# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=506

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 507

---

## [Elasticsearch backup](https://discuss.elastic.co/t/elasticsearch-backup/335848)

<div class="topic-metadata">

**Author:** [@Akshay\_Patidar](https://discuss.elastic.co/u/Akshay_Patidar)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 4:30am UTC](https://discuss.elastic.co/t/elasticsearch-backup/335848 "2023-06-20T04:30:10Z")

</div>

As specific date interval for slm policy in not possible so what is the alternative way for taking backup of Elasticsearch for specific date interval Example : like I wanted to take backup daily from 15/06 to 30/06

---

## [Enrichment doesn't work sometimes](https://discuss.elastic.co/t/enrichment-doesnt-work-sometimes/336366)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 4:27am UTC](https://discuss.elastic.co/t/enrichment-doesnt-work-sometimes/336366 "2023-06-20T04:27:43Z")

</div>

Currently we have a situation where the enrichment processor of the elasticsearch ingest pipeline doesn't always work. Elastic-Stack: 8.8.1 The syslog messages have the identical structure and are parsed correctly. …

---

## [Switching 'cluster.routing.allocation' between node-upgrades](https://discuss.elastic.co/t/switching-cluster-routing-allocation-between-node-upgrades/335843)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 4:26am UTC](https://discuss.elastic.co/t/switching-cluster-routing-allocation-between-node-upgrades/335843 "2023-06-20T04:26:49Z")

</div>

We have a three-node cluster onprem, and during rolling upgrade of the individual Elastic-nodes, we tend to toggle 'cluster.routing.allocation.enable' between 'primaries' and null. Is this necessary to do between each i…

---

## [Multiple child inastances of a single client or multiple clients, which is better for bulk indexing in large rates?](https://discuss.elastic.co/t/multiple-child-inastances-of-a-single-client-or-multiple-clients-which-is-better-for-bulk-indexing-in-large-rates/336293)

<div class="topic-metadata">

**Author:** [@shameel](https://discuss.elastic.co/u/shameel)\
**Replies:** 6\
**Last updated:** [June 20, 2023, 4:23am UTC](https://discuss.elastic.co/t/multiple-child-inastances-of-a-single-client-or-multiple-clients-which-is-better-for-bulk-indexing-in-large-rates/336293 "2023-06-20T04:23:26Z")

</div>

Hi Im using Elasticsearch v7.5.0 and I have a huge number of documents being ingested per second, as per the documentation it is recommended to use multiple clients for bulk indexing to reduce load. Can I get the same re…

---

## [\[percolate\_query\] mapping for \`percolator type\` in script(painless)](https://discuss.elastic.co/t/percolate-query-mapping-for-percolator-type-in-script-painless/336408)

<div class="topic-metadata">

**Author:** [@SEUNGHYO](https://discuss.elastic.co/u/SEUNGHYO)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 12:38am UTC](https://discuss.elastic.co/t/percolate-query-mapping-for-percolator-type-in-script-painless/336408 "2023-06-20T00:38:20Z")

</div>

Hello I'm Checking how to update "percolate query" \> "percolator type" field through \_update\_by\_query. But, # Create Index PUT test\_shlee\_percolate\_20230619 { "mappings": { "properties": { "pa001": { …

---

## [Elastic agent and port mirroring](https://discuss.elastic.co/t/elastic-agent-and-port-mirroring/336185)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 12:31am UTC](https://discuss.elastic.co/t/elastic-agent-and-port-mirroring/336185 "2023-06-20T00:31:36Z")

</div>

If i have a server that i make it as destination of port mirroring how can i use this mirrored traffic to ingest it in elastic agent to parse it and deliver it to Elasticsearch.

---

## [Multiple index templates may not match during index creation](https://discuss.elastic.co/t/multiple-index-templates-may-not-match-during-index-creation/336186)

<div class="topic-metadata">

**Author:** [@alpine\_f1](https://discuss.elastic.co/u/alpine_f1)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 12:30am UTC](https://discuss.elastic.co/t/multiple-index-templates-may-not-match-during-index-creation/336186 "2023-06-20T00:30:15Z")

</div>

Hello, We are currently running Elastic v7.17 as docker containers in my organization. I tried upgrading to 8.7.1 and during deployment , I am getting below errors and the containers are down. How should I address t…

---

## [Can I have mutiple key-value pair in watcher params?](https://discuss.elastic.co/t/can-i-have-mutiple-key-value-pair-in-watcher-params/336187)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 0\
**Last updated:** [June 16, 2023, 4:18am UTC](https://discuss.elastic.co/t/can-i-have-mutiple-key-value-pair-in-watcher-params/336187 "2023-06-16T04:18:20Z")

</div>

Hi, I am curretly using watcher to set up tasks. But when I set up condition part, I want to make the params can contan mutiple key-value pair, so that in future I can easily change them to other value I want, but I enc…

---

## [C# Client 8.0.10 does not have the DateRange filter](https://discuss.elastic.co/t/c-client-8-0-10-does-not-have-the-daterange-filter/336121)

<div class="topic-metadata">

**Author:** [@Jose\_Mieses](https://discuss.elastic.co/u/Jose_Mieses)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 4:02pm UTC](https://discuss.elastic.co/t/c-client-8-0-10-does-not-have-the-daterange-filter/336121 "2023-06-15T16:02:11Z")

</div>

I'm interested to know when the DataRange query will be available in .Net Client. We are trying to implement this features to one of our apps. I checked the latest release notes and nothing has been mentioned.

---

## [How Statsd output plugin work](https://discuss.elastic.co/t/how-statsd-output-plugin-work/336298)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 10:55pm UTC](https://discuss.elastic.co/t/how-statsd-output-plugin-work/336298 "2023-06-19T22:55:12Z")

</div>

Hi I have logfile that need to count number of this string on it "connection failed" now question is log file created last day and continuously new log add to it. which of these Statsd output configuration options "co…

---

## [Format version is not supported (resource BufferedChecksumIndexInput (SimpleFSIndexInput))](https://discuss.elastic.co/t/format-version-is-not-supported-resource-bufferedchecksumindexinput-simplefsindexinput/336390)

<div class="topic-metadata">

**Author:** [@amal\_srivastava](https://discuss.elastic.co/u/amal_srivastava)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 8:49pm UTC](https://discuss.elastic.co/t/format-version-is-not-supported-resource-bufferedchecksumindexinput-simplefsindexinput/336390 "2023-06-19T20:49:27Z")

</div>

Hi, One of my elasticsearch index is red and when i dig this into deep i am getting this below error GET \_cluster/allocation/explain { "index" : "design", "shard" : 0, "primary" : true, "current\_state" : "unassign…

---

## [aws-cloudwatch obtaining logs exception](https://discuss.elastic.co/t/aws-cloudwatch-obtaining-logs-exception/336401)

<div class="topic-metadata">

**Author:** [@Askas00](https://discuss.elastic.co/u/Askas00)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 7:38pm UTC](https://discuss.elastic.co/t/aws-cloudwatch-obtaining-logs-exception/336401 "2023-06-19T19:38:14Z")

</div>

When I use the aws-cloudwatch input plug-in to obtain the logs stored in cloudwatchlogs, the number of logs obtained is inconsistent with the number of logs in cloudwatchlogs. The route53 logs are stored in cloudwatchlog…

---

## [\[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"input\\", \\"filter\\", \\"output\\" at line](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-input-filter-output-at-line/336352)

<div class="topic-metadata">

**Author:** [@dropp.dev.hamidreza](https://discuss.elastic.co/u/dropp.dev.hamidreza)\
**Replies:** 6\
**Last updated:** [June 19, 2023, 7:36pm UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-input-filter-output-at-line/336352 "2023-06-19T19:36:41Z")

</div>

Hi, I'm trying to set up ELK stack with docker and docker compose and while setting up pipeline in logstash is gave me error in logstash container logs: \[INFO \]\[logstash.runner \] JVM bootstrap flags: \[-Xms4g, -…

---

## [Elasticsearch Master Not discovered](https://discuss.elastic.co/t/elasticsearch-master-not-discovered/336375)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 2\
**Last updated:** [June 19, 2023, 3:16pm UTC](https://discuss.elastic.co/t/elasticsearch-master-not-discovered/336375 "2023-06-19T15:16:33Z")

</div>

Hi all, I'm trying to form a cluster of 3 Nodes using Elasticsearch V8.8. I'm testing how this should work on the first 2 nodes and this really driving me crazy. My initial attempt was to start the first node as a clust…

---

## [Club char\_filter for a regex pattern and synonyms in the same query](https://discuss.elastic.co/t/club-char-filter-for-a-regex-pattern-and-synonyms-in-the-same-query/336383)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 2:53pm UTC](https://discuss.elastic.co/t/club-char-filter-for-a-regex-pattern-and-synonyms-in-the-same-query/336383 "2023-06-19T14:53:58Z")

</div>

I have an index that has candidate resumes. Resume has 2 fields: a) name b) resume Name has name of candidate and resume has a blob of text like "address:""chicago.st", "skill":"python", "email":"myemail@ymail.com". I …

---

## [Filebeat log to multiple outputs like file and syslog](https://discuss.elastic.co/t/filebeat-log-to-multiple-outputs-like-file-and-syslog/335743)

<div class="topic-metadata">

**Author:** [@michaelbu](https://discuss.elastic.co/u/michaelbu)\
**Replies:** 7\
**Last updated:** [June 19, 2023, 2:53pm UTC](https://discuss.elastic.co/t/filebeat-log-to-multiple-outputs-like-file-and-syslog/335743 "2023-06-19T14:53:04Z")

</div>

Hi, I'm using filebeat on Linux in this version: $ rpm -qa | grep filebeat filebeat-8.7.0-1.x86\_64 I would like to log filebeat to logfiles and also to syslog. This is the configuration snippet: logging: to\_files: …

---

## [FATAL Error: Unable to complete saved object migrations for the \[.kibana\] index: Migrations failed. Reason: 2 transformation errors were encountered](https://discuss.elastic.co/t/fatal-error-unable-to-complete-saved-object-migrations-for-the-kibana-index-migrations-failed-reason-2-transformation-errors-were-encountered/336382)

<div class="topic-metadata">

**Author:** [@Jasmine\_Blooms](https://discuss.elastic.co/u/Jasmine_Blooms)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 2:49pm UTC](https://discuss.elastic.co/t/fatal-error-unable-to-complete-saved-object-migrations-for-the-kibana-index-migrations-failed-reason-2-transformation-errors-were-encountered/336382 "2023-06-19T14:49:30Z")

</div>

Hi All, While performing migration of kibana using eck-operator from 7.8.1 to 7.17.10, we are facing the following issue: FATAL Error: Unable to complete saved object migrations for the \[.kibana\] index: Migrations fa…

---

## [Specify an index in search query](https://discuss.elastic.co/t/specify-an-index-in-search-query/336221)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 2:41pm UTC](https://discuss.elastic.co/t/specify-an-index-in-search-query/336221 "2023-06-19T14:41:30Z")

</div>

I need to search multiple indexes on Elasticsearch, My problem is that on each index I have the same field name (is\_active), how do I specify that it's the field of the other index ? GET index-1,index-2/\_search { "que…

---

## [Kibana watcher error throwing SSL handshake even though CA is same for both Kibana & Elasticsearch](https://discuss.elastic.co/t/kibana-watcher-error-throwing-ssl-handshake-even-though-ca-is-same-for-both-kibana-elasticsearch/336256)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 2:21pm UTC](https://discuss.elastic.co/t/kibana-watcher-error-throwing-ssl-handshake-even-though-ca-is-same-for-both-kibana-elasticsearch/336256 "2023-06-19T14:21:28Z")

</div>

Kibana watcher error throwing SSL handshake even though CA is same for both Kibana & Elasticsearch. Here's the error: Attaching the watcher definition as well. "error" : { "root\_cause" : \[ …

---

## [elasticsearch/distribution/docker/src/docker/Dockerfile - regarding the absence of files with setuid](https://discuss.elastic.co/t/elasticsearch-distribution-docker-src-docker-dockerfile-regarding-the-absence-of-files-with-setuid/336378)

<div class="topic-metadata">

**Author:** [@raperez](https://discuss.elastic.co/u/raperez)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 2:08pm UTC](https://discuss.elastic.co/t/elasticsearch-distribution-docker-src-docker-dockerfile-regarding-the-absence-of-files-with-setuid/336378 "2023-06-19T14:08:27Z")

</div>

Hi all! I am reaching you because I am working with the following Elasticsearch image as base, and I would like to ask some questions about the following line of the Dockerfile. The comments of the Dockerfile, regardin…

---

## [Character group tokenizer in ElasticSearch](https://discuss.elastic.co/t/character-group-tokenizer-in-elasticsearch/336212)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 4\
**Last updated:** [June 19, 2023, 2:00pm UTC](https://discuss.elastic.co/t/character-group-tokenizer-in-elasticsearch/336212 "2023-06-19T14:00:53Z")

</div>

Hello, I want to implement Character group tokenizer in elasticsearch. How Do I implement an index with char\_group tokenizer. I am putting this setting in my index: { "index": { "analysis": { "number\_of\_sha…

---

## [Calculate and display failure rate based on a "keyword" field](https://discuss.elastic.co/t/calculate-and-display-failure-rate-based-on-a-keyword-field/336099)

<div class="topic-metadata">

**Author:** [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 1:53pm UTC](https://discuss.elastic.co/t/calculate-and-display-failure-rate-based-on-a-keyword-field/336099 "2023-06-19T13:53:32Z")

</div>

Hello, For a MFT platform, each transfer is tagged with a status\_code, based on letters "E" for Ended, "C" for Canceled. I have to find out the partners with high failure rates over time. Do you have an idea on how to…

---

## [Unable to find apikey warning](https://discuss.elastic.co/t/unable-to-find-apikey-warning/335956)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 4\
**Last updated:** [June 19, 2023, 1:41pm UTC](https://discuss.elastic.co/t/unable-to-find-apikey-warning/335956 "2023-06-19T13:41:05Z")

</div>

Hello, for the info my cluster is on version 7.17.4 and it's based on 3 nodes that are all master eligible and data nodes. I keep getting this warning on my master node logs non-stop, \[2023-06-13T15:44:07,212\]\[WARN \]\[…

---

## [Cannot initialize custom codec plugin](https://discuss.elastic.co/t/cannot-initialize-custom-codec-plugin/336371)

<div class="topic-metadata">

**Author:** [@ofekinger](https://discuss.elastic.co/u/ofekinger)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 1:28pm UTC](https://discuss.elastic.co/t/cannot-initialize-custom-codec-plugin/336371 "2023-06-19T13:28:07Z")

</div>

Hello. I'm working on a new codec plugin that parses protobuf data in a unique way (meaning I can't use the existing protobuf plugin). Here's the plugin code: package com.ofekinger.logstash.plugins.mycodec; import co…

---

## [Differnce in results when the search query contains a hyphen](https://discuss.elastic.co/t/differnce-in-results-when-the-search-query-contains-a-hyphen/336324)

<div class="topic-metadata">

**Author:** [@zigoo0](https://discuss.elastic.co/u/zigoo0)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 1:00pm UTC](https://discuss.elastic.co/t/differnce-in-results-when-the-search-query-contains-a-hyphen/336324 "2023-06-19T13:00:46Z")

</div>

Hello team, I have an elasticsearch index that contains hostnames and email addresses. When searching the index, my aim is to retrieve all hostnames and emails that contains certain domain Following examples will expla…

---

## [Create button with filters in dashboards](https://discuss.elastic.co/t/create-button-with-filters-in-dashboards/336243)

<div class="topic-metadata">

**Author:** [@SYGH](https://discuss.elastic.co/u/SYGH)\
**Replies:** 5\
**Last updated:** [June 19, 2023, 12:39pm UTC](https://discuss.elastic.co/t/create-button-with-filters-in-dashboards/336243 "2023-06-19T12:39:35Z")

</div>

Hello, I need to create a button on the dashboard to enable a filter based on the value of X. At the same time, when you click it again, the filter is removed. Please tell me how to create this button.

---

## [Elasticsearch killed at time of start](https://discuss.elastic.co/t/elasticsearch-killed-at-time-of-start/336312)

<div class="topic-metadata">

**Author:** [@deepakmahajan00](https://discuss.elastic.co/u/deepakmahajan00)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 12:28pm UTC](https://discuss.elastic.co/t/elasticsearch-killed-at-time-of-start/336312 "2023-06-19T12:28:49Z")

</div>

Starting Elasticsearch Server …

---

## [LogStash Configurations for Log4Net, Log4J etc](https://discuss.elastic.co/t/logstash-configurations-for-log4net-log4j-etc/336258)

<div class="topic-metadata">

**Author:** [@Tomahawk](https://discuss.elastic.co/u/Tomahawk)\
**Replies:** 2\
**Last updated:** [June 19, 2023, 11:55am UTC](https://discuss.elastic.co/t/logstash-configurations-for-log4net-log4j-etc/336258 "2023-06-19T11:55:34Z")

</div>

Bit of a left field question….. In a highly regulated space and restricted industry, log files coming from multiple apps (100-200) with Log4Net and Log4J, Python Native logging libraries. No real customisation done by t…

---

## [Format version is not supported (resource BufferedChecksumIndexInput (SimpleFSIndexInput))](https://discuss.elastic.co/t/format-version-is-not-supported-resource-bufferedchecksumindexinput-simplefsindexinput/336348)

<div class="topic-metadata">

**Author:** [@amal\_srivastava](https://discuss.elastic.co/u/amal_srivastava)\
**Replies:** 2\
**Last updated:** [June 19, 2023, 11:14am UTC](https://discuss.elastic.co/t/format-version-is-not-supported-resource-bufferedchecksumindexinput-simplefsindexinput/336348 "2023-06-19T11:14:44Z")

</div>

Hi, One of my elasticsearch index is red and when i dig this into deep i am getting this below error GET \_cluster/allocation/explain { "index" : "design", "shard" : 0, "primary" : true, "current\_state" : "unassign…

---

## [Errors Updating logstash from 8.5.3 to 8.8.0](https://discuss.elastic.co/t/errors-updating-logstash-from-8-5-3-to-8-8-0/335531)

<div class="topic-metadata">

**Author:** [@cperzrt10](https://discuss.elastic.co/u/cperzrt10)\
**Replies:** 6\
**Last updated:** [June 19, 2023, 10:03am UTC](https://discuss.elastic.co/t/errors-updating-logstash-from-8-5-3-to-8-8-0/335531 "2023-06-19T10:03:52Z")

</div>

I have update all my Elasticsearch cluster, and kibana to the version 8.8.0 from 8.5.3, when update Logstash it doesnt start runing and show the next error \[2023-06-08T13:06:33,163\]\[WARN \]\[logstash.outputs.elasticsearch…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=505)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=507)
