# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=439

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 440

---

## [Metricbeat - Limit of total fields \[1000\] has been exceeded-urgent](https://discuss.elastic.co/t/metricbeat-limit-of-total-fields-1000-has-been-exceeded-urgent/341824)

<div class="topic-metadata">

**Author:** [@EL\_MALKI\_MOHAMED](https://discuss.elastic.co/u/EL_MALKI_MOHAMED)\
**Replies:** 5\
**Last updated:** [August 29, 2023, 12:50am UTC](https://discuss.elastic.co/t/metricbeat-limit-of-total-fields-1000-has-been-exceeded-urgent/341824 "2023-08-29T00:50:03Z")

</div>

Hello, Can u help me I have problem. I am having errors trying to ingest system metrics (system module) .The logs are ingested via a common beats pipeline running having the following configuration: logstashPipeline: …

---

## [Term negation and fuzziness](https://discuss.elastic.co/t/term-negation-and-fuzziness/341645)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 9:47pm UTC](https://discuss.elastic.co/t/term-negation-and-fuzziness/341645 "2023-08-28T21:47:49Z")

</div>

The use case is a search engine over text documents for the general public. We were previously using a simple match query, but recently switched to simple\_query\_string in order to easily support phrase matching. I'm fi…

---

## [Is it safe to delete logs-deprecation indices, where can we disable creation of these indices?](https://discuss.elastic.co/t/is-it-safe-to-delete-logs-deprecation-indices-where-can-we-disable-creation-of-these-indices/341714)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 9:34pm UTC](https://discuss.elastic.co/t/is-it-safe-to-delete-logs-deprecation-indices-where-can-we-disable-creation-of-these-indices/341714 "2023-08-28T21:34:44Z")

</div>

We have some system indices generated by ES, can we turn off generation of these indices and is it safe to delete them? health status index green open .ds-ilm-history-5-2023.06.02-000012 green open .ds-.logs-dep…

---

## [Logstash Logs output for jdbc](https://discuss.elastic.co/t/logstash-logs-output-for-jdbc/341826)

<div class="topic-metadata">

**Author:** [@nbrenke](https://discuss.elastic.co/u/nbrenke)\
**Replies:** 4\
**Last updated:** [August 28, 2023, 8:12pm UTC](https://discuss.elastic.co/t/logstash-logs-output-for-jdbc/341826 "2023-08-28T20:12:08Z")

</div>

I have a silly question:: I have several jdbc pipelines setup that pull data directly from a sql database. Short of the following that shows up in my logs \[2022-10-28T18:40:00,344\]\[INFO \]\[logstash.inputs.jdbc \] (0…

---

## [Investigate high GC time when indexing](https://discuss.elastic.co/t/investigate-high-gc-time-when-indexing/341154)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 17\
**Last updated:** [August 28, 2023, 7:42pm UTC](https://discuss.elastic.co/t/investigate-high-gc-time-when-indexing/341154 "2023-08-28T19:42:54Z")

</div>

Hello, I am looking for some advice as to why we are seeing a high GC time on our Elasticsearch cluster. On average, we see 5 - 8% of GC time across all the nodes. This is the setup we have: 150 data nodes 1000 primar…

---

## [Retrieving millions of large documents](https://discuss.elastic.co/t/retrieving-millions-of-large-documents/341803)

<div class="topic-metadata">

**Author:** [@Tomer\_Avira](https://discuss.elastic.co/u/Tomer_Avira)\
**Replies:** 6\
**Last updated:** [August 28, 2023, 6:06pm UTC](https://discuss.elastic.co/t/retrieving-millions-of-large-documents/341803 "2023-08-28T18:06:58Z")

</div>

Hello everyone, first time i am requesting your help. I am working with elastic version 8.5.3 with java client 7.17.1, let me represent you with the problem I'm having. I have daily indices with the largest of them hol…

---

## [Where is Kibana Watcher UI?](https://discuss.elastic.co/t/where-is-kibana-watcher-ui/341832)

<div class="topic-metadata">

**Author:** [@Constantine\_White](https://discuss.elastic.co/u/Constantine_White)\
**Replies:** 4\
**Last updated:** [August 28, 2023, 5:53pm UTC](https://discuss.elastic.co/t/where-is-kibana-watcher-ui/341832 "2023-08-28T17:53:43Z")

</div>

Hello Elastic forums, Could you please tell me what am I doing wrong or am I just a bit opposite of smart? I'm trying to set up Kibana alerts on logs events, I've discovered that a "Watcher" is a thing and it's (curren…

---

## [Disable logstash license check?](https://discuss.elastic.co/t/disable-logstash-license-check/341788)

<div class="topic-metadata">

**Author:** [@jacobdanielrose](https://discuss.elastic.co/u/jacobdanielrose)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 4:40pm UTC](https://discuss.elastic.co/t/disable-logstash-license-check/341788 "2023-08-28T16:40:42Z")

</div>

Hi! I am trying to connect a logstash instance to an elasticseach which is part of a deployment of IBM Cloudpak for AIOps. It uses an elasticsearch instance to store related incident data from ticket systems. The versio…

---

## [Problem multiline pattern matching](https://discuss.elastic.co/t/problem-multiline-pattern-matching/341107)

<div class="topic-metadata">

**Author:** [@mcondamin](https://discuss.elastic.co/u/mcondamin)\
**Replies:** 8\
**Last updated:** [August 28, 2023, 5:25pm UTC](https://discuss.elastic.co/t/problem-multiline-pattern-matching/341107 "2023-08-28T17:25:52Z")

</div>

Hi guys ! I defer to you because I encounter a problem concerning the configuration of the pattern to aggregate several lines of logs on the same document. Here is an excerpt from my log: 2023-08-17 16:13:15.389 |CB R…

---

## [Performance impact of setting 'namespace' in Elastic agent policy config](https://discuss.elastic.co/t/performance-impact-of-setting-namespace-in-elastic-agent-policy-config/341294)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 5:14pm UTC](https://discuss.elastic.co/t/performance-impact-of-setting-namespace-in-elastic-agent-policy-config/341294 "2023-08-28T17:14:22Z")

</div>

I have about 2000 Elastic agents (version 8.9.0) connected to a system with 3 Fleet servers (version 8.9.0). We have about 20 different agent policies, because the various Elastic agents are sending slightly different …

---

## [How to setup Cloudflare Logpush via HTTP Endpoint?](https://discuss.elastic.co/t/how-to-setup-cloudflare-logpush-via-http-endpoint/341818)

<div class="topic-metadata">

**Author:** [@nlcsdev](https://discuss.elastic.co/u/nlcsdev)\
**Replies:** 0\
**Last updated:** [August 28, 2023, 3:35pm UTC](https://discuss.elastic.co/t/how-to-setup-cloudflare-logpush-via-http-endpoint/341818 "2023-08-28T15:35:51Z")

</div>

Hello, I am trying to use the Cloudflare Logpush integration via HTTP Endpoint. I have read both the documentation on Cloudflare and Elasticsearch and I am still confused. I have Elasticsearch and Kibana 8.9.0 deployed…

---

## [How do parse log format apache access](https://discuss.elastic.co/t/how-do-parse-log-format-apache-access/341790)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 3:19pm UTC](https://discuss.elastic.co/t/how-do-parse-log-format-apache-access/341790 "2023-08-28T15:19:04Z")

</div>

Good afternoon I have a log with the format of the apache access log service (access\_log) 10.0.xx.xx - - \[28/Aug/2023:15:25:18 +0700\] "GET /xxx/en/neoclassic/cases/main HTTP/1.0" 200 2007 133793 "-" "Mozilla/5.0 (Wind…

---

## [Varying data types in object causing mapping errors](https://discuss.elastic.co/t/varying-data-types-in-object-causing-mapping-errors/341717)

<div class="topic-metadata">

**Author:** [@Wesley84](https://discuss.elastic.co/u/Wesley84)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 2:39pm UTC](https://discuss.elastic.co/t/varying-data-types-in-object-causing-mapping-errors/341717 "2023-08-28T14:39:28Z")

</div>

I have a data object called "weekly\_values" that I want to send to an existing elastic index. This object contains fields which when populated have a float data type. However these fields do not always have a value and w…

---

## [Elastic master node down, how to make slave new master?](https://discuss.elastic.co/t/elastic-master-node-down-how-to-make-slave-new-master/341568)

<div class="topic-metadata">

**Author:** [@webfr](https://discuss.elastic.co/u/webfr)\
**Replies:** 7\
**Last updated:** [August 28, 2023, 2:32pm UTC](https://discuss.elastic.co/t/elastic-master-node-down-how-to-make-slave-new-master/341568 "2023-08-28T14:32:26Z")

</div>

Hello, my master node is currently down since few days, how to make my slave new master if problem on master persists? Thanks.

---

## [Migrate elasticsearch data from 7.17 to 8.6.2 server](https://discuss.elastic.co/t/migrate-elasticsearch-data-from-7-17-to-8-6-2-server/341807)

<div class="topic-metadata">

**Author:** [@HiteshSingh](https://discuss.elastic.co/u/HiteshSingh)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 2:00pm UTC](https://discuss.elastic.co/t/migrate-elasticsearch-data-from-7-17-to-8-6-2-server/341807 "2023-08-28T14:00:19Z")

</div>

We are running elasticsearch on a single node. We are in the process of upgrading our Elasticsearch server from 7.17 to 8.6.2 and we want to migrate elasticsearch data from 7.17 to 8.6.2 version. What is the best appro…

---

## [Rust - How to use PIT?](https://discuss.elastic.co/t/rust-how-to-use-pit/341809)

<div class="topic-metadata">

**Author:** [@Frederick\_Sauvage](https://discuss.elastic.co/u/Frederick_Sauvage)\
**Replies:** 0\
**Last updated:** [August 28, 2023, 1:35pm UTC](https://discuss.elastic.co/t/rust-how-to-use-pit/341809 "2023-08-28T13:35:28Z")

</div>

Hi, I'm trying to add PIT in but I don't find how to do. My code is similar as : let client = Elasticsearch::default(); let s = client.search(SearchParts::None).size(1000).timeout("120s"); let search = Search::new().…

---

## [Setup Elasticsearch cluster mode](https://discuss.elastic.co/t/setup-elasticsearch-cluster-mode/341228)

<div class="topic-metadata">

**Author:** [@HiteshSingh](https://discuss.elastic.co/u/HiteshSingh)\
**Replies:** 13\
**Last updated:** [August 28, 2023, 1:16pm UTC](https://discuss.elastic.co/t/setup-elasticsearch-cluster-mode/341228 "2023-08-28T13:16:58Z")

</div>

I want to setup cluster mode between 2 linux servers One of them will be master and data node and other one will only be a data node. Whenever i try to setup any external IP/interfaces to transport.host, elasticsearch …

---

## [Logstash connecting to more than 1 Database](https://discuss.elastic.co/t/logstash-connecting-to-more-than-1-database/341791)

<div class="topic-metadata">

**Author:** [@Ong](https://discuss.elastic.co/u/Ong)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 1:10pm UTC](https://discuss.elastic.co/t/logstash-connecting-to-more-than-1-database/341791 "2023-08-28T13:10:00Z")

</div>

I have 2 separate MSSQL databases and would like to extract data from them, combine it and send it to ES for indexing. Can Logstash connect to more than 1 MSSQL database, retrieve certain data from them then combine the…

---

## [New python client (8.x) for sql query](https://discuss.elastic.co/t/new-python-client-8-x-for-sql-query/340083)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [August 28, 2023, 12:52pm UTC](https://discuss.elastic.co/t/new-python-client-8-x-for-sql-query/340083 "2023-08-28T12:52:50Z")

</div>

I am using sql query in my old python client 7.x and it works like this data = es.sql.query(body={"query": sql\_query1, "fetch\_size": 30000}) now using new client 8.x it give me this warning DeprecationWarning: The 'b…

---

## [Error during build for Beats version 8.9.1](https://discuss.elastic.co/t/error-during-build-for-beats-version-8-9-1/341778)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 12:25pm UTC](https://discuss.elastic.co/t/error-during-build-for-beats-version-8-9-1/341778 "2023-08-28T12:25:28Z")

</div>

Hi, I am facing the below error while building the beats repo. Please help to resolve the issue. Thanks Error: running "go build -o build/golang-crossbuild/filebeat-linux-amd64 -buildmode pie -trimpath -tags=withjourna…

---

## [Cannot retrieve search results in kibana:\[parent\] Data too large, data for \[indices:data/read/async\_search/get\]](https://discuss.elastic.co/t/cannot-retrieve-search-results-in-kibana-parent-data-too-large-data-for-indices-data-read-async-search-get/341514)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 10:24am UTC](https://discuss.elastic.co/t/cannot-retrieve-search-results-in-kibana-parent-data-too-large-data-for-indices-data-read-async-search-get/341514 "2023-08-28T10:24:16Z")

</div>

Hello All, I am facing one issue while executing a perl script from logstash and getting data,the data is configured to get from perl script execution through loh=gstash every 30 min. I am unbale to see any data in disc…

---

## [Fleet Integration Assets Fail After Upgrade to 8.9.0](https://discuss.elastic.co/t/fleet-integration-assets-fail-after-upgrade-to-8-9-0/341368)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 10:00am UTC](https://discuss.elastic.co/t/fleet-integration-assets-fail-after-upgrade-to-8-9-0/341368 "2023-08-28T10:00:56Z")

</div>

I've just upgraded our Cluster from 8.8.0 to 8.9.0 and now all the dashboards and visualizations shipping with fleet integrations are no longer working. If I try to re-install the fleet integration it fails and in the Ki…

---

## [Pls help me on Kibana Piechart Donut with center total count](https://discuss.elastic.co/t/pls-help-me-on-kibana-piechart-donut-with-center-total-count/341677)

<div class="topic-metadata">

**Author:** [@Ram\_Raj](https://discuss.elastic.co/u/Ram_Raj)\
**Replies:** 3\
**Last updated:** [August 28, 2023, 9:23am UTC](https://discuss.elastic.co/t/pls-help-me-on-kibana-piechart-donut-with-center-total-count/341677 "2023-08-28T09:23:36Z")

</div>

I have to show PieChart with center value as total count and each slice to show the value. Example like. Total number of Invoices in the center of Pie Chart and slices with invoice source like Contracts, Projects, onli…

---

## [Show data in a Dashboard/Visualization only if a condition is met - Anonymization of Data](https://discuss.elastic.co/t/show-data-in-a-dashboard-visualization-only-if-a-condition-is-met-anonymization-of-data/341495)

<div class="topic-metadata">

**Author:** [@JD11](https://discuss.elastic.co/u/JD11)\
**Replies:** 3\
**Last updated:** [August 28, 2023, 7:16am UTC](https://discuss.elastic.co/t/show-data-in-a-dashboard-visualization-only-if-a-condition-is-met-anonymization-of-data/341495 "2023-08-28T07:16:08Z")

</div>

Hi together, I have to create a visualization that MUST only show the data/graphic if a condition is met. More context to this question: In Elasticsearch we have docs containing the stock information of different bicy…

---

## [Elastic Agent tags not part of the log content](https://discuss.elastic.co/t/elastic-agent-tags-not-part-of-the-log-content/341009)

<div class="topic-metadata">

**Author:** [@raulgs](https://discuss.elastic.co/u/raulgs)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 6:07am UTC](https://discuss.elastic.co/t/elastic-agent-tags-not-part-of-the-log-content/341009 "2023-08-28T06:07:55Z")

</div>

Hi community, at my company we use managed Elastic Agents to collect logs from kubernetes. To figure out which cluster the logs belong, every cluster is labeled with a specific kubernetes label that identifies it. This…

---

## [Aggregating In Elastic Search](https://discuss.elastic.co/t/aggregating-in-elastic-search/341762)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 1\
**Last updated:** [August 27, 2023, 11:45pm UTC](https://discuss.elastic.co/t/aggregating-in-elastic-search/341762 "2023-08-27T23:45:36Z")

</div>

Hi @leandrojmp , I have a below requirement, where I need to perform aggregation based on certain fields of Elasticsearch. Documents indexed are as below PUT rollup-index/\_doc/1 { "environment" : "preview", "person…

---

## [Slicing without point in time](https://discuss.elastic.co/t/slicing-without-point-in-time/341765)

<div class="topic-metadata">

**Author:** [@kmcclellan](https://discuss.elastic.co/u/kmcclellan)\
**Replies:** 0\
**Last updated:** [August 27, 2023, 10:04pm UTC](https://discuss.elastic.co/t/slicing-without-point-in-time/341765 "2023-08-27T22:04:13Z")

</div>

When you specify "slices" for a search request, you will receive an error if the search is not a point-in-time or scrolled query: "\[slice\] can only be used with \[scroll\] or \[point-in-time\] requests". I don't quite under…

---

## [Atlassian access logs Index not getting created or data not sent / visible in Opensearch](https://discuss.elastic.co/t/atlassian-access-logs-index-not-getting-created-or-data-not-sent-visible-in-opensearch/341742)

<div class="topic-metadata">

**Author:** [@danmed](https://discuss.elastic.co/u/danmed)\
**Replies:** 29\
**Last updated:** [August 27, 2023, 8:04pm UTC](https://discuss.elastic.co/t/atlassian-access-logs-index-not-getting-created-or-data-not-sent-visible-in-opensearch/341742 "2023-08-27T20:04:18Z")

</div>

I'm trying to use Logstash to send Atlassian access logs to opensearch. I'm absolutely new to the topic but can successfully send other logs and view them. It's the jira access logs that I cannot make work. Having tri…

---

## [Elastic Agent/Beats DNS Processor Caching Bad Performance?](https://discuss.elastic.co/t/elastic-agent-beats-dns-processor-caching-bad-performance/341757)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [August 27, 2023, 4:37pm UTC](https://discuss.elastic.co/t/elastic-agent-beats-dns-processor-caching-bad-performance/341757 "2023-08-27T16:37:08Z")

</div>

Hello All, I was recently messing around with an Elastic Agent Netflow integration setup, but was noticing that events were being dropped. The integration definition looked something like: inputs: - id: netflow-netf…

---

## [Why Elastic Search allow to put number in text field?](https://discuss.elastic.co/t/why-elastic-search-allow-to-put-number-in-text-field/341756)

<div class="topic-metadata">

**Author:** [@Krzysztof\_Lempicki](https://discuss.elastic.co/u/Krzysztof_Lempicki)\
**Replies:** 1\
**Last updated:** [August 27, 2023, 3:04pm UTC](https://discuss.elastic.co/t/why-elastic-search-allow-to-put-number-in-text-field/341756 "2023-08-27T15:04:54Z")

</div>

Hi, I have mapping like this: "mappings": { "dynamic": "strict", "properties": { "name": { "typ…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=438)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=440)
