# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=487

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 488

---

## [Dotted Lines not working for formula in LENS](https://discuss.elastic.co/t/dotted-lines-not-working-for-formula-in-lens/337613)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 5:05pm UTC](https://discuss.elastic.co/t/dotted-lines-not-working-for-formula-in-lens/337613 "2023-07-07T17:05:15Z")

</div>

Hello Team, When I am trying to put dotted lines for missing hour, LENS is not showing it for some of the Graphs. While for some of the graphs its working pretty fine. Not showing here Working here fine Can you …

---

## [Field dynamics kibana Painless](https://discuss.elastic.co/t/field-dynamics-kibana-painless/337799)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 2\
**Last updated:** [July 7, 2023, 4:57pm UTC](https://discuss.elastic.co/t/field-dynamics-kibana-painless/337799 "2023-07-07T16:57:54Z")

</div>

hello, can you help me? I have a field containing the time of a possible solution to a demand and I would like to create a dynamic field that counts how much time is left to overflow type: ''' now() - doc\['forecast'\].v…

---

## [Where to change auto\_expand\_replicas for enrich indices?](https://discuss.elastic.co/t/where-to-change-auto-expand-replicas-for-enrich-indices/337907)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 4:51pm UTC](https://discuss.elastic.co/t/where-to-change-auto-expand-replicas-for-enrich-indices/337907 "2023-07-07T16:51:51Z")

</div>

Hello, I need to change the auto\_expand\_replicas for the indices created by enrich policies, the .enrich-\* indices, but I could not find any system template with this mapping, so it seems to be hard-coded elsewhere. Cu…

---

## [Mapping flow logs with ES](https://discuss.elastic.co/t/mapping-flow-logs-with-es/337906)

<div class="topic-metadata">

**Author:** [@nishanth\_cheruku](https://discuss.elastic.co/u/nishanth_cheruku)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 4:40pm UTC](https://discuss.elastic.co/t/mapping-flow-logs-with-es/337906 "2023-07-07T16:40:14Z")

</div>

I am trying to send aws vpc flow logs from S3 to Elasticsearch by filebeats. Can anyone tell me how the mapping of fields is happening? I understand it takes the reference of elastic schema. But i still have the follow…

---

## [Plugin installation was unsuccessful due to error No kibana-enhanced-table plugins found in archive for kibana docker version 8.2.3](https://discuss.elastic.co/t/plugin-installation-was-unsuccessful-due-to-error-no-kibana-enhanced-table-plugins-found-in-archive-for-kibana-docker-version-8-2-3/337865)

<div class="topic-metadata">

**Author:** [@Piyumitha\_Nirman](https://discuss.elastic.co/u/Piyumitha_Nirman)\
**Replies:** 6\
**Last updated:** [July 7, 2023, 3:44pm UTC](https://discuss.elastic.co/t/plugin-installation-was-unsuccessful-due-to-error-no-kibana-enhanced-table-plugins-found-in-archive-for-kibana-docker-version-8-2-3/337865 "2023-07-07T15:44:36Z")

</div>

\[2/3\] RUN /usr/share/kibana/bin/kibana-plugin install https://github.com/fbaligand/kibana-enhanced-table/releases/download/v1.13.0/enhanced-table-1.13.0\_6.6.0.zip: #0 0.811 Attempting to transfer from https://github.co…

---

## [Java heap space](https://discuss.elastic.co/t/java-heap-space/337902)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 2\
**Last updated:** [July 7, 2023, 3:44pm UTC](https://discuss.elastic.co/t/java-heap-space/337902 "2023-07-07T15:44:25Z")

</div>

Hello, how to resolve this problem my jvm is 16g Thanks

---

## [How to setup logstash workers or batch size](https://discuss.elastic.co/t/how-to-setup-logstash-workers-or-batch-size/337903)

<div class="topic-metadata">

**Author:** [@lz840408](https://discuss.elastic.co/u/lz840408)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 3:22pm UTC](https://discuss.elastic.co/t/how-to-setup-logstash-workers-or-batch-size/337903 "2023-07-07T15:22:50Z")

</div>

i have es cluster 6.1.3 i want migrate data to es 7.17.9 i used logstash 7.17.9 to make it my index count has only 1200 doc my logstash config file: input { elasticsearch { hosts =\> \["10.251.0.11:39202","10.25…

---

## [SPLIT Pipeline is not working correctly](https://discuss.elastic.co/t/split-pipeline-is-not-working-correctly/337880)

<div class="topic-metadata">

**Author:** [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Replies:** 16\
**Last updated:** [July 7, 2023, 2:55pm UTC](https://discuss.elastic.co/t/split-pipeline-is-not-working-correctly/337880 "2023-07-07T14:55:56Z")

</div>

Hello All, Thanks in advance. We have configured the logstash on ServerA and pipeline is configured. All the filebeat agents are sending data successfully to ServerA. PipelinePrimary.conf To avoid delay and better l…

---

## [Move index to data warm manually](https://discuss.elastic.co/t/move-index-to-data-warm-manually/337885)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 7\
**Last updated:** [July 7, 2023, 2:53pm UTC](https://discuss.elastic.co/t/move-index-to-data-warm-manually/337885 "2023-07-07T14:53:06Z")

</div>

Hi, i can move a index from data hot to datawarm manullay with command rsync in linux from /var/lib/elasticsearch/nodes/uid(index) if the api ilm/\_move cant' work ? Thanks

---

## [Time Period for Individuals Visualization in Dash Board](https://discuss.elastic.co/t/time-period-for-individuals-visualization-in-dash-board/337845)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 4\
**Last updated:** [July 7, 2023, 2:49pm UTC](https://discuss.elastic.co/t/time-period-for-individuals-visualization-in-dash-board/337845 "2023-07-07T14:49:44Z")

</div>

Hi, I have applied a separate time span filter in one of my visualizations in the dashboard, but when I change the dashboard time period, this custom-based visualization also gets changed. I don't want this to happen. H…

---

## [Is it possible to parse NLP query on specific field?](https://discuss.elastic.co/t/is-it-possible-to-parse-nlp-query-on-specific-field/337900)

<div class="topic-metadata">

**Author:** [@learntech004](https://discuss.elastic.co/u/learntech004)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 2:34pm UTC](https://discuss.elastic.co/t/is-it-possible-to-parse-nlp-query-on-specific-field/337900 "2023-07-07T14:34:57Z")

</div>

Hi I am trying to use ELSR model. One of my requirement is - I have a view column and if user searches using a NLP query like " Give me all documents viewed more than 10 times", will the model return only those documen…

---

## [Force merge optimise in background process](https://discuss.elastic.co/t/force-merge-optimise-in-background-process/337768)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 8\
**Last updated:** [July 7, 2023, 2:33pm UTC](https://discuss.elastic.co/t/force-merge-optimise-in-background-process/337768 "2023-07-07T14:33:19Z")

</div>

Hi I need to change the force merge process in the background for count of segments. Also how I can steering/manipulating force merge. In my case I have the index which is really updating by data. So If this index is s…

---

## [Unable to send data from Otel Collector to Elasticsearch using Elastic APM](https://discuss.elastic.co/t/unable-to-send-data-from-otel-collector-to-elasticsearch-using-elastic-apm/337871)

<div class="topic-metadata">

**Author:** [@Prateek\_Kumar](https://discuss.elastic.co/u/Prateek_Kumar)\
**Replies:** 3\
**Last updated:** [July 7, 2023, 12:30pm UTC](https://discuss.elastic.co/t/unable-to-send-data-from-otel-collector-to-elasticsearch-using-elastic-apm/337871 "2023-07-07T12:30:01Z")

</div>

Hi Team, I am new to OpenTelemetry. I am trying to do setup using yaml files appraoch but facing 'connection refused' issue while connecting apm to elasticsearch. What I have achieved so far: Able to receive data in …

---

## [What is this error?](https://discuss.elastic.co/t/what-is-this-error/337869)

<div class="topic-metadata">

**Author:** [@inbeom\_cho](https://discuss.elastic.co/u/inbeom_cho)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 12:29pm UTC](https://discuss.elastic.co/t/what-is-this-error/337869 "2023-07-07T12:29:39Z")

</div>

hi all my logstash jvm config is Xms 2g Xmx 2g and 3 server and each server has 2conf file conf file is 1workers config and content is input { jdbc {oracle} } output { jdbc { postgresql} } logstash no proble…

---

## [Is it okay to use different react-router version in plugin?](https://discuss.elastic.co/t/is-it-okay-to-use-different-react-router-version-in-plugin/336874)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 8\
**Last updated:** [July 7, 2023, 12:28pm UTC](https://discuss.elastic.co/t/is-it-okay-to-use-different-react-router-version-in-plugin/336874 "2023-07-07T12:28:08Z")

</div>

Hi, I am developing a custom plugin in React. I am using a different version of React Router in my plugin, than the one being used by kibana. Kibana - react-router v5 Plugin - react-router v6 versions.json in kiban…

---

## [Java JDBC : http client did not trust this server's certificate, closing connection](https://discuss.elastic.co/t/java-jdbc-http-client-did-not-trust-this-servers-certificate-closing-connection/337421)

<div class="topic-metadata">

**Author:** [@dprutean](https://discuss.elastic.co/u/dprutean)\
**Replies:** 3\
**Last updated:** [July 7, 2023, 12:22pm UTC](https://discuss.elastic.co/t/java-jdbc-http-client-did-not-trust-this-servers-certificate-closing-connection/337421 "2023-07-07T12:22:57Z")

</div>

I created a docker container using: docker run --name elasticsearch -p 9200:9200 -p 9300:9300 -e "discovery.type=single-node" -it docker.elastic.co/elasticsearch/elasticsearch:8.8.2 This prints out the password and the…

---

## [Index routing and deletion](https://discuss.elastic.co/t/index-routing-and-deletion/337809)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 12:16pm UTC](https://discuss.elastic.co/t/index-routing-and-deletion/337809 "2023-07-07T12:16:31Z")

</div>

Hello, I hope my message finds community members and their loved ones safe and healthy. I have a three-node cluster with two nodes storing data and one being a voting-only node. The current status of the cluster is ye…

---

## [Comments field not display for some Affected Services values in Nabled Alert](https://discuss.elastic.co/t/comments-field-not-display-for-some-affected-services-values-in-nabled-alert/337879)

<div class="topic-metadata">

**Author:** [@Dana\_Pavaday](https://discuss.elastic.co/u/Dana_Pavaday)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 9:55am UTC](https://discuss.elastic.co/t/comments-field-not-display-for-some-affected-services-values-in-nabled-alert/337879 "2023-07-07T09:55:23Z")

</div>

Hello everyone, I have a dashboard (consists of Client, Hostname, AffectedService and Comments) to check the performance of Affected Services. But the Comments values are not being displayed in the dashboard for Affecte…

---

## [Increase size of JVM Heap in Elastic cloud](https://discuss.elastic.co/t/increase-size-of-jvm-heap-in-elastic-cloud/337754)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 3\
**Last updated:** [July 7, 2023, 8:58am UTC](https://discuss.elastic.co/t/increase-size-of-jvm-heap-in-elastic-cloud/337754 "2023-07-07T08:58:15Z")

</div>

Hi, I wonder if there is a way to increase the JVM Heap size of a node. I am curretly using cloud hosted Elasticsearch, and just want to increase 200mb of the heap Max size for one of my instance

---

## [ECK Stack - no persistent volumes available for this claim and no storage class is set](https://discuss.elastic.co/t/eck-stack-no-persistent-volumes-available-for-this-claim-and-no-storage-class-is-set/337875)

<div class="topic-metadata">

**Author:** [@simonebenati](https://discuss.elastic.co/u/simonebenati)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 8:53am UTC](https://discuss.elastic.co/t/eck-stack-no-persistent-volumes-available-for-this-claim-and-no-storage-class-is-set/337875 "2023-07-07T08:53:59Z")

</div>

As the title says I am not able to provision a pvc, the error is: "no persistent volumes available for this claim and no storage class is set" And therefore the describe of the elasticsearch pod says: pod has unbou…

---

## [How to visualise aggregated queries in dashboard](https://discuss.elastic.co/t/how-to-visualise-aggregated-queries-in-dashboard/337873)

<div class="topic-metadata">

**Author:** [@Feelec](https://discuss.elastic.co/u/Feelec)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 8:44am UTC](https://discuss.elastic.co/t/how-to-visualise-aggregated-queries-in-dashboard/337873 "2023-07-07T08:44:27Z")

</div>

Hi all, I'm using OpenSearch v 2.5.0 with Kibana and I'm trying to visualise a metric which is a calculation of the count of duplicated ID's and then determine the average of this count. I can get the value in Dev Tools…

---

## [How to update preconfigured fleet agent policies](https://discuss.elastic.co/t/how-to-update-preconfigured-fleet-agent-policies/337801)

<div class="topic-metadata">

**Author:** [@GeorgeGkinis](https://discuss.elastic.co/u/GeorgeGkinis)\
**Replies:** 2\
**Last updated:** [July 7, 2023, 7:10am UTC](https://discuss.elastic.co/t/how-to-update-preconfigured-fleet-agent-policies/337801 "2023-07-07T07:10:15Z")

</div>

Hi, I have a question regarding on how to update preconfigured agent policies residing in kibana.yml. We deploy on ECK and our stack is version 8.8.1. The first time we deploy kibana the preconfigured policies residin…

---

## [Reindexing failed with TAG Mismatch Exception](https://discuss.elastic.co/t/reindexing-failed-with-tag-mismatch-exception/335839)

<div class="topic-metadata">

**Author:** [@awenest](https://discuss.elastic.co/u/awenest)\
**Replies:** 2\
**Last updated:** [July 7, 2023, 5:23am UTC](https://discuss.elastic.co/t/reindexing-failed-with-tag-mismatch-exception/335839 "2023-07-07T05:23:55Z")

</div>

I have increased the socket timeout to 15 minutes since I am trying to reindex ~ 40k records. But within 6 minutes I get below exception : Caused by: org.springframework.dao.DataAccessResourceFailureException: Tag mism…

---

## [Winlogbeat Fatal Error 8.7.0+ name already used](https://discuss.elastic.co/t/winlogbeat-fatal-error-8-7-0-name-already-used/337093)

<div class="topic-metadata">

**Author:** [@dwissm1](https://discuss.elastic.co/u/dwissm1)\
**Replies:** 12\
**Last updated:** [July 7, 2023, 12:33am UTC](https://discuss.elastic.co/t/winlogbeat-fatal-error-8-7-0-name-already-used/337093 "2023-07-07T00:33:28Z")

</div>

Hey Folks, Running into some fatal errors with Winlogbeat. Started happening around 8.7.0 and I am now getting to try to fix it. I was on 8.6.2 and and was working fine, anything 8.7+ it has a fatal error but if I go …

---

## [How work many output jdbc at same time?](https://discuss.elastic.co/t/how-work-many-output-jdbc-at-same-time/337746)

<div class="topic-metadata">

**Author:** [@inbeom\_cho](https://discuss.elastic.co/u/inbeom_cho)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 12:10am UTC](https://discuss.elastic.co/t/how-work-many-output-jdbc-at-same-time/337746 "2023-07-07T00:10:47Z")

</div>

hi all, my pipelines.yml - pipeline.id: test1 pipeline.workers: 1 path.config: "/app/logstash/config/conf.d/test1.conf" - pipeline.id: test2 pipeline.workers: 1 path.config: "/app/logstash/config/conf.d/test2.c…

---

## [MountVolume.SetUp failed for volume "elasticsearch-master-certs" : secret "elasticsearch-master-certs" not found](https://discuss.elastic.co/t/mountvolume-setup-failed-for-volume-elasticsearch-master-certs-secret-elasticsearch-master-certs-not-found/337850)

<div class="topic-metadata">

**Author:** [@Shikder\_Reyad](https://discuss.elastic.co/u/Shikder_Reyad)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 11:58pm UTC](https://discuss.elastic.co/t/mountvolume-setup-failed-for-volume-elasticsearch-master-certs-secret-elasticsearch-master-certs-not-found/337850 "2023-07-06T23:58:43Z")

</div>

Warning FailedMount 5s (x8 over 69s) kubelet MountVolume.SetUp failed for volume "elasticsearch-master-certs" : secret "elasticsearch-master-certs" not found container create stuck filebeat-filebeat-bvbnl…

---

## [Regarding the ranking of the inspection results of elasticsearch](https://discuss.elastic.co/t/regarding-the-ranking-of-the-inspection-results-of-elasticsearch/337424)

<div class="topic-metadata">

**Author:** [@kimjinyoung](https://discuss.elastic.co/u/kimjinyoung)\
**Replies:** 4\
**Last updated:** [July 6, 2023, 11:52pm UTC](https://discuss.elastic.co/t/regarding-the-ranking-of-the-inspection-results-of-elasticsearch/337424 "2023-07-06T23:52:02Z")

</div>

hi! I would like to ask you about Elasticsearch's test result ranking. "If there is ""kimchy"" in the data below." user.id kimchy\_00 kimchy\_01 kimchy\_02 .. kimchy\_50 example of elasticsearch below GET /\_search { "…

---

## [Downloading the kibana report from outside](https://discuss.elastic.co/t/downloading-the-kibana-report-from-outside/337784)

<div class="topic-metadata">

**Author:** [@Vatsal\_Sharma](https://discuss.elastic.co/u/Vatsal_Sharma)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 10:01pm UTC](https://discuss.elastic.co/t/downloading-the-kibana-report-from-outside/337784 "2023-07-06T22:01:41Z")

</div>

I was trying to download report from kibana in csv format, from the discover section and outside kibana, I used the post url and as per documentation generated a path where the kibana report is there as wrtten in the doc…

---

## [Why \`/\_cat/indices\` shows system indices?](https://discuss.elastic.co/t/why-cat-indices-shows-system-indices/337837)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 10:00pm UTC](https://discuss.elastic.co/t/why-cat-indices-shows-system-indices/337837 "2023-07-06T22:00:44Z")

</div>

The system indices have names starting with a dot, like .xxxxxx. And usually, the command GET \_cat/indices/\_all does not show the system indices, so they are hidden by default. For learning purposes, we recently went th…

---

## [Help understanding boolean query and boosting?](https://discuss.elastic.co/t/help-understanding-boolean-query-and-boosting/337842)

<div class="topic-metadata">

**Author:** [@reswob](https://discuss.elastic.co/u/reswob)\
**Replies:** 2\
**Last updated:** [July 6, 2023, 9:22pm UTC](https://discuss.elastic.co/t/help-understanding-boolean-query-and-boosting/337842 "2023-07-06T21:22:52Z")

</div>

So I'm doing some self training in my lab. I wanted to create a query looking for value A in field A OR value B in field B and return all records that met that either criteria. Value A is type long and value B is text …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=486)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=488)
