# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=507

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 508

---

## [Logstash batch import nested objects](https://discuss.elastic.co/t/logstash-batch-import-nested-objects/336342)

<div class="topic-metadata">

**Author:** [@Joker\_Lu](https://discuss.elastic.co/u/Joker_Lu)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 9:23am UTC](https://discuss.elastic.co/t/logstash-batch-import-nested-objects/336342 "2023-06-19T09:23:55Z")

</div>

Hi everyone, I want to batch import nested objects to ES, but when i paging my nested objects, it will cover my previous data. Can anyone have a solution for this.

---

## [Issue with ingesting data and disk size](https://discuss.elastic.co/t/issue-with-ingesting-data-and-disk-size/336087)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 9:23am UTC](https://discuss.elastic.co/t/issue-with-ingesting-data-and-disk-size/336087 "2023-06-19T09:23:29Z")

</div>

I am facing a very weird issue. I tried uploading 30 GB of csv data in Elasticsearch using python client. The below is the disk usage when I quit ingestion:- shards disk.indices disk.used disk.avail disk.total disk.pe…

---

## [Upgrading kibana and Elastic from 7.9 to 8.7](https://discuss.elastic.co/t/upgrading-kibana-and-elastic-from-7-9-to-8-7/335906)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 5\
**Last updated:** [June 19, 2023, 8:49am UTC](https://discuss.elastic.co/t/upgrading-kibana-and-elastic-from-7-9-to-8-7/335906 "2023-06-19T08:49:42Z")

</div>

Hi. I am in the process to upgrade my kibana and Elasticsearch from 7.9 to 8.7. I installed 7.17 but did not back up the data from version 7.9. What shall I do now? Someone, please guide.

---

## [Server public URL Warning](https://discuss.elastic.co/t/server-public-url-warning/336338)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 8:39am UTC](https://discuss.elastic.co/t/server-public-url-warning/336338 "2023-06-19T08:39:54Z")

</div>

HI Team, I'm using Version 7.16 ELK and when i try to hit the kibana URL im getting below warning message "server.publicBaseUrl is missing and should be configured when running in a production environment" if i add th…

---

## [No Logs appearing in Kibana](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208)

<div class="topic-metadata">

**Author:** [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Replies:** 15\
**Last updated:** [June 19, 2023, 8:21am UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208 "2023-06-19T08:21:27Z")

</div>

Those are my statistics. When I tcpdump port 5044 I see traffic coming from the host where I have winlogbeat running and when I tcpdump port 9200 on the server I see a lot of traffic. So I suppose Data is reaching ela…

---

## [Fleet: This output type currently does not support connectivity to a remote Elasticsearch cluster](https://discuss.elastic.co/t/fleet-this-output-type-currently-does-not-support-connectivity-to-a-remote-elasticsearch-cluster/336336)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 8:15am UTC](https://discuss.elastic.co/t/fleet-this-output-type-currently-does-not-support-connectivity-to-a-remote-elasticsearch-cluster/336336 "2023-06-19T08:15:22Z")

</div>

I'm currently testing Fleet and added a dedicated fleet server and a dedicated "collector server" VM with elastic agent installed. Everything is now managed via Kibana and my goal is to collect stuff via the collector VM…

---

## [Getting unrelated data while searching with -\* in simple\_query\_string](https://discuss.elastic.co/t/getting-unrelated-data-while-searching-with-in-simple-query-string/336192)

<div class="topic-metadata">

**Author:** [@ms.t](https://discuss.elastic.co/u/ms.t)\
**Replies:** 4\
**Last updated:** [June 19, 2023, 8:10am UTC](https://discuss.elastic.co/t/getting-unrelated-data-while-searching-with-in-simple-query-string/336192 "2023-06-19T08:10:50Z")

</div>

Hi I am using simple\_query\_string method with suffix \* (operator) for getting result But when i am searching with odd number of - getting unrelated data but with even number of - getting empty data.

---

## [Need help with Elasticsearch and Elastic agent](https://discuss.elastic.co/t/need-help-with-elasticsearch-and-elastic-agent/335502)

<div class="topic-metadata">

**Author:** [@SanketBaraiya](https://discuss.elastic.co/u/SanketBaraiya)\
**Replies:** 7\
**Last updated:** [June 19, 2023, 7:20am UTC](https://discuss.elastic.co/t/need-help-with-elasticsearch-and-elastic-agent/335502 "2023-06-19T07:20:21Z")

</div>

I am facing the problem in my elk server. Whenever I start the elasticsearch service the outgoing traffic increases to \>10 MBps. This is what is shown in the processes. I also have stopped both filebeat and metricbea…

---

## [Upgrde 7.8 to 7](https://discuss.elastic.co/t/upgrde-7-8-to-7/336264)

<div class="topic-metadata">

**Author:** [@Abhishek\_Tiwari1](https://discuss.elastic.co/u/Abhishek_Tiwari1)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 6:39am UTC](https://discuss.elastic.co/t/upgrde-7-8-to-7/336264 "2023-06-19T06:39:42Z")

</div>

HI Team, Need help , we are facing issue after upgrade elasticseach from 7.8 to 7.17.10, Issue first it incresed respoonce time Chche value decresed drasticily from 7.8 to 7.17.10 on search . Please help Thanks Abh…

---

## [How to delete/clear an invalidated api key from '/\_security/api\_key' list?](https://discuss.elastic.co/t/how-to-delete-clear-an-invalidated-api-key-from-security-api-key-list/336069)

<div class="topic-metadata">

**Author:** [@ade.syseng](https://discuss.elastic.co/u/ade.syseng)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 4:30am UTC](https://discuss.elastic.co/t/how-to-delete-clear-an-invalidated-api-key-from-security-api-key-list/336069 "2023-06-19T04:30:27Z")

</div>

Hi, Is it possible to delete these invalidated api keys from '/\_security/api\_key'? I just want to keep the list clean from invalidated keys. Any suggestion or solution for this issue? Note: Elasticsearch and Kibana …

---

## [Index status red with reason failed engine (reason: \[merge failed\])](https://discuss.elastic.co/t/index-status-red-with-reason-failed-engine-reason-merge-failed/336249)

<div class="topic-metadata">

**Author:** [@Fajaruddin\_Shiddiq](https://discuss.elastic.co/u/Fajaruddin_Shiddiq)\
**Replies:** 7\
**Last updated:** [June 19, 2023, 1:55am UTC](https://discuss.elastic.co/t/index-status-red-with-reason-failed-engine-reason-merge-failed/336249 "2023-06-19T01:55:47Z")

</div>

Hi, one of my index seems corrupt because of failed during merge process as below org.apache.lucene.index.MergePolicy$MergeException: org.apache.lucene.index.CorruptIndexException: docs out of order (594 \<= 594 ) (reso…

---

## [Unable to find in Java Client API ES 8.7 replacement of fieldsAndWeights in QueryStringQueryBuilder of earlier version](https://discuss.elastic.co/t/unable-to-find-in-java-client-api-es-8-7-replacement-of-fieldsandweights-in-querystringquerybuilder-of-earlier-version/336285)

<div class="topic-metadata">

**Author:** [@ramyogi](https://discuss.elastic.co/u/ramyogi)\
**Replies:** 4\
**Last updated:** [June 19, 2023, 12:20am UTC](https://discuss.elastic.co/t/unable-to-find-in-java-client-api-es-8-7-replacement-of-fieldsandweights-in-querystringquerybuilder-of-earlier-version/336285 "2023-06-19T00:20:16Z")

</div>

Before ES 8 we were using below query. final BoolQueryBuilder expectedBooleanQuery = QueryBuilders.boolQuery(); expectedBooleanQuery.must( QueryBuilders.queryStringQuery("water") .defaultOperato…

---

## [Problems spinning up the docker compose example](https://discuss.elastic.co/t/problems-spinning-up-the-docker-compose-example/336268)

<div class="topic-metadata">

**Author:** [@Sasho](https://discuss.elastic.co/u/Sasho)\
**Replies:** 2\
**Last updated:** [June 18, 2023, 9:17pm UTC](https://discuss.elastic.co/t/problems-spinning-up-the-docker-compose-example/336268 "2023-06-18T21:17:06Z")

</div>

Hello, I'm following the instructions on Start a multi-node cluster with Docker Compose. I believe I have set up everything correctly. My .env file looks like this: # Password for the 'elastic' user (at least 6 chara…

---

## [Recent ecommerce requirement change ballooned our hosting costs x7. Need help with data model](https://discuss.elastic.co/t/recent-ecommerce-requirement-change-ballooned-our-hosting-costs-x7-need-help-with-data-model/336308)

<div class="topic-metadata">

**Author:** [@sdata47](https://discuss.elastic.co/u/sdata47)\
**Replies:** 0\
**Last updated:** [June 18, 2023, 6:14pm UTC](https://discuss.elastic.co/t/recent-ecommerce-requirement-change-ballooned-our-hosting-costs-x7-need-help-with-data-model/336308 "2023-06-18T18:14:54Z")

</div>

We're having a serious issue using Elasticsearch at work without large hosting costs. A recent requirement change bumped us up from $120 to $700 a month. Essentially, this is the issue. We have a catalog of products, …

---

## [Transform + Enrichment Policy](https://discuss.elastic.co/t/transform-enrichment-policy/334878)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 12\
**Last updated:** [June 18, 2023, 5:13pm UTC](https://discuss.elastic.co/t/transform-enrichment-policy/334878 "2023-06-18T17:13:47Z")

</div>

Hello, I had the idea to use the target index of a sum aggregation transform as the same target index for an enrichment policy. Essentially, I want to perform a join on the field being grouped on in the transform and en…

---

## [Little confuse about decay function source code](https://discuss.elastic.co/t/little-confuse-about-decay-function-source-code/336296)

<div class="topic-metadata">

**Author:** [@RandalTeng](https://discuss.elastic.co/u/RandalTeng)\
**Replies:** 2\
**Last updated:** [June 18, 2023, 8:36am UTC](https://discuss.elastic.co/t/little-confuse-about-decay-function-source-code/336296 "2023-06-18T08:36:15Z")

</div>

hi guys, I recently read some source code about the decay function. there is some code doc, I can't figure out why it should be. the code line is: https://github.com/elastic/elasticsearch/blob/13fb93511c23fe0d1a02de07…

---

## [Updating index is not working for existing data inside json object](https://discuss.elastic.co/t/updating-index-is-not-working-for-existing-data-inside-json-object/336291)

<div class="topic-metadata">

**Author:** [@J\_S](https://discuss.elastic.co/u/J_S)\
**Replies:** 1\
**Last updated:** [June 18, 2023, 7:15am UTC](https://discuss.elastic.co/t/updating-index-is-not-working-for-existing-data-inside-json-object/336291 "2023-06-18T07:15:53Z")

</div>

I am repeatedly fetching rows from a database. I insert them into elasticsearch using the unique key as the document\_id. For any fields not on the current document I want to add any missing columns to the exiting documen…

---

## [Event.remove method not working inside aggregate section in code block](https://discuss.elastic.co/t/event-remove-method-not-working-inside-aggregate-section-in-code-block/336201)

<div class="topic-metadata">

**Author:** [@J\_S](https://discuss.elastic.co/u/J_S)\
**Replies:** 20\
**Last updated:** [June 18, 2023, 3:37am UTC](https://discuss.elastic.co/t/event-remove-method-not-working-inside-aggregate-section-in-code-block/336201 "2023-06-18T03:37:16Z")

</div>

Hi All, I am newbie to ELK stack, I am trying to remove the field called "attributes" while aggregate the data inside code block. But it is not removing the already existing "attributes" in the corresponding "id" but on…

---

## [Unable to Use Elasticsearch Object Export API](https://discuss.elastic.co/t/unable-to-use-elasticsearch-object-export-api/336287)

<div class="topic-metadata">

**Author:** [@vdashora](https://discuss.elastic.co/u/vdashora)\
**Replies:** 1\
**Last updated:** [June 18, 2023, 1:05am UTC](https://discuss.elastic.co/t/unable-to-use-elasticsearch-object-export-api/336287 "2023-06-18T01:05:18Z")

</div>

Hi all, I'm trying to export a dashboard we have in Kibana using the API command. I've written a Python script but when I run the command it gives me this error: Export failed with status code: 404 {"statusCode":404,"e…

---

## [X-pack/metricbeat/module/statsd: Unable to parse float values (statsd module) of counter metric type](https://discuss.elastic.co/t/x-pack-metricbeat-module-statsd-unable-to-parse-float-values-statsd-module-of-counter-metric-type/330095)

<div class="topic-metadata">

**Author:** [@shmsr\_elastic](https://discuss.elastic.co/u/shmsr_elastic)\
**Replies:** 1\
**Last updated:** [June 17, 2023, 7:04pm UTC](https://discuss.elastic.co/t/x-pack-metricbeat-module-statsd-unable-to-parse-float-values-statsd-module-of-counter-metric-type/330095 "2023-06-17T19:04:59Z")

</div>

I was exploring statsd's module code in beats while making some changes to the same and I noticed that the for metrics of type counter, we just support integers (of base 10 and 64 bitsize) and in case it is not the same…

---

## [Can you forward logs going into elasticsearch to a third party?](https://discuss.elastic.co/t/can-you-forward-logs-going-into-elasticsearch-to-a-third-party/334800)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 3\
**Last updated:** [June 17, 2023, 3:32pm UTC](https://discuss.elastic.co/t/can-you-forward-logs-going-into-elasticsearch-to-a-third-party/334800 "2023-06-17T15:32:43Z")

</div>

I have a single instance of elasticsearch, kibana and i am getting the data in this via agents and filebeats. is there a way to "forward" the data that is ingested into elasticsearch to another device or instance?

---

## [Logstash to Elasticsearch there is 10-20min for delay, also not all logs are indexed](https://discuss.elastic.co/t/logstash-to-elasticsearch-there-is-10-20min-for-delay-also-not-all-logs-are-indexed/336241)

<div class="topic-metadata">

**Author:** [@mayank\_singh](https://discuss.elastic.co/u/mayank_singh)\
**Replies:** 3\
**Last updated:** [June 17, 2023, 3:20pm UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-there-is-10-20min-for-delay-also-not-all-logs-are-indexed/336241 "2023-06-17T15:20:49Z")

</div>

Hi, I am sending logs from Logstash to Elasticsearch. The Elasticsearch seems to be working fine but there is 10-20mins of delay in logs index also getting below error on logstash, any help would be greatly appreciated. …

---

## [Update field with new values is not possible using aggregate filter](https://discuss.elastic.co/t/update-field-with-new-values-is-not-possible-using-aggregate-filter/336266)

<div class="topic-metadata">

**Author:** [@J\_S](https://discuss.elastic.co/u/J_S)\
**Replies:** 0\
**Last updated:** [June 17, 2023, 10:27am UTC](https://discuss.elastic.co/t/update-field-with-new-values-is-not-possible-using-aggregate-filter/336266 "2023-06-17T10:27:51Z")

</div>

I am trying to update a JSON object called "attributes" inside aggregate filter. In some cases, I may or may not have attributes in Index, if it is not available means I will insert "attributes" as new JSON object field…

---

## [Reindex From json File only specific log file path docs](https://discuss.elastic.co/t/reindex-from-json-file-only-specific-log-file-path-docs/336195)

<div class="topic-metadata">

**Author:** [@bill210kouk](https://discuss.elastic.co/u/bill210kouk)\
**Replies:** 2\
**Last updated:** [June 17, 2023, 9:43am UTC](https://discuss.elastic.co/t/reindex-from-json-file-only-specific-log-file-path-docs/336195 "2023-06-17T09:43:18Z")

</div>

Good Morning I hope you're Alright. I'm a newbie and i would like to ask something. I've made an export process with elasticdump and it was a success. I would like to ask . My end goal is to keep only valuable documents…

---

## [Problems while using \_bulk api via camel rest route](https://discuss.elastic.co/t/problems-while-using-bulk-api-via-camel-rest-route/336238)

<div class="topic-metadata">

**Author:** [@markchennai](https://discuss.elastic.co/u/markchennai)\
**Replies:** 1\
**Last updated:** [June 17, 2023, 7:36am UTC](https://discuss.elastic.co/t/problems-while-using-bulk-api-via-camel-rest-route/336238 "2023-06-17T07:36:03Z")

</div>

Message History (source location and message history is disabled) Source ID Processor Elapsed (ms) route1/route1 …

---

## [Elasticsearch does not start](https://discuss.elastic.co/t/elasticsearch-does-not-start/336261)

<div class="topic-metadata">

**Author:** [@pan\_sjan](https://discuss.elastic.co/u/pan_sjan)\
**Replies:** 4\
**Last updated:** [June 17, 2023, 6:09am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start/336261 "2023-06-17T06:09:55Z")

</div>

I am using the es 7.17.10 tarball from https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-7.17.10-linux-x86\_64.tar.gz The Java version I have is JDK 18 # /usr/java/latest/bin/java -version openjdk vers…

---

## [Possible issue with tracking\_column\_type =\> "timestamp" in 8.1.1](https://discuss.elastic.co/t/possible-issue-with-tracking-column-type-timestamp-in-8-1-1/336255)

<div class="topic-metadata">

**Author:** [@SrxDevOps](https://discuss.elastic.co/u/SrxDevOps)\
**Replies:** 1\
**Last updated:** [June 16, 2023, 8:18pm UTC](https://discuss.elastic.co/t/possible-issue-with-tracking-column-type-timestamp-in-8-1-1/336255 "2023-06-16T20:18:17Z")

</div>

After updating from 7x to 8.1.1 any pipeline that uses tracking\_column\_type =\> "timestamp" fails with the error \[2023-06-16T14:37:50,485\]\[ERROR\]\[logstash.javapipeline \]\[Questions\] Pipeline error {:pipeline\_id=\>"Quest…

---

## [Normalising scores?](https://discuss.elastic.co/t/normalising-scores/336149)

<div class="topic-metadata">

**Author:** [@catmanjan](https://discuss.elastic.co/u/catmanjan)\
**Replies:** 1\
**Last updated:** [June 16, 2023, 8:49pm UTC](https://discuss.elastic.co/t/normalising-scores/336149 "2023-06-16T20:49:31Z")

</div>

I've been searching how to normalise the scores so we can display the score as a percentage to the end user - it seems that this is/was not possible? That seems incredible to me... Is there really no way to tell elastic…

---

## [Convert datetime to another timezone in logstash](https://discuss.elastic.co/t/convert-datetime-to-another-timezone-in-logstash/336214)

<div class="topic-metadata">

**Author:** [@ashokkrishna99\_Vemur](https://discuss.elastic.co/u/ashokkrishna99_Vemur)\
**Replies:** 8\
**Last updated:** [June 16, 2023, 8:06pm UTC](https://discuss.elastic.co/t/convert-datetime-to-another-timezone-in-logstash/336214 "2023-06-16T20:06:33Z")

</div>

I am getting logs from a firewall which are in GMT timezone. For example firewall sending rt=Jun 16 2023 11:24:40 GMT I want to convert that time to MYT rt=June 16 2023 19:24:40 MYT. How can I do that. filter { grok…

---

## [How can I modify the path Elasticsearch 2.4.6 uses to run Java in Linux?](https://discuss.elastic.co/t/how-can-i-modify-the-path-elasticsearch-2-4-6-uses-to-run-java-in-linux/335893)

<div class="topic-metadata">

**Author:** [@Latitude](https://discuss.elastic.co/u/Latitude)\
**Replies:** 4\
**Last updated:** [June 16, 2023, 7:59pm UTC](https://discuss.elastic.co/t/how-can-i-modify-the-path-elasticsearch-2-4-6-uses-to-run-java-in-linux/335893 "2023-06-16T19:59:31Z")

</div>

Brand new to Elasticsearch. Can anyone explain how how to modify the path Elasticsearch v2.4.6 uses for Java on Linux? There is a discrepancy between Test and Production and I need to change Test to match Production: Pr…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=506)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=508)
