# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=585

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 586

---

## [Is there anyway to store document to the index pattern {YYYY.MM.dd} but in CST time {YYYY.MM.dd} via logstash?](https://discuss.elastic.co/t/is-there-anyway-to-store-document-to-the-index-pattern-yyyy-mm-dd-but-in-cst-time-yyyy-mm-dd-via-logstash/328910)

<div class="topic-metadata">

**Author:** [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 1:54am UTC](https://discuss.elastic.co/t/is-there-anyway-to-store-document-to-the-index-pattern-yyyy-mm-dd-but-in-cst-time-yyyy-mm-dd-via-logstash/328910 "2023-03-31T01:54:19Z")

</div>

Hi I have noticed Logstash stores documents to a {YYYY.MM.dd} index in UTC time. However, my local time is CST time. So, for example, my local time is now 2023/3/30 7:40 AM. The Logstash will store the data to index {20…

---

## [No support for nested math in formula?](https://discuss.elastic.co/t/no-support-for-nested-math-in-formula/327977)

<div class="topic-metadata">

**Author:** [@smchamberlin](https://discuss.elastic.co/u/smchamberlin)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 1:49am UTC](https://discuss.elastic.co/t/no-support-for-nested-math-in-formula/327977 "2023-03-31T01:49:35Z")

</div>

Hello, I was able to get this working in python, but getting the following error when I try to nest math functions in an equation for a heat map lens: Is this not supported? Thank you.

---

## [Filebeat Registry File Growing](https://discuss.elastic.co/t/filebeat-registry-file-growing/328983)

<div class="topic-metadata">

**Author:** [@Rich\_Liberty](https://discuss.elastic.co/u/Rich_Liberty)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 11:23pm UTC](https://discuss.elastic.co/t/filebeat-registry-file-growing/328983 "2023-03-30T23:23:25Z")

</div>

Filebeats 7.4.0 running in a relatively large and busy Tanzu Kubernetes cluster (1.20.x) The Filebeat registry file /var/lib/filebeat-data/registry/filebeat/data.json grows causing disk throttling as the file size gets…

---

## [High CPU usage after updating filebeat from 7.12.0 to 8.6.2](https://discuss.elastic.co/t/high-cpu-usage-after-updating-filebeat-from-7-12-0-to-8-6-2/327249)

<div class="topic-metadata">

**Author:** [@germain\_nganko](https://discuss.elastic.co/u/germain_nganko)\
**Replies:** 10\
**Last updated:** [March 30, 2023, 11:17pm UTC](https://discuss.elastic.co/t/high-cpu-usage-after-updating-filebeat-from-7-12-0-to-8-6-2/327249 "2023-03-30T23:17:57Z")

</div>

After updating to filebeat to 8.6.2 I observe an increase in cpu usage. also tested on 8.6.1 same thing, went back to 8.0.0 and could also observe an increase there, however less than in 8.6.2 and 8.6.1. Is there anythi…

---

## [Issue when installing Elasticsearch using helm by staying in rancher](https://discuss.elastic.co/t/issue-when-installing-elasticsearch-using-helm-by-staying-in-rancher/328827)

<div class="topic-metadata">

**Author:** [@thirumoorthy](https://discuss.elastic.co/u/thirumoorthy)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 11:15pm UTC](https://discuss.elastic.co/t/issue-when-installing-elasticsearch-using-helm-by-staying-in-rancher/328827 "2023-03-30T23:15:23Z")

</div>

my values.yaml file antiAffinity: hard antiAffinityTopologyKey: kubernetes.io/hostname clusterHealthCheckParams: wait\_for\_status=green&timeout=1s clusterName: elasticsearch createCert: true enableServiceLinks: tru…

---

## [Does multinode cluster require different certificates or just one will suffice?](https://discuss.elastic.co/t/does-multinode-cluster-require-different-certificates-or-just-one-will-suffice/328963)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 11:05pm UTC](https://discuss.elastic.co/t/does-multinode-cluster-require-different-certificates-or-just-one-will-suffice/328963 "2023-03-30T23:05:56Z")

</div>

Hey team, I have a multi node cluster running which has a hot warm architecture. I have multiple hot nodes running on a single machine as docker images and multiple warm nodes running on another machine(this is also a s…

---

## [doc\['LogMessage.keyword'\].size() returns 0 meaning there is no such field when that field exists and has value](https://discuss.elastic.co/t/doc-logmessage-keyword-size-returns-0-meaning-there-is-no-such-field-when-that-field-exists-and-has-value/328665)

<div class="topic-metadata">

**Author:** [@skazan](https://discuss.elastic.co/u/skazan)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 10:04pm UTC](https://discuss.elastic.co/t/doc-logmessage-keyword-size-returns-0-meaning-there-is-no-such-field-when-that-field-exists-and-has-value/328665 "2023-03-30T22:04:52Z")

</div>

I coded a scripted field named "unique\_log\_message\_\_" as show below. The whole purpose of such field is to show a unique version of some other field named "LogMessage.keyword". And to get into a unique value, I simply re…

---

## [Is there a quick and easy way to check if my node is running in compressed oop?](https://discuss.elastic.co/t/is-there-a-quick-and-easy-way-to-check-if-my-node-is-running-in-compressed-oop/328971)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 9:48pm UTC](https://discuss.elastic.co/t/is-there-a-quick-and-easy-way-to-check-if-my-node-is-running-in-compressed-oop/328971 "2023-03-30T21:48:52Z")

</div>

version 7.15.3

---

## [JVM Heap size larger than 32 GB](https://discuss.elastic.co/t/jvm-heap-size-larger-than-32-gb/328869)

<div class="topic-metadata">

**Author:** [@Milad\_Heydariaan](https://discuss.elastic.co/u/Milad_Heydariaan)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 9:35pm UTC](https://discuss.elastic.co/t/jvm-heap-size-larger-than-32-gb/328869 "2023-03-30T21:35:11Z")

</div>

We have several machines with 512 GB of RAM and I wanted to know if we can set JVM heap size for Elasticsearch larger than 32 GB (up to 256 GB). This page says we should keep the heap size below the threshold for compre…

---

## [Elasticsearch static settings - per node?](https://discuss.elastic.co/t/elasticsearch-static-settings-per-node/328691)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 7\
**Last updated:** [March 30, 2023, 9:30pm UTC](https://discuss.elastic.co/t/elasticsearch-static-settings-per-node/328691 "2023-03-30T21:30:21Z")

</div>

Hi, I am trying to understand the logic behind the static settings. I am trying to keep all nodes with the same configuration/settings where possible, but I'm curios and want to validate about the right way of doing it…

---

## [Configuration as Code for Elasticsearch](https://discuss.elastic.co/t/configuration-as-code-for-elasticsearch/328449)

<div class="topic-metadata">

**Author:** [@sonnenhund](https://discuss.elastic.co/u/sonnenhund)\
**Replies:** 14\
**Last updated:** [March 30, 2023, 9:17pm UTC](https://discuss.elastic.co/t/configuration-as-code-for-elasticsearch/328449 "2023-03-30T21:17:46Z")

</div>

Hi! We are attempting to stand up a full ELK stack and wish to have Elasticsearch fully configured, including ILM policies, Index Templates, and if necessary bootstrapping indices, such that when data begins flowing int…

---

## [Kibana Refused To connect on Browser after Installation (via RPM)](https://discuss.elastic.co/t/kibana-refused-to-connect-on-browser-after-installation-via-rpm/328873)

<div class="topic-metadata">

**Author:** [@abbyode](https://discuss.elastic.co/u/abbyode)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 8:49pm UTC](https://discuss.elastic.co/t/kibana-refused-to-connect-on-browser-after-installation-via-rpm/328873 "2023-03-30T20:49:43Z")

</div>

I am having issues connecting to kibana via browser. The service started successfully via cli but I'm unable to connect on port 5601 - "refused connection". Kibana.yml file: For more configuration options see the confi…

---

## [How to grok catalina log file](https://discuss.elastic.co/t/how-to-grok-catalina-log-file/328895)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 7:24am UTC](https://discuss.elastic.co/t/how-to-grok-catalina-log-file/328895 "2023-03-30T07:24:33Z")

</div>

I have context my config logstash for tomcat filtertomcat filter { if \[fileset\]\[module\] == "tomcat" { if \[fileset\]\[name\] == "tomcatcatalina" { grok { match =\> \[ "message", "(?m)%{TOMCAT\_DATESTAMP:timestamp} %{LOG…

---

## [Is logstash necessarily](https://discuss.elastic.co/t/is-logstash-necessarily/328833)

<div class="topic-metadata">

**Author:** [@LilBaloche](https://discuss.elastic.co/u/LilBaloche)\
**Replies:** 8\
**Last updated:** [March 30, 2023, 8:30pm UTC](https://discuss.elastic.co/t/is-logstash-necessarily/328833 "2023-03-30T20:30:36Z")

</div>

Hi everyone I'm testing ELK in a virtual environment (WinServer AD + DNS, Ubuntu Server 22.04, Ubuntu Client 22.04 and Win 10 Client) I've installed ELK stack on an Ubuntu Server 22.04 (I've been helped by a youtube vi…

---

## [Joining instances to form cluster](https://discuss.elastic.co/t/joining-instances-to-form-cluster/328860)

<div class="topic-metadata">

**Author:** [@DRW-ATCA](https://discuss.elastic.co/u/DRW-ATCA)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 6:23pm UTC](https://discuss.elastic.co/t/joining-instances-to-form-cluster/328860 "2023-03-30T18:23:46Z")

</div>

reference:ERROR: Failed to determine the health of the cluster - #7 by DRW-ATCA My goal is to create a 6-instance cluster in a private VPC (AWS), 1 master, 5 data nodes, with additional instances hosting Kibana and rela…

---

## [ERROR: Failed to determine the health of the cluster](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster/328746)

<div class="topic-metadata">

**Author:** [@DRW-ATCA](https://discuss.elastic.co/u/DRW-ATCA)\
**Replies:** 11\
**Last updated:** [March 30, 2023, 5:20pm UTC](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster/328746 "2023-03-30T17:20:52Z")

</div>

I am trying to add nodes to a cluster for ES 8.6.2 in an AWS EC2 environment. After creating a master node and the first of several data nodes, the two instances give healthy responses to the following commands but do n…

---

## [Logstash not reading my config](https://discuss.elastic.co/t/logstash-not-reading-my-config/328958)

<div class="topic-metadata">

**Author:** [@M\_D](https://discuss.elastic.co/u/M_D)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 5:13pm UTC](https://discuss.elastic.co/t/logstash-not-reading-my-config/328958 "2023-03-30T17:13:32Z")

</div>

I have my config under /etc/logstash/conf.d/myconfig.conf. Below is my simple config input { file { path =\> "/home/foo/logs/\*.log" start\_position =\> "beginning" # stat\_interval =\> 1 # discover\_interval =\>…

---

## [Elastic document\_id](https://discuss.elastic.co/t/elastic-document-id/328738)

<div class="topic-metadata">

**Author:** [@bmagistro1](https://discuss.elastic.co/u/bmagistro1)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 4:08pm UTC](https://discuss.elastic.co/t/elastic-document-id/328738 "2023-03-30T16:08:51Z")

</div>

Is there any defined behavior for document\_id (Elasticsearch output plugin | Logstash Reference \[8.6\] | Elastic) similar to pipeline (Elasticsearch output plugin | Logstash Reference \[8.6\] | Elastic)? We have at least o…

---

## [Date Histogram doesn't work with calendar\_interval month](https://discuss.elastic.co/t/date-histogram-doesnt-work-with-calendar-interval-month/328848)

<div class="topic-metadata">

**Author:** [@Tobse](https://discuss.elastic.co/u/Tobse)\
**Replies:** 8\
**Last updated:** [March 30, 2023, 3:24pm UTC](https://discuss.elastic.co/t/date-histogram-doesnt-work-with-calendar-interval-month/328848 "2023-03-30T15:24:01Z")

</div>

I have tried to use a group\_by with a date\_histogram by month. Our example works like expected with "calendar\_interval": "day" but returns nothing with "calendar\_interval": "month". In fact it seems wo work with day, wee…

---

## [Dataview with some columns excluded](https://discuss.elastic.co/t/dataview-with-some-columns-excluded/328942)

<div class="topic-metadata">

**Author:** [@joerg55](https://discuss.elastic.co/u/joerg55)\
**Replies:** 9\
**Last updated:** [March 30, 2023, 3:16pm UTC](https://discuss.elastic.co/t/dataview-with-some-columns-excluded/328942 "2023-03-30T15:16:35Z")

</div>

Hi community, I want to create a data view of an index without some columns. The background is that these columns lead to the display of 'no results' with certain filters. I only have this one index and I don't have the…

---

## [Trying to create tranform job which would not go through all documents](https://discuss.elastic.co/t/trying-to-create-tranform-job-which-would-not-go-through-all-documents/328905)

<div class="topic-metadata">

**Author:** [@Kiril\_Karamanolev](https://discuss.elastic.co/u/Kiril_Karamanolev)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 3:14pm UTC](https://discuss.elastic.co/t/trying-to-create-tranform-job-which-would-not-go-through-all-documents/328905 "2023-03-30T15:14:14Z")

</div>

Hello, Started using transform but I am struggling to find how to look at only recent documents not from the beginning (because I have 1-year historical data) The JSON of the job is: { "id": "ops\_authrate\_1m", "au…

---

## [How to distribute Primary & Replica shards equally across the nodes](https://discuss.elastic.co/t/how-to-distribute-primary-replica-shards-equally-across-the-nodes/328950)

<div class="topic-metadata">

**Author:** [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 3:03pm UTC](https://discuss.elastic.co/t/how-to-distribute-primary-replica-shards-equally-across-the-nodes/328950 "2023-03-30T15:03:05Z")

</div>

Hi Team, I have Elastic cluster with 3 Master, 5 Data & 2 Client nodes. I have created index called my-index with 5 Primary and 1 Replica also i used setting called number of shards per node is 2. But i could see at f…

---

## [Match query with specific order of terms](https://discuss.elastic.co/t/match-query-with-specific-order-of-terms/328936)

<div class="topic-metadata">

**Author:** [@Rafael\_Kubina](https://discuss.elastic.co/u/Rafael_Kubina)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 2:09pm UTC](https://discuss.elastic.co/t/match-query-with-specific-order-of-terms/328936 "2023-03-30T14:09:14Z")

</div>

We need to match a set of terms in a field while taking the order into account. Example: The document: { "my\_field": "foo bar" } It should match when the user search for foo bar, foo bar baz or baz foo bar but no…

---

## [Correct way to do tiebreaking with search\_after query without PIT](https://discuss.elastic.co/t/correct-way-to-do-tiebreaking-with-search-after-query-without-pit/328941)

<div class="topic-metadata">

**Author:** [@martsraits](https://discuss.elastic.co/u/martsraits)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 1:05pm UTC](https://discuss.elastic.co/t/correct-way-to-do-tiebreaking-with-search-after-query-without-pit/328941 "2023-03-30T13:05:03Z")

</div>

Hi We use search\_after queries to support infinite scroll in the front end. Previously we used \_id field for sorting to keep consistent order. In newer versions of Elasticsearch it's not possible to use \_id field for so…

---

## [Icmp not responding as expected in Elastic](https://discuss.elastic.co/t/icmp-not-responding-as-expected-in-elastic/328900)

<div class="topic-metadata">

**Author:** [@TheNewGuy123](https://discuss.elastic.co/u/TheNewGuy123)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 1:03pm UTC](https://discuss.elastic.co/t/icmp-not-responding-as-expected-in-elastic/328900 "2023-03-30T13:03:26Z")

</div>

Hey, I setup my heartbeat monitoring and I have configured all three kind of monitors: http, tcp and icmp. So I got tcp and http to work correctly, but no luck with icmp (which is the one I actually need). So I am checki…

---

## [Scripted field for date + 12 months](https://discuss.elastic.co/t/scripted-field-for-date-12-months/328715)

<div class="topic-metadata">

**Author:** [@redfox](https://discuss.elastic.co/u/redfox)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 12:30pm UTC](https://discuss.elastic.co/t/scripted-field-for-date-12-months/328715 "2023-03-30T12:30:44Z")

</div>

How would I create a scripted field in Kibana that adds 12 months to the value in existing date field in the index?

---

## [Unable to communicate between 2 master nodes creating cluster issue](https://discuss.elastic.co/t/unable-to-communicate-between-2-master-nodes-creating-cluster-issue/328931)

<div class="topic-metadata">

**Author:** [@devarajsit](https://discuss.elastic.co/u/devarajsit)\
**Replies:** 4\
**Last updated:** [March 30, 2023, 12:31pm UTC](https://discuss.elastic.co/t/unable-to-communicate-between-2-master-nodes-creating-cluster-issue/328931 "2023-03-30T12:31:54Z")

</div>

I tried creating a new Elasticsearch cluster with 3 master nodes, 3 data nodes and 2 clients. All the 3 master nodes status is in Running but when i verified the logs of the third node, it says time out connecting to 1st…

---

## [I have created a Kibana dashboard for Top 10 Process by CPU Usage , the data is not coming up for 15 or 30 minutes or even for 1 hour](https://discuss.elastic.co/t/i-have-created-a-kibana-dashboard-for-top-10-process-by-cpu-usage-the-data-is-not-coming-up-for-15-or-30-minutes-or-even-for-1-hour/328760)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 12:30pm UTC](https://discuss.elastic.co/t/i-have-created-a-kibana-dashboard-for-top-10-process-by-cpu-usage-the-data-is-not-coming-up-for-15-or-30-minutes-or-even-for-1-hour/328760 "2023-03-30T12:30:41Z")

</div>

Kibana version -7.17.3, elk version 7.17.3 I have used the field - system.process.cpu.total.pct and aggregation is average... i dont see data coming up for 15 or 30 mints or even 1 hour interval time . I only get it f…

---

## [Elasticsearch 7.3.2 witjh Java 17](https://discuss.elastic.co/t/elasticsearch-7-3-2-witjh-java-17/328932)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 12:29pm UTC](https://discuss.elastic.co/t/elasticsearch-7-3-2-witjh-java-17/328932 "2023-03-30T12:29:57Z")

</div>

Hi Team, We need run the elasticsearch 7.3.2 with java 17 version ,myself able to run the elasticsearch with java17 version, is this casue any issues in future.

---

## [Vector functions are not available in Sort Context? \[painless\] \[painful\]](https://discuss.elastic.co/t/vector-functions-are-not-available-in-sort-context-painless-painful/328737)

<div class="topic-metadata">

**Author:** [@MarynaCherniavska](https://discuss.elastic.co/u/MarynaCherniavska)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 11:58am UTC](https://discuss.elastic.co/t/vector-functions-are-not-available-in-sort-context-painless-painful/328737 "2023-03-30T11:58:17Z")

</div>

Dear team, I am trying to use dotProduct() in a script sort and failing. The simplified case looks like this: Setting up the data PUT test\_index { "mappings": { "properties": { "v": { "type": "dens…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=584)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=586)
