# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=380

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 381

---

## [What's the equivalent of NEST TermRangeQuery in the new ES 8.x client?](https://discuss.elastic.co/t/whats-the-equivalent-of-nest-termrangequery-in-the-new-es-8-x-client/346538)

<div class="topic-metadata">

**Author:** [@yansklyarenko](https://discuss.elastic.co/u/yansklyarenko)\
**Replies:** 2\
**Last updated:** [November 7, 2023, 8:50am UTC](https://discuss.elastic.co/t/whats-the-equivalent-of-nest-termrangequery-in-the-new-es-8-x-client/346538 "2023-11-07T08:50:48Z")

</div>

The NEST client for ES 7 has TermRangeQuery class, which covers the case when the rage query is used with Text and Keyword fields. However, I can't find the equivalent in the new ES 8.x client. There's a class called Ra…

---

## [\_ingest.timestamp does not match my local time](https://discuss.elastic.co/t/ingest-timestamp-does-not-match-my-local-time/346600)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 3\
**Last updated:** [November 7, 2023, 8:15am UTC](https://discuss.elastic.co/t/ingest-timestamp-does-not-match-my-local-time/346600 "2023-11-07T08:15:47Z")

</div>

I am currently in GMT+8 time zone, I have created this pipeline so that when indexing new document, the new document is created with a timestamp PUT \_ingest/pipeline/add-current-time { "processors": \[ { "se…

---

## [Change path.data in elasticsearh cluster node](https://discuss.elastic.co/t/change-path-data-in-elasticsearh-cluster-node/346596)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 7:07am UTC](https://discuss.elastic.co/t/change-path-data-in-elasticsearh-cluster-node/346596 "2023-11-07T07:07:26Z")

</div>

May I got 3 node elasticsearch cluster. Is it possible to change the path.data If yes. What is the recommended procedure?

---

## [Extend the size of ElasticSearch path.data](https://discuss.elastic.co/t/extend-the-size-of-elasticsearch-path-data/346595)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 7:04am UTC](https://discuss.elastic.co/t/extend-the-size-of-elasticsearch-path-data/346595 "2023-11-07T07:04:00Z")

</div>

I got a elasticsearch cluster with 3 nodes. Each node got a path.data (size 5T) Which is a virtual harddisk. I would like to know is it possible to enlarge the disk storage by extend the virtual disk to 10T. If it is …

---

## [Kibana Timeseries or Area chart to split chart on two fileds value](https://discuss.elastic.co/t/kibana-timeseries-or-area-chart-to-split-chart-on-two-fileds-value/346497)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 3:43am UTC](https://discuss.elastic.co/t/kibana-timeseries-or-area-chart-to-split-chart-on-two-fileds-value/346497 "2023-11-07T03:43:07Z")

</div>

Hello All, I have a requirement for below data and not sure which visual could achieve the requirement properly.Ideal requirement is of Timeseries using TSVB or someother visual also fine.Plz let know if this is possibl…

---

## [Elastic ILM Filebeat](https://discuss.elastic.co/t/elastic-ilm-filebeat/345716)

<div class="topic-metadata">

**Author:** [@lehu](https://discuss.elastic.co/u/lehu)\
**Replies:** 4\
**Last updated:** [November 7, 2023, 5:37am UTC](https://discuss.elastic.co/t/elastic-ilm-filebeat/345716 "2023-11-07T05:37:40Z")

</div>

Hi, so I created a working lifecycle policy and I want it to apply it to the indices that are daily created by filebeat. But my filebeat configuration uses setup.template.name and setup.template.pattern and I dont want …

---

## [Duplicates logs are available on running the query for same time](https://discuss.elastic.co/t/duplicates-logs-are-available-on-running-the-query-for-same-time/346586)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 5:32am UTC](https://discuss.elastic.co/t/duplicates-logs-are-available-on-running-the-query-for-same-time/346586 "2023-11-07T05:32:03Z")

</div>

Duplicates logs are available on running the query for same time (now-1m) We are running the query for last now-1m based upon our use case however we seeing duplicates getting generated in Output. Please help with the p…

---

## [Curl ssl error to elasticsearch server via filebeat](https://discuss.elastic.co/t/curl-ssl-error-to-elasticsearch-server-via-filebeat/346420)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 2\
**Last updated:** [November 7, 2023, 4:52am UTC](https://discuss.elastic.co/t/curl-ssl-error-to-elasticsearch-server-via-filebeat/346420 "2023-11-07T04:52:57Z")

</div>

This is my filebeat output test : filebeat test output elasticsearch: https://172.10.110.29:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: 172.10.110.29 dial up..…

---

## [How to catch an exception for "Authentication using apikey failed - api key is expired"](https://discuss.elastic.co/t/how-to-catch-an-exception-for-authentication-using-apikey-failed-api-key-is-expired/346158)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 4:48am UTC](https://discuss.elastic.co/t/how-to-catch-an-exception-for-authentication-using-apikey-failed-api-key-is-expired/346158 "2023-11-07T04:48:54Z")

</div>

I am using client lib to perform a search operation. The API key used for constructing an ElasticsearchClient expired. How can I catch this specific type of "API Key expired" error, so that I can handle it, e.g. creating…

---

## [Elastic SQL CLI Error](https://discuss.elastic.co/t/elastic-sql-cli-error/345905)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 6\
**Last updated:** [November 7, 2023, 4:46am UTC](https://discuss.elastic.co/t/elastic-sql-cli-error/345905 "2023-11-07T04:46:29Z")

</div>

HI Team, I am able to connect to Elastic sql CLI but while querying the index data getting below error. Could you please help me on this. sql\> select \* from employee; Communication error \[Cannot POST address http://1…

---

## [Use search or scroll for large dataset which needs aggregations](https://discuss.elastic.co/t/use-search-or-scroll-for-large-dataset-which-needs-aggregations/346578)

<div class="topic-metadata">

**Author:** [@nboisnea1](https://discuss.elastic.co/u/nboisnea1)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 10:45pm UTC](https://discuss.elastic.co/t/use-search-or-scroll-for-large-dataset-which-needs-aggregations/346578 "2023-11-06T22:45:38Z")

</div>

Hi! I'm new to Elasticsearch and I have a particular use case for which I don't know if I should use a basic search or a scroll search. I have an index in which I periodically save a copy of JSON documents. Each JSON do…

---

## [Connection reset by peer](https://discuss.elastic.co/t/connection-reset-by-peer/346570)

<div class="topic-metadata">

**Author:** [@milindyedge](https://discuss.elastic.co/u/milindyedge)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 8:58pm UTC](https://discuss.elastic.co/t/connection-reset-by-peer/346570 "2023-11-06T20:58:22Z")

</div>

We are using Elasticsearch cloud version. We are connecting to Elasticsearch cloud using Elasticsearch java api client. However, we are getting "IOException : connection reset by peer" error randomly. It seems this error…

---

## [My Elasticsearch experiences freezing 3 to 4 times a day](https://discuss.elastic.co/t/my-elasticsearch-experiences-freezing-3-to-4-times-a-day/346438)

<div class="topic-metadata">

**Author:** [@ihatecrypto](https://discuss.elastic.co/u/ihatecrypto)\
**Replies:** 9\
**Last updated:** [November 6, 2023, 8:39pm UTC](https://discuss.elastic.co/t/my-elasticsearch-experiences-freezing-3-to-4-times-a-day/346438 "2023-11-06T20:39:49Z")

</div>

Hello everyone, I'm currently facing an issue that's not well defined. . The freezing periods last approximately 30 to 60 seconds. During these periods, I'm unable to query it using Kibana or the Nodejs client. I've…

---

## [Sorting when scoring documents with child function\_score](https://discuss.elastic.co/t/sorting-when-scoring-documents-with-child-function-score/346551)

<div class="topic-metadata">

**Author:** [@AngX](https://discuss.elastic.co/u/AngX)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 6:28pm UTC](https://discuss.elastic.co/t/sorting-when-scoring-documents-with-child-function-score/346551 "2023-11-06T18:28:45Z")

</div>

Hi all, Running into a tricky requirement when it comes to sorting in search so would appreciate getting some thoughts or advice on the matter We have two collections of documents set with a join. The child documents h…

---

## [Plugin \[analysis-icu\] was built for Elasticsearch version 8.5.0 but version 8.9.1 is running](https://discuss.elastic.co/t/plugin-analysis-icu-was-built-for-elasticsearch-version-8-5-0-but-version-8-9-1-is-running/346062)

<div class="topic-metadata">

**Author:** [@lanz](https://discuss.elastic.co/u/lanz)\
**Replies:** 5\
**Last updated:** [November 6, 2023, 5:26pm UTC](https://discuss.elastic.co/t/plugin-analysis-icu-was-built-for-elasticsearch-version-8-5-0-but-version-8-9-1-is-running/346062 "2023-11-06T17:26:15Z")

</div>

Hello, I am trying to upgrade the ELK from 8.5.0 to 8.9.1 version, Once installed 8.9.1 version, I need to install the analysis-icu\] plug-in . Therefore I have followed the steps of this link ICU analysis plugin | Elas…

---

## [Server-client search architecture with PIT in ElasticSearch](https://discuss.elastic.co/t/server-client-search-architecture-with-pit-in-elasticsearch/346545)

<div class="topic-metadata">

**Author:** [@forceson](https://discuss.elastic.co/u/forceson)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 4:41pm UTC](https://discuss.elastic.co/t/server-client-search-architecture-with-pit-in-elasticsearch/346545 "2023-11-06T16:41:58Z")

</div>

I want to use search\_after and PIT to provide consistent search results. The guide documentation suggests that PITs should be generated in the background and utilized after each search, rather than after every search. M…

---

## [SNMP with Logstash (Pipeline Error)](https://discuss.elastic.co/t/snmp-with-logstash-pipeline-error/346533)

<div class="topic-metadata">

**Author:** [@Funkster](https://discuss.elastic.co/u/Funkster)\
**Replies:** 2\
**Last updated:** [November 6, 2023, 4:03pm UTC](https://discuss.elastic.co/t/snmp-with-logstash-pipeline-error/346533 "2023-11-06T16:03:19Z")

</div>

Hello, I am trying to get SNMP-Loggin to work whithin ELK in Logstash and I get the following Error: root@vm-kibana:~# /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/logstash-snmp.conf --path.settings=/etc/lo…

---

## [Need assist with Painless scripting](https://discuss.elastic.co/t/need-assist-with-painless-scripting/345116)

<div class="topic-metadata">

**Author:** [@KristjanH](https://discuss.elastic.co/u/KristjanH)\
**Replies:** 3\
**Last updated:** [November 6, 2023, 3:58pm UTC](https://discuss.elastic.co/t/need-assist-with-painless-scripting/345116 "2023-11-06T15:58:25Z")

</div>

I'm trying to make a script that sorts text that contains text + numbers in numbering order. Example, we have the the data: "Box 1", "Box 2", "Box 3", "Box 10", "Box 20" By using normal alphabetical ordering then it w…

---

## [Multiple Pipelines with condition](https://discuss.elastic.co/t/multiple-pipelines-with-condition/346405)

<div class="topic-metadata">

**Author:** [@Manasa4](https://discuss.elastic.co/u/Manasa4)\
**Replies:** 4\
**Last updated:** [November 6, 2023, 3:44pm UTC](https://discuss.elastic.co/t/multiple-pipelines-with-condition/346405 "2023-11-06T15:44:20Z")

</div>

Hi Team, I have been trying to add a condition on my multi processor pipeline. { "4modelprocessor\_peopleagg": { "processors": \[ { "pipeline": { "name": "ner\_pipeline\_peopleagg" } }, { "pipeline": { "name": "e…

---

## [Filebeat large number of files opened](https://discuss.elastic.co/t/filebeat-large-number-of-files-opened/346433)

<div class="topic-metadata">

**Author:** [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 2:49pm UTC](https://discuss.elastic.co/t/filebeat-large-number-of-files-opened/346433 "2023-11-06T14:49:29Z")

</div>

Have issue on 1 machine sending logs from filebeat to kafka, it's lagging a lot and restarting a filebeat takes more than 45 minutes to completely restart it. - clean\_inactive: 18h close\_removed: true close\_inactive…

---

## [What is the purpose to clone the Event's fields so many times in processing event](https://discuss.elastic.co/t/what-is-the-purpose-to-clone-the-events-fields-so-many-times-in-processing-event/346526)

<div class="topic-metadata">

**Author:** [@qshuai](https://discuss.elastic.co/u/qshuai)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 1:28pm UTC](https://discuss.elastic.co/t/what-is-the-purpose-to-clone-the-events-fields-so-many-times-in-processing-event/346526 "2023-11-06T13:28:03Z")

</div>

There are many times to Clone Event's fields in processing event. The method Clone is: // Clone returns a copy of the MapStr. It recursively makes copies of inner // maps. func (m MapStr) Clone() MapStr { result := Map…

---

## [Extra Volume attached to elasticsearch but not not able to use](https://discuss.elastic.co/t/extra-volume-attached-to-elasticsearch-but-not-not-able-to-use/346512)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 12:42pm UTC](https://discuss.elastic.co/t/extra-volume-attached-to-elasticsearch-but-not-not-able-to-use/346512 "2023-11-06T12:42:49Z")

</div>

Hi, I have attached 50 gb of volume to the ec2 instance of ecs in which elasticsearch service is running.But after running GET /\_cat/allocation?v in elasticsearch shards disk.indices disk.used disk.avail disk.total dis…

---

## [Use index action to write to multiple indices](https://discuss.elastic.co/t/use-index-action-to-write-to-multiple-indices/346369)

<div class="topic-metadata">

**Author:** [@rorii](https://discuss.elastic.co/u/rorii)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 12:34pm UTC](https://discuss.elastic.co/t/use-index-action-to-write-to-multiple-indices/346369 "2023-11-06T12:34:11Z")

</div>

I have following action in my watcher: "actions": { "writetoindex": { "transform": { "script": { "id": "my\_tranform\_script", } } "index": { "index": "myindex…

---

## [Clearing the search context manually after reindexing is done](https://discuss.elastic.co/t/clearing-the-search-context-manually-after-reindexing-is-done/346517)

<div class="topic-metadata">

**Author:** [@Achyut\_Muley](https://discuss.elastic.co/u/Achyut_Muley)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 11:28am UTC](https://discuss.elastic.co/t/clearing-the-search-context-manually-after-reindexing-is-done/346517 "2023-11-06T11:28:36Z")

</div>

We have a shell script which takes the name of an index and then reindexes it. We are using ES 7.17.0 The reindex command- response=$(curl -u $CREDENTIALS -X POST "$PROTOCOL://$HOST:9200/\_reindex?slices=50&refresh&wai…

---

## [About ES8.10.4 pytorch\_inference](https://discuss.elastic.co/t/about-es8-10-4-pytorch-inference/346513)

<div class="topic-metadata">

**Author:** [@jaeho](https://discuss.elastic.co/u/jaeho)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 10:37am UTC](https://discuss.elastic.co/t/about-es8-10-4-pytorch-inference/346513 "2023-11-06T10:37:31Z")

</div>

Hello, I'm using Elasticsearch 8.10.4. I'm aiming to perform vector searches using a custom model through eland. You can find more details on this at NLP를 배포하는 방법: 텍스트 임베딩 및 벡터 검색 | Elastic Blog. I'm facing a long inde…

---

## [Prometheus exporter for Elasticsearch version 7.17.14](https://discuss.elastic.co/t/prometheus-exporter-for-elasticsearch-version-7-17-14/346510)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 10:12am UTC](https://discuss.elastic.co/t/prometheus-exporter-for-elasticsearch-version-7-17-14/346510 "2023-11-06T10:12:44Z")

</div>

Hello Team: I have upgraded Elasticsearch to version 7.17.14. We are using Prometheus - Grafana Dashboard to monitor the metrics of Elasticsearch Cluster and its Machine. I am unable to find Prometheus Exporter for El…

---

## [Kibana not working properly](https://discuss.elastic.co/t/kibana-not-working-properly/346028)

<div class="topic-metadata">

**Author:** [@chatim](https://discuss.elastic.co/u/chatim)\
**Replies:** 7\
**Last updated:** [November 6, 2023, 9:56am UTC](https://discuss.elastic.co/t/kibana-not-working-properly/346028 "2023-11-06T09:56:03Z")

</div>

Hello, I'm running a dockerized elastic cluster composed of 3 master and 3 data nodes on AWS instances, using rsyslog and logstash, i collect and store syslog events on elasticsearch index. till now everything was good…

---

## [Sending cisco switch logs to elasticsearch](https://discuss.elastic.co/t/sending-cisco-switch-logs-to-elasticsearch/346458)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 2\
**Last updated:** [November 6, 2023, 9:39am UTC](https://discuss.elastic.co/t/sending-cisco-switch-logs-to-elasticsearch/346458 "2023-11-06T09:39:36Z")

</div>

Hello community. I want to send my cisco switches logs to Elasticsearch, and we can't install elastic agent or beats to switches so what are the best ways we can send those logs to the elasticsearch.

---

## [Boolean should query wrong result](https://discuss.elastic.co/t/boolean-should-query-wrong-result/346381)

<div class="topic-metadata">

**Author:** [@Lukas\_Cern](https://discuss.elastic.co/u/Lukas_Cern)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 9:14am UTC](https://discuss.elastic.co/t/boolean-should-query-wrong-result/346381 "2023-11-06T09:14:47Z")

</div>

Depending on order of queries, there is no match (wrong) or there is a match (correct). This wrong behavior is only the case of queryes containing one of synonyms. This is my index, data and explain queries: PUT /pokus…

---

## [Configuring Lifecycle on Elastic Agent](https://discuss.elastic.co/t/configuring-lifecycle-on-elastic-agent/346499)

<div class="topic-metadata">

**Author:** [@frappo](https://discuss.elastic.co/u/frappo)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 8:33am UTC](https://discuss.elastic.co/t/configuring-lifecycle-on-elastic-agent/346499 "2023-11-06T08:33:13Z")

</div>

Hi, I am experiencing an issue with the configuration of an index lifecycle policy for my logs. The policy work perfectly on the hot-warm phase, but indices never go to cold phase. There is something I am missing?

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=379)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=381)
