# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=346

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 347

---

## [Create an alert in Kibata when no documents are received](https://discuss.elastic.co/t/create-an-alert-in-kibata-when-no-documents-are-received/349787)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 1\
**Last updated:** [December 21, 2023, 4:36pm UTC](https://discuss.elastic.co/t/create-an-alert-in-kibata-when-no-documents-are-received/349787 "2023-12-21T16:36:15Z")

</div>

I want to create an Alert when no new documents (of a certain type) are created in an index for a certain amount if time. What is the best wat to achieve this? And It would be nice to in corporate this in the standard A…

---

## [Osquery yara rules](https://discuss.elastic.co/t/osquery-yara-rules/349795)

<div class="topic-metadata">

**Author:** [@sh1dow3r](https://discuss.elastic.co/u/sh1dow3r)\
**Replies:** 0\
**Last updated:** [December 21, 2023, 12:57pm UTC](https://discuss.elastic.co/t/osquery-yara-rules/349795 "2023-12-21T12:57:35Z")

</div>

Hey there.. I've already tried slack but no luck; hopefully someone here has encounter this issue and solved it. I have over 50 yara rules stored on gitlab in one file that I want to sweep the environment with the elas…

---

## [How to reshard the indices to overcome latency during high traffic in elasticsearch cluster](https://discuss.elastic.co/t/how-to-reshard-the-indices-to-overcome-latency-during-high-traffic-in-elasticsearch-cluster/349677)

<div class="topic-metadata">

**Author:** [@Karthikeyan\_Amaresan](https://discuss.elastic.co/u/Karthikeyan_Amaresan)\
**Replies:** 2\
**Last updated:** [December 21, 2023, 10:44am UTC](https://discuss.elastic.co/t/how-to-reshard-the-indices-to-overcome-latency-during-high-traffic-in-elasticsearch-cluster/349677 "2023-12-21T10:44:08Z")

</div>

During high traffic times, our Elasticsearch cluster is experiencing latency, and we are considering a resharding strategy to optimize performance. Below is our current index setup and the proposed resharding plan: Curr…

---

## [How to use timefilter element to filter time and affect to some element that integrate with itself?](https://discuss.elastic.co/t/how-to-use-timefilter-element-to-filter-time-and-affect-to-some-element-that-integrate-with-itself/349781)

<div class="topic-metadata">

**Author:** [@Dy\_Vanrith](https://discuss.elastic.co/u/Dy_Vanrith)\
**Replies:** 0\
**Last updated:** [December 21, 2023, 9:40am UTC](https://discuss.elastic.co/t/how-to-use-timefilter-element-to-filter-time-and-affect-to-some-element-that-integrate-with-itself/349781 "2023-12-21T09:40:22Z")

</div>

Example i have 2 element One element for report canvas base on date that i want to filter filters | essql query= { string "SELECT \* FROM "2023.12.\*" " } | markdown " {{#each rows}} Total Rejected Total Retract …

---

## [Extracting nested fileds with grok or kv](https://discuss.elastic.co/t/extracting-nested-fileds-with-grok-or-kv/349766)

<div class="topic-metadata">

**Author:** [@cass1ope1a](https://discuss.elastic.co/u/cass1ope1a)\
**Replies:** 0\
**Last updated:** [December 21, 2023, 7:29am UTC](https://discuss.elastic.co/t/extracting-nested-fileds-with-grok-or-kv/349766 "2023-12-21T07:29:38Z")

</div>

I have logs like: Server response. Body={"valid":\[{"someId":"12345","someType":"somevalue123","isSome":true}\],"invalid":\[\]} current pipeline config: if \[syslog\_tag\] =~ "json" { json { source =\> root\_…

---

## [Dashboard level DSL filter does not work for Vega/Aggregate charts](https://discuss.elastic.co/t/dashboard-level-dsl-filter-does-not-work-for-vega-aggregate-charts/349746)

<div class="topic-metadata">

**Author:** [@xiyuewan](https://discuss.elastic.co/u/xiyuewan)\
**Replies:** 3\
**Last updated:** [December 20, 2023, 10:48pm UTC](https://discuss.elastic.co/t/dashboard-level-dsl-filter-does-not-work-for-vega-aggregate-charts/349746 "2023-12-20T22:48:25Z")

</div>

Hello - I have a dashboard level DSL filter (geo filter) and it won't apply to aggregate charts and vega charts, but works fine for Lens. Is this expected?

---

## [Create a Java Query from a DSL terms query](https://discuss.elastic.co/t/create-a-java-query-from-a-dsl-terms-query/349584)

<div class="topic-metadata">

**Author:** [@Edgar\_Osorio](https://discuss.elastic.co/u/Edgar_Osorio)\
**Replies:** 2\
**Last updated:** [December 20, 2023, 9:52pm UTC](https://discuss.elastic.co/t/create-a-java-query-from-a-dsl-terms-query/349584 "2023-12-20T21:52:46Z")

</div>

Given the following Query { "query":{ "bool" : { "must" : \[ { "terms" : { "\_id" : \["8606874","21387518","16704862","23947520","23897437","1050114","24967566","50356…

---

## [Question about parsed files](https://discuss.elastic.co/t/question-about-parsed-files/349747)

<div class="topic-metadata">

**Author:** [@astateofmind](https://discuss.elastic.co/u/astateofmind)\
**Replies:** 1\
**Last updated:** [December 20, 2023, 7:08pm UTC](https://discuss.elastic.co/t/question-about-parsed-files/349747 "2023-12-20T19:08:46Z")

</div>

Quite simple: If I configure a bunch of log files as paths and I apply that config to a diverse set of servers (so some servers will not have some of those log files) will that affect performance or anything? Lets say …

---

## [Persistent ECS warning](https://discuss.elastic.co/t/persistent-ecs-warning/349743)

<div class="topic-metadata">

**Author:** [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)\
**Replies:** 3\
**Last updated:** [December 20, 2023, 6:03pm UTC](https://discuss.elastic.co/t/persistent-ecs-warning/349743 "2023-12-20T18:03:45Z")

</div>

logstash 8.11.3 Can anyone tell me why with the following config, and everything else at the default install, why I continue to get the \[logstash.codecs.jsonlines\] ECS compatibility is enabled but \`target\` option was n…

---

## [Time-series data out of order](https://discuss.elastic.co/t/time-series-data-out-of-order/349741)

<div class="topic-metadata">

**Author:** [@lkw](https://discuss.elastic.co/u/lkw)\
**Replies:** 0\
**Last updated:** [December 20, 2023, 4:54pm UTC](https://discuss.elastic.co/t/time-series-data-out-of-order/349741 "2023-12-20T16:54:21Z")

</div>

I have a data stream in use for some custom application logs. There are about 10 months of logs in it and a handful of rolled-over backing indices. I also have about 3 years worth of historic application logs that I'd l…

---

## [How to add permission for short url for user?](https://discuss.elastic.co/t/how-to-add-permission-for-short-url-for-user/349713)

<div class="topic-metadata">

**Author:** [@PeLbmaN](https://discuss.elastic.co/u/PeLbmaN)\
**Replies:** 1\
**Last updated:** [December 20, 2023, 4:23pm UTC](https://discuss.elastic.co/t/how-to-add-permission-for-short-url-for-user/349713 "2023-12-20T16:23:04Z")

</div>

I have a question about how to add the ability to create short links, which role is responsible for this (I have a basic license)?

---

## [How to select multiple new index patterns in Kiban](https://discuss.elastic.co/t/how-to-select-multiple-new-index-patterns-in-kiban/349456)

<div class="topic-metadata">

**Author:** [@Satsan](https://discuss.elastic.co/u/Satsan)\
**Replies:** 2\
**Last updated:** [December 20, 2023, 3:58pm UTC](https://discuss.elastic.co/t/how-to-select-multiple-new-index-patterns-in-kiban/349456 "2023-12-20T15:58:24Z")

</div>

How to efficiently add or select multiple new index patterns in Kibana? I need to incorporate over 90 + directory logs into the Kibana dashboard. Manually adding the index pattern for each of them is time-consuming. Is t…

---

## [Enrich document with data from same index](https://discuss.elastic.co/t/enrich-document-with-data-from-same-index/349705)

<div class="topic-metadata">

**Author:** [@rickardo](https://discuss.elastic.co/u/rickardo)\
**Replies:** 8\
**Last updated:** [December 20, 2023, 3:37pm UTC](https://discuss.elastic.co/t/enrich-document-with-data-from-same-index/349705 "2023-12-20T15:37:31Z")

</div>

Hi, we got one index that we insert documents where one can follow e.g. a session and what is done, i.e.: document 1; sessionId = 17 type=created country=DE document 2: sessionId = 17 type=action now at insertion…

---

## [Logstash with ouput clickhouse plugin more than 80% logs are missing](https://discuss.elastic.co/t/logstash-with-ouput-clickhouse-plugin-more-than-80-logs-are-missing/349724)

<div class="topic-metadata">

**Author:** [@Anandh\_Kumar1](https://discuss.elastic.co/u/Anandh_Kumar1)\
**Replies:** 1\
**Last updated:** [December 20, 2023, 2:58pm UTC](https://discuss.elastic.co/t/logstash-with-ouput-clickhouse-plugin-more-than-80-logs-are-missing/349724 "2023-12-20T14:58:11Z")

</div>

I am using logstash version 7.17.15 in production environment, In that i am using the ouput plugin is clickhouse and the version is 20.8.3.18. Using the filebeat I am moving the logs into logstash which is there is remo…

---

## [Stack\_Elasticsearch\_Log\_Kibana7.17.15](https://discuss.elastic.co/t/stack-elasticsearch-log-kibana7-17-15/349714)

<div class="topic-metadata">

**Author:** [@sossoulokoariel](https://discuss.elastic.co/u/sossoulokoariel)\
**Replies:** 4\
**Last updated:** [December 20, 2023, 2:57pm UTC](https://discuss.elastic.co/t/stack-elasticsearch-log-kibana7-17-15/349714 "2023-12-20T14:57:12Z")

</div>

Help me

---

## [Bucket aggregation with java api version 8.11](https://discuss.elastic.co/t/bucket-aggregation-with-java-api-version-8-11/349729)

<div class="topic-metadata">

**Author:** [@Darth\_vader\_22](https://discuss.elastic.co/u/Darth_vader_22)\
**Replies:** 0\
**Last updated:** [December 20, 2023, 1:54pm UTC](https://discuss.elastic.co/t/bucket-aggregation-with-java-api-version-8-11/349729 "2023-12-20T13:54:51Z")

</div>

Hi everyone ! can anyone please help me convert below query in java i'm struggling with the aggregation part i have been stuck to this for days now , any help would be appreciated { "query": {}, "aggregations": { "a…

---

## [Change number of shards and refresh interval for all datastreams of Elastic Agent](https://discuss.elastic.co/t/change-number-of-shards-and-refresh-interval-for-all-datastreams-of-elastic-agent/349725)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 0\
**Last updated:** [December 20, 2023, 1:14pm UTC](https://discuss.elastic.co/t/change-number-of-shards-and-refresh-interval-for-all-datastreams-of-elastic-agent/349725 "2023-12-20T13:14:35Z")

</div>

Hello, Currently all the data collected by the Elastic Agent integrations uses a default number of shards of 1 and a refresh interval of 1s, those configurations are not optimal for our use case and are starting to impa…

---

## [Installation of logstash-output-opensearch in an airgap environment(no internet access on server)](https://discuss.elastic.co/t/installation-of-logstash-output-opensearch-in-an-airgap-environment-no-internet-access-on-server/349717)

<div class="topic-metadata">

**Author:** [@kushak\_kain](https://discuss.elastic.co/u/kushak_kain)\
**Replies:** 2\
**Last updated:** [December 20, 2023, 12:34pm UTC](https://discuss.elastic.co/t/installation-of-logstash-output-opensearch-in-an-airgap-environment-no-internet-access-on-server/349717 "2023-12-20T12:34:06Z")

</div>

Hello Experts, I need your assistance in installing logstash-output-opensearch in an airgap environment(our servers can not connect to internet) We are receiving the following error while executing the command : ./log…

---

## [Using elastic client with latest version for various operations](https://discuss.elastic.co/t/using-elastic-client-with-latest-version-for-various-operations/349678)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 1\
**Last updated:** [December 20, 2023, 9:10am UTC](https://discuss.elastic.co/t/using-elastic-client-with-latest-version-for-various-operations/349678 "2023-12-20T09:10:17Z")

</div>

Hi, I am trying to migrate my java client to 8.11 stack from 7.17. Earlier, I had to pass auth token as request options in all requests. Now, there are so many incompatible methods where I dont see option to pass reque…

---

## [Delete (or retain) specific documents from ILM-frozen searchable snapshot](https://discuss.elastic.co/t/delete-or-retain-specific-documents-from-ilm-frozen-searchable-snapshot/349698)

<div class="topic-metadata">

**Author:** [@maxboone](https://discuss.elastic.co/u/maxboone)\
**Replies:** 0\
**Last updated:** [December 20, 2023, 8:54am UTC](https://discuss.elastic.co/t/delete-or-retain-specific-documents-from-ilm-frozen-searchable-snapshot/349698 "2023-12-20T08:54:30Z")

</div>

Hey ELKers, We're running logging through Elastic but weren't very specific on our log indexes and had Elastic Agent pump all the logs in logs-kubernetes.container\_logs. Most of these logs have by now rotated through to…

---

## [Relation between shard size and sum of its segments size](https://discuss.elastic.co/t/relation-between-shard-size-and-sum-of-its-segments-size/349671)

<div class="topic-metadata">

**Author:** [@Tommaso\_Parisi](https://discuss.elastic.co/u/Tommaso_Parisi)\
**Replies:** 1\
**Last updated:** [December 20, 2023, 7:35am UTC](https://discuss.elastic.co/t/relation-between-shard-size-and-sum-of-its-segments-size/349671 "2023-12-20T07:35:00Z")

</div>

Hello, I was under the assumption that the disk space used by a shard is the sum of the disk space of its segments. I have and index with 1 Million document and 3 shards and it seems to me that this is not true. Can so…

---

## [Elastic Search becomes unresponsive after some time](https://discuss.elastic.co/t/elastic-search-becomes-unresponsive-after-some-time/348311)

<div class="topic-metadata">

**Author:** [@EVINDX](https://discuss.elastic.co/u/EVINDX)\
**Replies:** 2\
**Last updated:** [December 20, 2023, 7:34am UTC](https://discuss.elastic.co/t/elastic-search-becomes-unresponsive-after-some-time/348311 "2023-12-20T07:34:22Z")

</div>

We are facing issues with the Elasticsearch in the production environment where Elasticsearch stops responding intermittently and service needs to be restarted in-order to recover from this state. Logs collected from El…

---

## [How do I add a custom dashboard with charts for latency, throughput, and transaction failure rate in APM Service?](https://discuss.elastic.co/t/how-do-i-add-a-custom-dashboard-with-charts-for-latency-throughput-and-transaction-failure-rate-in-apm-service/349635)

<div class="topic-metadata">

**Author:** [@Mang-Joo](https://discuss.elastic.co/u/Mang-Joo)\
**Replies:** 2\
**Last updated:** [December 20, 2023, 6:38am UTC](https://discuss.elastic.co/t/how-do-i-add-a-custom-dashboard-with-charts-for-latency-throughput-and-transaction-failure-rate-in-apm-service/349635 "2023-12-20T06:38:58Z")

</div>

Hello People. The version of elk stack is 8.8.0 I want to clone chart in apm service overview (Latency, Throughput, Failed transaction rate and Time spent by span type) Is there a way to add these metrics in a custom …

---

## [High CPU Utilization - Tune performance](https://discuss.elastic.co/t/high-cpu-utilization-tune-performance/349691)

<div class="topic-metadata">

**Author:** [@castroivan](https://discuss.elastic.co/u/castroivan)\
**Replies:** 0\
**Last updated:** [December 20, 2023, 5:37am UTC](https://discuss.elastic.co/t/high-cpu-utilization-tune-performance/349691 "2023-12-20T05:37:14Z")

</div>

Hi team, First time posting a topic in here. I have a 6-node cluster which look like this: heap.percent ram.percent cpu load\_1m load\_5m load\_15m node.role master name 31 92 18 9.53 8.86 8…

---

## [Sql query returns nothing , but output file udpated](https://discuss.elastic.co/t/sql-query-returns-nothing-but-output-file-udpated/349622)

<div class="topic-metadata">

**Author:** [@gayatri\_SN](https://discuss.elastic.co/u/gayatri_SN)\
**Replies:** 3\
**Last updated:** [December 20, 2023, 5:28am UTC](https://discuss.elastic.co/t/sql-query-returns-nothing-but-output-file-udpated/349622 "2023-12-20T05:28:21Z")

</div>

Hi, I'm using jdbc input streaming filter to get the data from query. but in some cases query returns empty or null value. \< last\_run\_metadata\_path =\> \<filepath/sql\_last\_value.yml statement\_filepath =\> \<filepath/quer…

---

## [Date Mapping Template Not Being Applied Correctly](https://discuss.elastic.co/t/date-mapping-template-not-being-applied-correctly/349469)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 6\
**Last updated:** [December 19, 2023, 11:28pm UTC](https://discuss.elastic.co/t/date-mapping-template-not-being-applied-correctly/349469 "2023-12-19T23:28:10Z")

</div>

Hi, I'm receiving the following data set into ES from Logstash: { "fields": { "date-code": "180502", "form-factor": "FORM1", "serial-no": "1122334455", "vendor": "VENDOR-PRE", "vendor-part": "PART…

---

## [Reindex after Shrink to rename index (to the original one)?](https://discuss.elastic.co/t/reindex-after-shrink-to-rename-index-to-the-original-one/349606)

<div class="topic-metadata">

**Author:** [@HyebinHong](https://discuss.elastic.co/u/HyebinHong)\
**Replies:** 2\
**Last updated:** [December 19, 2023, 11:45pm UTC](https://discuss.elastic.co/t/reindex-after-shrink-to-rename-index-to-the-original-one/349606 "2023-12-19T23:45:23Z")

</div>

Hello, Elastic! According to my former question, I realized I need to change my settings related to shards and replicas. (Huge thanks to @Christian\_Dahlqvist ) Here is my former question Reducing replica was easy with…

---

## [Error when start the elastics services](https://discuss.elastic.co/t/error-when-start-the-elastics-services/349682)

<div class="topic-metadata">

**Author:** [@Antonio\_Sanchez](https://discuss.elastic.co/u/Antonio_Sanchez)\
**Replies:** 1\
**Last updated:** [December 19, 2023, 10:54pm UTC](https://discuss.elastic.co/t/error-when-start-the-elastics-services/349682 "2023-12-19T22:54:28Z")

</div>

Hello I'm installing a elastics services on a server ubuntu 22.4 but when I start the services I recibet the next error: \[sudo\] password for toor: Job for elasticsearch.service failed because the control process exite…

---

## [Max Window Size is Set to 10000 but the Terms aggregations is giving single filter value larger than max window size.](https://discuss.elastic.co/t/max-window-size-is-set-to-10000-but-the-terms-aggregations-is-giving-single-filter-value-larger-than-max-window-size/348924)

<div class="topic-metadata">

**Author:** [@santhosh.linga](https://discuss.elastic.co/u/santhosh.linga)\
**Replies:** 11\
**Last updated:** [December 19, 2023, 10:30pm UTC](https://discuss.elastic.co/t/max-window-size-is-set-to-10000-but-the-terms-aggregations-is-giving-single-filter-value-larger-than-max-window-size/348924 "2023-12-19T22:30:18Z")

</div>

We have created an index and are querying the index to display the complete dataset. However, we have encountered performance issues, as we are dealing with 1 million records in response to user search queries. To addres…

---

## [Custom TCP integration with TLS](https://discuss.elastic.co/t/custom-tcp-integration-with-tls/349679)

<div class="topic-metadata">

**Author:** [@CodeMonky](https://discuss.elastic.co/u/CodeMonky)\
**Replies:** 4\
**Last updated:** [December 19, 2023, 10:10pm UTC](https://discuss.elastic.co/t/custom-tcp-integration-with-tls/349679 "2023-12-19T22:10:42Z")

</div>

Good day all. I hope this is a simple question, but I've not been able to find any info. For the custom TCP integration that can be used when there's not an Elastic provided integration to use for data ingestion: does i…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=345)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=347)
