# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=544

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 545

---

## [Increase heap size of Elastic Cluster in dev tools](https://discuss.elastic.co/t/increase-heap-size-of-elastic-cluster-in-dev-tools/333165)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [May 13, 2023, 4:56am UTC](https://discuss.elastic.co/t/increase-heap-size-of-elastic-cluster-in-dev-tools/333165 "2023-05-13T04:56:25Z")

</div>

Hi all, I'm trying to increase Elastic RAM alloted to Elastic. I know i have to change -Xmx=1G -Xms=1G in jvm options file. But I have access only to elastic and kibana. Is there a way to increase in dev tools or a…

---

## [Run ELK with docker compose](https://discuss.elastic.co/t/run-elk-with-docker-compose/332969)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 7\
**Last updated:** [May 12, 2023, 11:29pm UTC](https://discuss.elastic.co/t/run-elk-with-docker-compose/332969 "2023-05-12T23:29:56Z")

</div>

Hi everyone I want to run the ELK 8.7.0 using docker compose I create the docker-compose.yml file with this configuration : version: '3' services: mysql: container\_name: mysql hostname: mysql image: 'm…

---

## [Suricata Logs Not Received by Elastic Cloud](https://discuss.elastic.co/t/suricata-logs-not-received-by-elastic-cloud/333334)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 6:19pm UTC](https://discuss.elastic.co/t/suricata-logs-not-received-by-elastic-cloud/333334 "2023-05-12T18:19:11Z")

</div>

I have set up both the 'Windows' and 'Suricata' integrations, using the same Agent Policy. Both integrations are showing that my client machine is connected. On the client, I have installed the Elastic Agent, however onl…

---

## [Tema integration message formatting for alert](https://discuss.elastic.co/t/tema-integration-message-formatting-for-alert/333321)

<div class="topic-metadata">

**Author:** [@Gaston\_Beltramelli](https://discuss.elastic.co/u/Gaston_Beltramelli)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 6:04pm UTC](https://discuss.elastic.co/t/tema-integration-message-formatting-for-alert/333321 "2023-05-12T18:04:06Z")

</div>

Hello everyone! I need help for formatting an alert to TEAMS integration, i've been trying to add a new line in the message but i couldn´t find much info about t in kibana i set up this Alerta para {{context.group}} {…

---

## [Aggregations count vs hits count](https://discuss.elastic.co/t/aggregations-count-vs-hits-count/332648)

<div class="topic-metadata">

**Author:** [@NNI](https://discuss.elastic.co/u/NNI)\
**Replies:** 3\
**Last updated:** [May 12, 2023, 5:01pm UTC](https://discuss.elastic.co/t/aggregations-count-vs-hits-count/332648 "2023-05-12T17:01:11Z")

</div>

Hi I would like to concern on aggregations count for explain in more details But for the sake of presenting the case a little background : I have cluster contains with 3 master nodes, 3 ingest nodes, 3 data nodes so t…

---

## [Show which tokens were not found in full text search](https://discuss.elastic.co/t/show-which-tokens-were-not-found-in-full-text-search/333331)

<div class="topic-metadata">

**Author:** [@kadermetov](https://discuss.elastic.co/u/kadermetov)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 4:48pm UTC](https://discuss.elastic.co/t/show-which-tokens-were-not-found-in-full-text-search/333331 "2023-05-12T16:48:34Z")

</div>

Hello, beautiful community! Is there a way to determine which words (tokens) in a phrase was or wasn't found during full text search. I need it to make something like Google does: Under each query result it shows wh…

---

## [About ELK STack](https://discuss.elastic.co/t/about-elk-stack/333296)

<div class="topic-metadata">

**Author:** [@Anil\_Sai\_Pinnelli](https://discuss.elastic.co/u/Anil_Sai_Pinnelli)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 3:54pm UTC](https://discuss.elastic.co/t/about-elk-stack/333296 "2023-05-12T15:54:55Z")

</div>

Commands to link Mysql DB to elasticsearch using logstash. I am having one configuration file but, it did'nt worked for me!! input { jdbc { jdbc\_driver\_library =\> "/root/mysql-connector-java-5.1.30-bin.jar" jdbc\_dri…

---

## [After add xpack.security.enabled,my kibana does not work](https://discuss.elastic.co/t/after-add-xpack-security-enabled-my-kibana-does-not-work/333253)

<div class="topic-metadata">

**Author:** [@Dadaguai](https://discuss.elastic.co/u/Dadaguai)\
**Replies:** 8\
**Last updated:** [May 12, 2023, 1:48pm UTC](https://discuss.elastic.co/t/after-add-xpack-security-enabled-my-kibana-does-not-work/333253 "2023-05-12T13:48:22Z")

</div>

my elasticsearch.yml as follows: http.host: 0.0.0.0 http.cors.enabled: true http.cors.allow-origin: "\*" network.host: 172.17.0.9 discovery.type: single-node http.port: 9200 action.auto\_create\_index: true http.cors.allow…

---

## [Verify internode communication is using TLS](https://discuss.elastic.co/t/verify-internode-communication-is-using-tls/332975)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 5\
**Last updated:** [May 12, 2023, 2:51pm UTC](https://discuss.elastic.co/t/verify-internode-communication-is-using-tls/332975 "2023-05-12T14:51:18Z")

</div>

Having set up TLS for internode communication per is there a way to confirm that is is being used? E.g. is there something specific that gets written to the log during start up when it's in use, or is there something t…

---

## [How to determine the bottleneck between Filebeat and ES?](https://discuss.elastic.co/t/how-to-determine-the-bottleneck-between-filebeat-and-es/333272)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 2:48pm UTC](https://discuss.elastic.co/t/how-to-determine-the-bottleneck-between-filebeat-and-es/333272 "2023-05-12T14:48:01Z")

</div>

Hi, I'm trying to determine the bottleneck for my Netflow setup, to see if I can further optimize the performance. I am ingesting Netflow traffic into a Linux server running both filebeat and elasticsearch 7.1.4. I'm u…

---

## [Upgrade Elastic and Kibana from 7.17 to 8.7 - S](https://discuss.elastic.co/t/upgrade-elastic-and-kibana-from-7-17-to-8-7-s/333036)

<div class="topic-metadata">

**Author:** [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Replies:** 6\
**Last updated:** [May 12, 2023, 2:32pm UTC](https://discuss.elastic.co/t/upgrade-elastic-and-kibana-from-7-17-to-8-7-s/333036 "2023-05-12T14:32:53Z")

</div>

Hello, We are in the process of migrating our Elasticsearch and Kibana from 7.17 to 8.7. We are facing an issue where after upgrading Elasticsearch works out fine but when starting Kibana we are seeing these errors. "A…

---

## [CSV Response Data Format from SQL Rest API](https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 2:20pm UTC](https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224 "2023-05-12T14:20:12Z")

</div>

Hi, I was told in a previous post: that Elasticsearch cannot return csv as response data: Then I found this: I've been trying to play around with it, but must admit I'm a little lost. I have a Kibana query that lo…

---

## [ScrollID is coming as null](https://discuss.elastic.co/t/scrollid-is-coming-as-null/330938)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 5\
**Last updated:** [May 12, 2023, 1:47pm UTC](https://discuss.elastic.co/t/scrollid-is-coming-as-null/330938 "2023-05-12T13:47:59Z")

</div>

I am using elastic8. with java client. I first used elasticclient.search() request this returned scrollId then i used same scrollID to call client.scroll(scrollID) api however the first call elasticclient.search() i…

---

## [Multithreading in Kafka input plugin for Filebeat](https://discuss.elastic.co/t/multithreading-in-kafka-input-plugin-for-filebeat/333309)

<div class="topic-metadata">

**Author:** [@Hichem](https://discuss.elastic.co/u/Hichem)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 1:33pm UTC](https://discuss.elastic.co/t/multithreading-in-kafka-input-plugin-for-filebeat/333309 "2023-05-12T13:33:11Z")

</div>

I'm using the Filebeat Kafka input plugin to consume data from Kafka and send it to Elastic. I noticed Filebeat starts 1 consumer thread only. Is there a way to increase the number of consumers? I tried changing the ma…

---

## [3 Node Elasticsearch cluster is failing repeatedly with error: this node is unhealthy: health check failed due to broken node lock](https://discuss.elastic.co/t/3-node-elasticsearch-cluster-is-failing-repeatedly-with-error-this-node-is-unhealthy-health-check-failed-due-to-broken-node-lock/333234)

<div class="topic-metadata">

**Author:** [@akansha.agarwal1](https://discuss.elastic.co/u/akansha.agarwal1)\
**Replies:** 3\
**Last updated:** [May 12, 2023, 1:17pm UTC](https://discuss.elastic.co/t/3-node-elasticsearch-cluster-is-failing-repeatedly-with-error-this-node-is-unhealthy-health-check-failed-due-to-broken-node-lock/333234 "2023-05-12T13:17:16Z")

</div>

Hi All, I am stuck in a very weird situation. My 3-node ES cluster is failing after 8-10 days abruptly with error: \[WARN \]\[o.e.c.c.ClusterFormationFailureHelper\] \[elasticsearch-0.es-service\] this node is unhealthy: he…

---

## [Create a new index when document has a particular field?](https://discuss.elastic.co/t/create-a-new-index-when-document-has-a-particular-field/333307)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 1:06pm UTC](https://discuss.elastic.co/t/create-a-new-index-when-document-has-a-particular-field/333307 "2023-05-12T13:06:15Z")

</div>

Is it possible to create a new index everytime my document has a particular field updated? say all docs with 'tenant':"100" are part of one index and if a document comes with a field "tenant":101, a new index is created…

---

## [Index Thread Pools](https://discuss.elastic.co/t/index-thread-pools/333302)

<div class="topic-metadata">

**Author:** [@Mohit\_Munjal](https://discuss.elastic.co/u/Mohit_Munjal)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 12:54pm UTC](https://discuss.elastic.co/t/index-thread-pools/333302 "2023-05-12T12:54:34Z")

</div>

My objective is to calculate how many index requests can a elasticsearch cluster hold in it's queue before starting rejecting it. My elasticsearch cluster(v6.8) has 8 data nodes of r5.xlarge instance i.e. 4 vCPU's. In …

---

## [Invalid NEST response built from a successful (404) low level call on GET:](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-successful-404-low-level-call-on-get/333044)

<div class="topic-metadata">

**Author:** [@LhamoDev](https://discuss.elastic.co/u/LhamoDev)\
**Replies:** 6\
**Last updated:** [May 12, 2023, 12:23pm UTC](https://discuss.elastic.co/t/invalid-nest-response-built-from-a-successful-404-low-level-call-on-get/333044 "2023-05-12T12:23:28Z")

</div>

Hello I'm doing a Get Request in my code: var response = await Repository.ElasticClient.GetAsync\<Reservation\>(maskId).ConfigureAwait(false); And I'm getting this as a response: Invalid NEST response built from a succ…

---

## [Using Contains string or "wildcard" in filter button](https://discuss.elastic.co/t/using-contains-string-or-wildcard-in-filter-button/333247)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 11:28am UTC](https://discuss.elastic.co/t/using-contains-string-or-wildcard-in-filter-button/333247 "2023-05-12T11:28:25Z")

</div>

Hi all, I'm trying to use "wildcard" option in filter as shown below i.e location.keyword : \*PASO\* show me any string that contains PASO string anywhere in the word. I know I can use in KQL in search bar or DSL quer…

---

## [ILM leaves empty shards of 225bytes](https://discuss.elastic.co/t/ilm-leaves-empty-shards-of-225bytes/333252)

<div class="topic-metadata">

**Author:** [@Lin\_Yu](https://discuss.elastic.co/u/Lin_Yu)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 11:27am UTC](https://discuss.elastic.co/t/ilm-leaves-empty-shards-of-225bytes/333252 "2023-05-12T11:27:52Z")

</div>

Hello, I'm using elastcisearch v8.5 and filebeat. My question is : How could i solve 0 bytes shard keep rolling over? How to delete 0bytes shards? How to set up ILM correctly? This is the configuration of filebeat.y…

---

## [How do I 'Update All Fields Where'](https://discuss.elastic.co/t/how-do-i-update-all-fields-where/333293)

<div class="topic-metadata">

**Author:** [@ste1](https://discuss.elastic.co/u/ste1)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-do-i-update-all-fields-where/333293 "2023-05-12T11:21:05Z")

</div>

I have a few different indicies that have logs in them that were digested using Logstash. The filter in my config looks like this: filter { csv { autodetect\_column\_names =\> false columns =\> \["uid", "ip"\] …

---

## [Why does the performance difference occur when searching in the regular or keyword field?](https://discuss.elastic.co/t/why-does-the-performance-difference-occur-when-searching-in-the-regular-or-keyword-field/333289)

<div class="topic-metadata">

**Author:** [@Ruveyda\_Aksoy](https://discuss.elastic.co/u/Ruveyda_Aksoy)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 11:13am UTC](https://discuss.elastic.co/t/why-does-the-performance-difference-occur-when-searching-in-the-regular-or-keyword-field/333289 "2023-05-12T11:13:39Z")

</div>

Hi, I have a question regarding query performance. The data types of the fields I am querying are as follows. "primaryIdentificationNumber" : { "type" : "keyword", "fields" : { …

---

## [Collapse feature and total\_hist after collapse](https://discuss.elastic.co/t/collapse-feature-and-total-hist-after-collapse/333288)

<div class="topic-metadata">

**Author:** [@\_zogaj](https://discuss.elastic.co/u/_zogaj)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 11:12am UTC](https://discuss.elastic.co/t/collapse-feature-and-total-hist-after-collapse/333288 "2023-05-12T11:12:41Z")

</div>

As Elastisearch documantion said: The total number of hits in the response indicates the number of matching documents without collapsing. The total number of distinct group is unknown. I am using a search with paginatio…

---

## [Reasoning behind Geonames Rally Design](https://discuss.elastic.co/t/reasoning-behind-geonames-rally-design/333271)

<div class="topic-metadata">

**Author:** [@lquenti](https://discuss.elastic.co/u/lquenti)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 11:04am UTC](https://discuss.elastic.co/t/reasoning-behind-geonames-rally-design/333271 "2023-05-12T11:04:28Z")

</div>

Hi, I am currently evaluating Elasticsearch for a HPC related data lake infrastructure. For that, we are currently using rally benchmarker, especially with the geonames and nyc taxis. Since our HPC environment is batch…

---

## [Fleet & Elastic Agent not working](https://discuss.elastic.co/t/fleet-elastic-agent-not-working/333282)

<div class="topic-metadata">

**Author:** [@knit](https://discuss.elastic.co/u/knit)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 10:24am UTC](https://discuss.elastic.co/t/fleet-elastic-agent-not-working/333282 "2023-05-12T10:24:29Z")

</div>

Hi Team, We recently moved log data (/var/lib/elasticsearch) from AWS EBS to S3. During this process all the services were stopped except elasticagent. After successful data transfer, integrations through filebeat is wo…

---

## [Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[nginx\_uat\_test-frontend\_mobile-test\] does not point to index \[nginx\_uat\_test-frontend\_mobile\_2023.05.12\]](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-nginx-uat-test-frontend-mobile-test-does-not-point-to-index-nginx-uat-test-frontend-mobile-2023-05-12/333276)

<div class="topic-metadata">

**Author:** [@Alwyn\_Tiu](https://discuss.elastic.co/u/Alwyn_Tiu)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 9:54am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-nginx-uat-test-frontend-mobile-test-does-not-point-to-index-nginx-uat-test-frontend-mobile-2023-05-12/333276 "2023-05-12T09:54:03Z")

</div>

Rule： { "del-test" : { "version" : 1, "modified\_date" : "2023-05-11T09:30:54.350Z", "policy" : { "phases" : { "hot" : { "min\_age" : "0ms", "actions" : { "rollover" : { "max\_age" : "1d" }, "set\_priority" : { …

---

## [How works Allocation shards data tiers recommanded](https://discuss.elastic.co/t/how-works-allocation-shards-data-tiers-recommanded/333274)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 9:17am UTC](https://discuss.elastic.co/t/how-works-allocation-shards-data-tiers-recommanded/333274 "2023-05-12T09:17:14Z")

</div>

Hi everybody, Fine ? Questions about the allocation of the shards :wink: I have a big index that has his dedicated index template with 3 primary shards and 1 replica { "order": 1, "index\_patterns": \[ "tdir\_busin…

---

## [Can't access connect to Fleet Server](https://discuss.elastic.co/t/cant-access-connect-to-fleet-server/333248)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 8:20am UTC](https://discuss.elastic.co/t/cant-access-connect-to-fleet-server/333248 "2023-05-12T08:20:10Z")

</div>

Last day I completed configure cluster elasticsearch and I access to kibana is ok but I only cannot access Fleet. And Here is the error picture and details from the log https-in/1: SSL handshake failure message":"F…

---

## [Kibana visualization](https://discuss.elastic.co/t/kibana-visualization/333217)

<div class="topic-metadata">

**Author:** [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 7:48am UTC](https://discuss.elastic.co/t/kibana-visualization/333217 "2023-05-12T07:48:38Z")

</div>

Hi I am trying to build a visualization. Here is the scenario. i have two coulmns, lets say company\_name and cost\_paid\_by\_company. i need to show the cost\_paid\_by\_company which is higher and lower than the threshold in…

---

## [How to add buckets in horizontal bars chart in lens?](https://discuss.elastic.co/t/how-to-add-buckets-in-horizontal-bars-chart-in-lens/330667)

<div class="topic-metadata">

**Author:** [@Yves\_Frerot](https://discuss.elastic.co/u/Yves_Frerot)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 7:41am UTC](https://discuss.elastic.co/t/how-to-add-buckets-in-horizontal-bars-chart-in-lens/330667 "2023-05-12T07:41:14Z")

</div>

I have a chart with a formula as metric. I succeed in a lens horizontal bar graph. But I want to do it for all values of a field with 4 values. I understand the option that consists in repeating the same graph with 4 fil…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=543)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=545)
