# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=605

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 606

---

## [Slower Perfomance with Elaticsearch cluster in kubernetes compared to Docker](https://discuss.elastic.co/t/slower-perfomance-with-elaticsearch-cluster-in-kubernetes-compared-to-docker/325759)

<div class="topic-metadata">

**Author:** [@samdevops](https://discuss.elastic.co/u/samdevops)\
**Replies:** 12\
**Last updated:** [March 14, 2023, 10:30am UTC](https://discuss.elastic.co/t/slower-perfomance-with-elaticsearch-cluster-in-kubernetes-compared-to-docker/325759 "2023-03-14T10:30:02Z")

</div>

We are facing issues with Elasticsearch deployment resulting in response time being slower in EKS to that in Docker. In both cases, we are using AWS to provision EC2 instances. Docker consists of a single EC2 instance w…

---

## [Cannot read properties of undefined (reading 'KPIs') Getting this error when trying to built dashboard using VEGA](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-kpis-getting-this-error-when-trying-to-built-dashboard-using-vega/327647)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 10:21am UTC](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-kpis-getting-this-error-when-trying-to-built-dashboard-using-vega/327647 "2023-03-14T10:21:59Z")

</div>

Hello team, I am getting the above mentioned error "Cannot read properties of undefined (reading 'KPIs')" when I am trying to execute below code in VEGA { "$schema": "https://vega.github.io/schema/vega/v4.17.json", …

---

## [Sorting in Lens pies](https://discuss.elastic.co/t/sorting-in-lens-pies/327436)

<div class="topic-metadata">

**Author:** [@InesCM](https://discuss.elastic.co/u/InesCM)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 9:48am UTC](https://discuss.elastic.co/t/sorting-in-lens-pies/327436 "2023-03-14T09:48:50Z")

</div>

Hi there! I thought that this was an issue with Legacy (aggregation based) visualizations, but I'm seeing this in Lens too... Am I missing something, or this makes no sense? When I slice a donut chart by ranges, the co…

---

## [How to set auto-reloading conf files in logstash.yml or pipeline.yml](https://discuss.elastic.co/t/how-to-set-auto-reloading-conf-files-in-logstash-yml-or-pipeline-yml/327425)

<div class="topic-metadata">

**Author:** [@terrymu](https://discuss.elastic.co/u/terrymu)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 9:39am UTC](https://discuss.elastic.co/t/how-to-set-auto-reloading-conf-files-in-logstash-yml-or-pipeline-yml/327425 "2023-03-14T09:39:51Z")

</div>

Hi All, I know here is a feature that can auto-reloading conf files without logstash restart action. So my question is easy, how to turn on auto-reloading function in logstash.yml or pipeline.yml ? I need an workin…

---

## [Upgrade to 7.x aggregation performance degradation](https://discuss.elastic.co/t/upgrade-to-7-x-aggregation-performance-degradation/327449)

<div class="topic-metadata">

**Author:** [@dbajra94](https://discuss.elastic.co/u/dbajra94)\
**Replies:** 1\
**Last updated:** [March 14, 2023, 8:51am UTC](https://discuss.elastic.co/t/upgrade-to-7-x-aggregation-performance-degradation/327449 "2023-03-14T08:51:39Z")

</div>

We are currently in process of migrating our Cloud tenants to 7.16.3 in preparation for an internal 8.6 Elasticsearch upgrade of our software. However, we have noticed that our aggregation queries have suffered a hard un…

---

## [Issue with datastream, each similar datastream have own hidden index](https://discuss.elastic.co/t/issue-with-datastream-each-similar-datastream-have-own-hidden-index/327201)

<div class="topic-metadata">

**Author:** [@danoque](https://discuss.elastic.co/u/danoque)\
**Replies:** 5\
**Last updated:** [March 14, 2023, 8:45am UTC](https://discuss.elastic.co/t/issue-with-datastream-each-similar-datastream-have-own-hidden-index/327201 "2023-03-14T08:45:11Z")

</div>

I have issue after i configured datastream without "Component Templates". I created datastream with , so like this: "my-index-pattern-" in field "Index patterns". And then, each day elastic creats new datastream with h…

---

## [Metricbeat on Openshift & Nginx](https://discuss.elastic.co/t/metricbeat-on-openshift-nginx/327335)

<div class="topic-metadata">

**Author:** [@Ivan\_Hosea](https://discuss.elastic.co/u/Ivan_Hosea)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 3:38am UTC](https://discuss.elastic.co/t/metricbeat-on-openshift-nginx/327335 "2023-03-14T03:38:07Z")

</div>

Hi, I was wondering if there's any way to monitor nginx inside openshift service with metricbeat & filebeat. Can anyone help me with this?

---

## [Use of customized Managed ILM policies](https://discuss.elastic.co/t/use-of-customized-managed-ilm-policies/327594)

<div class="topic-metadata">

**Author:** [@Savva\_Morozov](https://discuss.elastic.co/u/Savva_Morozov)\
**Replies:** 5\
**Last updated:** [March 14, 2023, 1:44am UTC](https://discuss.elastic.co/t/use-of-customized-managed-ilm-policies/327594 "2023-03-14T01:44:19Z")

</div>

Hello! I would like to know is it safe to use customized Managed ILM policies? And can it be that after some update of the cluster that customized Managed ILM policies will be reset to default values? I've also tried …

---

## [How the 'Transform API' Works](https://discuss.elastic.co/t/how-the-transform-api-works/327516)

<div class="topic-metadata">

**Author:** [@SEUNGHYO](https://discuss.elastic.co/u/SEUNGHYO)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 1:00am UTC](https://discuss.elastic.co/t/how-the-transform-api-works/327516 "2023-03-14T01:00:50Z")

</div>

Hello. I was check "search \> aggregation (size=0)" and "transform \> pivot \> aggregation (\_preview)" I checked that the transform side has much fewer tooks. (Same aggs, small size set for simple comparison -\> There wa…

---

## [Disabling an integration in fleet](https://discuss.elastic.co/t/disabling-an-integration-in-fleet/327600)

<div class="topic-metadata">

**Author:** [@marcoderama](https://discuss.elastic.co/u/marcoderama)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 10:00pm UTC](https://discuss.elastic.co/t/disabling-an-integration-in-fleet/327600 "2023-03-13T22:00:58Z")

</div>

I'm testing various agent policy incantations within fleet so I have a bunch of them now. As such, I have more going on at once than I'd like. It would be useful if I could mark an agent policy as "disabled" within fle…

---

## [Extract stored field in elasticsearch document using start and end offset](https://discuss.elastic.co/t/extract-stored-field-in-elasticsearch-document-using-start-and-end-offset/327598)

<div class="topic-metadata">

**Author:** [@Ancel](https://discuss.elastic.co/u/Ancel)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 9:43pm UTC](https://discuss.elastic.co/t/extract-stored-field-in-elasticsearch-document-using-start-and-end-offset/327598 "2023-03-13T21:43:30Z")

</div>

Hi all, I am seeking some pointers. Given the start and end offsets of text within a document field (e.g. as provided by the termvectors API), I would like to extract the stored text between those offsets. This text was …

---

## [Cannot restore index \[.security-7\]](https://discuss.elastic.co/t/cannot-restore-index-security-7/327473)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 6\
**Last updated:** [March 13, 2023, 9:39pm UTC](https://discuss.elastic.co/t/cannot-restore-index-security-7/327473 "2023-03-13T21:39:19Z")

</div>

Hello everyone, I'm trying to migrate all my users from my old 7.9 cluster to a new 8.5 cluster. I was reviewing the documentation and proceeded to take a snapshot of the security indexes of my old cluster to be able t…

---

## [Upgrade 7 -\> 8. depreciation messages -- ruby api](https://discuss.elastic.co/t/upgrade-7-8-depreciation-messages-ruby-api/327590)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 9:04pm UTC](https://discuss.elastic.co/t/upgrade-7-8-depreciation-messages-ruby-api/327590 "2023-03-13T21:04:54Z")

</div>

I am about to attempt to upgrade my test system from 7.17 to the latest 8.x... I have custom written ingestion processes which uses the ruby elasticsearch gem. Migration assistant says all is good but when I look at th…

---

## [Is there a way to output logs to s3 from filebeat without using logstash?](https://discuss.elastic.co/t/is-there-a-way-to-output-logs-to-s3-from-filebeat-without-using-logstash/327581)

<div class="topic-metadata">

**Author:** [@Z4ck404](https://discuss.elastic.co/u/Z4ck404)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 6:29pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-output-logs-to-s3-from-filebeat-without-using-logstash/327581 "2023-03-13T18:29:34Z")

</div>

Continuing the discussion from Does Filebeat support output to S3?:

---

## [Piece\_id.keyword vs piece\_id](https://discuss.elastic.co/t/piece-id-keyword-vs-piece-id/327584)

<div class="topic-metadata">

**Author:** [@Rafa\_H](https://discuss.elastic.co/u/Rafa_H)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 6:11pm UTC](https://discuss.elastic.co/t/piece-id-keyword-vs-piece-id/327584 "2023-03-13T18:11:28Z")

</div>

Hello everyone. I am new to the community. I have a question related to elasticsearch and would appreciate your support. In the platform we are developing, in the local env and staging env elasticsearch works only if k…

---

## [Logstash error failed to install template](https://discuss.elastic.co/t/logstash-error-failed-to-install-template/327521)

<div class="topic-metadata">

**Author:** [@supraja\_inamadugu](https://discuss.elastic.co/u/supraja_inamadugu)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 6:06pm UTC](https://discuss.elastic.co/t/logstash-error-failed-to-install-template/327521 "2023-03-13T18:06:17Z")

</div>

\[ERROR\] 2023-03-12 22:42:30.743 \[Ruby-0-Thread-10: /opt/homebrew/Cellar/logstash/8.6.1/libexec/vendor/bundle/jruby/2.6.0/gems/logstash-output-elasticsearch-11.12.1-java/lib/logstash/plugin\_mixins/elasticsearch/common.rb:…

---

## [SLM should be happening only for Delete Phase indices](https://discuss.elastic.co/t/slm-should-be-happening-only-for-delete-phase-indices/327546)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 5:28pm UTC](https://discuss.elastic.co/t/slm-should-be-happening-only-for-delete-phase-indices/327546 "2023-03-13T17:28:59Z")

</div>

Hi All, I am using ELK version 8.0.0, where we are using SLM policy but wanted to know it there any option to make sure when the SLM happens it should be only happening for indices which are in delete phase. Currently i…

---

## [User only with access to content they have created](https://discuss.elastic.co/t/user-only-with-access-to-content-they-have-created/327574)

<div class="topic-metadata">

**Author:** [@abrooky](https://discuss.elastic.co/u/abrooky)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 4:36pm UTC](https://discuss.elastic.co/t/user-only-with-access-to-content-they-have-created/327574 "2023-03-13T16:36:53Z")

</div>

Can someone point me the in the right direction. I've built a simple search as you type tool for a website catalogue which will be used by multiple websites. I need to make sure that each tenant have a unique user/pass …

---

## [Grok parser and nested brackets](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 5\
**Last updated:** [March 13, 2023, 4:03pm UTC](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454 "2023-03-13T16:03:57Z")

</div>

Hi, I have log event like this 2023-03-03T11:11:11.000Z INFO (foo (bar) bla bla \[bla\]) 2023-03-03T11:11:11.000Z \[foo (bar) bla bla \[bla\]\] I want to parse it with grok filter like timestamp: 2023-03-03T11:11:11.000Z l…

---

## [Prometheus remote\_write to metricbeat shows up in Kibana for one minute, then stops working](https://discuss.elastic.co/t/prometheus-remote-write-to-metricbeat-shows-up-in-kibana-for-one-minute-then-stops-working/325651)

<div class="topic-metadata">

**Author:** [@megaxm](https://discuss.elastic.co/u/megaxm)\
**Replies:** 4\
**Last updated:** [March 13, 2023, 4:00pm UTC](https://discuss.elastic.co/t/prometheus-remote-write-to-metricbeat-shows-up-in-kibana-for-one-minute-then-stops-working/325651 "2023-03-13T16:00:18Z")

</div>

Hi. I have set up the elk stack in one server. And also on the same server we have installed metricbeat. Version 8.6.1 for elk as well as metricbeat When we send the metrics to metricbeat we see that metrics are shown …

---

## [Is it possible to "conditionaly" analyze same field differently? \[synonyms\]](https://discuss.elastic.co/t/is-it-possible-to-conditionaly-analyze-same-field-differently-synonyms/326441)

<div class="topic-metadata">

**Author:** [@astrodi](https://discuss.elastic.co/u/astrodi)\
**Replies:** 3\
**Last updated:** [March 13, 2023, 3:16pm UTC](https://discuss.elastic.co/t/is-it-possible-to-conditionaly-analyze-same-field-differently-synonyms/326441 "2023-03-13T15:16:46Z")

</div>

Hi there, The index contains 3 business units, the goal is to provide different set of synonyms for each BU. The field is unstructured text (PDF rendition), occupying 95% of overall index storage, currently analyzed t…

---

## [Does every index have its own shard?](https://discuss.elastic.co/t/does-every-index-have-its-own-shard/327526)

<div class="topic-metadata">

**Author:** [@emrethedev](https://discuss.elastic.co/u/emrethedev)\
**Replies:** 10\
**Last updated:** [March 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/does-every-index-have-its-own-shard/327526 "2023-03-13T15:02:47Z")

</div>

Hi, (Sorry if this is a double post but i could not find answer.) Does every index have its own shard or may they have common shards? We know that when we create an index, it has 5 shards by default. So when we create a…

---

## [Geohash\_grid aggregation in opensearch](https://discuss.elastic.co/t/geohash-grid-aggregation-in-opensearch/327553)

<div class="topic-metadata">

**Author:** [@hmkhitaryan](https://discuss.elastic.co/u/hmkhitaryan)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 2:41pm UTC](https://discuss.elastic.co/t/geohash-grid-aggregation-in-opensearch/327553 "2023-03-13T14:41:35Z")

</div>

Hi. I'm gettin this error when trying "geohash\_grid" aggregation in java opensearch api. Seems opensearch doesn't have geohash\_grid aggregation type, So what can be the analog? "aggs": { "filter\_agg": { "filt…

---

## [Issues with log rotation - Filebeat lock logs file](https://discuss.elastic.co/t/issues-with-log-rotation-filebeat-lock-logs-file/327565)

<div class="topic-metadata">

**Author:** [@akhil](https://discuss.elastic.co/u/akhil)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 2:26pm UTC](https://discuss.elastic.co/t/issues-with-log-rotation-filebeat-lock-logs-file/327565 "2023-03-13T14:26:24Z")

</div>

Hi All, We are having some issues with filbeat. Actually filebeat is locking a logs file and because of this the log rotation is not working. The data is keep getting ingested in the same file. Every time we have to re…

---

## [Filebeat pods keeps increasing Memory usage](https://discuss.elastic.co/t/filebeat-pods-keeps-increasing-memory-usage/325124)

<div class="topic-metadata">

**Author:** [@oandre7](https://discuss.elastic.co/u/oandre7)\
**Replies:** 12\
**Last updated:** [March 13, 2023, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-pods-keeps-increasing-memory-usage/325124 "2023-03-13T14:23:01Z")

</div>

Hi all, We are having a quite a strange issue that running filebeat in any version higher than 8.0.0 will cause filebeats agent to start increasing Memory consumption until the pod is OOM killed. As mentioned versions 8…

---

## [Aggregation on specific object in an array](https://discuss.elastic.co/t/aggregation-on-specific-object-in-an-array/327533)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 3\
**Last updated:** [March 13, 2023, 1:27pm UTC](https://discuss.elastic.co/t/aggregation-on-specific-object-in-an-array/327533 "2023-03-13T13:27:33Z")

</div>

Hi, So my document has a structure as below. I would like to aggregate based on \*\*value\*\*, but only on the object with {"label": "Business Priority"}. Can you help how I can achieve this?

---

## [Elastic Cloud showing "Unhealthy" but all zones are "Healthy"](https://discuss.elastic.co/t/elastic-cloud-showing-unhealthy-but-all-zones-are-healthy/327482)

<div class="topic-metadata">

**Author:** [@matto](https://discuss.elastic.co/u/matto)\
**Replies:** 8\
**Last updated:** [March 13, 2023, 1:26pm UTC](https://discuss.elastic.co/t/elastic-cloud-showing-unhealthy-but-all-zones-are-healthy/327482 "2023-03-13T13:26:00Z")

</div>

We are running Magneto 2.4 using Elastic hosted on Elastic.co. Elastic Cloud version 7.17 due to Magento 2.4 requirements. Recently our Elastic Cloud is showing "Unhealthy" but all zones are "Healthy" - screenshot atta…

---

## [Are there any limits to the number of snapshot repositories?](https://discuss.elastic.co/t/are-there-any-limits-to-the-number-of-snapshot-repositories/327541)

<div class="topic-metadata">

**Author:** [@John\_Newman1](https://discuss.elastic.co/u/John_Newman1)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 1:23pm UTC](https://discuss.elastic.co/t/are-there-any-limits-to-the-number-of-snapshot-repositories/327541 "2023-03-13T13:23:27Z")

</div>

Hi, I'm looking to backup a lot of historical indices, for now and going into the future, we have two a day going back till 2010. For our use case we'd like to set the base\_path per index, this means that we'll need to …

---

## [Questions regarding working with pie charts](https://discuss.elastic.co/t/questions-regarding-working-with-pie-charts/327554)

<div class="topic-metadata">

**Author:** [@marcober](https://discuss.elastic.co/u/marcober)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 1:20pm UTC](https://discuss.elastic.co/t/questions-regarding-working-with-pie-charts/327554 "2023-03-13T13:20:45Z")

</div>

Hi, I'm new using Kibana and I have some questions regarding working with pie charts. There are two things that I've been trying to do but I have not been able to: With a KQL query I was able to handle my data and ge…

---

## [Asa integration in elastic agent](https://discuss.elastic.co/t/asa-integration-in-elastic-agent/327163)

<div class="topic-metadata">

**Author:** [@bex](https://discuss.elastic.co/u/bex)\
**Replies:** 7\
**Last updated:** [March 13, 2023, 12:54pm UTC](https://discuss.elastic.co/t/asa-integration-in-elastic-agent/327163 "2023-03-13T12:54:33Z")

</div>

Can anyone please advise with "Asa" integration in elastic agent? As we know, there are 2 ways: I am sending logs of ASA(192.168.110.1) by syslog udp to logstash(192.168.110.243). When checking by tcpdump, I see that…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=604)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=606)
