# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=515

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 516

---

## [What are the benefits of using sync reindexing API instead of async reindexing API?](https://discuss.elastic.co/t/what-are-the-benefits-of-using-sync-reindexing-api-instead-of-async-reindexing-api/335712)

<div class="topic-metadata">

**Author:** [@sanskarfc](https://discuss.elastic.co/u/sanskarfc)\
**Replies:** 0\
**Last updated:** [June 11, 2023, 6:22am UTC](https://discuss.elastic.co/t/what-are-the-benefits-of-using-sync-reindexing-api-instead-of-async-reindexing-api/335712 "2023-06-11T06:22:04Z")

</div>

What are the benefits of using sync reindexing API instead of async reindexing API? If the size of the documents is in multiple GBs, it looks like it is always better to use async API instead of sync API :thinking:

---

## [Convert 2 nodes with roles \[data\] to \[data\_hot, data\_content\] and \[warm\]](https://discuss.elastic.co/t/convert-2-nodes-with-roles-data-to-data-hot-data-content-and-warm/335685)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 1\
**Last updated:** [June 11, 2023, 2:51am UTC](https://discuss.elastic.co/t/convert-2-nodes-with-roles-data-to-data-hot-data-content-and-warm/335685 "2023-06-11T02:51:26Z")

</div>

Salut, Elastic Fulks My production cluster is set up as follows: 1 master node two data nodes \[data\] 1 coordinator I want to convert the 2 data nodes to first one to \[data\_content,data\_hot\]. second one to \[data\_war…

---

## [How to filter against a wildcard name of a field?](https://discuss.elastic.co/t/how-to-filter-against-a-wildcard-name-of-a-field/335693)

<div class="topic-metadata">

**Author:** [@Wpq](https://discuss.elastic.co/u/Wpq)\
**Replies:** 2\
**Last updated:** [June 10, 2023, 7:54pm UTC](https://discuss.elastic.co/t/how-to-filter-against-a-wildcard-name-of-a-field/335693 "2023-06-10T19:54:31Z")

</div>

I have documents that have fields such as vulns.something\_1.a vulns.something\_1.b the element something\_1 may change between documents some documents have the vulns entries, and some do not. My problem: I would like …

---

## [How to add hostname to logs from syslog or snmp source if they don't include only IP, no hostname](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-from-syslog-or-snmp-source-if-they-dont-include-only-ip-no-hostname/335691)

<div class="topic-metadata">

**Author:** [@PackElend](https://discuss.elastic.co/u/PackElend)\
**Replies:** 2\
**Last updated:** [June 10, 2023, 2:54pm UTC](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-from-syslog-or-snmp-source-if-they-dont-include-only-ip-no-hostname/335691 "2023-06-10T14:54:40Z")

</div>

Hello, I'm aware of How to add hostname to logs that normally do not contain hostname? but that is not applicable to my case. My router's firewall sends syslog message but they only contain the IP of the host causing t…

---

## [Price of Entreprise license on prem](https://discuss.elastic.co/t/price-of-entreprise-license-on-prem/335532)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 6\
**Last updated:** [June 10, 2023, 2:11pm UTC](https://discuss.elastic.co/t/price-of-entreprise-license-on-prem/335532 "2023-06-10T14:11:16Z")

</div>

I want to use the searchable snapshot capability in my on-premises 7.17.9 cluster; what is the cost of the enterprise license?

---

## [ApiError(406, 'Content-Type header \[application/vnd.elasticsearch+json; compatible-with=8\] is not supported',](https://discuss.elastic.co/t/apierror-406-content-type-header-application-vnd-elasticsearch-json-compatible-with-8-is-not-supported/334579)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 8\
**Last updated:** [June 10, 2023, 1:11pm UTC](https://discuss.elastic.co/t/apierror-406-content-type-header-application-vnd-elasticsearch-json-compatible-with-8-is-not-supported/334579 "2023-06-10T13:11:23Z")

</div>

Hii.. ApiError(406, 'Content-Type header \[application/vnd.elasticsearch+json; compatible-with=8\] is not supported', 'Content-Type header \[application/vnd.elasticsearch+json; compatible-with=8\] is not supported') When I…

---

## [Elasticsearch is not starting on windows with installer](https://discuss.elastic.co/t/elasticsearch-is-not-starting-on-windows-with-installer/335675)

<div class="topic-metadata">

**Author:** [@Nilesh\_Brahmkshatriy](https://discuss.elastic.co/u/Nilesh_Brahmkshatriy)\
**Replies:** 2\
**Last updated:** [June 10, 2023, 10:38am UTC](https://discuss.elastic.co/t/elasticsearch-is-not-starting-on-windows-with-installer/335675 "2023-06-10T10:38:43Z")

</div>

We have installed the elasticsearch version 7.0.1 in windows 11 but not starting the service. Can you please help us to solve the issue?

---

## [Elasticsearch in RKE in running status but not active](https://discuss.elastic.co/t/elasticsearch-in-rke-in-running-status-but-not-active/335655)

<div class="topic-metadata">

**Author:** [@Mhvrke](https://discuss.elastic.co/u/Mhvrke)\
**Replies:** 10\
**Last updated:** [June 10, 2023, 6:10am UTC](https://discuss.elastic.co/t/elasticsearch-in-rke-in-running-status-but-not-active/335655 "2023-06-10T06:10:38Z")

</div>

Hi! I need help with the following escenario: I’m running Elasticsearch in cluster mode in 3 worker nodes in RKE. Suddenly stopped from working and Kibana went down as Elasticsearch presents 503 error service unavailable…

---

## [Setting multinode elk cluster](https://discuss.elastic.co/t/setting-multinode-elk-cluster/335165)

<div class="topic-metadata">

**Author:** [@rajeshri](https://discuss.elastic.co/u/rajeshri)\
**Replies:** 2\
**Last updated:** [June 10, 2023, 6:05am UTC](https://discuss.elastic.co/t/setting-multinode-elk-cluster/335165 "2023-06-10T06:05:25Z")

</div>

cluster.name: my-cluster node.name: master-1 path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch network.host: 172.31.82.55 http.port: 9200 discovery.seed\_hosts: \["172.31.82.55", "172.31.86.217"\] c…

---

## [How to add \_size mapping to index legacy template in elasticsearch?](https://discuss.elastic.co/t/how-to-add-size-mapping-to-index-legacy-template-in-elasticsearch/335672)

<div class="topic-metadata">

**Author:** [@Amirhossein\_eidy](https://discuss.elastic.co/u/Amirhossein_eidy)\
**Replies:** 1\
**Last updated:** [June 10, 2023, 5:16am UTC](https://discuss.elastic.co/t/how-to-add-size-mapping-to-index-legacy-template-in-elasticsearch/335672 "2023-06-10T05:16:38Z")

</div>

Hi friends I have installed size mapping plugin and I added it to Kibana meta fields too I could successfully enable "\_size" in Elasticsearch via bellow command and see the result in kibana PUT logstash-2023-06-06 { …

---

## [Elastic Store Data](https://discuss.elastic.co/t/elastic-store-data/335624)

<div class="topic-metadata">

**Author:** [@Suleman\_Ahmed](https://discuss.elastic.co/u/Suleman_Ahmed)\
**Replies:** 1\
**Last updated:** [June 9, 2023, 10:49pm UTC](https://discuss.elastic.co/t/elastic-store-data/335624 "2023-06-09T22:49:25Z")

</div>

Hello! I am new to elastic and wanted to know that Elastic store data in indexes or in text? Will be greateful if refer to any documentation link. Thanks Suleman

---

## [Read segments directly from the snapshot](https://discuss.elastic.co/t/read-segments-directly-from-the-snapshot/335122)

<div class="topic-metadata">

**Author:** [@Ariel\_Zach](https://discuss.elastic.co/u/Ariel_Zach)\
**Replies:** 10\
**Last updated:** [June 9, 2023, 10:46pm UTC](https://discuss.elastic.co/t/read-segments-directly-from-the-snapshot/335122 "2023-06-09T22:46:00Z")

</div>

Hello, I'm trying to read Lucene files (segments) directly from the files generated in the snapshot, but I'm encountering errors. Could you guide me on how to do it? Thank you.

---

## [Updating table column values e.g. status using a SQL query meeting a condition](https://discuss.elastic.co/t/updating-table-column-values-e-g-status-using-a-sql-query-meeting-a-condition/335664)

<div class="topic-metadata">

**Author:** [@Raj\_obsv](https://discuss.elastic.co/u/Raj_obsv)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 10:40pm UTC](https://discuss.elastic.co/t/updating-table-column-values-e-g-status-using-a-sql-query-meeting-a-condition/335664 "2023-06-09T22:40:56Z")

</div>

In canvas I have a requirement to display couple of Job status of last 30 days which frequency is daily however on some days 2-3 jobs are not schedule. As expected no timestamp or any entry will be created in elastic for…

---

## [ElasticSearch returns "index not found error" for an index that exists](https://discuss.elastic.co/t/elasticsearch-returns-index-not-found-error-for-an-index-that-exists/335658)

<div class="topic-metadata">

**Author:** [@RA31](https://discuss.elastic.co/u/RA31)\
**Replies:** 1\
**Last updated:** [June 9, 2023, 9:08pm UTC](https://discuss.elastic.co/t/elasticsearch-returns-index-not-found-error-for-an-index-that-exists/335658 "2023-06-09T21:08:53Z")

</div>

I have an index pattern "barney", which shows on Kibana Management screen and on Discover. But when I hit the \_cat/indices API, it does not show the index pattern in the list of indices returned. When triggering barney/…

---

## [Use of PHP overloads](https://discuss.elastic.co/t/use-of-php-overloads/335653)

<div class="topic-metadata">

**Author:** [@Marcelo\_Saldanha](https://discuss.elastic.co/u/Marcelo_Saldanha)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 6:59pm UTC](https://discuss.elastic.co/t/use-of-php-overloads/335653 "2023-06-09T18:59:07Z")

</div>

Could you help me? Since the 06/01 I have my website being crashed by PHP load, and generates the following errors: Elasticsearch\\Common\\Exceptions\\Missing404Exception: {"error":{"root\_cause":\[{"type":"illegal\_argume…

---

## [Document insertion not showing in Kibana](https://discuss.elastic.co/t/document-insertion-not-showing-in-kibana/335640)

<div class="topic-metadata">

**Author:** [@John\_Connolly](https://discuss.elastic.co/u/John_Connolly)\
**Replies:** 2\
**Last updated:** [June 9, 2023, 5:19pm UTC](https://discuss.elastic.co/t/document-insertion-not-showing-in-kibana/335640 "2023-06-09T17:19:33Z")

</div>

I inherited an Elasticsearch instance that is on version 6.3. I am able to insert data into it and retrieve this data using the \_search endpoint. When I go into Kibana and try to view this data though it is not able to s…

---

## [ElasticsearchClient API says Name does not resolve](https://discuss.elastic.co/t/elasticsearchclient-api-says-name-does-not-resolve/335572)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 7\
**Last updated:** [June 9, 2023, 4:47pm UTC](https://discuss.elastic.co/t/elasticsearchclient-api-says-name-does-not-resolve/335572 "2023-06-09T16:47:56Z")

</div>

I am converting my existing Java code to the new Elastic Java API. My system is ES 7.17.9. When I send a query, I get the following error: 2023-06-08 20:58:00.918Z ERROR \[ForkJoinPool.commonPool-worker-9\] c.n.b.a.h.c.El…

---

## [Issue with Range query using hour\_minute format](https://discuss.elastic.co/t/issue-with-range-query-using-hour-minute-format/335567)

<div class="topic-metadata">

**Author:** [@Daniel\_Scott](https://discuss.elastic.co/u/Daniel_Scott)\
**Replies:** 4\
**Last updated:** [June 9, 2023, 3:33pm UTC](https://discuss.elastic.co/t/issue-with-range-query-using-hour-minute-format/335567 "2023-06-09T15:33:52Z")

</div>

I'm having issue using the range query with the various time formats. Here is my query in question: { "\_source": \["created\_on"\], "fields": \[{ "field": "created\_on", "format": "hour\_minute" }\], "query": { "rang…

---

## [Runninning two configs in parallel without conflict with schedule](https://discuss.elastic.co/t/runninning-two-configs-in-parallel-without-conflict-with-schedule/335575)

<div class="topic-metadata">

**Author:** [@geothomas](https://discuss.elastic.co/u/geothomas)\
**Replies:** 3\
**Last updated:** [June 9, 2023, 3:19pm UTC](https://discuss.elastic.co/t/runninning-two-configs-in-parallel-without-conflict-with-schedule/335575 "2023-06-09T15:19:55Z")

</div>

I am trying to create elasticsearch index from oracle table. I have two configs, one delta.conf \*input {\* \* jdbc\* \*{\* \* jdbc\_driver\_library =\> "\<path\>/ojdbc10.jar"\* \* jdbc\_driver\_class =\> "Java::oracle.jdbc.dri…

---

## [Elasticsearch GCS snapshots RepositoryException](https://discuss.elastic.co/t/elasticsearch-gcs-snapshots-repositoryexception/335336)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 4\
**Last updated:** [June 9, 2023, 2:46pm UTC](https://discuss.elastic.co/t/elasticsearch-gcs-snapshots-repositoryexception/335336 "2023-06-09T14:46:32Z")

</div>

Hi Team, We are suddenly facing the snapshot exception in GCS with \[2023-06-05T11:40:34,219\]\[WARN \]\[r.suppressed \] \[###\] path: /\_snapshot/e#-repo/###\_gcs\_ss\_2023-06-05-1130, params: {pretty=true, repositor…

---

## [Sending logs to syslog using logstash](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952)

<div class="topic-metadata">

**Author:** [@mariya](https://discuss.elastic.co/u/mariya)\
**Replies:** 16\
**Last updated:** [June 9, 2023, 2:43pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952 "2023-06-09T14:43:43Z")

</div>

I installed winlogbeat and Logstash on my WInodows and I want to send logs to Logstash that will forward the logs to pfSense,I mean using Logstash as an aggregator with the logstash-output-tcp to send events to Syslog. a…

---

## [Elastic APM agent not instrumenting on simple Kafka producer](https://discuss.elastic.co/t/elastic-apm-agent-not-instrumenting-on-simple-kafka-producer/335641)

<div class="topic-metadata">

**Author:** [@sangramreddy](https://discuss.elastic.co/u/sangramreddy)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 2:29pm UTC](https://discuss.elastic.co/t/elastic-apm-agent-not-instrumenting-on-simple-kafka-producer/335641 "2023-06-09T14:29:42Z")

</div>

We are trying Elastic APM in our org. Our apps are all backend Java communicated over Kafka. We noticed that the out of the box instrumentation is not properly working. So we created 3 basic java spring boot apps which…

---

## [Does "filebeat setup -e" need to be run every time I enable a module, or only once for all modules?](https://discuss.elastic.co/t/does-filebeat-setup-e-need-to-be-run-every-time-i-enable-a-module-or-only-once-for-all-modules/335557)

<div class="topic-metadata">

**Author:** [@andrew.klaassen](https://discuss.elastic.co/u/andrew.klaassen)\
**Replies:** 2\
**Last updated:** [June 9, 2023, 2:25pm UTC](https://discuss.elastic.co/t/does-filebeat-setup-e-need-to-be-run-every-time-i-enable-a-module-or-only-once-for-all-modules/335557 "2023-06-09T14:25:22Z")

</div>

So far I've been running "filebeat setup -e" every time I enable a new filebeat module. However, looking at its output, it seems to be setting stuff up for all of my modules, even the disabled ones. Do I need to run "f…

---

## [Plugin in Elasticsearch to find the term Dictionary](https://discuss.elastic.co/t/plugin-in-elasticsearch-to-find-the-term-dictionary/335630)

<div class="topic-metadata">

**Author:** [@Atomic\_Structure](https://discuss.elastic.co/u/Atomic_Structure)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 11:47am UTC](https://discuss.elastic.co/t/plugin-in-elasticsearch-to-find-the-term-dictionary/335630 "2023-06-09T11:47:53Z")

</div>

I am writing a plugin to find the term dictionary. It creates a new REST endpoint. I am not able to get leafreader, any idea how could I proceed. By getting the leafreader I could directly use it to get terms.

---

## [Kibana can't work with Elasticsearch explicit date format as input](https://discuss.elastic.co/t/kibana-cant-work-with-elasticsearch-explicit-date-format-as-input/334941)

<div class="topic-metadata">

**Author:** [@ggomez](https://discuss.elastic.co/u/ggomez)\
**Replies:** 5\
**Last updated:** [June 9, 2023, 11:27am UTC](https://discuss.elastic.co/t/kibana-cant-work-with-elasticsearch-explicit-date-format-as-input/334941 "2023-06-09T11:27:56Z")

</div>

Hello. In the company that I work for, we are currently using Elasticsearch 8.6.2 + Kibana 8.6.2 (both with authentication enabled) for create a custom dashboard where we are showing some metrics that we need. As the T…

---

## [Sophos XG logs that removes the pipe but are in the Elastichsearch](https://discuss.elastic.co/t/sophos-xg-logs-that-removes-the-pipe-but-are-in-the-elastichsearch/334601)

<div class="topic-metadata">

**Author:** [@marotaal](https://discuss.elastic.co/u/marotaal)\
**Replies:** 1\
**Last updated:** [June 9, 2023, 10:58am UTC](https://discuss.elastic.co/t/sophos-xg-logs-that-removes-the-pipe-but-are-in-the-elastichsearch/334601 "2023-06-09T10:58:22Z")

</div>

Thank you for your time. I’m new to the ELK system. I’m collecting information from a Sophos XG 19.5 The structure I have is: Firewall XG (19.5) --\> Filebeat (7.17.10) -\> Elastichsearch (7.17.8) I have detected that…

---

## [Route to pages in plugin](https://discuss.elastic.co/t/route-to-pages-in-plugin/334581)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 8\
**Last updated:** [June 9, 2023, 10:45am UTC](https://discuss.elastic.co/t/route-to-pages-in-plugin/334581 "2023-06-09T10:45:37Z")

</div>

Hi, I am creating an external plugin in React. How can i implement routes in plugin? Like giving path for different components/pages. Is there any inbuilt way of doing the same in Kibana?... like there is for toast, h…

---

## [About elastic full seach text score](https://discuss.elastic.co/t/about-elastic-full-seach-text-score/335598)

<div class="topic-metadata">

**Author:** [@GithubRyze](https://discuss.elastic.co/u/GithubRyze)\
**Replies:** 1\
**Last updated:** [June 9, 2023, 10:39am UTC](https://discuss.elastic.co/t/about-elastic-full-seach-text-score/335598 "2023-06-09T10:39:03Z")

</div>

We have 4 docs in Elastictsearch index. the docs content as below: 1. { “content”: "elastic a good engine"} 2. { “content”: "elastic a nice password"} 3. { “content”: "elastic password is 12344fe"} 4. { “content…

---

## [Logstash and Filebeat on Windows](https://discuss.elastic.co/t/logstash-and-filebeat-on-windows/333568)

<div class="topic-metadata">

**Author:** [@Raul\_dum](https://discuss.elastic.co/u/Raul_dum)\
**Replies:** 7\
**Last updated:** [June 9, 2023, 9:34am UTC](https://discuss.elastic.co/t/logstash-and-filebeat-on-windows/333568 "2023-06-09T09:34:46Z")

</div>

Hi, I am having problems with my Logstash and Filebeat. Everytime I start Filebeat and Logstash to send logs to kibana,nothing appears in kibana but logstash and filebeat seem to be working just fine,I wonder if anybod…

---

## [Kibana - TypeError: Failed to fetch](https://discuss.elastic.co/t/kibana-typeerror-failed-to-fetch/335612)

<div class="topic-metadata">

**Author:** [@YaroslavSh](https://discuss.elastic.co/u/YaroslavSh)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 10:10am UTC](https://discuss.elastic.co/t/kibana-typeerror-failed-to-fetch/335612 "2023-06-09T10:10:45Z")

</div>

Hi. I cannot find referenced anywhere. I was wondering if anyone has come across this? An internal server error occurred. Version: 7.17.7 Build: 47059 Error at fetch\_Fetch.fetchResponse (https://development-kibana.…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=514)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=516)
