# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=610

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 611

---

## [Elastic Search Heap size](https://discuss.elastic.co/t/elastic-search-heap-size/327266)

<div class="topic-metadata">

**Author:** [@Jozelle\_Cinco](https://discuss.elastic.co/u/Jozelle_Cinco)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 2:38pm UTC](https://discuss.elastic.co/t/elastic-search-heap-size/327266 "2023-03-08T14:38:51Z")

</div>

Hi! We have a Headless Drupal 9 site (FE: Gatsby) with Elasticsearch that's currently encountering \[circuit\_breaking\_exception\] when doing a search. As per some discussions it is suggested we adjust the Heap size on Pro…

---

## [Logstash syslog message, doesn't choose right if statement](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181)

<div class="topic-metadata">

**Author:** [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 2:36pm UTC](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181 "2023-03-08T14:36:26Z")

</div>

Hi, I'm trying to create a logstash pipeline for cisco FMC audit log. I have create 3 if statements and would like for logstash to parse the syslog message according to the if statement. Here is two example syslog mes…

---

## [Example of testing cumstom plugins](https://discuss.elastic.co/t/example-of-testing-cumstom-plugins/327038)

<div class="topic-metadata">

**Author:** [@iljaskajrris](https://discuss.elastic.co/u/iljaskajrris)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 2:33pm UTC](https://discuss.elastic.co/t/example-of-testing-cumstom-plugins/327038 "2023-03-08T14:33:34Z")

</div>

Hi team, i develop plugin for Kibana 7.10 and wonder if there any working example of functional tests for that. Can anybody help?

---

## [I have imported the dashboard](https://discuss.elastic.co/t/i-have-imported-the-dashboard/327144)

<div class="topic-metadata">

**Author:** [@ghorpade84](https://discuss.elastic.co/u/ghorpade84)\
**Replies:** 6\
**Last updated:** [March 8, 2023, 2:20pm UTC](https://discuss.elastic.co/t/i-have-imported-the-dashboard/327144 "2023-03-08T14:20:56Z")

</div>

I have imported the dashboard from git however dashboard shows no data in it , visualization id not found

---

## [Filebeat Helm chart 8.x requires \`elasticsearch-master-certs\`](https://discuss.elastic.co/t/filebeat-helm-chart-8-x-requires-elasticsearch-master-certs/325049)

<div class="topic-metadata">

**Author:** [@Roman\_Kournjaev](https://discuss.elastic.co/u/Roman_Kournjaev)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 2:15pm UTC](https://discuss.elastic.co/t/filebeat-helm-chart-8-x-requires-elasticsearch-master-certs/325049 "2023-03-08T14:15:55Z")

</div>

We are using beats to ship our logs from k8s to the elastic cloud. I would like to upgrade our beats helm chart version from 7.x to 8.x and it introduces a breaking change where i would have to create a secret with elas…

---

## [Logstash ignore\_older opposite](https://discuss.elastic.co/t/logstash-ignore-older-opposite/327279)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 2:13pm UTC](https://discuss.elastic.co/t/logstash-ignore-older-opposite/327279 "2023-03-08T14:13:47Z")

</div>

Hello, I would like Logstash to read only files older than one day. How can I do that? It would be sort of the opposite of "ignore\_older". Thx

---

## [Filebeat shared folder](https://discuss.elastic.co/t/filebeat-shared-folder/327106)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 2:04pm UTC](https://discuss.elastic.co/t/filebeat-shared-folder/327106 "2023-03-08T14:04:32Z")

</div>

Hello, I have to install Filebeat on a server (windows). Filebeat will have to read logs file on a shared folder. In my .yml, i got that : filebeat.inputs: - type: log paths: - \\\\dpm\\\*.log But this doesn't work…

---

## [Shard allocation - strange behaviour of index tier preference](https://discuss.elastic.co/t/shard-allocation-strange-behaviour-of-index-tier-preference/326746)

<div class="topic-metadata">

**Author:** [@Michael\_Hyatt](https://discuss.elastic.co/u/Michael_Hyatt)\
**Replies:** 11\
**Last updated:** [March 8, 2023, 1:56pm UTC](https://discuss.elastic.co/t/shard-allocation-strange-behaviour-of-index-tier-preference/326746 "2023-03-08T13:56:43Z")

</div>

Hi there, I have a hot-warm cluster with 2 hot and 2 warm nodes (Elastic cloud v8.6.1). I also have an index that I want to distribute to both, hot and warm-tier nodes. To do that, I want to set up the number of replica…

---

## [Change Wilnogbeat index name](https://discuss.elastic.co/t/change-wilnogbeat-index-name/327273)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 1:08pm UTC](https://discuss.elastic.co/t/change-wilnogbeat-index-name/327273 "2023-03-08T13:08:03Z")

</div>

Hi, I want to change index name from winlogbeat and i am following your instructions. This is my yml file: But still getting this error: Exiting: error loading template: failed to put data stream: could not put data…

---

## [Query index from within an AnalysisProvider?](https://discuss.elastic.co/t/query-index-from-within-an-analysisprovider/327191)

<div class="topic-metadata">

**Author:** [@jnioche](https://discuss.elastic.co/u/jnioche)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 12:38pm UTC](https://discuss.elastic.co/t/query-index-from-within-an-analysisprovider/327191 "2023-03-08T12:38:38Z")

</div>

Hi, Here is the context of my question: Synonym graph token filter backed by Elastic index I am writing a custom AnalysisPlugin to generate a list of synonyms from an Elastic index instead of using a static file. A na…

---

## [Performance implications of \`index.max\_result\_window\` vs \`track\_total\_hits\`](https://discuss.elastic.co/t/performance-implications-of-index-max-result-window-vs-track-total-hits/327270)

<div class="topic-metadata">

**Author:** [@Cristian\_Calara](https://discuss.elastic.co/u/Cristian_Calara)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 12:21pm UTC](https://discuss.elastic.co/t/performance-implications-of-index-max-result-window-vs-track-total-hits/327270 "2023-03-08T12:21:15Z")

</div>

Hello, For example, if we would have 50.000 results for a search query. If we really need to return an exact total number of matches and we enabled track\_total\_hits to get it. Should we just as well increase the max\_res…

---

## [Elastic search container upgrade from 7.10.2 to 7.17.9](https://discuss.elastic.co/t/elastic-search-container-upgrade-from-7-10-2-to-7-17-9/327061)

<div class="topic-metadata">

**Author:** [@sundar.s](https://discuss.elastic.co/u/sundar.s)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 12:03pm UTC](https://discuss.elastic.co/t/elastic-search-container-upgrade-from-7-10-2-to-7-17-9/327061 "2023-03-08T12:03:11Z")

</div>

Hi, We are trying to upgrade from 7.10.2 Elasticsearch containers to 7.17.9. Can I ran my Elasticsearch container directly on the data node created/used by 7.10.2 containers ? Do I need to do additional steps to make s…

---

## [What is the best method to backup Fleet policies](https://discuss.elastic.co/t/what-is-the-best-method-to-backup-fleet-policies/327265)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 10:55am UTC](https://discuss.elastic.co/t/what-is-the-best-method-to-backup-fleet-policies/327265 "2023-03-08T10:55:51Z")

</div>

Hello, In the event of server failures, I have snapshots to recover data. But how can I recover fleet server integration configurations, installed agents and their policies?

---

## [Elastic.Clients.Elasticsearch 8.x (custom) serialization](https://discuss.elastic.co/t/elastic-clients-elasticsearch-8-x-custom-serialization/324435)

<div class="topic-metadata">

**Author:** [@KoalaBear](https://discuss.elastic.co/u/KoalaBear)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 10:11am UTC](https://discuss.elastic.co/t/elastic-clients-elasticsearch-8-x-custom-serialization/324435 "2023-03-08T10:11:32Z")

</div>

I would like to do something like we have in Netwonsoft Json: options.SerializerSettings.ReferenceLoopHandling = Newtonsoft.Json.ReferenceLoopHandling.Ignore And also have in System.Text.Json: JsonSerializerOptions op…

---

## [How to filter date with optional keyword search](https://discuss.elastic.co/t/how-to-filter-date-with-optional-keyword-search/327260)

<div class="topic-metadata">

**Author:** [@gopikrish](https://discuss.elastic.co/u/gopikrish)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 10:08am UTC](https://discuss.elastic.co/t/how-to-filter-date-with-optional-keyword-search/327260 "2023-03-08T10:08:48Z")

</div>

Hi All , while retrieving data from ELK, I need to filter records between two date(mandatory) with keyword (optional) parameter. The searching keyword is only present in value format not in key value pair. For eg ; { …

---

## [Vega kibana Dashboard Lagging](https://discuss.elastic.co/t/vega-kibana-dashboard-lagging/327259)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 9:56am UTC](https://discuss.elastic.co/t/vega-kibana-dashboard-lagging/327259 "2023-03-08T09:56:46Z")

</div>

I created a vega kibana dashboard from an elasticsearch query with different mark types: 2 areas, rule, rect and symbols I created a tooltip too but when hovering with the mouse , I got the Vega Kibana dashboard lagging…

---

## [Index.mapping.depth.limit not persistent after an index rollover](https://discuss.elastic.co/t/index-mapping-depth-limit-not-persistent-after-an-index-rollover/327182)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 8:58am UTC](https://discuss.elastic.co/t/index-mapping-depth-limit-not-persistent-after-an-index-rollover/327182 "2023-03-08T08:58:52Z")

</div>

Hi everyone, I notice that when the current index is rollovered, the index.mapping.depth.limit is not take into account for the new created index. We are running an elasticsearch cluster and after we have created the f…

---

## [Not able to remove tag from xml](https://discuss.elastic.co/t/not-able-to-remove-tag-from-xml/326771)

<div class="topic-metadata">

**Author:** [@Navya\_04](https://discuss.elastic.co/u/Navya_04)\
**Replies:** 14\
**Last updated:** [March 8, 2023, 8:32am UTC](https://discuss.elastic.co/t/not-able-to-remove-tag-from-xml/326771 "2023-03-08T08:32:22Z")

</div>

I am trying to load xml through logstash. I have an unwnated tag which needs to be removed from xml while parsing. Used remove\_tag but not able to remove the tag while indexing to Elasticsearch xml File \<?xml version="…

---

## [Filebeat connection error with logstash](https://discuss.elastic.co/t/filebeat-connection-error-with-logstash/327208)

<div class="topic-metadata">

**Author:** [@sebglon](https://discuss.elastic.co/u/sebglon)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 8:24am UTC](https://discuss.elastic.co/t/filebeat-connection-error-with-logstash/327208 "2023-03-08T08:24:03Z")

</div>

Hi, We have a K8s cluster with more than 30 nodes. on each nodes we have a filebeat agent to collect container logs and node logs. filebeat agents send data to 3 logstash on the same cluster. On some nodes and after …

---

## [About elasticsearch and kibana snapshot and backup feature](https://discuss.elastic.co/t/about-elasticsearch-and-kibana-snapshot-and-backup-feature/327198)

<div class="topic-metadata">

**Author:** [@Rakesh\_Bare1](https://discuss.elastic.co/u/Rakesh_Bare1)\
**Replies:** 6\
**Last updated:** [March 8, 2023, 7:41am UTC](https://discuss.elastic.co/t/about-elasticsearch-and-kibana-snapshot-and-backup-feature/327198 "2023-03-08T07:41:10Z")

</div>

hey, i am used elasticsearch is cluster. i want to take snapshot of my es. i have create snapshot directory and mention in elasticsearch.yml in path.repo. after that elasticsearch docker not running. i have check logs …

---

## [Metricbeat VM Can't Connect To Elasticsearch On Different Device](https://discuss.elastic.co/t/metricbeat-vm-cant-connect-to-elasticsearch-on-different-device/326722)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 44\
**Last updated:** [March 8, 2023, 12:47am UTC](https://discuss.elastic.co/t/metricbeat-vm-cant-connect-to-elasticsearch-on-different-device/326722 "2023-03-08T00:47:22Z")

</div>

Hello i'm new on ELK, Metricbeat on my VM can't connect to my laptop for monitoring the system on VM, i already following the instruction from many source but still can't connect from Metricbeat VM to my laptop for monit…

---

## [What is the deciding factor for the number of coordinating only node in a cluster and how to route the requests?](https://discuss.elastic.co/t/what-is-the-deciding-factor-for-the-number-of-coordinating-only-node-in-a-cluster-and-how-to-route-the-requests/326842)

<div class="topic-metadata">

**Author:** [@pruthvi](https://discuss.elastic.co/u/pruthvi)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 12:54am UTC](https://discuss.elastic.co/t/what-is-the-deciding-factor-for-the-number-of-coordinating-only-node-in-a-cluster-and-how-to-route-the-requests/326842 "2023-03-08T00:54:28Z")

</div>

Hi, I have a requirement to index 100TB of data per month in ES with ILM. No. dedicated master nodes – 3 nodes. Total no. of hot nodes - 66 nodes. Total no. of warm nodes - 216 nodes. Above calculations are based on…

---

## [Create new field value is incorrect](https://discuss.elastic.co/t/create-new-field-value-is-incorrect/326912)

<div class="topic-metadata">

**Author:** [@ikonrao](https://discuss.elastic.co/u/ikonrao)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:54pm UTC](https://discuss.elastic.co/t/create-new-field-value-is-incorrect/326912 "2023-03-07T22:54:34Z")

</div>

Hi, I have a field which has value in seconds. I need to view it in hours. I used create new field and used script to convert it into hours. What i have observed is it is not able to take decimal values. For example, …

---

## [Logstash writer permissions](https://discuss.elastic.co/t/logstash-writer-permissions/327099)

<div class="topic-metadata">

**Author:** [@jfs1](https://discuss.elastic.co/u/jfs1)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 3:45pm UTC](https://discuss.elastic.co/t/logstash-writer-permissions/327099 "2023-03-06T15:45:03Z")

</div>

On a new on-premises 8.6 logstash+elasticsearch deployment, I have the following error when configuring my "logstash\_writer" role as explained in Secure your connection to Elasticsearch | Logstash Reference \[8.6\] | Elast…

---

## [ElasticSearch and Kibana Migration](https://discuss.elastic.co/t/elasticsearch-and-kibana-migration/327146)

<div class="topic-metadata">

**Author:** [@Ramesh\_Ramachandran](https://discuss.elastic.co/u/Ramesh_Ramachandran)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:25pm UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-migration/327146 "2023-03-07T22:25:37Z")

</div>

Hi Team, We are in the process of migrating Elasticsearch and Kibana from 8.2.2 to 8.5.3. We have deployed ES and Kibana in AKS with helm chart deployment. On migrating we are facing the below issue. \[2023-03-07T05:17…

---

## [Error in installing kibana](https://discuss.elastic.co/t/error-in-installing-kibana/327092)

<div class="topic-metadata">

**Author:** [@Ahmed\_Khaled](https://discuss.elastic.co/u/Ahmed_Khaled)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 10:23pm UTC](https://discuss.elastic.co/t/error-in-installing-kibana/327092 "2023-03-07T22:23:51Z")

</div>

hello team, I am a beginner in using elastic stack and I have a problem (Kibana server is not ready) how I can fix it please????

---

## [Map Alert Rules to Kibana Widgets](https://discuss.elastic.co/t/map-alert-rules-to-kibana-widgets/327127)

<div class="topic-metadata">

**Author:** [@jsoule6](https://discuss.elastic.co/u/jsoule6)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 12:28am UTC](https://discuss.elastic.co/t/map-alert-rules-to-kibana-widgets/327127 "2023-03-07T00:28:02Z")

</div>

Hello, We are looking to use Kibana dashboard capability to provide monitoring capability for our customer. We are going to be create alert rules based on numerous custom conditions and would like to map the rules to wi…

---

## [Number of Zones for Zone awared Shard allocation](https://discuss.elastic.co/t/number-of-zones-for-zone-awared-shard-allocation/327169)

<div class="topic-metadata">

**Author:** [@Mani2](https://discuss.elastic.co/u/Mani2)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:20pm UTC](https://discuss.elastic.co/t/number-of-zones-for-zone-awared-shard-allocation/327169 "2023-03-07T22:20:37Z")

</div>

Hello, What can be the criteria of deciding the maximum number of zones within a data centre. For ex, If I have 30 Racks in a Data Centre, and if I have Primary and Secondary shards are 1,2 so minimum zones require will…

---

## [Getting authentication failure when logging into kibana](https://discuss.elastic.co/t/getting-authentication-failure-when-logging-into-kibana/327222)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:06pm UTC](https://discuss.elastic.co/t/getting-authentication-failure-when-logging-into-kibana/327222 "2023-03-07T22:06:42Z")

</div>

I am trying to log into kibana as the elastic user to do some maintenance but the login fails -- server shows: Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\] I ca…

---

## [Why does this SIMPLE Kibana script not work?](https://discuss.elastic.co/t/why-does-this-simple-kibana-script-not-work/327228)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 9:46pm UTC](https://discuss.elastic.co/t/why-does-this-simple-kibana-script-not-work/327228 "2023-03-07T21:46:00Z")

</div>

Following right from the documentation: hubEvent.rssi is a String like '-98 dBm' I want to return a number def rssi = doc\['hubEvent.rssi.keyword'\].value; if (rssi != null) { int lastdBIndex = rssi.lastIndexOf('d…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=609)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=611)
