# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=591

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 592

---

## [Does implementing security require a rolling restart or full cluster restart](https://discuss.elastic.co/t/does-implementing-security-require-a-rolling-restart-or-full-cluster-restart/328603)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 10:33am UTC](https://discuss.elastic.co/t/does-implementing-security-require-a-rolling-restart-or-full-cluster-restart/328603 "2023-03-27T10:33:03Z")

</div>

I have a cluster(non-https) running in the production environment with docker and now I want to implement security on that cluster. While adding https related configurations, certs etc.. to all the nodes in cluster, wil…

---

## [Set Size in Elastic Java Client 8.6](https://discuss.elastic.co/t/set-size-in-elastic-java-client-8-6/328599)

<div class="topic-metadata">

**Author:** [@shravan](https://discuss.elastic.co/u/shravan)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 10:24am UTC](https://discuss.elastic.co/t/set-size-in-elastic-java-client-8-6/328599 "2023-03-27T10:24:14Z")

</div>

Hi! I was trying to connect to Elasticsearch using Java Client 8.6. I was unable to find this in docs or code - How would I be able to set "size" to limit the result set in Java? Thank You for your help!!

---

## [Elasticsearch.bat installation freeze](https://discuss.elastic.co/t/elasticsearch-bat-installation-freeze/328464)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 7\
**Last updated:** [March 27, 2023, 10:15am UTC](https://discuss.elastic.co/t/elasticsearch-bat-installation-freeze/328464 "2023-03-27T10:15:59Z")

</div>

Hi all :slight\_smile: My main goal is to use Winlogbeat to visualize our Eventlogs. I can only use the self-managed version. -------------------------------------------------------------------------------------- Inst…

---

## [Runtime Fields & Tile serve](https://discuss.elastic.co/t/runtime-fields-tile-serve/328512)

<div class="topic-metadata">

**Author:** [@YB\_Coding](https://discuss.elastic.co/u/YB_Coding)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 10:14am UTC](https://discuss.elastic.co/t/runtime-fields-tile-serve/328512 "2023-03-27T10:14:08Z")

</div>

Hello guys, I wanted to have a confirmation before going in with Elasticsearch. I would like to display roads on a Map (Mapbox). Let's say these roads have a maxSpeed, length and a width properties. I would like to comp…

---

## [\[spring-data-elasticsearch\] how to dynamically assign index by argument column value](https://discuss.elastic.co/t/spring-data-elasticsearch-how-to-dynamically-assign-index-by-argument-column-value/328594)

<div class="topic-metadata">

**Author:** [@dan\_kim](https://discuss.elastic.co/u/dan_kim)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 9:20am UTC](https://discuss.elastic.co/t/spring-data-elasticsearch-how-to-dynamically-assign-index-by-argument-column-value/328594 "2023-03-27T09:20:41Z")

</div>

Hello I'm trying to save transactional data of product on elasticsearch and building spring boot as data-pipe line server . there are lots of index with same column like CategoryA\_Trasaction and CategoryB\_Transaction..…

---

## [NEST/.NET boost probably shouldn't be type double](https://discuss.elastic.co/t/nest-net-boost-probably-shouldnt-be-type-double/328589)

<div class="topic-metadata">

**Author:** [@catmanjan](https://discuss.elastic.co/u/catmanjan)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 8:56am UTC](https://discuss.elastic.co/t/nest-net-boost-probably-shouldnt-be-type-double/328589 "2023-03-27T08:56:17Z")

</div>

I wanted to boost a particular field higher than others, using TermQuery the Boost parameter is of type double. If I set the value to double.MaxValue I get a server error "boost must be a positive float, got Infinity" S…

---

## [Dynamic buckets ranges?](https://discuss.elastic.co/t/dynamic-buckets-ranges/328584)

<div class="topic-metadata">

**Author:** [@henrilabarre](https://discuss.elastic.co/u/henrilabarre)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 8:02am UTC](https://discuss.elastic.co/t/dynamic-buckets-ranges/328584 "2023-03-27T08:02:31Z")

</div>

Hi all I have a list a properties with zip code, square meter, number of rooms, sale price... in ES and with an input I want to build a query to get the optimal price range for a new property which depend of course of a…

---

## [Supplement vlan.id to DNS data](https://discuss.elastic.co/t/supplement-vlan-id-to-dns-data/328453)

<div class="topic-metadata">

**Author:** [@infofs](https://discuss.elastic.co/u/infofs)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 8:02am UTC](https://discuss.elastic.co/t/supplement-vlan-id-to-dns-data/328453 "2023-03-27T08:02:23Z")

</div>

I am sending all DNS traffic to logstash. Is it possible to add vlan data (especially the vlan.id) to this output? This is my packetbeat.yml: # =============================== Network device ===========================…

---

## [Typo or peculiarity related to \`setup.ilm.check\_exists\` in documentation](https://discuss.elastic.co/t/typo-or-peculiarity-related-to-setup-ilm-check-exists-in-documentation/327974)

<div class="topic-metadata">

**Author:** [@NominaSumpta](https://discuss.elastic.co/u/NominaSumpta)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 7:58am UTC](https://discuss.elastic.co/t/typo-or-peculiarity-related-to-setup-ilm-check-exists-in-documentation/327974 "2023-03-27T07:58:11Z")

</div>

The documentation for Metricbeat (https://github.com/elastic/beats/blob/master/libbeat/docs/security/users.asciidoc) says: When using ILM, turn off the ILM setup check The documentation (Configure index lifecycle man…

---

## [Logstash: replacement of the Coralogix/Ruby output plugin with http output plugin requires x2 resources](https://discuss.elastic.co/t/logstash-replacement-of-the-coralogix-ruby-output-plugin-with-http-output-plugin-requires-x2-resources/327558)

<div class="topic-metadata">

**Author:** [@AlexKonkin](https://discuss.elastic.co/u/AlexKonkin)\
**Replies:** 4\
**Last updated:** [March 27, 2023, 6:56am UTC](https://discuss.elastic.co/t/logstash-replacement-of-the-coralogix-ruby-output-plugin-with-http-output-plugin-requires-x2-resources/327558 "2023-03-27T06:56:31Z")

</div>

According to the Coralogix they are going to drop support of their Coralogix/Ruby based plugin. As the replacement it is proposed to use http output plugin. You can find the relevant details by navigating the URL below:…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/327631)

<div class="topic-metadata">

**Author:** [@Networks\_Fms](https://discuss.elastic.co/u/Networks_Fms)\
**Replies:** 4\
**Last updated:** [March 27, 2023, 6:56am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/327631 "2023-03-27T06:56:28Z")

</div>

I am getting kibana server not ready yet, Status of kibana is up. ● kibana.service - Kibana Loaded: loaded (/usr/lib/systemd/system/kibana.service; enabled; vendor preset: disabled) Active: active (running) since Tue …

---

## [Stack Monitoring does not show my added ES cluster](https://discuss.elastic.co/t/stack-monitoring-does-not-show-my-added-es-cluster/328562)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 4\
**Last updated:** [March 27, 2023, 6:39am UTC](https://discuss.elastic.co/t/stack-monitoring-does-not-show-my-added-es-cluster/328562 "2023-03-27T06:39:38Z")

</div>

Hello, I have deployed an elastic-agent and included the elasticsearch integration. The agent runs without Fleet, and data is filling the indexes. The problem is that I so not see the cluster appear in my Stack Monito…

---

## [\[Newbie\] Multiple dissects in same Filebeat configuration processor](https://discuss.elastic.co/t/newbie-multiple-dissects-in-same-filebeat-configuration-processor/328575)

<div class="topic-metadata">

**Author:** [@Akshay\_M\_B](https://discuss.elastic.co/u/Akshay_M_B)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 6:27am UTC](https://discuss.elastic.co/t/newbie-multiple-dissects-in-same-filebeat-configuration-processor/328575 "2023-03-27T06:27:59Z")

</div>

Hi, I am really new to filebeat and wanted know if there is a way we can have multiple dissect tokenizer based on different file inputs in the same configuration? For my case, I am trying to send logs from nginx as well…

---

## [Ingress configuration to access Kibana from the internet](https://discuss.elastic.co/t/ingress-configuration-to-access-kibana-from-the-internet/328406)

<div class="topic-metadata">

**Author:** [@arazmi](https://discuss.elastic.co/u/arazmi)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 6:33am UTC](https://discuss.elastic.co/t/ingress-configuration-to-access-kibana-from-the-internet/328406 "2023-03-27T06:33:48Z")

</div>

I've been following this guide here Deploy a Kibana instance | Elastic Cloud on Kubernetes \[master\] | Elastic, and I have also configured the following ingress: apiVersion: networking.k8s.io/v1 kind: Ingress metadata: …

---

## [How not present the duplicated data using elasticsearch \_search query api](https://discuss.elastic.co/t/how-not-present-the-duplicated-data-using-elasticsearch-search-query-api/328322)

<div class="topic-metadata">

**Author:** [@LongKang\_Fan](https://discuss.elastic.co/u/LongKang_Fan)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 3:01am UTC](https://discuss.elastic.co/t/how-not-present-the-duplicated-data-using-elasticsearch-search-query-api/328322 "2023-03-27T03:01:56Z")

</div>

Hi. I am using Filebeat -\> Logstash -\> Elasticsearch to save my logfiles. I have saved a field called casename to the index pattern like caselog-{YYYY.MM.dd} and I want to query all the case names in that index but just…

---

## [Indices\_boost not work for has\_child query](https://discuss.elastic.co/t/indices-boost-not-work-for-has-child-query/328566)

<div class="topic-metadata">

**Author:** [@Tiago1515](https://discuss.elastic.co/u/Tiago1515)\
**Replies:** 0\
**Last updated:** [March 26, 2023, 7:57pm UTC](https://discuss.elastic.co/t/indices-boost-not-work-for-has-child-query/328566 "2023-03-26T19:57:33Z")

</div>

Context Elasticsearch version: 8.8.0-SNAPSHOT (Commit: 56633e0a2934b03090ab726c33e5289129c98bfe \[56633e0\]) Lucene version: lucene-join-9.6.0-SNAPSHOT I create two equals indices: PUT /question\_answer\_1 { "aliases": …

---

## [Search request's timeout doesn't work as expected](https://discuss.elastic.co/t/search-requests-timeout-doesnt-work-as-expected/328247)

<div class="topic-metadata">

**Author:** [@hari-ram-s](https://discuss.elastic.co/u/hari-ram-s)\
**Replies:** 17\
**Last updated:** [March 26, 2023, 7:24pm UTC](https://discuss.elastic.co/t/search-requests-timeout-doesnt-work-as-expected/328247 "2023-03-26T19:24:21Z")

</div>

ES Verson: 7.15.0 We were exploring the significant\_text plugin of ES (via REST API) for generating word cloud from our data. As the query took more time to execute, we decided to use a timeout. Here is what the officia…

---

## [Runing multiple Kibana Instances vs load balancing](https://discuss.elastic.co/t/runing-multiple-kibana-instances-vs-load-balancing/328550)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 5\
**Last updated:** [March 26, 2023, 4:14pm UTC](https://discuss.elastic.co/t/runing-multiple-kibana-instances-vs-load-balancing/328550 "2023-03-26T16:14:56Z")

</div>

Want to load balancing multiple Kibana v.8.6 instances, wondering if login sessions are to be considered state-less or if we need to apply session stickyness and if rooted sticky on what, cookie...? Also what to do abou…

---

## [Tasks are stuck for hours for index creation & setting update](https://discuss.elastic.co/t/tasks-are-stuck-for-hours-for-index-creation-setting-update/328523)

<div class="topic-metadata">

**Author:** [@sanders\_2345](https://discuss.elastic.co/u/sanders_2345)\
**Replies:** 8\
**Last updated:** [March 26, 2023, 3:28pm UTC](https://discuss.elastic.co/t/tasks-are-stuck-for-hours-for-index-creation-setting-update/328523 "2023-03-26T15:28:51Z")

</div>

Our cluster has 4k+ indices, 36 data nodes(8c & 32g). ,3 mn (4c & 16g) Write is on 10k+ & read is very less No of primary shards - 4k+, replica 1 Es version: 5.x All tasks are running for hrs. Logs throwing RemoteTr…

---

## [Grok pattern for timestamp with month short name](https://discuss.elastic.co/t/grok-pattern-for-timestamp-with-month-short-name/328119)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 4\
**Last updated:** [March 26, 2023, 9:15am UTC](https://discuss.elastic.co/t/grok-pattern-for-timestamp-with-month-short-name/328119 "2023-03-26T09:15:55Z")

</div>

Wondering how to convert timestamps given like: 2023-mar.-20 23:44:44 PM to @timestamp and adding a default timezone info

---

## [Why when i build data back to es config max\_buckets it back to default](https://discuss.elastic.co/t/why-when-i-build-data-back-to-es-config-max-buckets-it-back-to-default/328545)

<div class="topic-metadata">

**Author:** [@xuan\_do](https://discuss.elastic.co/u/xuan_do)\
**Replies:** 0\
**Last updated:** [March 26, 2023, 8:41am UTC](https://discuss.elastic.co/t/why-when-i-build-data-back-to-es-config-max-buckets-it-back-to-default/328545 "2023-03-26T08:41:28Z")

</div>

when I upload data to es, config max\_buckets sometimes resets its value default. Why is that

---

## [Using new elasticsearch client 8.0.8, creating a index , add a record and update the existing record](https://discuss.elastic.co/t/using-new-elasticsearch-client-8-0-8-creating-a-index-add-a-record-and-update-the-existing-record/328522)

<div class="topic-metadata">

**Author:** [@sudhakarvaradharaj](https://discuss.elastic.co/u/sudhakarvaradharaj)\
**Replies:** 1\
**Last updated:** [March 26, 2023, 7:46am UTC](https://discuss.elastic.co/t/using-new-elasticsearch-client-8-0-8-creating-a-index-add-a-record-and-update-the-existing-record/328522 "2023-03-26T07:46:03Z")

</div>

I am using client 8.0.8 Elastic.Clients.Elasticsearch to create index, add a record and update the existing record to the index. What is the appropriate method to add and update the index. Here is the code snippet I us…

---

## [LRU cache in the Jdbc streaming filter plugin](https://discuss.elastic.co/t/lru-cache-in-the-jdbc-streaming-filter-plugin/328538)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [March 26, 2023, 7:05am UTC](https://discuss.elastic.co/t/lru-cache-in-the-jdbc-streaming-filter-plugin/328538 "2023-03-26T07:05:08Z")

</div>

Hi All, when I parse the value to Jdbc streaming filter plugin to run the query for extract the results in the target, this values existing in the other input plugin, but the amount of values more than the time of quer…

---

## [Dashboards and index patterns lost after upgrade from 7 to 8](https://discuss.elastic.co/t/dashboards-and-index-patterns-lost-after-upgrade-from-7-to-8/328531)

<div class="topic-metadata">

**Author:** [@SANDEEP\_SOMAPANGU](https://discuss.elastic.co/u/SANDEEP_SOMAPANGU)\
**Replies:** 2\
**Last updated:** [March 26, 2023, 3:40am UTC](https://discuss.elastic.co/t/dashboards-and-index-patterns-lost-after-upgrade-from-7-to-8/328531 "2023-03-26T03:40:53Z")

</div>

Hello, we recently upgraded from kibana version 7 to 8. In the previous version, we stored our configuration in the index named .kibana-abc\_7.17.9\_001. However, it appears that version 8 no longer supports this kind of i…

---

## [Java low level client example](https://discuss.elastic.co/t/java-low-level-client-example/328526)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 1\
**Last updated:** [March 26, 2023, 12:15am UTC](https://discuss.elastic.co/t/java-low-level-client-example/328526 "2023-03-26T00:15:44Z")

</div>

I am trying to find a good example of a low level Elasticsearch client (with plain java/non spring) but no luck. Can anyone please point the right direction?

---

## [Logstash - rabbitmq config to get multiple queues data to multiple elastic indeces](https://discuss.elastic.co/t/logstash-rabbitmq-config-to-get-multiple-queues-data-to-multiple-elastic-indeces/328520)

<div class="topic-metadata">

**Author:** [@qrshat](https://discuss.elastic.co/u/qrshat)\
**Replies:** 5\
**Last updated:** [March 25, 2023, 10:20pm UTC](https://discuss.elastic.co/t/logstash-rabbitmq-config-to-get-multiple-queues-data-to-multiple-elastic-indeces/328520 "2023-03-25T22:20:13Z")

</div>

scenario: rabbitmq have different queues more than three. I want to make logstash configuration to get data from the rabbitmq queue and index this data to Elasticsearch. In order to that I have created logstash conf fi…

---

## [Elasticsearch Cluster Multi Node Shared File System Repository SMB Issue](https://discuss.elastic.co/t/elasticsearch-cluster-multi-node-shared-file-system-repository-smb-issue/328472)

<div class="topic-metadata">

**Author:** [@ali.sharjeel](https://discuss.elastic.co/u/ali.sharjeel)\
**Replies:** 3\
**Last updated:** [March 25, 2023, 3:33pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-multi-node-shared-file-system-repository-smb-issue/328472 "2023-03-25T15:33:01Z")

</div>

Hi Team! I am trying to register shared file system repository in elasticsearch 8.6.2. I have windows server where i have created a directory and have shared it using smb and have mounted that directory using NFS CIFS on…

---

## [Elastic Search was not loaded](https://discuss.elastic.co/t/elastic-search-was-not-loaded/328504)

<div class="topic-metadata">

**Author:** [@Alex\_David\_Hurtado\_Y](https://discuss.elastic.co/u/Alex_David_Hurtado_Y)\
**Replies:** 1\
**Last updated:** [March 25, 2023, 11:23am UTC](https://discuss.elastic.co/t/elastic-search-was-not-loaded/328504 "2023-03-25T11:23:08Z")

</div>

HI, i´m using laradock with laravel, on the laravel project is integrte elasticsearch and inatalled the imgae the elasticsearch. The project get a command to fill a table using elasticsearch, buy trow the error: Elastic…

---

## [ECK operator](https://discuss.elastic.co/t/eck-operator/328516)

<div class="topic-metadata">

**Author:** [@abdul90082](https://discuss.elastic.co/u/abdul90082)\
**Replies:** 0\
**Last updated:** [March 25, 2023, 10:20am UTC](https://discuss.elastic.co/t/eck-operator/328516 "2023-03-25T10:20:56Z")

</div>

Hi everyone! we would like to use ES operator in all our cluster to monitor kubernetes logs. We have tried to get fleet and the agents working based on our scenario that looks the following: We are trying to send the l…

---

## [Is it normal for my ElasticSearch process to consume 10% of the CPU even when there are no read or write requests?](https://discuss.elastic.co/t/is-it-normal-for-my-elasticsearch-process-to-consume-10-of-the-cpu-even-when-there-are-no-read-or-write-requests/328507)

<div class="topic-metadata">

**Author:** [@zzzzer91](https://discuss.elastic.co/u/zzzzer91)\
**Replies:** 2\
**Last updated:** [March 25, 2023, 6:50am UTC](https://discuss.elastic.co/t/is-it-normal-for-my-elasticsearch-process-to-consume-10-of-the-cpu-even-when-there-are-no-read-or-write-requests/328507 "2023-03-25T06:50:33Z")

</div>

Elasticsearch Version elasticsearch-8.5.3 Installed Plugins No response Java Version bundled OS Version 4.19.188-10.el7 Problem Description Is it normal for Elasticsearch to consume 10% CPU even without requests afte…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=590)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=592)
