# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=564

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 565

---

## [Size of an index](https://discuss.elastic.co/t/size-of-an-index/330387)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 2\
**Last updated:** [April 21, 2023, 4:55am UTC](https://discuss.elastic.co/t/size-of-an-index/330387 "2023-04-21T04:55:13Z")

</div>

I have 9 tenants. Each tenant is about 1 TB. Could I create 1 index for each tenant? so 9 indices in total? this would mean each index is 1 TB 9 TB of data over 9 indices. To maintain safe shard size, my index will hav…

---

## [Logstash MYSQL jdbc](https://discuss.elastic.co/t/logstash-mysql-jdbc/330410)

<div class="topic-metadata">

**Author:** [@gabrile\_jaime\_gomez](https://discuss.elastic.co/u/gabrile_jaime_gomez)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 6:00am UTC](https://discuss.elastic.co/t/logstash-mysql-jdbc/330410 "2023-04-21T06:00:28Z")

</div>

H i, I'm trying to integrate with mysql and I get the following error. \[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"Java::JavaLang…

---

## [PlainElastic Agent Installation](https://discuss.elastic.co/t/plainelastic-agent-installation/330402)

<div class="topic-metadata">

**Author:** [@Christian\_V](https://discuss.elastic.co/u/Christian_V)\
**Replies:** 2\
**Last updated:** [April 21, 2023, 5:44am UTC](https://discuss.elastic.co/t/plainelastic-agent-installation/330402 "2023-04-21T05:44:21Z")

</div>

Hello, I tried to install via zip/tar on either on windows or linux host, both finished and there is a connection to the self managed fleet server. On Windows if i call diagnost I get the message: Error: failed to fet…

---

## [Elasticsearch helm](https://discuss.elastic.co/t/elasticsearch-helm/330391)

<div class="topic-metadata">

**Author:** [@thirumoorthy](https://discuss.elastic.co/u/thirumoorthy)\
**Replies:** 4\
**Last updated:** [April 21, 2023, 4:26am UTC](https://discuss.elastic.co/t/elasticsearch-helm/330391 "2023-04-21T04:26:45Z")

</div>

Warning Unhealthy 11s (x31 over 4m50s) kubelet Readiness probe failed: Waiting for elasticsearch cluster to become ready (request params: "wait\_for\_status=green&timeout=2s" ) Cluster is not yet ready (requ…

---

## [Accessing kibana detections](https://discuss.elastic.co/t/accessing-kibana-detections/330493)

<div class="topic-metadata">

**Author:** [@hobbyist](https://discuss.elastic.co/u/hobbyist)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 3:53am UTC](https://discuss.elastic.co/t/accessing-kibana-detections/330493 "2023-04-21T03:53:10Z")

</div>

Is it possible to access/modify detection rules in Kibana via CLI? If version matters, I am using version 7.10.2 on linux.

---

## [Setup.template.name Setup template.pattern have to be set](https://discuss.elastic.co/t/setup-template-name-setup-template-pattern-have-to-be-set/330383)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves2](https://discuss.elastic.co/u/Joel_Goncalves2)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 1:47am UTC](https://discuss.elastic.co/t/setup-template-name-setup-template-pattern-have-to-be-set/330383 "2023-04-21T01:47:42Z")

</div>

I am trying to send packetbeat data to another index and it is giving me this error. Error initializing beat: setup.template.name and setup.template.pattern have to be set …

---

## [ES pagination under the hood](https://discuss.elastic.co/t/es-pagination-under-the-hood/329679)

<div class="topic-metadata">

**Author:** [@eslearner58](https://discuss.elastic.co/u/eslearner58)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 12:17am UTC](https://discuss.elastic.co/t/es-pagination-under-the-hood/329679 "2023-04-21T00:17:07Z")

</div>

I am trying to implement pagination for quite heavy ES queries so I did some research on the options available, but documentation didn't answer some of my questions: search\_after is the recommended way for doing the d…

---

## [ElasticSearch watcher configuration](https://discuss.elastic.co/t/elasticsearch-watcher-configuration/330486)

<div class="topic-metadata">

**Author:** [@Praveen\_kr](https://discuss.elastic.co/u/Praveen_kr)\
**Replies:** 1\
**Last updated:** [April 21, 2023, 12:13am UTC](https://discuss.elastic.co/t/elasticsearch-watcher-configuration/330486 "2023-04-21T00:13:20Z")

</div>

Hi Team, This is to inform you all. We are implementing watcher in our company. We have 13 nodes( Master nodes - 3 and data nodes -10). When I tried to add the settings as before in my Elasticsearch yml file as attache…

---

## [How to remove extra unnecessary details from kibana anonymous user public dashboard](https://discuss.elastic.co/t/how-to-remove-extra-unnecessary-details-from-kibana-anonymous-user-public-dashboard/330289)

<div class="topic-metadata">

**Author:** [@aman\_giri](https://discuss.elastic.co/u/aman_giri)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 11:35pm UTC](https://discuss.elastic.co/t/how-to-remove-extra-unnecessary-details-from-kibana-anonymous-user-public-dashboard/330289 "2023-04-20T23:35:59Z")

</div>

I have created an anonymous user in kibana.yml using that configuration no credentials are required to access the public dashboard with url i.e http://xx.xxx.xx.xx:5601/s/adv\_public/app/dashboards#/view/bc58c7d6-9073-4a…

---

## [Index rotation hour increases](https://discuss.elastic.co/t/index-rotation-hour-increases/330376)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 11:12pm UTC](https://discuss.elastic.co/t/index-rotation-hour-increases/330376 "2023-04-20T23:12:31Z")

</div>

Hi, I am using ILM to rollover my indexes after a maximum age of 1 day. After some debug I noticed a strange pattern with this: 1 - first index is rotated at 2:34am 2 - second index is rotated at 2:44am 3 - third ind…

---

## [Multiline json data into logstash](https://discuss.elastic.co/t/multiline-json-data-into-logstash/330484)

<div class="topic-metadata">

**Author:** [@andrew0087b](https://discuss.elastic.co/u/andrew0087b)\
**Replies:** 0\
**Last updated:** [April 20, 2023, 9:56pm UTC](https://discuss.elastic.co/t/multiline-json-data-into-logstash/330484 "2023-04-20T21:56:45Z")

</div>

Hello, I have the following JSON structure that I want to parse with Logstash: { "messages" : \[ { "remoteReferenceId" : "133883", "sender" : { "name" : "User1" } }, { "remoteReferenceId" : "13…

---

## [New data stream creation fails](https://discuss.elastic.co/t/new-data-stream-creation-fails/330481)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 9:31pm UTC](https://discuss.elastic.co/t/new-data-stream-creation-fails/330481 "2023-04-20T21:31:37Z")

</div>

I am trying to create my own data stream with ILM and index .ds but it is not working Follwing worked PUT \_ilm/policy/sachin { "policy": { "phases": { "hot": { "min\_age": "0ms", "actions": …

---

## [Can I make a node in a cluster migrate to another cluster?](https://discuss.elastic.co/t/can-i-make-a-node-in-a-cluster-migrate-to-another-cluster/330474)

<div class="topic-metadata">

**Author:** [@camiyu1](https://discuss.elastic.co/u/camiyu1)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 9:25pm UTC](https://discuss.elastic.co/t/can-i-make-a-node-in-a-cluster-migrate-to-another-cluster/330474 "2023-04-20T21:25:36Z")

</div>

Hello, I am currently operating an Elasticsearch cluster of three nodes. Let's say them "cluster A" and "node A1, A2, A3" There is a separate cluster of one node. Let's say it "cluster B" and "node B1" Node B1 has a lo…

---

## [Multitenancy](https://discuss.elastic.co/t/multitenancy/330357)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 3\
**Last updated:** [April 20, 2023, 9:20pm UTC](https://discuss.elastic.co/t/multitenancy/330357 "2023-04-20T21:20:15Z")

</div>

I want to set up a multitenant elasticsearch cluster. say I have :expressionless: 100 GB index (tenant 1) 150 GB index (tenant 2) 20 GB (tenant 3) 30 GB (tenant 4) How could I set up multitenancy? how do I route the …

---

## [Do we need to add ECS Logger to our Filebeat just to get log.level as a field in the JSON?](https://discuss.elastic.co/t/do-we-need-to-add-ecs-logger-to-our-filebeat-just-to-get-log-level-as-a-field-in-the-json/329779)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 7\
**Last updated:** [April 20, 2023, 9:00pm UTC](https://discuss.elastic.co/t/do-we-need-to-add-ecs-logger-to-our-filebeat-just-to-get-log-level-as-a-field-in-the-json/329779 "2023-04-20T21:00:38Z")

</div>

I've been rereading the Filebeat documentation to try to deepen my understanding of how it works. We have been configuring Filebeat manually with inputs like this: - type: filestream id: my-api fields: app\_id: …

---

## [Error with sql-cli jar](https://discuss.elastic.co/t/error-with-sql-cli-jar/322371)

<div class="topic-metadata">

**Author:** [@nikssssss](https://discuss.elastic.co/u/nikssssss)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 8:09pm UTC](https://discuss.elastic.co/t/error-with-sql-cli-jar/322371 "2023-04-20T20:09:08Z")

</div>

hello, i have tried SQL CLI stand alone Java application and is not working. I always get an error message: "Cannot communicate with the server ..... . This version of CLI only works with Elasticsearch version 8.5.3. (M…

---

## [Logstash can't connect to elasticsearch](https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch/330041)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 7:50pm UTC](https://discuss.elastic.co/t/logstash-cant-connect-to-elasticsearch/330041 "2023-04-20T19:50:41Z")

</div>

Hi friends, please your help, we have this message: in log from logstash \[2023-04-14T20:49:18,951\]\[INFO \]\[logstash.outputs.elasticsearch\]\[rpa\_centria\_test\] Failed to perform request {:message=\>"PKIX path building failed…

---

## [Geoshape query and spatial relations](https://discuss.elastic.co/t/geoshape-query-and-spatial-relations/330470)

<div class="topic-metadata">

**Author:** [@JbalancioLP](https://discuss.elastic.co/u/JbalancioLP)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 7:35pm UTC](https://discuss.elastic.co/t/geoshape-query-and-spatial-relations/330470 "2023-04-20T19:35:02Z")

</div>

I'd like to return documents using the geoshape query, but I'm having trouble deciding which spatial relation to use. The document has a location as a geopoint. I will be searching by providing a polygon. Should I use th…

---

## [Master node network bandwidth requirements](https://discuss.elastic.co/t/master-node-network-bandwidth-requirements/330468)

<div class="topic-metadata">

**Author:** [@Aurel1](https://discuss.elastic.co/u/Aurel1)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 7:22pm UTC](https://discuss.elastic.co/t/master-node-network-bandwidth-requirements/330468 "2023-04-20T19:22:57Z")

</div>

Hello, I have a cluster with dedicated master nodes. I recently noticed, that the current master has relatively high network bandwidth requirements (sustained non-stop ~15Mb/s in, and ~15Mb/s out). It seems that the traf…

---

## [.\\winlogbeat.exe -c winlogbeat.yml hangs](https://discuss.elastic.co/t/winlogbeat-exe-c-winlogbeat-yml-hangs/330465)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 20, 2023, 6:23pm UTC](https://discuss.elastic.co/t/winlogbeat-exe-c-winlogbeat-yml-hangs/330465 "2023-04-20T18:23:18Z")

</div>

Hi, I could not delete the winglogbeat service, but when I used the command .\\unstall etc that was suggested, I had to reboot to delete it. Then running this ".\\winlogbeat.exe -c winlogbeat.yml" in powershell hangs. It…

---

## [Merging hybrid search results (BM25 + HNSW) in elastic 8.7](https://discuss.elastic.co/t/merging-hybrid-search-results-bm25-hnsw-in-elastic-8-7/330225)

<div class="topic-metadata">

**Author:** [@Francisco\_Rocha](https://discuss.elastic.co/u/Francisco_Rocha)\
**Replies:** 3\
**Last updated:** [April 20, 2023, 5:57pm UTC](https://discuss.elastic.co/t/merging-hybrid-search-results-bm25-hnsw-in-elastic-8-7/330225 "2023-04-20T17:57:50Z")

</div>

Hi there! I'm new to Elastic and have been trying to do a information retrieval system for 500k documents of text using python and docker (for elastic 8.7). I'm not really sure how to go about doing an hybrid search (BM…

---

## [Elasticsearch 8.5 Java Client increase field weights during search](https://discuss.elastic.co/t/elasticsearch-8-5-java-client-increase-field-weights-during-search/330408)

<div class="topic-metadata">

**Author:** [@Denko](https://discuss.elastic.co/u/Denko)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 5:35pm UTC](https://discuss.elastic.co/t/elasticsearch-8-5-java-client-increase-field-weights-during-search/330408 "2023-04-20T17:35:04Z")

</div>

Hi! I'm trying to figure out how to boost weights for some of the fields in the index during a search. For instance, I have the name field and I'd like Elasticsearch to give it x2 relevance score. Is it possible to do th…

---

## [Modifiy a runtime field](https://discuss.elastic.co/t/modifiy-a-runtime-field/330430)

<div class="topic-metadata">

**Author:** [@abkrim](https://discuss.elastic.co/u/abkrim)\
**Replies:** 0\
**Last updated:** [April 20, 2023, 5:30pm UTC](https://discuss.elastic.co/t/modifiy-a-runtime-field/330430 "2023-04-20T17:30:30Z")

</div>

If have a runtime filed in my index "runtime": { "total\_consumption": { "type": "double", "script": { "source": """ double sum = 0; if (doc\['pa1\_w'\].size() == …

---

## [Working hours on the visualization](https://discuss.elastic.co/t/working-hours-on-the-visualization/330405)

<div class="topic-metadata">

**Author:** [@b2ron](https://discuss.elastic.co/u/b2ron)\
**Replies:** 0\
**Last updated:** [April 20, 2023, 4:07pm UTC](https://discuss.elastic.co/t/working-hours-on-the-visualization/330405 "2023-04-20T16:07:30Z")

</div>

Is it possible to show working hours on the visualization? I have a dashboard, but I want to see the working hours on it. ideal case if I can choose working hours from a list (different countries, time zones...) chart…

---

## [Critical security vulnerabilities reported with go version 1.19.7](https://discuss.elastic.co/t/critical-security-vulnerabilities-reported-with-go-version-1-19-7/330200)

<div class="topic-metadata">

**Author:** [@manojrkrish](https://discuss.elastic.co/u/manojrkrish)\
**Replies:** 2\
**Last updated:** [April 20, 2023, 3:58pm UTC](https://discuss.elastic.co/t/critical-security-vulnerabilities-reported-with-go-version-1-19-7/330200 "2023-04-20T15:58:41Z")

</div>

Hi, Recently few critical vulnerabilities are reported in go version 1.19.7 with below CVEs. https://nvd.nist.gov/vuln/detail/CVE-2023-24536 https://nvd.nist.gov/vuln/detail/CVE-2023-24537 https://nvd.nist.gov/vuln/d…

---

## [Ingest node discovery](https://discuss.elastic.co/t/ingest-node-discovery/330399)

<div class="topic-metadata">

**Author:** [@frank\_2](https://discuss.elastic.co/u/frank_2)\
**Replies:** 0\
**Last updated:** [April 20, 2023, 2:47pm UTC](https://discuss.elastic.co/t/ingest-node-discovery/330399 "2023-04-20T14:47:25Z")

</div>

Hello, I have a high write / ingest volume and have configured dedicated ingest nodes for my cluster. I have non-Elasticsearch workers in front of these ingest nodes which pre-process data and which are happily sending…

---

## [About Beats Input](https://discuss.elastic.co/t/about-beats-input/330322)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 5\
**Last updated:** [April 20, 2023, 2:40pm UTC](https://discuss.elastic.co/t/about-beats-input/330322 "2023-04-20T14:40:54Z")

</div>

Hi, We occasionally receive log lines like this at the beats input: {"level":"info","ts":1681833658.6787357,"caller":"filterprocessor@v0.75.0/traces.go:74","msg":"Span filter configured","env":"","hostname":"tst","tags…

---

## [Unit test using Springboot to check if an index exists in Elasticsearch](https://discuss.elastic.co/t/unit-test-using-springboot-to-check-if-an-index-exists-in-elasticsearch/330384)

<div class="topic-metadata">

**Author:** [@Maleesha\_De\_Silva](https://discuss.elastic.co/u/Maleesha_De_Silva)\
**Replies:** 3\
**Last updated:** [April 20, 2023, 1:40pm UTC](https://discuss.elastic.co/t/unit-test-using-springboot-to-check-if-an-index-exists-in-elasticsearch/330384 "2023-04-20T13:40:01Z")

</div>

How do I write a unit test case using Springboot to check if an index exists in Elasticsearch version 8.7?

---

## [Elastic to Snowflake index movemnet](https://discuss.elastic.co/t/elastic-to-snowflake-index-movemnet/330392)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 1:32pm UTC](https://discuss.elastic.co/t/elastic-to-snowflake-index-movemnet/330392 "2023-04-20T13:32:32Z")

</div>

Hi Team, We would like to move certain indices (4-5 indices ) from elasticsearch to snowflake on a day to day basis. Please provide the possible methods to do the same. ELK version :7.17 platinum Thanks, Shalini.

---

## [Elasticsearch with Tomcat nodecommunication](https://discuss.elastic.co/t/elasticsearch-with-tomcat-nodecommunication/330390)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 1\
**Last updated:** [April 20, 2023, 1:04pm UTC](https://discuss.elastic.co/t/elasticsearch-with-tomcat-nodecommunication/330390 "2023-04-20T13:04:41Z")

</div>

Hi Team, We are using Tomcat application and elasticsearch 7.3 with Java 8 We are using the ransport client to communicate each other. Now we are planning to update the TOMCAT application node with java 17 and Elastic…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=563)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=565)
