# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=547

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 548

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/332956)

<div class="topic-metadata">

**Author:** [@Ali\_Trache](https://discuss.elastic.co/u/Ali_Trache)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 1:13am UTC](https://discuss.elastic.co/t/elasticsearch/332956 "2023-05-11T01:13:16Z")

</div>

hello ; please i want somme repense for me . thank you 1-How to size ELk storage? 2-How to check storage status and detect possible saturation? Can it be integrated into an “ELK” Dashboard? 3- how can we expand the s…

---

## [Visualization of parts of URL](https://discuss.elastic.co/t/visualization-of-parts-of-url/332858)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 1:12am UTC](https://discuss.elastic.co/t/visualization-of-parts-of-url/332858 "2023-05-11T01:12:09Z")

</div>

How to reopen the closed issue Visualization of parts of URL ? @jughosta I just saw the reply. How to use the proposed solution to filter parts of the URL and show it in my pie chart? Thanks.

---

## [Read after write consistency (test refresh interval)](https://discuss.elastic.co/t/read-after-write-consistency-test-refresh-interval/332809)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 1:05am UTC](https://discuss.elastic.co/t/read-after-write-consistency-test-refresh-interval/332809 "2023-05-11T01:05:33Z")

</div>

I have a refresh interval of 1 s. I want to confirm that this is actually happening. Is there a test to validate the item getting indexed is getting searchable in a second? If so, How do I do that? I am ingesting documen…

---

## [Legend of a map](https://discuss.elastic.co/t/legend-of-a-map/332999)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 4\
**Last updated:** [May 11, 2023, 1:04am UTC](https://discuss.elastic.co/t/legend-of-a-map/332999 "2023-05-11T01:04:59Z")

</div>

Hi, Just a question : For the moment it's impossible to change the label in the legend of a map. Do you know if this feature is expected or not? t would be very useful because sometimes the legend is not very meaningfu…

---

## [With Java API Client, update by appending to field array of document](https://discuss.elastic.co/t/with-java-api-client-update-by-appending-to-field-array-of-document/332859)

<div class="topic-metadata">

**Author:** [@rrrrrr](https://discuss.elastic.co/u/rrrrrr)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 3:09am UTC](https://discuss.elastic.co/t/with-java-api-client-update-by-appending-to-field-array-of-document/332859 "2023-05-09T03:09:03Z")

</div>

Hello, Is there any examples to update a document partially ? I would like to append to a field array utilizing Java API Client. I would like to not use Scripts or Java High Level Client if possible. Thank you, Reza …

---

## [Search rate of index is too high in Kibana, but no query in actually](https://discuss.elastic.co/t/search-rate-of-index-is-too-high-in-kibana-but-no-query-in-actually/332883)

<div class="topic-metadata">

**Author:** [@hongbo](https://discuss.elastic.co/u/hongbo)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 12:57am UTC](https://discuss.elastic.co/t/search-rate-of-index-is-too-high-in-kibana-but-no-query-in-actually/332883 "2023-05-11T00:57:26Z")

</div>

search rate of index is too high in kibana stack-monitoring, but no query in actually. at the same time, with the primaries(number\_of\_shards) increase, the search rate value increase. for example, i have three index: m…

---

## [Aliases Error in Ingest pipeline Index](https://discuss.elastic.co/t/aliases-error-in-ingest-pipeline-index/332814)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 12:54am UTC](https://discuss.elastic.co/t/aliases-error-in-ingest-pipeline-index/332814 "2023-05-11T00:54:29Z")

</div>

Hi Team, We are processing the logs using API key from below path. C# -\> ingest pipeline -\> Elasticsearch -\> kibana We ran the below template but Aliases not working, it shows none. Please find the snapshot attached. …

---

## [BulkRequest with Java API Client missing document part](https://discuss.elastic.co/t/bulkrequest-with-java-api-client-missing-document-part/333077)

<div class="topic-metadata">

**Author:** [@DavJane](https://discuss.elastic.co/u/DavJane)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 11:00am UTC](https://discuss.elastic.co/t/bulkrequest-with-java-api-client-missing-document-part/333077 "2023-05-10T11:00:47Z")

</div>

Hi all, I am migrating from Elasticsearch high rest client 6.x to Java API client and have encountered an issue with the BulkRequest. I am creating a json string and sending that in as part of the document part of the …

---

## [Multisearch (bulk) knn searches](https://discuss.elastic.co/t/multisearch-bulk-knn-searches/333095)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 12:27am UTC](https://discuss.elastic.co/t/multisearch-bulk-knn-searches/333095 "2023-05-11T00:27:50Z")

</div>

Hello, I want to use knn searching on dense\_vectors for similarity searches, but I want to issue multiple requests at once using the Multisearch API. Is this possible? The Java client library (co.elastic.clients:elast…

---

## [Import data csv/json](https://discuss.elastic.co/t/import-data-csv-json/333090)

<div class="topic-metadata">

**Author:** [@Haitem\_Touiss](https://discuss.elastic.co/u/Haitem_Touiss)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 12:03am UTC](https://discuss.elastic.co/t/import-data-csv-json/333090 "2023-05-11T00:03:01Z")

</div>

Hello, I am having difficulty importing data into Elasticsearch version 7.17, but it is working fine in the latest version. I have tried several methods, including using Logstash and Beats, but none of them seem to be w…

---

## [Disabling the \_size mapping?](https://discuss.elastic.co/t/disabling-the-size-mapping/332831)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 11:57pm UTC](https://discuss.elastic.co/t/disabling-the-size-mapping/332831 "2023-05-10T23:57:28Z")

</div>

I want to enable and disable the size mapping. Enable worked fine after the index refreshed and I disable the \_size set to false but I still able to query the \_size. How can I disable so no one can query?

---

## [Unable to recover my cluster](https://discuss.elastic.co/t/unable-to-recover-my-cluster/333000)

<div class="topic-metadata">

**Author:** [@Ashu\_Mahajan](https://discuss.elastic.co/u/Ashu_Mahajan)\
**Replies:** 12\
**Last updated:** [May 10, 2023, 10:58pm UTC](https://discuss.elastic.co/t/unable-to-recover-my-cluster/333000 "2023-05-10T22:58:56Z")

</div>

We moved our data to new version of elasticsearch. The new cluster have 3 master, 3 hot and 3 warm nodes. Everything was working fine till this morning and all of a cluster health went red. After looking at it further, I…

---

## [Question about Elasticsearch query](https://discuss.elastic.co/t/question-about-elasticsearch-query/331074)

<div class="topic-metadata">

**Author:** [@sayerszero](https://discuss.elastic.co/u/sayerszero)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 9:50pm UTC](https://discuss.elastic.co/t/question-about-elasticsearch-query/331074 "2023-05-10T21:50:02Z")

</div>

New to the community and not sure this is the best category for this question, but here goes: We're trying to monitor CPU thresholds through Rules and Connectors with beats 7.16. We originally were doing this using Metr…

---

## [Logtash with saml](https://discuss.elastic.co/t/logtash-with-saml/333131)

<div class="topic-metadata">

**Author:** [@Pablo\_Crosio](https://discuss.elastic.co/u/Pablo_Crosio)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 9:22pm UTC](https://discuss.elastic.co/t/logtash-with-saml/333131 "2023-05-10T21:22:38Z")

</div>

Is it possible to connect with Logtash to OpenSearch using SAML authentication? We are able to integrate with SAML and Azure AD to log in to dashboards but we are unable to connect Logtash to OpenSearch with an Azure AD…

---

## [Issue regarding setup and local host](https://discuss.elastic.co/t/issue-regarding-setup-and-local-host/333017)

<div class="topic-metadata">

**Author:** [@Tushar25](https://discuss.elastic.co/u/Tushar25)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 9:16pm UTC](https://discuss.elastic.co/t/issue-regarding-setup-and-local-host/333017 "2023-05-10T21:16:45Z")

</div>

Hello there, I'm having an issue doing the setup of the version 8.7.1, (http:// localhost:9200/) this link requires a password to which the default USERNAME('elastic') and PASSWORD('changeme') is not working or giving a…

---

## [Duplicating Event To Multiple Indices](https://discuss.elastic.co/t/duplicating-event-to-multiple-indices/332955)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 3\
**Last updated:** [May 10, 2023, 4:18pm UTC](https://discuss.elastic.co/t/duplicating-event-to-multiple-indices/332955 "2023-05-10T16:18:40Z")

</div>

I have events coming in with an ID of 123. Is it possible to have this event indexed into two different indices by doing something like below? output { if \[log\] == 123 { elasticsearch { index =\> "123logs" …

---

## [Ukrainian analyzer](https://discuss.elastic.co/t/ukrainian-analyzer/333062)

<div class="topic-metadata">

**Author:** [@Vladimir\_Talabko](https://discuss.elastic.co/u/Vladimir_Talabko)\
**Replies:** 16\
**Last updated:** [May 10, 2023, 3:46pm UTC](https://discuss.elastic.co/t/ukrainian-analyzer/333062 "2023-05-10T15:46:35Z")

</div>

Hello! I have a hosting with installed the Ukrainian plugin from this page Ukrainian analysis plugin | Elasticsearch Plugins and Integrations \[8.7\] | Elastic . It's proven by this command: bin/elasticsearch-plugin list …

---

## [Vega Directed Graph Breaks w/ Input Sliders](https://discuss.elastic.co/t/vega-directed-graph-breaks-w-input-sliders/332589)

<div class="topic-metadata">

**Author:** [@ikiril01](https://discuss.elastic.co/u/ikiril01)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 3:43pm UTC](https://discuss.elastic.co/t/vega-directed-graph-breaks-w-input-sliders/332589 "2023-05-10T15:43:34Z")

</div>

I'm trying to build a force-directed graph in Kibana (v8.3.3) using Vega. I've got the graph built out successfully, with the caveat that sometimes it can display quite a large amount of data, thus making it overwhelmin…

---

## [Kibana - Automatizar login acceso a kibana](https://discuss.elastic.co/t/kibana-automatizar-login-acceso-a-kibana/333032)

<div class="topic-metadata">

**Author:** [@Javier\_Garcia\_Alvare](https://discuss.elastic.co/u/Javier_Garcia_Alvare)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 3:15pm UTC](https://discuss.elastic.co/t/kibana-automatizar-login-acceso-a-kibana/333032 "2023-05-10T15:15:55Z")

</div>

Buenos días, versión 6.8.3 Es posible el automatizar el login de acceso a kibana y en la url de acceso pasar las credenciales y que apunten a un dashboard. Gracias, un saludo Javier.

---

## [Elasticsearch not updating data from Logstash](https://discuss.elastic.co/t/elasticsearch-not-updating-data-from-logstash/333097)

<div class="topic-metadata">

**Author:** [@VVlad23](https://discuss.elastic.co/u/VVlad23)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 2:51pm UTC](https://discuss.elastic.co/t/elasticsearch-not-updating-data-from-logstash/333097 "2023-05-10T14:51:09Z")

</div>

Hello! So it's been some time I've spent trying to figure out what exactly is happening and why there is a problem. We're sending information from a server through Filebeat to Logstash. Logstash is installed on one of …

---

## [Winlogbeat 8.7.1 service crashes immediately after starting](https://discuss.elastic.co/t/winlogbeat-8-7-1-service-crashes-immediately-after-starting/332948)

<div class="topic-metadata">

**Author:** [@Mike7](https://discuss.elastic.co/u/Mike7)\
**Replies:** 6\
**Last updated:** [May 10, 2023, 2:39pm UTC](https://discuss.elastic.co/t/winlogbeat-8-7-1-service-crashes-immediately-after-starting/332948 "2023-05-10T14:39:54Z")

</div>

Hi All, On a fresh install (Server 2022) the Winlogbeat service crashes immediately after starting (when there are events in the monitored log present) or - when the log is cleared - it crashes after the first event com…

---

## [Suggestions response doesnt contain index information or information about document where the suggestion was found](https://discuss.elastic.co/t/suggestions-response-doesnt-contain-index-information-or-information-about-document-where-the-suggestion-was-found/332543)

<div class="topic-metadata">

**Author:** [@schawla](https://discuss.elastic.co/u/schawla)\
**Replies:** 3\
**Last updated:** [May 10, 2023, 2:18pm UTC](https://discuss.elastic.co/t/suggestions-response-doesnt-contain-index-information-or-information-about-document-where-the-suggestion-was-found/332543 "2023-05-10T14:18:57Z")

</div>

Hi, I am trying to trace a suggestion to its source document returned by my search suggestion query in Elasticsearch 7.9 It seems the suggest Options only returns the suggested text , frequency and score. I see that the…

---

## [Difference between UNIX\_MS and epoch\_millis in date processor?](https://discuss.elastic.co/t/difference-between-unix-ms-and-epoch-millis-in-date-processor/333048)

<div class="topic-metadata">

**Author:** [@chengye233](https://discuss.elastic.co/u/chengye233)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 1:40pm UTC](https://discuss.elastic.co/t/difference-between-unix-ms-and-epoch-millis-in-date-processor/333048 "2023-05-10T13:40:17Z")

</div>

Hi, I use ingest pipeline to add @timestamp field automatically from a exist date type field. My exist date type field is called uploadTime and it's date format is epoch\_millis. In the processor, I firstly use epoch\_mi…

---

## [Vector knn search with more than 1024 dimensions](https://discuss.elastic.co/t/vector-knn-search-with-more-than-1024-dimensions/332819)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 4\
**Last updated:** [May 10, 2023, 1:35pm UTC](https://discuss.elastic.co/t/vector-knn-search-with-more-than-1024-dimensions/332819 "2023-05-10T13:35:26Z")

</div>

If I understood correctly, from version 8.8 elasticsearch will support knn search for vectors over 1024 dimensions. Is there any indication when this will be released? I'm trying to work with openai embeddings (2nd gener…

---

## [Cannot set custom data view for a bar chart in Kibana Lens](https://discuss.elastic.co/t/cannot-set-custom-data-view-for-a-bar-chart-in-kibana-lens/333086)

<div class="topic-metadata">

**Author:** [@NotSoOld](https://discuss.elastic.co/u/NotSoOld)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 1:32pm UTC](https://discuss.elastic.co/t/cannot-set-custom-data-view-for-a-bar-chart-in-kibana-lens/333086 "2023-05-10T13:32:50Z")

</div>

Hello. Seems like there is a bug in Kibana Lens when I try to set custom data view for the one of my dashboard components (a bar chart). Here are the steps to follow: Add bar chart to dashboard Bar chart will have some…

---

## [Winlogbeat doesn't drop events](https://discuss.elastic.co/t/winlogbeat-doesnt-drop-events/332557)

<div class="topic-metadata">

**Author:** [@h49nakxs](https://discuss.elastic.co/u/h49nakxs)\
**Replies:** 4\
**Last updated:** [May 10, 2023, 1:08pm UTC](https://discuss.elastic.co/t/winlogbeat-doesnt-drop-events/332557 "2023-05-10T13:08:27Z")

</div>

Hi there, How the hell are we supposed to configure winlogbeats (ecs.version : 1.6.0) to drop events ? I've tried, many, many variations, but none of them worked. - name: Security processors: - drop\_event.…

---

## [Search Query Based on Nested Fields](https://discuss.elastic.co/t/search-query-based-on-nested-fields/333084)

<div class="topic-metadata">

**Author:** [@Mustafa\_AYDOGDU](https://discuss.elastic.co/u/Mustafa_AYDOGDU)\
**Replies:** 4\
**Last updated:** [May 10, 2023, 1:04pm UTC](https://discuss.elastic.co/t/search-query-based-on-nested-fields/333084 "2023-05-10T13:04:01Z")

</div>

I have this kind of data: "1655184519597531137": { "reply\_depth": 1, "gather\_likes": false, "gather\_user\_data": "false", "keyword": "galatasaray", "gather\_retw…

---

## [How to duplicate a rule?](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 7\
**Last updated:** [May 10, 2023, 12:40pm UTC](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042 "2023-05-10T12:40:13Z")

</div>

Hello, I have to create several rules-alerts that are very similar. Is there a way to duplicate (copy/paste) a rule ? Thank you.

---

## [Elasticsearch / logstash Log time shift](https://discuss.elastic.co/t/elasticsearch-logstash-log-time-shift/332898)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 6\
**Last updated:** [May 10, 2023, 12:28pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-log-time-shift/332898 "2023-05-10T12:28:54Z")

</div>

I currently have a small problem and I don't know why it happens. I have my log 2023-05-09 09:20:11 \[DEBUG\] org.apache.activemq.transport.AbstractInactivityMonitor:150 -\> WriteChecker: 10000ms elapsed since last write …

---

## [Term suggester returning correct suggestions for misspelled words outside of suggester data source](https://discuss.elastic.co/t/term-suggester-returning-correct-suggestions-for-misspelled-words-outside-of-suggester-data-source/333083)

<div class="topic-metadata">

**Author:** [@MilanGatyas](https://discuss.elastic.co/u/MilanGatyas)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 12:26pm UTC](https://discuss.elastic.co/t/term-suggester-returning-correct-suggestions-for-misspelled-words-outside-of-suggester-data-source/333083 "2023-05-10T12:26:07Z")

</div>

Please help me understand why this happens. We use Elasticsearch 7.10 term suggester. The field didYouMean.trigram we use for the suggestions has the following mapping "didYouMean" : { "type" : "text", "fields" : { …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=546)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=548)
