# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=320

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 321

---

## [Logstash XML file not parsing](https://discuss.elastic.co/t/logstash-xml-file-not-parsing/352048)

<div class="topic-metadata">

**Author:** [@Shawn\_Lim](https://discuss.elastic.co/u/Shawn_Lim)\
**Replies:** 2\
**Last updated:** [January 30, 2024, 9:31am UTC](https://discuss.elastic.co/t/logstash-xml-file-not-parsing/352048 "2024-01-30T09:31:03Z")

</div>

Hi guys, I'm very new to Elasticsearch stack, need some help over here... Currently I'm trying to parse XML file, output to Elasticsearch and use it on Grafana for visualization. Now I facing a problem is my XML files …

---

## [Adding a label to the dataset - Multiple entries (large scale)](https://discuss.elastic.co/t/adding-a-label-to-the-dataset-multiple-entries-large-scale/351817)

<div class="topic-metadata">

**Author:** [@kaganova](https://discuss.elastic.co/u/kaganova)\
**Replies:** 7\
**Last updated:** [January 30, 2024, 8:25am UTC](https://discuss.elastic.co/t/adding-a-label-to-the-dataset-multiple-entries-large-scale/351817 "2024-01-30T08:25:38Z")

</div>

Hey, I'm querying a large API dataset with ~200k different tokens. I'm trying to query a subset of the activity, by token - of about ~170k values. I've tried using a filter for multiple values ("not in 30k") but I get …

---

## [Elastic Performance for Spatial Queries Slows Down when Geometries are in Millions](https://discuss.elastic.co/t/elastic-performance-for-spatial-queries-slows-down-when-geometries-are-in-millions/351959)

<div class="topic-metadata">

**Author:** [@purijs](https://discuss.elastic.co/u/purijs)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 6:58am UTC](https://discuss.elastic.co/t/elastic-performance-for-spatial-queries-slows-down-when-geometries-are-in-millions/351959 "2024-01-30T06:58:36Z")

</div>

I have a usecase to query ES for spatial intersection query with a Multipolygon. I tried two approaches where I store documents in flat structure, where 1 Polygon represents 1 document and in another setup I aggregate do…

---

## [ Filebeat: 0 Documents After Index Rollover](https://discuss.elastic.co/t/filebeat-0-documents-after-index-rollover/352060)

<div class="topic-metadata">

**Author:** [@Megha\_Varshney](https://discuss.elastic.co/u/Megha_Varshney)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 6:37am UTC](https://discuss.elastic.co/t/filebeat-0-documents-after-index-rollover/352060 "2024-01-30T06:37:46Z")

</div>

I am experiencing an issue with Filebeat where, after an index rollover, the new index shows 0 documents, and no data seems to be indexed. Here are the details of my setup:' Filebeat Configuration: filebeat.inputs: - t…

---

## [\[ElasticSearch v.7.5\] How to delete all indexes older than 6 month automatically?](https://discuss.elastic.co/t/elasticsearch-v-7-5-how-to-delete-all-indexes-older-than-6-month-automatically/351036)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 18\
**Last updated:** [January 30, 2024, 6:28am UTC](https://discuss.elastic.co/t/elasticsearch-v-7-5-how-to-delete-all-indexes-older-than-6-month-automatically/351036 "2024-01-30T06:28:23Z")

</div>

How to delete all indexes older than 6 month automatically?

---

## [After Implementing Elastic Search in Oracle's WEb center content, we are seeing no enhancement in Performance](https://discuss.elastic.co/t/after-implementing-elastic-search-in-oracles-web-center-content-we-are-seeing-no-enhancement-in-performance/352055)

<div class="topic-metadata">

**Author:** [@Subhs](https://discuss.elastic.co/u/Subhs)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 5:50am UTC](https://discuss.elastic.co/t/after-implementing-elastic-search-in-oracles-web-center-content-we-are-seeing-no-enhancement-in-performance/352055 "2024-01-30T05:50:30Z")

</div>

I have implemented Elastic Search in Oracle Web Center content( a content management repository from Oracle) as Oracle supports Elastic Search. But we are seeing no enhancement in performance compared to Database search.…

---

## [URL templating - Is it possible to split the output of event.values?](https://discuss.elastic.co/t/url-templating-is-it-possible-to-split-the-output-of-event-values/351659)

<div class="topic-metadata">

**Author:** [@azulgrana](https://discuss.elastic.co/u/azulgrana)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 5:29am UTC](https://discuss.elastic.co/t/url-templating-is-it-possible-to-split-the-output-of-event-values/351659 "2024-01-30T05:29:49Z")

</div>

Hi there! I'm working on a "Table row click" drill down for one of my Lens tables, my goal is to have a drill down off a hidden field (report Id) to make it easier for the users. the event.values variable return an arr…

---

## [Logstash cpu usage is very high](https://discuss.elastic.co/t/logstash-cpu-usage-is-very-high/351619)

<div class="topic-metadata">

**Author:** [@Manoj\_Sangwan](https://discuss.elastic.co/u/Manoj_Sangwan)\
**Replies:** 3\
**Last updated:** [January 30, 2024, 4:56am UTC](https://discuss.elastic.co/t/logstash-cpu-usage-is-very-high/351619 "2024-01-30T04:56:32Z")

</div>

Logstash CPU usage is up to 90% and assuming this would increase with data growth. From the Application side seems everything fine. How to solve this issue in my project?

---

## [EFK Deployment on Openshift](https://discuss.elastic.co/t/efk-deployment-on-openshift/352053)

<div class="topic-metadata">

**Author:** [@bkrraj](https://discuss.elastic.co/u/bkrraj)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 4:47am UTC](https://discuss.elastic.co/t/efk-deployment-on-openshift/352053 "2024-01-30T04:47:14Z")

</div>

Hi , We are planning to Implement EFK on our PROD RedHat OpenShift cluster. Can anyone help us with the steps. Thanks Bala

---

## [Increase number of shards for an existing data stream](https://discuss.elastic.co/t/increase-number-of-shards-for-an-existing-data-stream/352045)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 2:07am UTC](https://discuss.elastic.co/t/increase-number-of-shards-for-an-existing-data-stream/352045 "2024-01-30T02:07:19Z")

</div>

Hi, I have been using the \_split API to change the number of shards on an existing index. This has been a simple task and has worked as expected. I have not had much success doing the same for a data stream which may …

---

## [Elastic search is missing a hit when returning inner hits but the hit shows in highlights](https://discuss.elastic.co/t/elastic-search-is-missing-a-hit-when-returning-inner-hits-but-the-hit-shows-in-highlights/352042)

<div class="topic-metadata">

**Author:** [@warrengoldman](https://discuss.elastic.co/u/warrengoldman)\
**Replies:** 0\
**Last updated:** [January 29, 2024, 11:34pm UTC](https://discuss.elastic.co/t/elastic-search-is-missing-a-hit-when-returning-inner-hits-but-the-hit-shows-in-highlights/352042 "2024-01-29T23:34:41Z")

</div>

I have verified this via java api connection to Elasticsearch AND via kibana console. inner hits is missing chapter 7 verse 7 (note: highlights DOES show this instance, but inner hits ONLY has 3 or the 4 hits). The text …

---

## [High level of storage usage onky for 3 servers](https://discuss.elastic.co/t/high-level-of-storage-usage-onky-for-3-servers/351948)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 2\
**Last updated:** [January 29, 2024, 9:35pm UTC](https://discuss.elastic.co/t/high-level-of-storage-usage-onky-for-3-servers/351948 "2024-01-29T21:35:01Z")

</div>

I have 40 servers in Elk cluster version 7.5. A majority of them have a stable storage usage of around 65%, but 3 of them always have a usage over 85% and they grow up continuously What could be the reason?

---

## [Trying to decrypt data but it is not working as expected](https://discuss.elastic.co/t/trying-to-decrypt-data-but-it-is-not-working-as-expected/351977)

<div class="topic-metadata">

**Author:** [@Pallavibhushan](https://discuss.elastic.co/u/Pallavibhushan)\
**Replies:** 4\
**Last updated:** [January 29, 2024, 7:22pm UTC](https://discuss.elastic.co/t/trying-to-decrypt-data-but-it-is-not-working-as-expected/351977 "2024-01-29T19:22:47Z")

</div>

Below is my config input { file { path =\> "C:/logstash-7.16.2/data/input/test\*.json" start\_position =\> "beginning" sincedb\_path =\> "null" } } filter { json { source =\> "message" target =\> "document" } mutate…

---

## [How is elastic agent gathering statistics?](https://discuss.elastic.co/t/how-is-elastic-agent-gathering-statistics/352028)

<div class="topic-metadata">

**Author:** [@aorona](https://discuss.elastic.co/u/aorona)\
**Replies:** 0\
**Last updated:** [January 29, 2024, 6:11pm UTC](https://discuss.elastic.co/t/how-is-elastic-agent-gathering-statistics/352028 "2024-01-29T18:11:51Z")

</div>

Is elastic agent parsing the text output of observability tools or is it reading directly from the OS libraries and kernel interfaces?

---

## [Elastic Date Math Rounding](https://discuss.elastic.co/t/elastic-date-math-rounding/352027)

<div class="topic-metadata">

**Author:** [@AidenRourke](https://discuss.elastic.co/u/AidenRourke)\
**Replies:** 0\
**Last updated:** [January 29, 2024, 6:04pm UTC](https://discuss.elastic.co/t/elastic-date-math-rounding/352027 "2024-01-29T18:04:10Z")

</div>

The date\_histogram aggregation has a parameter called offset. This property can be used to change a weekly bucket to be Monday to Sunday (the default) to Sunday to Saturday. I'm wondering if there's a simliar solution f…

---

## [How to get the summation of inner\_hits hits total value](https://discuss.elastic.co/t/how-to-get-the-summation-of-inner-hits-hits-total-value/352022)

<div class="topic-metadata">

**Author:** [@warrengoldman](https://discuss.elastic.co/u/warrengoldman)\
**Replies:** 0\
**Last updated:** [January 29, 2024, 5:27pm UTC](https://discuss.elastic.co/t/how-to-get-the-summation-of-inner-hits-hits-total-value/352022 "2024-01-29T17:27:07Z")

</div>

Cannot figure out the syntax for aggregations per the doc for this. Would think this type of request is very common... { "bible-book": { "mappings": { "properties": { "book": { "type": "tex…

---

## ["Cropping" result string around matches?](https://discuss.elastic.co/t/cropping-result-string-around-matches/351998)

<div class="topic-metadata">

**Author:** [@Seb\_Jones](https://discuss.elastic.co/u/Seb_Jones)\
**Replies:** 2\
**Last updated:** [January 29, 2024, 4:43pm UTC](https://discuss.elastic.co/t/cropping-result-string-around-matches/351998 "2024-01-29T16:43:40Z")

</div>

Hi Folks, Meilisearch offers a "cropping" function that trims or shortens the result string while still including the matching term. So using an example from their docs (which this forum won't let me link to …

---

## [How to send JSON body in rule?](https://discuss.elastic.co/t/how-to-send-json-body-in-rule/351768)

<div class="topic-metadata">

**Author:** [@navin547](https://discuss.elastic.co/u/navin547)\
**Replies:** 3\
**Last updated:** [January 29, 2024, 3:45pm UTC](https://discuss.elastic.co/t/how-to-send-json-body-in-rule/351768 "2024-01-29T15:45:43Z")

</div>

Hi, I have created a webhook connector which uses servicenow api to send, then I have created a rule and used that webhook connector so whenever that rule trigger I need to send that alert data in body as a JSON as ser…

---

## [Write log category to field](https://discuss.elastic.co/t/write-log-category-to-field/352000)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 1\
**Last updated:** [January 29, 2024, 3:22pm UTC](https://discuss.elastic.co/t/write-log-category-to-field/352000 "2024-01-29T15:22:37Z")

</div>

Hello, if i have logs like this: 2024-01-29 15:09:43,102 - ERROR - DB:Test1 - Test Error 2024-01-29 15:09:48,653 - ERROR - DB:Test2 - Test Error 2024-01-29 15:09:49,041 - ERROR - DB:Test1 - Test Error 2024-01-29 15:09:…

---

## [Reindex multiple indices - missing data stream](https://discuss.elastic.co/t/reindex-multiple-indices-missing-data-stream/352002)

<div class="topic-metadata">

**Author:** [@Oscar\_Yerpes](https://discuss.elastic.co/u/Oscar_Yerpes)\
**Replies:** 0\
**Last updated:** [January 29, 2024, 2:45pm UTC](https://discuss.elastic.co/t/reindex-multiple-indices-missing-data-stream/352002 "2024-01-29T14:45:57Z")

</div>

Hello all, Elastic version is 8.1 I have daily indices from an ILM that I would like to reindex in a single monthly index. I've tried the following: POST \_reindex { "source": { "index": ".ds-hpc-slurm-2023.10.\*…

---

## [Normalizer lowercase not found](https://discuss.elastic.co/t/normalizer-lowercase-not-found/351882)

<div class="topic-metadata">

**Author:** [@M.Ronge](https://discuss.elastic.co/u/M.Ronge)\
**Replies:** 2\
**Last updated:** [January 29, 2024, 2:35pm UTC](https://discuss.elastic.co/t/normalizer-lowercase-not-found/351882 "2024-01-29T14:35:58Z")

</div>

We develop an open source Java EE web application that uses Elasticsearch. This works wonderfully productively and very stable on countless servers. I now updated a single server, where it had been running smoothly so fa…

---

## [Filebeat fails connection to Logstash on Kubernetes](https://discuss.elastic.co/t/filebeat-fails-connection-to-logstash-on-kubernetes/351822)

<div class="topic-metadata">

**Author:** [@Ziggiyzoo](https://discuss.elastic.co/u/Ziggiyzoo)\
**Replies:** 5\
**Last updated:** [January 29, 2024, 2:14pm UTC](https://discuss.elastic.co/t/filebeat-fails-connection-to-logstash-on-kubernetes/351822 "2024-01-29T14:14:19Z")

</div>

Hi, I'm trying to connect a Filebeats deployment to Logstash but I am having error getting Filebeat to connect. A connection attempt failed because the connected party did not properly respond after a period of time, o…

---

## [How to add new config file to logstash which is created by docker compose?](https://discuss.elastic.co/t/how-to-add-new-config-file-to-logstash-which-is-created-by-docker-compose/351655)

<div class="topic-metadata">

**Author:** [@shrm](https://discuss.elastic.co/u/shrm)\
**Replies:** 3\
**Last updated:** [January 29, 2024, 1:43pm UTC](https://discuss.elastic.co/t/how-to-add-new-config-file-to-logstash-which-is-created-by-docker-compose/351655 "2024-01-29T13:43:48Z")

</div>

How to add a new config file to logstash which is created by docker-compose? I created my service with docker-compose and log stash is connected to kibana and elasticsearch. Now I created a new config file for logstash…

---

## [Performance Problems](https://discuss.elastic.co/t/performance-problems/348035)

<div class="topic-metadata">

**Author:** [@fgonzalez](https://discuss.elastic.co/u/fgonzalez)\
**Replies:** 27\
**Last updated:** [January 29, 2024, 1:34pm UTC](https://discuss.elastic.co/t/performance-problems/348035 "2024-01-29T13:34:47Z")

</div>

Good morning, I have several Elasticsearch clusters and they are giving me performance problems. I have located (I think) the problems but I need you to confirm if I am on the right track. Basic configuration normally …

---

## [Elastic-agent fleet upgrade windows - DNS lookup failure](https://discuss.elastic.co/t/elastic-agent-fleet-upgrade-windows-dns-lookup-failure/351992)

<div class="topic-metadata">

**Author:** [@beno](https://discuss.elastic.co/u/beno)\
**Replies:** 0\
**Last updated:** [January 29, 2024, 1:17pm UTC](https://discuss.elastic.co/t/elastic-agent-fleet-upgrade-windows-dns-lookup-failure/351992 "2024-01-29T13:17:26Z")

</div>

Hello, I would like to upgrade my fleet server running on a windows server from Elastic 8.10.2 to Elastic 8.11.3. I run the upgrade through the UI from Fleet-\>Agents page. When I do this, I get the following 2 errors: …

---

## [Delete dictionary from array if one key is empty](https://discuss.elastic.co/t/delete-dictionary-from-array-if-one-key-is-empty/351863)

<div class="topic-metadata">

**Author:** [@ITIC](https://discuss.elastic.co/u/ITIC)\
**Replies:** 2\
**Last updated:** [January 29, 2024, 1:08pm UTC](https://discuss.elastic.co/t/delete-dictionary-from-array-if-one-key-is-empty/351863 "2024-01-29T13:08:00Z")

</div>

Hi! It's been a while since I last wrestled with logstash, and I can feel the rust! I'm trying to delete an array element with delete\_if, and I have trouble with it. The element itself is a dictionary, and the conditi…

---

## [Dense\_vector type changes to “float” after loading the data](https://discuss.elastic.co/t/dense-vector-type-changes-to-float-after-loading-the-data/350309)

<div class="topic-metadata">

**Author:** [@Rakesh\_Kalange](https://discuss.elastic.co/u/Rakesh_Kalange)\
**Replies:** 5\
**Last updated:** [January 29, 2024, 12:40pm UTC](https://discuss.elastic.co/t/dense-vector-type-changes-to-float-after-loading-the-data/350309 "2024-01-29T12:40:53Z")

</div>

Hi, I'm trying to load vector\_value into Elasticsearch, index creation and data loading finished without any error. But the result of mapping shows type "float", not "dense\_vector". The version of Elasticsearch is 7.…

---

## [Mutate and gsub usage](https://discuss.elastic.co/t/mutate-and-gsub-usage/351769)

<div class="topic-metadata">

**Author:** [@Sara93](https://discuss.elastic.co/u/Sara93)\
**Replies:** 3\
**Last updated:** [January 29, 2024, 12:32pm UTC](https://discuss.elastic.co/t/mutate-and-gsub-usage/351769 "2024-01-29T12:32:11Z")

</div>

Hi, I was trying to fetch below fileds from the log 2024-01-10 04:21:52.018 -06:00 \[INF\] \[2696100223720240110042151-10\] {"Message":"Device\_Response\_2696100223720240110042151-10","ApiEndPoint":"ws://10.136.41.18:50000/"…

---

## [Log Configuration](https://discuss.elastic.co/t/log-configuration/351974)

<div class="topic-metadata">

**Author:** [@tejas.d](https://discuss.elastic.co/u/tejas.d)\
**Replies:** 3\
**Last updated:** [January 29, 2024, 12:18pm UTC](https://discuss.elastic.co/t/log-configuration/351974 "2024-01-29T12:18:52Z")

</div>

How can i define Application log files when i have a suffix as system date after .log in filebeat.yml folder Examle: C:/path/folder/\*.log29012024

---

## [Update\_by\_query?routing=orgid performance veryslow](https://discuss.elastic.co/t/update-by-query-routing-orgid-performance-veryslow/351940)

<div class="topic-metadata">

**Author:** [@Sankar\_S](https://discuss.elastic.co/u/Sankar_S)\
**Replies:** 6\
**Last updated:** [January 29, 2024, 12:16pm UTC](https://discuss.elastic.co/t/update-by-query-routing-orgid-performance-veryslow/351940 "2024-01-29T12:16:51Z")

</div>

Hello All, /\_update\_by\_query { "query": { "bool": { "filter": \[ { "term": { "my\_key": "myapikey" } } \] } }, "script": { "source": """ …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=319)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=321)
