# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=404

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 405

---

## [Elasticsearch-relevance-engine and chatgpt(openAI) multi-region](https://discuss.elastic.co/t/elasticsearch-relevance-engine-and-chatgpt-openai-multi-region/344644)

<div class="topic-metadata">

**Author:** [@Wheelontrac](https://discuss.elastic.co/u/Wheelontrac)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 11:12am UTC](https://discuss.elastic.co/t/elasticsearch-relevance-engine-and-chatgpt-openai-multi-region/344644 "2023-10-09T11:12:20Z")

</div>

Hi Team, how we can take the advantage of elasticsearch-relevance-engine with chatgpt(openAI) for a use case where we have 2 Elasticsearch database which resides in 2 different regions and we want to perform a search …

---

## [Elasticsearch design feasibility](https://discuss.elastic.co/t/elasticsearch-design-feasibility/344621)

<div class="topic-metadata">

**Author:** [@mr\_zer0](https://discuss.elastic.co/u/mr_zer0)\
**Replies:** 9\
**Last updated:** [October 9, 2023, 10:15am UTC](https://discuss.elastic.co/t/elasticsearch-design-feasibility/344621 "2023-10-09T10:15:14Z")

</div>

Hello All, Would need your help in validation of few numbers, based on your experience. Would be happy to get a response or some feedback. I wanted to check if the below numbers are feasible to be handled by Elasticse…

---

## [Cannot register new repository \[local-backup\] failed to create repository](https://discuss.elastic.co/t/cannot-register-new-repository-local-backup-failed-to-create-repository/344632)

<div class="topic-metadata">

**Author:** [@Keremcan\_Seker](https://discuss.elastic.co/u/Keremcan_Seker)\
**Replies:** 1\
**Last updated:** [October 9, 2023, 9:41am UTC](https://discuss.elastic.co/t/cannot-register-new-repository-local-backup-failed-to-create-repository/344632 "2023-10-09T09:41:26Z")

</div>

i'm getting this eroor while creating a repositry for backups in docker this is my settings on compose file the path setting is on the bottom i saw from another elastic topic and created the backup directory and gi…

---

## [Duplicate logs whenever server reboots](https://discuss.elastic.co/t/duplicate-logs-whenever-server-reboots/344635)

<div class="topic-metadata">

**Author:** [@ShubhamKumarJena](https://discuss.elastic.co/u/ShubhamKumarJena)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 9:40am UTC](https://discuss.elastic.co/t/duplicate-logs-whenever-server-reboots/344635 "2023-10-09T09:40:02Z")

</div>

Hi All, I have my datascience logs on a linux machine and I use Filebeat installed on the client linux machine which forwards logs to Logstash, we parse it and forward those logs to Elasticsearch. The issue is that when…

---

## [Update a value in documents contained in different indexes](https://discuss.elastic.co/t/update-a-value-in-documents-contained-in-different-indexes/344634)

<div class="topic-metadata">

**Author:** [@Ric31](https://discuss.elastic.co/u/Ric31)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 9:19am UTC](https://discuss.elastic.co/t/update-a-value-in-documents-contained-in-different-indexes/344634 "2023-10-09T09:19:06Z")

</div>

Hello everyone! I just started studying/working in Elastic and was wondering if there is any native function that goes to update documents in all the indexes they are in when I need to update a value in a document. Ex:…

---

## [Elastic Search](https://discuss.elastic.co/t/elastic-search/343614)

<div class="topic-metadata">

**Author:** [@Gopal\_Gupta](https://discuss.elastic.co/u/Gopal_Gupta)\
**Replies:** 2\
**Last updated:** [October 9, 2023, 7:15am UTC](https://discuss.elastic.co/t/elastic-search/343614 "2023-10-09T07:15:17Z")

</div>

PROBLEM STATEMENT I am using Join field type Sample Mapping { "mappings": { "properties": { "firstname": { "type": "keyword" }, "lastname": { "type": "keyword" }, "my\_jo…

---

## [elasticSearch query\_string not applying on .keyword version of field](https://discuss.elastic.co/t/elasticsearch-query-string-not-applying-on-keyword-version-of-field/344606)

<div class="topic-metadata">

**Author:** [@cpawali](https://discuss.elastic.co/u/cpawali)\
**Replies:** 5\
**Last updated:** [October 9, 2023, 7:09am UTC](https://discuss.elastic.co/t/elasticsearch-query-string-not-applying-on-keyword-version-of-field/344606 "2023-10-09T07:09:58Z")

</div>

I am trying to query index with { "query": { "query\_string": { "query": "application\_id:app-20231008232923-0060" } } } But records with application\_id:app-20231008232923-0061 are also showing up in result Her…

---

## [Files crawling count issue in filebeat \[8.6.2\]](https://discuss.elastic.co/t/files-crawling-count-issue-in-filebeat-8-6-2/344620)

<div class="topic-metadata">

**Author:** [@rapetr2](https://discuss.elastic.co/u/rapetr2)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 6:02am UTC](https://discuss.elastic.co/t/files-crawling-count-issue-in-filebeat-8-6-2/344620 "2023-10-09T06:02:42Z")

</div>

We were previously using the filebeat version 7.17.3 and we keep on monitoring the filebeat daily to prepare the reports. Recently, we have upgraded the filebeat to version 8.6.2 and we have observed two things: We obs…

---

## [Config logstash for using kafka and jdbc input](https://discuss.elastic.co/t/config-logstash-for-using-kafka-and-jdbc-input/344612)

<div class="topic-metadata">

**Author:** [@azar\_uac](https://discuss.elastic.co/u/azar_uac)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 3:50am UTC](https://discuss.elastic.co/t/config-logstash-for-using-kafka-and-jdbc-input/344612 "2023-10-09T03:50:00Z")

</div>

How to config Logstash to get table name , index name from kafka input message and use them in jdbc input for get table data of mssql database and send table data to index of elasticsearch

---

## [【filebeat】Did Filebeat consider adding a Grok processor in the processors module?](https://discuss.elastic.co/t/filebeat-did-filebeat-consider-adding-a-grok-processor-in-the-processors-module/344610)

<div class="topic-metadata">

**Author:** [@Enha](https://discuss.elastic.co/u/Enha)\
**Replies:** 0\
**Last updated:** [October 9, 2023, 2:43am UTC](https://discuss.elastic.co/t/filebeat-did-filebeat-consider-adding-a-grok-processor-in-the-processors-module/344610 "2023-10-09T02:43:01Z")

</div>

Did Filebeat consider adding a Grok processor in the processing module? It would be very smooth to use Filebeat to format multiline data when the destination is not Elasticsearch, without the need for an additional layer…

---

## [Iframe dasboard keep reload every 5 seconds](https://discuss.elastic.co/t/iframe-dasboard-keep-reload-every-5-seconds/344526)

<div class="topic-metadata">

**Author:** [@ThaoNguyen](https://discuss.elastic.co/u/ThaoNguyen)\
**Replies:** 4\
**Last updated:** [October 9, 2023, 1:26am UTC](https://discuss.elastic.co/t/iframe-dasboard-keep-reload-every-5-seconds/344526 "2023-10-09T01:26:47Z")

</div>

I embed dashboard in my webapp and dashboard keep reload every 5 seconds with a pink loading bar at the top of frame, every time dashboard get reload all the filters I picked before are removed like timestamp (reverted …

---

## [Convert a csv file column to array of json](https://discuss.elastic.co/t/convert-a-csv-file-column-to-array-of-json/344584)

<div class="topic-metadata">

**Author:** [@Sudharsan\_Aravind](https://discuss.elastic.co/u/Sudharsan_Aravind)\
**Replies:** 1\
**Last updated:** [October 8, 2023, 8:45pm UTC](https://discuss.elastic.co/t/convert-a-csv-file-column-to-array-of-json/344584 "2023-10-08T20:45:16Z")

</div>

I have a csv file, where there is this one column with array of json. column1, column2, array\_json\_col, column4, ... item1, item2, "\[{'type': 'StillImage', 'format': 'image/jpeg', 'url',: 'https://sample.url'}, {'type':…

---

## [Centralized Kibana to fetch logstash data from multiple DC](https://discuss.elastic.co/t/centralized-kibana-to-fetch-logstash-data-from-multiple-dc/343571)

<div class="topic-metadata">

**Author:** [@Kvoyce2023](https://discuss.elastic.co/u/Kvoyce2023)\
**Replies:** 39\
**Last updated:** [October 7, 2023, 9:46pm UTC](https://discuss.elastic.co/t/centralized-kibana-to-fetch-logstash-data-from-multiple-dc/343571 "2023-10-07T21:46:49Z")

</div>

Hi everyone : I got 3 data centers where each one got its own kibana, logstash, and ES cluster with 3 ES nodes.Each DC got its own CA and certiticates which are distributed to all ES nodes. So ourl goal is to get centr…

---

## [Sharepoint sites storage reports (o365 module)](https://discuss.elastic.co/t/sharepoint-sites-storage-reports-o365-module/344600)

<div class="topic-metadata">

**Author:** [@Fabiano\_Vieira](https://discuss.elastic.co/u/Fabiano_Vieira)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 1:07pm UTC](https://discuss.elastic.co/t/sharepoint-sites-storage-reports-o365-module/344600 "2023-10-08T13:07:13Z")

</div>

Hello, I recently added the o365 integration on ELK server with my tenant(Microsoft 365 Services). It works perfeclty but I wanted to monitor the storage of my sites on Sharepoint, I didn't find any field(o365.audit\*) t…

---

## [Percolator on Elasticsearch version 8 with JAVA API](https://discuss.elastic.co/t/percolator-on-elasticsearch-version-8-with-java-api/344343)

<div class="topic-metadata">

**Author:** [@sloren](https://discuss.elastic.co/u/sloren)\
**Replies:** 3\
**Last updated:** [October 8, 2023, 9:39am UTC](https://discuss.elastic.co/t/percolator-on-elasticsearch-version-8-with-java-api/344343 "2023-10-08T09:39:01Z")

</div>

Hello, Is there a way to use the percolator in the new version of Elasticsearch (8.8.2) with the Java API? my index mapping { "my\_index\_1": { "mappings": { "dynamic": "strict", "properties": { …

---

## [Problem installation Elasticsearch - fatal exception while booting Elasticsearch java.lang.IllegalStateException: failed to obtain node locks](https://discuss.elastic.co/t/problem-installation-elasticsearch-fatal-exception-while-booting-elasticsearch-java-lang-illegalstateexception-failed-to-obtain-node-locks/344550)

<div class="topic-metadata">

**Author:** [@Andres\_Giraldo](https://discuss.elastic.co/u/Andres_Giraldo)\
**Replies:** 2\
**Last updated:** [October 8, 2023, 9:27am UTC](https://discuss.elastic.co/t/problem-installation-elasticsearch-fatal-exception-while-booting-elasticsearch-java-lang-illegalstateexception-failed-to-obtain-node-locks/344550 "2023-10-08T09:27:20Z")

</div>

Hi I am doing a new installation of elasticsearch, I have done it several times but I have changed to a server with nvme (I don't know if it is the problem) and I have not been able to do it, I am doing it through ssh, …

---

## [\[filebeat\] In Filebeat, when using the move\_fields processor with the ignore\_missing: true setting to ignore missing keys, it doesn't work as expected](https://discuss.elastic.co/t/filebeat-in-filebeat-when-using-the-move-fields-processor-with-the-ignore-missing-true-setting-to-ignore-missing-keys-it-doesnt-work-as-expected/344591)

<div class="topic-metadata">

**Author:** [@Enha](https://discuss.elastic.co/u/Enha)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 8:11am UTC](https://discuss.elastic.co/t/filebeat-in-filebeat-when-using-the-move-fields-processor-with-the-ignore-missing-true-setting-to-ignore-missing-keys-it-doesnt-work-as-expected/344591 "2023-10-08T08:11:23Z")

</div>

In Filebeat 8.10.2, when using the move\_fields processor with the ignore\_missing: true setting to ignore missing keys, it doesn't work as expected. Instead of ignoring the missing field and continuing the processing, an …

---

## [How to solve the hostname field missing in apm log?](https://discuss.elastic.co/t/how-to-solve-the-hostname-field-missing-in-apm-log/344589)

<div class="topic-metadata">

**Author:** [@TedMeng](https://discuss.elastic.co/u/TedMeng)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 6:39am UTC](https://discuss.elastic.co/t/how-to-solve-the-hostname-field-missing-in-apm-log/344589 "2023-10-08T06:39:21Z")

</div>

the same log, hostname shows in the jeager log but not in the APM log, Could you help me check what's wrong with it? Thanks very munch

---

## [Elasticsearch beats upgradations](https://discuss.elastic.co/t/elasticsearch-beats-upgradations/344586)

<div class="topic-metadata">

**Author:** [@rahul1989](https://discuss.elastic.co/u/rahul1989)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 5:26am UTC](https://discuss.elastic.co/t/elasticsearch-beats-upgradations/344586 "2023-10-08T05:26:40Z")

</div>

Hello, i have upgraded my elastic cloud from 7.x to 8.9.1 so, i have to upgrade the filebeat, logstash, metricbeats and heartbeat. this beats are running on "red hat enterprise linux" and this are the current beats ver…

---

## [Salesforce Integration with Elasticsearch cloud](https://discuss.elastic.co/t/salesforce-integration-with-elasticsearch-cloud/344585)

<div class="topic-metadata">

**Author:** [@rahul1989](https://discuss.elastic.co/u/rahul1989)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 5:11am UTC](https://discuss.elastic.co/t/salesforce-integration-with-elasticsearch-cloud/344585 "2023-10-08T05:11:48Z")

</div>

Hello, my query is i have to integrate salesforce application with Elasticsearch cloud to see the logs or data and i am using the architecture like this beats=\> logstash=\> elasticsearch \<= kibana. so, could you guide o…

---

## [Elasticsearch7 Not showing Filename /Folder name from Azure Blob Storage in Ubuntu OS](https://discuss.elastic.co/t/elasticsearch7-not-showing-filename-folder-name-from-azure-blob-storage-in-ubuntu-os/344582)

<div class="topic-metadata">

**Author:** [@muralif9](https://discuss.elastic.co/u/muralif9)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 4:07am UTC](https://discuss.elastic.co/t/elasticsearch7-not-showing-filename-folder-name-from-azure-blob-storage-in-ubuntu-os/344582 "2023-10-08T04:07:52Z")

</div>

Dear All, I have installed Elasticsearch 7 and Logstash7 in Ubuntu20.04 OS ,Logstash Data input is reading from Azure Blob Storage. The Setup is working fine but the Index in Elasticsearch not displaying the Foldernam…

---

## [\[filebeat\]Suspect Redis connection pool configuration issue causing discrepancy between maximum connection settings and actual results](https://discuss.elastic.co/t/filebeat-suspect-redis-connection-pool-configuration-issue-causing-discrepancy-between-maximum-connection-settings-and-actual-results/344578)

<div class="topic-metadata">

**Author:** [@wang-qijia](https://discuss.elastic.co/u/wang-qijia)\
**Replies:** 0\
**Last updated:** [October 8, 2023, 2:17am UTC](https://discuss.elastic.co/t/filebeat-suspect-redis-connection-pool-configuration-issue-causing-discrepancy-between-maximum-connection-settings-and-actual-results/344578 "2023-10-08T02:17:56Z")

</div>

Description: I am experiencing an issue with the maximum connection settings in Redis not matching the expected behavior. I suspect that there might be a problem with the Redis connection pool configuration. Specifical…

---

## [Reindex in elasticsearch 7.17 as pre-upgrade to 8.x](https://discuss.elastic.co/t/reindex-in-elasticsearch-7-17-as-pre-upgrade-to-8-x/344575)

<div class="topic-metadata">

**Author:** [@Indu\_Nallithodi](https://discuss.elastic.co/u/Indu_Nallithodi)\
**Replies:** 0\
**Last updated:** [October 7, 2023, 11:48pm UTC](https://discuss.elastic.co/t/reindex-in-elasticsearch-7-17-as-pre-upgrade-to-8-x/344575 "2023-10-07T23:48:24Z")

</div>

Elasticsearch team: in need of a guidancee/help Now am in a upgrade from 6.8 to 8.x(latest) Progress: Have 6.8 server with 6.8 indices(created in 5.6 and upgraded to 6.8 few years back) with multi-type Reindexed to s…

---

## [Deleting Array Element USING NEST](https://discuss.elastic.co/t/deleting-array-element-using-nest/344573)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [October 7, 2023, 7:45pm UTC](https://discuss.elastic.co/t/deleting-array-element-using-nest/344573 "2023-10-07T19:45:40Z")

</div>

Can anyone assist us in how to delete an element of an array in Elasticsearch using NEST syntax. Thanks

---

## [How Can I Open Document Explorer Graph?](https://discuss.elastic.co/t/how-can-i-open-document-explorer-graph/344565)

<div class="topic-metadata">

**Author:** [@newx](https://discuss.elastic.co/u/newx)\
**Replies:** 2\
**Last updated:** [October 7, 2023, 2:02pm UTC](https://discuss.elastic.co/t/how-can-i-open-document-explorer-graph/344565 "2023-10-07T14:02:42Z")

</div>

Hi, I created one node elastic cluster with one rollover index. This stage works very well. BUT, there is no default green counter graph with time selector(you can see from their original documents: https://www.elastic…

---

## [Date Maths in Kibana Query Language](https://discuss.elastic.co/t/date-maths-in-kibana-query-language/344556)

<div class="topic-metadata">

**Author:** [@Marcos\_Ivan\_Robles\_H](https://discuss.elastic.co/u/Marcos_Ivan_Robles_H)\
**Replies:** 2\
**Last updated:** [October 7, 2023, 2:25am UTC](https://discuss.elastic.co/t/date-maths-in-kibana-query-language/344556 "2023-10-07T02:25:40Z")

</div>

I am trying to use date math in my query without success. When I paste a KQL query on the web explorer's address bar I got a successful result with an example like this: base url + time:(from:'2023-10-06T20:44:13.558Z…

---

## [Using Date plugin to parse apache2 error log datetime](https://discuss.elastic.co/t/using-date-plugin-to-parse-apache2-error-log-datetime/344547)

<div class="topic-metadata">

**Author:** [@lobart78](https://discuss.elastic.co/u/lobart78)\
**Replies:** 2\
**Last updated:** [October 6, 2023, 11:00pm UTC](https://discuss.elastic.co/t/using-date-plugin-to-parse-apache2-error-log-datetime/344547 "2023-10-06T23:00:07Z")

</div>

Hi all ! I am trying to use Logstash to parse apache2 error logs. These logs contain a dattime in a format e.g. Fri Oct 03 09:07:41.570 2023. I have already successfully transfered this string into a field "eventfire" …

---

## [How to give specific disk threshold for specific node in a Elastic cluster](https://discuss.elastic.co/t/how-to-give-specific-disk-threshold-for-specific-node-in-a-elastic-cluster/344247)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 5\
**Last updated:** [October 6, 2023, 7:00pm UTC](https://discuss.elastic.co/t/how-to-give-specific-disk-threshold-for-specific-node-in-a-elastic-cluster/344247 "2023-10-06T19:00:03Z")

</div>

Hi, I have a multi-node cluster. I want to allocate only 100 shards to a specific node in the elastic cluster. (But other nodes should be allocated more than 100 shards.) I have one node that has less disk space than …

---

## [How to calculate EPS-Events per second in Elastic cluster](https://discuss.elastic.co/t/how-to-calculate-eps-events-per-second-in-elastic-cluster/344548)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 6:55pm UTC](https://discuss.elastic.co/t/how-to-calculate-eps-events-per-second-in-elastic-cluster/344548 "2023-10-06T18:55:27Z")

</div>

Hi, I want to calculate the average and maximum EPS in my cluster. I'm using the ELK 8.1.2 version. Thank you..! Hiruni

---

## [Documented options to disable xpack plugins in kibana not working as expected and cause container fail to start](https://discuss.elastic.co/t/documented-options-to-disable-xpack-plugins-in-kibana-not-working-as-expected-and-cause-container-fail-to-start/344529)

<div class="topic-metadata">

**Author:** [@hakakuma](https://discuss.elastic.co/u/hakakuma)\
**Replies:** 1\
**Last updated:** [October 6, 2023, 3:55pm UTC](https://discuss.elastic.co/t/documented-options-to-disable-xpack-plugins-in-kibana-not-working-as-expected-and-cause-container-fail-to-start/344529 "2023-10-06T15:55:24Z")

</div>

We are trying kibana 8.9.0 container as a standalone server for the first time and we are trying to disable certain xpack packages using kibana.yml We wanted to disable the below plugins and we are following elastic doc…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=403)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=405)
