# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=599

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 600

---

## [How to index the PDF documents](https://discuss.elastic.co/t/how-to-index-the-pdf-documents/327987)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 8\
**Last updated:** [March 20, 2023, 10:36am UTC](https://discuss.elastic.co/t/how-to-index-the-pdf-documents/327987 "2023-03-20T10:36:03Z")

</div>

How to index the PDF and image documents into elasticsearch. Would like to extract the entities to enable the search on keywords. Whether the workplace search provide this functionality? Whether Apache Tika has been used…

---

## [How can I restore logs from /usr/share/elasticsearch/data/nodes/0?](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822)

<div class="topic-metadata">

**Author:** [@shawnmin](https://discuss.elastic.co/u/shawnmin)\
**Replies:** 6\
**Last updated:** [March 20, 2023, 10:09am UTC](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822 "2023-03-20T10:09:19Z")

</div>

I am using Elasticsearch as a backend to save logs collected from Fluentd logging agent. Specifically, I've set up an EFK logging architecture in my Kubernetes cluster. (AWS EKS cluster to be specific) I've mounted the …

---

## [Error during startup](https://discuss.elastic.co/t/error-during-startup/327941)

<div class="topic-metadata">

**Author:** [@Soren\_vdc](https://discuss.elastic.co/u/Soren_vdc)\
**Replies:** 7\
**Last updated:** [March 20, 2023, 9:51am UTC](https://discuss.elastic.co/t/error-during-startup/327941 "2023-03-20T09:51:07Z")

</div>

Hi, I receive this error during startup: \[ERROR\]\[o.e.b.Elasticsearch \] \[s2ab00jb.be.srv.dev.sys\] fatal exception while booting Elasticsearch java.lang.IllegalArgumentException: Could not load codec 'Lucene94'. Di…

---

## [Order BY Date field KIBANA Lens visualization ordered by alphabetically](https://discuss.elastic.co/t/order-by-date-field-kibana-lens-visualization-ordered-by-alphabetically/327523)

<div class="topic-metadata">

**Author:** [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 9:18am UTC](https://discuss.elastic.co/t/order-by-date-field-kibana-lens-visualization-ordered-by-alphabetically/327523 "2023-03-20T09:18:02Z")

</div>

Hi, I created a lens visualization in Kibana. I visualize data in tabular form like excel. When I set order on a date type field (date format like March-2023) it is not showed in correct order. Like Jan-2023, Feb-2023,…

---

## [How to use Escape key value in query\_string](https://discuss.elastic.co/t/how-to-use-escape-key-value-in-query-string/327972)

<div class="topic-metadata">

**Author:** [@anon55421226](https://discuss.elastic.co/u/anon55421226)\
**Replies:** 6\
**Last updated:** [March 20, 2023, 9:14am UTC](https://discuss.elastic.co/t/how-to-use-escape-key-value-in-query-string/327972 "2023-03-20T09:14:24Z")

</div>

So... according to the elasticsearch/QueryStringQueryBuilder.java at v7.16.3 · elastic/elasticsearch · GitHub code there should exists an escape parameter in the query\_string object, but how do i trigger it to escape my …

---

## [Is the basic free elasticsearch allows to send invitations and password reset mails?](https://discuss.elastic.co/t/is-the-basic-free-elasticsearch-allows-to-send-invitations-and-password-reset-mails/327938)

<div class="topic-metadata">

**Author:** [@coy\_aprieto](https://discuss.elastic.co/u/coy_aprieto)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 8:52am UTC](https://discuss.elastic.co/t/is-the-basic-free-elasticsearch-allows-to-send-invitations-and-password-reset-mails/327938 "2023-03-20T08:52:51Z")

</div>

Hi, I'm working on an elasticsearch platform for my company, and we are still using the free version for now. Is it possible to send invitations and password resets (i know alerts and generally mail stuff for kibana is…

---

## [How to get space\_id on server side](https://discuss.elastic.co/t/how-to-get-space-id-on-server-side/328054)

<div class="topic-metadata">

**Author:** [@iljaskajrris](https://discuss.elastic.co/u/iljaskajrris)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 8:50am UTC](https://discuss.elastic.co/t/how-to-get-space-id-on-server-side/328054 "2023-03-20T08:50:02Z")

</div>

Hi team, can you help me please to get space on the server side? I need to do smth like to get data based on space. router.get( { path: '/api/get\_data', validate: false, }, async (context, req, response) =\> { …

---

## [Unable to create an enrollment token](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token/327917)

<div class="topic-metadata">

**Author:** [@geb](https://discuss.elastic.co/u/geb)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 8:47am UTC](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token/327917 "2023-03-20T08:47:36Z")

</div>

Hi, i try to add a node at at new formed 8.6 cluster. As the first step i configured the ca, certificates and modified the elasticsearch.yml Cluster started -\> fine The error is also described in: This statement does…

---

## [How to add deletion policy in existing policy?](https://discuss.elastic.co/t/how-to-add-deletion-policy-in-existing-policy/328052)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 8:42am UTC](https://discuss.elastic.co/t/how-to-add-deletion-policy-in-existing-policy/328052 "2023-03-20T08:42:07Z")

</div>

I have a simple rotating policy and I want to add a deletion phase. This is not available in the UI, however I have done by creating a policy directly with PUT, including the delete section. My question is if it is poss…

---

## [Simple question about Index Rollover](https://discuss.elastic.co/t/simple-question-about-index-rollover/327999)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 5\
**Last updated:** [March 20, 2023, 8:07am UTC](https://discuss.elastic.co/t/simple-question-about-index-rollover/327999 "2023-03-20T08:07:19Z")

</div>

I have a simple policy for index rollover every day (or every 1gb). I use an index template -\> index pattern-\>index alias (see bellow). However it does not seem to rotate. Any ideas why (or how to test it? E.g if I send…

---

## [Fleet server limits](https://discuss.elastic.co/t/fleet-server-limits/328005)

<div class="topic-metadata">

**Author:** [@bex](https://discuss.elastic.co/u/bex)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 8:01am UTC](https://discuss.elastic.co/t/fleet-server-limits/328005 "2023-03-20T08:01:28Z")

</div>

Hello, I would like to clarify how many sources(elastic agents) can be managed by one fleet server? Is there any limits for fleet server? Best regards, Bex

---

## [Disable reads from few indices of an index pattern](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026)

<div class="topic-metadata">

**Author:** [@tarunpvss](https://discuss.elastic.co/u/tarunpvss)\
**Replies:** 7\
**Last updated:** [March 20, 2023, 7:06am UTC](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026 "2023-03-20T07:06:32Z")

</div>

Hi Team, I want to disable reads for few indices in an index pattern. I tried using index.blocks.read : true But due to this, when I am trying to query using index pattern, getting the below error { "error" : { …

---

## [Cannot suggest as I assume](https://discuss.elastic.co/t/cannot-suggest-as-i-assume/327604)

<div class="topic-metadata">

**Author:** [@Victor.Li](https://discuss.elastic.co/u/Victor.Li)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 7:19am UTC](https://discuss.elastic.co/t/cannot-suggest-as-i-assume/327604 "2023-03-14T07:19:27Z")

</div>

There's one field called 'table\_name' of which format is like 't\_data\_quality', 't\_data\_security'. Its mapping is "mappings": { "properties": { "table\_name": { "type": "text", "fields":{ "suggest":{ "type":"comp…

---

## [Exception "aggregation\_execution\_exception" after issues with not enough shards](https://discuss.elastic.co/t/exception-aggregation-execution-exception-after-issues-with-not-enough-shards/327907)

<div class="topic-metadata">

**Author:** [@Filisimus](https://discuss.elastic.co/u/Filisimus)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 6:43am UTC](https://discuss.elastic.co/t/exception-aggregation-execution-exception-after-issues-with-not-enough-shards/327907 "2023-03-20T06:43:51Z")

</div>

Hi guys, so we are using Graylog with Elasticsearch and when I tried to create additional indices we ran out of shards. I fixed the shard issue, created the new indices but if I use the new indices with existing indices…

---

## [Calculate disk space requirement for increasing replicas](https://discuss.elastic.co/t/calculate-disk-space-requirement-for-increasing-replicas/327552)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 6:29am UTC](https://discuss.elastic.co/t/calculate-disk-space-requirement-for-increasing-replicas/327552 "2023-03-20T06:29:52Z")

</div>

Im planning to increase replication of some of our indices and trying to understand the additional disk required for this. Looking at the test index below(1p:2r, store.size = 45mb, pri.store.size=15mb) would it be accura…

---

## [How is this hardware selection for 3 node cluster](https://discuss.elastic.co/t/how-is-this-hardware-selection-for-3-node-cluster/327715)

<div class="topic-metadata">

**Author:** [@jbates5873](https://discuss.elastic.co/u/jbates5873)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 6:23am UTC](https://discuss.elastic.co/t/how-is-this-hardware-selection-for-3-node-cluster/327715 "2023-03-20T06:23:48Z")

</div>

Hi All, We currently run a production 3 node cluster internally at our company on a VERY resource constrained server. We run it under a docker swarm, and have all or our services etc.. also within the swarm, so the 3 ho…

---

## [Kibana server is not ready yet and logstash 401 error](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-and-logstash-401-error/327247)

<div class="topic-metadata">

**Author:** [@Antony-m](https://discuss.elastic.co/u/Antony-m)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 4:52am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-and-logstash-401-error/327247 "2023-03-20T04:52:41Z")

</div>

@adityasinghal26 @renangenova I'm new to the ELK stack I watched a youtube tutorial and setup the ELK in my local using docker, here the youtube video link This is my docker-compose.yml file version: '3.6' services: …

---

## [Best practices for spot/preemptible instances](https://discuss.elastic.co/t/best-practices-for-spot-preemptible-instances/326812)

<div class="topic-metadata">

**Author:** [@marcoderama](https://discuss.elastic.co/u/marcoderama)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 4:43am UTC](https://discuss.elastic.co/t/best-practices-for-spot-preemptible-instances/326812 "2023-03-20T04:43:45Z")

</div>

I'm a noob with this stuff so looking for some guidance. Say I have a GCP cluster that uses preemptible instances, or an AWS cluster that uses spot instances. If I have an Agent policy with the "Google Cloud Platform" …

---

## [Multi node cluster failing to connect](https://discuss.elastic.co/t/multi-node-cluster-failing-to-connect/326753)

<div class="topic-metadata">

**Author:** [@vanwoes](https://discuss.elastic.co/u/vanwoes)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 4:29am UTC](https://discuss.elastic.co/t/multi-node-cluster-failing-to-connect/326753 "2023-03-20T04:29:02Z")

</div>

Hi, I'm having an issue with a multi node elasticsearch cluster where the nodes are failing to join in a docker swarm. received join request from \[{es01}{SBn0YXX-RyuPcEsz3vgdjA}{0l0I2h0HRteijUgnwwmvqg}{es01}{10.0.0.69}…

---

## [Can i strip different values from "message" field](https://discuss.elastic.co/t/can-i-strip-different-values-from-message-field/328018)

<div class="topic-metadata">

**Author:** [@Hramoff](https://discuss.elastic.co/u/Hramoff)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 4:07am UTC](https://discuss.elastic.co/t/can-i-strip-different-values-from-message-field/328018 "2023-03-20T04:07:28Z")

</div>

I am using logstash with syslog plugin to collect logs from vsphere. The problem is that I get a lot of unnecessary entries, over 12,000 different rows per minute. I want to whitelist only the values ​​that I want in th…

---

## [Decompress a gzip compressed string in logstash and push to es](https://discuss.elastic.co/t/decompress-a-gzip-compressed-string-in-logstash-and-push-to-es/327720)

<div class="topic-metadata">

**Author:** [@shdasgupta](https://discuss.elastic.co/u/shdasgupta)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 2:18am UTC](https://discuss.elastic.co/t/decompress-a-gzip-compressed-string-in-logstash-and-push-to-es/327720 "2023-03-20T02:18:45Z")

</div>

Team, I am trying to decompress a gzip compressed data using logstash - am not able to figure out how to do this. Input json: (this is fed through a file in this example. In actual, it is consuming a kafka message whic…

---

## [Indices not getting an ILM policy applied after rollover](https://discuss.elastic.co/t/indices-not-getting-an-ilm-policy-applied-after-rollover/327997)

<div class="topic-metadata">

**Author:** [@jba](https://discuss.elastic.co/u/jba)\
**Replies:** 3\
**Last updated:** [March 19, 2023, 5:46pm UTC](https://discuss.elastic.co/t/indices-not-getting-an-ilm-policy-applied-after-rollover/327997 "2023-03-19T17:46:22Z")

</div>

I have a problem with indices not getting an ILM policy applied after rollover on a cluster (Elasticsearch, Logstash, and Kibana) that have recently been upgraded from 7.17 to 8.4 and have had our old legacy templates co…

---

## [Sending HTTPS requests to es01 running on docker-compose](https://discuss.elastic.co/t/sending-https-requests-to-es01-running-on-docker-compose/327728)

<div class="topic-metadata">

**Author:** [@anjankow](https://discuss.elastic.co/u/anjankow)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 12:38am UTC](https://discuss.elastic.co/t/sending-https-requests-to-es01-running-on-docker-compose/327728 "2023-03-20T00:38:51Z")

</div>

I'm using docker-compose setup as described here: And I'm able to send requests to e01 using curl passing a certificate and username with password. Now I want to send requests from my application to e01 node. I tried …

---

## [While searching how do I exclude only one object and include other object inside a nested object](https://discuss.elastic.co/t/while-searching-how-do-i-exclude-only-one-object-and-include-other-object-inside-a-nested-object/327322)

<div class="topic-metadata">

**Author:** [@Nabin\_Upreti](https://discuss.elastic.co/u/Nabin_Upreti)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 11:51pm UTC](https://discuss.elastic.co/t/while-searching-how-do-i-exclude-only-one-object-and-include-other-object-inside-a-nested-object/327322 "2023-03-19T23:51:49Z")

</div>

I want to search minimum of the negotiated\_rate where negotiated type is not percentage. I used must not query to filter out percentage but this results to excluding the whole document. Here I expect the minimum negotia…

---

## [How to configure Elastic stack with Fleet server and APM integration using docker compose?](https://discuss.elastic.co/t/how-to-configure-elastic-stack-with-fleet-server-and-apm-integration-using-docker-compose/326974)

<div class="topic-metadata">

**Author:** [@hexsorcerer](https://discuss.elastic.co/u/hexsorcerer)\
**Replies:** 0\
**Last updated:** [March 4, 2023, 1:51am UTC](https://discuss.elastic.co/t/how-to-configure-elastic-stack-with-fleet-server-and-apm-integration-using-docker-compose/326974 "2023-03-04T01:51:56Z")

</div>

I'm trying to setup an example project with the following functionality: Elasticsearch Logstash Kibana Fleet Server Elastic Agent with APM Integration OpenTelemetry from a .NET Application Getting the basic ELK setup …

---

## [Groks solution in filebeat](https://discuss.elastic.co/t/groks-solution-in-filebeat/327133)

<div class="topic-metadata">

**Author:** [@ingri.mahecha](https://discuss.elastic.co/u/ingri.mahecha)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 3:22am UTC](https://discuss.elastic.co/t/groks-solution-in-filebeat/327133 "2023-03-07T03:22:29Z")

</div>

Hello community, Having encountered the problem of how to apply groks in filebeat, I want to share with you the solution I found with the PROCESSORS section and the Dissect function, I hope it helps you, as well as havi…

---

## [Collecting logs via VMware vSphere integration](https://discuss.elastic.co/t/collecting-logs-via-vmware-vsphere-integration/327165)

<div class="topic-metadata">

**Author:** [@tumbl3w33d](https://discuss.elastic.co/u/tumbl3w33d)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 10:38am UTC](https://discuss.elastic.co/t/collecting-logs-via-vmware-vsphere-integration/327165 "2023-03-07T10:38:28Z")

</div>

Disclaimer: I don't know much about VMware, so I'd be glad if you enlighten me when necessary. Hello, I am trying to understand how to use this agent integration to collect logs and metrics from a vSphere setup. Metric…

---

## [How to use event.category intrusion\_detection](https://discuss.elastic.co/t/how-to-use-event-category-intrusion-detection/327316)

<div class="topic-metadata">

**Author:** [@jjacksonrkk](https://discuss.elastic.co/u/jjacksonrkk)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 1:52am UTC](https://discuss.elastic.co/t/how-to-use-event-category-intrusion-detection/327316 "2023-03-09T01:52:46Z")

</div>

How can I activate intrusion\_detection in auditbeat event.category? When debugging, log.logger occurs as a publisher and the event.category includes intrusion\_detection, but when the daemon service is run, the intrusion…

---

## [Filebeat logs stored in /tmp are causing pod eviction](https://discuss.elastic.co/t/filebeat-logs-stored-in-tmp-are-causing-pod-eviction/327221)

<div class="topic-metadata">

**Author:** [@Varun\_Sriram](https://discuss.elastic.co/u/Varun_Sriram)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 6:21pm UTC](https://discuss.elastic.co/t/filebeat-logs-stored-in-tmp-are-causing-pod-eviction/327221 "2023-03-07T18:21:21Z")

</div>

Hi all, i am seeing an issue on my environment which is using filebeat for logging and monitoring where files with large amounts of storage used are getting created. I presume these are log files created by filebeat and…

---

## [Options List Control Ignores Filters and Queries](https://discuss.elastic.co/t/options-list-control-ignores-filters-and-queries/317334)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 10\
**Last updated:** [March 19, 2023, 11:28pm UTC](https://discuss.elastic.co/t/options-list-control-ignores-filters-and-queries/317334 "2023-03-19T23:28:23Z")

</div>

Please see original thread Options List Control Ignores Filters and Queries - Elastic Stack / Kibana - Discuss the Elastic Stack. Why does no notification go out when a topic is about to close? @Teresa\_Alvarez , One …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=598)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=600)
