss.elastic.co/u/sajmeister)\
**Replies:** 4\
**Last updated:** [February 12, 2024, 12:50pm UTC](https://discuss.elastic.co/t/alerts-to-servicenow-generic-pipeline/352631 "2024-02-12T12:50:48Z")

</div>

Hi, We use the free edition of Elasticsearch and don't use watchers. Would like to know is there a generic pipeline code that can be used to send alerts to ServiceNow ? If yes, please provide code so can test it. Che…

---

## [Elasticsearch Enterprise On-Prem Licensing details](https://discuss.elastic.co/t/elasticsearch-enterprise-on-prem-licensing-details/353057)

<div class="topic-metadata">

**Author:** [@Rehmat](https://discuss.elastic.co/u/Rehmat)\
**Replies:** 4\
**Last updated:** [February 12, 2024, 12:23pm UTC](https://discuss.elastic.co/t/elasticsearch-enterprise-on-prem-licensing-details/353057 "2024-02-12T12:23:56Z")

</div>

Hi Everyone, can someone share some detail about Elasticsearch Enterprise License On-Prem, will allow how many nodes, cluster, storage capacity per bare-metal node/vm, CPU/RAM ? thanks in advance

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=307)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=309)
