# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=580

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 581

---

## [High Number of indices affect on performance](https://discuss.elastic.co/t/high-number-of-indices-affect-on-performance/329355)

<div class="topic-metadata">

**Author:** [@sukur55](https://discuss.elastic.co/u/sukur55)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 7:46am UTC](https://discuss.elastic.co/t/high-number-of-indices-affect-on-performance/329355 "2023-04-05T07:46:24Z")

</div>

Does, number of indices has considerable affect on running/startup performance? like image having 100GB of data in 50 indices or having 100GB data on 300+ indices, how they differ from performance perspective? imagine I …

---

## [Several types as values to same key](https://discuss.elastic.co/t/several-types-as-values-to-same-key/329194)

<div class="topic-metadata">

**Author:** [@yael\_shifman](https://discuss.elastic.co/u/yael_shifman)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 7:34am UTC](https://discuss.elastic.co/t/several-types-as-values-to-same-key/329194 "2023-04-05T07:34:56Z")

</div>

I have jenkins logs in a json format. (taken with the API) the logs have different types of value to the same key: ''' { "\_class":"hudson.model.StringParameterValue", "name":"MANIFEST\_REVISION", "value":"master" }…

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/329375)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 1\
**Last updated:** [April 5, 2023, 7:34am UTC](https://discuss.elastic.co/t/elasticsearch/329375 "2023-04-05T07:34:48Z")

</div>

Hi Team, How to deploy metric beats through ECK. Is there any document fot this.

---

## [Custom service monitoring and autodiscovery](https://discuss.elastic.co/t/custom-service-monitoring-and-autodiscovery/329323)

<div class="topic-metadata">

**Author:** [@denisk](https://discuss.elastic.co/u/denisk)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 1:02pm UTC](https://discuss.elastic.co/t/custom-service-monitoring-and-autodiscovery/329323 "2023-04-04T13:02:49Z")

</div>

Hi, I have set up metric collection of a number of custom microservices using the http module. Per microservice I've create a separate yaml file, and in each yaml file looks something like this: # Each service has its …

---

## [Monitor API URL with Elastic](https://discuss.elastic.co/t/monitor-api-url-with-elastic/329371)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [April 5, 2023, 5:59am UTC](https://discuss.elastic.co/t/monitor-api-url-with-elastic/329371 "2023-04-05T05:59:40Z")

</div>

Hello, I would like to monitor the API URL in Azure with Elastic and the flow is like below image. My question is how do we grab the authentication token to monitor the API URL? And after grabbing the authenticatio…

---

## [Moving Index/shards from Hot Tier to Warm Tier using custom Attributes within zones using ILM](https://discuss.elastic.co/t/moving-index-shards-from-hot-tier-to-warm-tier-using-custom-attributes-within-zones-using-ilm/329277)

<div class="topic-metadata">

**Author:** [@vikasp](https://discuss.elastic.co/u/vikasp)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 5:09am UTC](https://discuss.elastic.co/t/moving-index-shards-from-hot-tier-to-warm-tier-using-custom-attributes-within-zones-using-ilm/329277 "2023-04-05T05:09:32Z")

</div>

I usually move an index to warm tier using ILM and the default \_tier\_preference if I have the nodes defined as data\_warm. Lets say I have multiple indices with varied number of shards. index1 with 5 shards and index 2 w…

---

## [Filebeat - 10000s of messages "Reader was closed. Closing.#011" flooding log](https://discuss.elastic.co/t/filebeat-10000s-of-messages-reader-was-closed-closing-011-flooding-log/329088)

<div class="topic-metadata">

**Author:** [@Alex\_Stuck](https://discuss.elastic.co/u/Alex_Stuck)\
**Replies:** 5\
**Last updated:** [April 5, 2023, 5:31am UTC](https://discuss.elastic.co/t/filebeat-10000s-of-messages-reader-was-closed-closing-011-flooding-log/329088 "2023-04-05T05:31:28Z")

</div>

Hey there Subject says it all. I have a simple filebeat agent pointing to some other team's LS that I don't control. I get spammed with the following line at a rate of up to 1000/minute and it doesn't stop. Here an exam…

---

## [Why my geoip lookup is failing?](https://discuss.elastic.co/t/why-my-geoip-lookup-is-failing/329353)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 12:52am UTC](https://discuss.elastic.co/t/why-my-geoip-lookup-is-failing/329353 "2023-04-05T00:52:47Z")

</div>

Hi Team, This is my logstash config and surprisingly my geoip lookup is failed, I am not sure why. Can someone pls help? input { stdin {} } filter { json { source =\> "message" remove\_field =\> …

---

## [Using Nested Field in Composite Aggregation](https://discuss.elastic.co/t/using-nested-field-in-composite-aggregation/329359)

<div class="topic-metadata">

**Author:** [@michael-jaxsta](https://discuss.elastic.co/u/michael-jaxsta)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 11:57pm UTC](https://discuss.elastic.co/t/using-nested-field-in-composite-aggregation/329359 "2023-04-04T23:57:01Z")

</div>

This question has been asked a few times in this community but have not got a response so hopefully someone reads this and helps me out! I'm trying to do a composite aggregation on documents which have nested fields. Sp…

---

## [Filebeat doesn't publish logs without "write" permission on index](https://discuss.elastic.co/t/filebeat-doesnt-publish-logs-without-write-permission-on-index/328870)

<div class="topic-metadata">

**Author:** [@Savva\_Morozov](https://discuss.elastic.co/u/Savva_Morozov)\
**Replies:** 5\
**Last updated:** [April 4, 2023, 10:30pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-publish-logs-without-write-permission-on-index/328870 "2023-04-04T22:30:15Z")

</div>

Hello! I created API key for Filebeat to publish log records to Elasticsearch using this documentation as a reference: Grant privileges and roles needed for publishing | Filebeat Reference \[8.6\] | Elastic. But after I d…

---

## [How do index rollover and tier transition work when they overlap](https://discuss.elastic.co/t/how-do-index-rollover-and-tier-transition-work-when-they-overlap/329240)

<div class="topic-metadata">

**Author:** [@EyadArafat](https://discuss.elastic.co/u/EyadArafat)\
**Replies:** 4\
**Last updated:** [April 4, 2023, 9:51pm UTC](https://discuss.elastic.co/t/how-do-index-rollover-and-tier-transition-work-when-they-overlap/329240 "2023-04-04T21:51:07Z")

</div>

Hi, I'm a little confused on how transitioning a data stream's write index to the warm phase would work if it's still not supposed to be rolled-over yet. Here's an example. Let's say I have an ILM to rollover the data …

---

## [Kibana8.6.2 not loading in browser](https://discuss.elastic.co/t/kibana8-6-2-not-loading-in-browser/328557)

<div class="topic-metadata">

**Author:** [@sivamca127](https://discuss.elastic.co/u/sivamca127)\
**Replies:** 16\
**Last updated:** [April 4, 2023, 8:57pm UTC](https://discuss.elastic.co/t/kibana8-6-2-not-loading-in-browser/328557 "2023-04-04T20:57:24Z")

</div>

Hi Team, I'm Brand new to ELK stack. I'm trying to configure ELK on my RHEL7.5 system. After Good struggle i was able to configure Elasticsearch and it was up and running . FYI Now i've configured Kibana and here is…

---

## [Elastic Cluster connection Issue](https://discuss.elastic.co/t/elastic-cluster-connection-issue/327593)

<div class="topic-metadata">

**Author:** [@Stalin](https://discuss.elastic.co/u/Stalin)\
**Replies:** 5\
**Last updated:** [April 4, 2023, 7:49pm UTC](https://discuss.elastic.co/t/elastic-cluster-connection-issue/327593 "2023-04-04T19:49:02Z")

</div>

Hi, We have frequently faced the below issue " Can not connect to the Elastic Search Cluster See the Kibana logs for details and try to reload the page" Someone pls help me on this!!

---

## [Logstash shutting down](https://discuss.elastic.co/t/logstash-shutting-down/329344)

<div class="topic-metadata">

**Author:** [@th\_shadoow](https://discuss.elastic.co/u/th_shadoow)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 5:55pm UTC](https://discuss.elastic.co/t/logstash-shutting-down/329344 "2023-04-04T17:55:15Z")

</div>

after installing logstash in a windows machine and tried launching it with the command : bin\\logstash -f logstash.conf it start but immediatlly shows an error message and shut down the error meassge : org.jruby.excepti…

---

## [Is it possible to reconnect to an Agent after uninstalling the Elastic Agent service?](https://discuss.elastic.co/t/is-it-possible-to-reconnect-to-an-agent-after-uninstalling-the-elastic-agent-service/328273)

<div class="topic-metadata">

**Author:** [@kreed](https://discuss.elastic.co/u/kreed)\
**Replies:** 3\
**Last updated:** [April 4, 2023, 5:27pm UTC](https://discuss.elastic.co/t/is-it-possible-to-reconnect-to-an-agent-after-uninstalling-the-elastic-agent-service/328273 "2023-04-04T17:27:46Z")

</div>

I am new the Elastic so this question may be trivial. For some background, I am working on an application that monitors the status of the Elastic Agent Windows service. I want this app to be able to uninstall and re-inst…

---

## [Logstash csv imports not all data into elastic search](https://discuss.elastic.co/t/logstash-csv-imports-not-all-data-into-elastic-search/329199)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 3:50pm UTC](https://discuss.elastic.co/t/logstash-csv-imports-not-all-data-into-elastic-search/329199 "2023-04-04T15:50:36Z")

</div>

Hi guys! Do you have any idea why I can't import all the data from csv.file via logstash into Elasticsearch? it always imports the same amount equal to 6873 and should be more than 53k. at runtime, the console displays …

---

## [Logging: How to set selectors correctly](https://discuss.elastic.co/t/logging-how-to-set-selectors-correctly/329341)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 3:14pm UTC](https://discuss.elastic.co/t/logging-how-to-set-selectors-correctly/329341 "2023-04-04T15:14:57Z")

</div>

Hi I need to debug some filebeat issues in one of our testsystems. I want to set loglevel to debug and I need help for setting the selectors correctly. I need to have all the logs which are related to registry, harvest…

---

## [Carbon Black Cloud Integration not working](https://discuss.elastic.co/t/carbon-black-cloud-integration-not-working/329336)

<div class="topic-metadata">

**Author:** [@stgalvisg](https://discuss.elastic.co/u/stgalvisg)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 2:46pm UTC](https://discuss.elastic.co/t/carbon-black-cloud-integration-not-working/329336 "2023-04-04T14:46:47Z")

</div>

Good day to you all! Since a few days ago I have a problem with the Carbon Black Cloud Integration in Elastic 8.4.1 with Fleet server. The API's Keys happened to be working just fine, I received the alert and audit alert…

---

## [Elasticsearch - getting GC and the node reconnect from the cluster](https://discuss.elastic.co/t/elasticsearch-getting-gc-and-the-node-reconnect-from-the-cluster/329232)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 2\
**Last updated:** [April 4, 2023, 2:04pm UTC](https://discuss.elastic.co/t/elasticsearch-getting-gc-and-the-node-reconnect-from-the-cluster/329232 "2023-04-04T14:04:11Z")

</div>

we are getting GC and during that time heap usage is reducing and even sometimes the node reconnects from the cluster below are the params we are using and the GC -XX:+UseConcMarkSweepGC -XX:+UseParNewGC -XX:CMSIniti…

---

## [Kibana custom plugin, how to implement a react-leaflet and leaflet libs?](https://discuss.elastic.co/t/kibana-custom-plugin-how-to-implement-a-react-leaflet-and-leaflet-libs/329219)

<div class="topic-metadata">

**Author:** [@Lilia](https://discuss.elastic.co/u/Lilia)\
**Replies:** 4\
**Last updated:** [April 4, 2023, 1:20pm UTC](https://discuss.elastic.co/t/kibana-custom-plugin-how-to-implement-a-react-leaflet-and-leaflet-libs/329219 "2023-04-04T13:20:58Z")

</div>

Hi all, Could you please tell me if anyone of you have successfully implement leaflet lib and react-leaflet to kibana custom plugin? Also I'm not able to find good explanation on how to implement map in custom plugin? W…

---

## [Indices Folder inside Backup not cleaning up](https://discuss.elastic.co/t/indices-folder-inside-backup-not-cleaning-up/328902)

<div class="topic-metadata">

**Author:** [@DVoss2](https://discuss.elastic.co/u/DVoss2)\
**Replies:** 2\
**Last updated:** [April 4, 2023, 1:16pm UTC](https://discuss.elastic.co/t/indices-folder-inside-backup-not-cleaning-up/328902 "2023-04-04T13:16:49Z")

</div>

Hi! We are creating daily backups with: curl -u elastic: -X PUT 127.0.0.1:9200/\_snapshot/backup/snapshot-$snapdate?wait\_for\_completion=true and delete older ones with curl -u elastic: -X DELETE "127.0.0.1:9200/\_sna…

---

## [Elasticsearch mail Alerts via index Connector](https://discuss.elastic.co/t/elasticsearch-mail-alerts-via-index-connector/329287)

<div class="topic-metadata">

**Author:** [@Pawan\_kumar1](https://discuss.elastic.co/u/Pawan_kumar1)\
**Replies:** 5\
**Last updated:** [April 4, 2023, 12:54pm UTC](https://discuss.elastic.co/t/elasticsearch-mail-alerts-via-index-connector/329287 "2023-04-04T12:54:25Z")

</div>

elasticsearch mail Alerts via index Connector

---

## [Curl -X GET 'http://localhost:9200' curl: (52) Empty reply from server](https://discuss.elastic.co/t/curl-x-get-http-localhost-9200-curl-52-empty-reply-from-server/329211)

<div class="topic-metadata">

**Author:** [@Adarsh\_R\_K](https://discuss.elastic.co/u/Adarsh_R_K)\
**Replies:** 7\
**Last updated:** [April 4, 2023, 12:49pm UTC](https://discuss.elastic.co/t/curl-x-get-http-localhost-9200-curl-52-empty-reply-from-server/329211 "2023-04-04T12:49:59Z")

</div>

elasticsearch service is active and running but got this error while accessing 9200, elasticsearch.yml file is properly configuredcurl -X GET 'http://localhost:9200' curl: (52) Empty reply from server

---

## [Downsampling Documentation](https://discuss.elastic.co/t/downsampling-documentation/329105)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 2\
**Last updated:** [April 4, 2023, 12:18pm UTC](https://discuss.elastic.co/t/downsampling-documentation/329105 "2023-04-04T12:18:48Z")

</div>

Hi, I have the feeling this step is wrong: This query won't return an aggregation, only hits: Or could it be that the previous step is a post and not a get?

---

## [Issue using a sshfs docker mount as a snapshot repository](https://discuss.elastic.co/t/issue-using-a-sshfs-docker-mount-as-a-snapshot-repository/328822)

<div class="topic-metadata">

**Author:** [@Benjamin\_Goetz](https://discuss.elastic.co/u/Benjamin_Goetz)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 11:29am UTC](https://discuss.elastic.co/t/issue-using-a-sshfs-docker-mount-as-a-snapshot-repository/328822 "2023-04-04T11:29:13Z")

</div>

Hello, I'm having trouble trying to get Elasticsearch to register a docker mount as a snapshot repository. The situation I'm migrating indices from a server to another, let's call them "old host" and "new host". Both …

---

## [Logstash consumes persistent queue size when no events stored](https://discuss.elastic.co/t/logstash-consumes-persistent-queue-size-when-no-events-stored/329311)

<div class="topic-metadata">

**Author:** [@ferdose\_shaik](https://discuss.elastic.co/u/ferdose_shaik)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 11:03am UTC](https://discuss.elastic.co/t/logstash-consumes-persistent-queue-size-when-no-events-stored/329311 "2023-04-04T11:03:25Z")

</div>

Hi, We are using persistent queue in Logstash to store the events when output is blocked. Please refer to the following configuration. - pipeline.id: syslog queue.type: persisted queue.max\_bytes: 128mb path.confi…

---

## [My filebeat is not able to talk with ealsticsearch](https://discuss.elastic.co/t/my-filebeat-is-not-able-to-talk-with-ealsticsearch/329304)

<div class="topic-metadata">

**Author:** [@madhav](https://discuss.elastic.co/u/madhav)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 11:01am UTC](https://discuss.elastic.co/t/my-filebeat-is-not-able-to-talk-with-ealsticsearch/329304 "2023-04-04T11:01:14Z")

</div>

I am getting below error while testing out put from filebeat. Let me know if anyone has any solution.

---

## [During scale in of logstash through HPA data remains in the persistence queue](https://discuss.elastic.co/t/during-scale-in-of-logstash-through-hpa-data-remains-in-the-persistence-queue/329307)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 10:42am UTC](https://discuss.elastic.co/t/during-scale-in-of-logstash-through-hpa-data-remains-in-the-persistence-queue/329307 "2023-04-04T10:42:31Z")

</div>

Problem Statement :- In our environment we are sending application logs from Fluentd to logstash where persistent queues are enabled. HPA is enabled on the logstash pod so when the load increases so logstash pods scale …

---

## [Elastic creating new Index on Bulk Api even though mapping is already provided](https://discuss.elastic.co/t/elastic-creating-new-index-on-bulk-api-even-though-mapping-is-already-provided/329294)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 5\
**Last updated:** [April 4, 2023, 10:39am UTC](https://discuss.elastic.co/t/elastic-creating-new-index-on-bulk-api-even-though-mapping-is-already-provided/329294 "2023-04-04T10:39:27Z")

</div>

Hi Community Members Using Elastic 8 with JAVA client.I first created template of mapping like below Index Name=A is created two in elastic 8 server instead of overwritingalready present mapping file { "settings": {…

---

## [Java API enforces specifying both min and max in extended bounds unlike RHLC](https://discuss.elastic.co/t/java-api-enforces-specifying-both-min-and-max-in-extended-bounds-unlike-rhlc/329202)

<div class="topic-metadata">

**Author:** [@awojcik64](https://discuss.elastic.co/u/awojcik64)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 11:47am UTC](https://discuss.elastic.co/t/java-api-enforces-specifying-both-min-and-max-in-extended-bounds-unlike-rhlc/329202 "2023-04-03T11:47:20Z")

</div>

Hello, Edit: tested on dockerized Elasticsearch 7.17.7, 7.17.9, client version is 7.17.9 During migration to Java API client (from rest high level client) I've encountered an inconsistency regarding extended bounds in …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=579)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=581)
