# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=612

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 613

---

## [Filebeat - Single line log without newline character](https://discuss.elastic.co/t/filebeat-single-line-log-without-newline-character/327157)

<div class="topic-metadata">

**Author:** [@True](https://discuss.elastic.co/u/True)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 8:45am UTC](https://discuss.elastic.co/t/filebeat-single-line-log-without-newline-character/327157 "2023-03-07T08:45:51Z")

</div>

Hello :smiling\_face\_with\_tear: Is there any possible method for shipping single-line logs without newline characters from Filebeat to Kafka? I'm using 8.6.1 Stack, and in Filebeat, filestream (log) type. The log is cr…

---

## [Apply minimum score parameter for the child queries](https://discuss.elastic.co/t/apply-minimum-score-parameter-for-the-child-queries/327139)

<div class="topic-metadata">

**Author:** [@Rahul\_S1](https://discuss.elastic.co/u/Rahul_S1)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 5:42am UTC](https://discuss.elastic.co/t/apply-minimum-score-parameter-for-the-child-queries/327139 "2023-03-07T05:42:19Z")

</div>

I'm trying to apply some minimum score criteria for my has child queries, my data looks like this: {"Product Code": "A", "properties" :\[{"PROPERTY\_NAME":"density","PROPERTY\_NAME Encoded":\[0.22,0.432,.....\],"value":"low"…

---

## [Zone within data Centre](https://discuss.elastic.co/t/zone-within-data-centre/327141)

<div class="topic-metadata">

**Author:** [@Mani2](https://discuss.elastic.co/u/Mani2)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 5:54am UTC](https://discuss.elastic.co/t/zone-within-data-centre/327141 "2023-03-07T05:54:19Z")

</div>

What can be criteria of deciding the maximum number of zones within a data centre. For ex, If I have 30 Racks in a Data Centre, and if I have Primary and Secondary shards are 1,2 so minimum zones require will be 3. If ea…

---

## [Different Version Elasticsearch, Kibana, Metricbeat](https://discuss.elastic.co/t/different-version-elasticsearch-kibana-metricbeat/327136)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 2\
**Last updated:** [March 7, 2023, 5:47am UTC](https://discuss.elastic.co/t/different-version-elasticsearch-kibana-metricbeat/327136 "2023-03-07T05:47:01Z")

</div>

is it ok if use Elasticsearch, Kibana, Metricbeat version 8.6.1 to connect to version 8.6.2?

---

## [How to write a collation rule for icu\_collation\_keyword field, with alphabets having atmost precedence?](https://discuss.elastic.co/t/how-to-write-a-collation-rule-for-icu-collation-keyword-field-with-alphabets-having-atmost-precedence/327019)

<div class="topic-metadata">

**Author:** [@Karthik\_Amar](https://discuss.elastic.co/u/Karthik_Amar)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 5:27am UTC](https://discuss.elastic.co/t/how-to-write-a-collation-rule-for-icu-collation-keyword-field-with-alphabets-having-atmost-precedence/327019 "2023-03-07T05:27:10Z")

</div>

Instead of using alternative locale option, I want to write a rules parameter to customise the sort behaviour with alphabets having atmost precedence. for the text values, $1232, Abi, £7232, 87343, Karthik I want the…

---

## [Auditbeat Version 8.4.1 event.category](https://discuss.elastic.co/t/auditbeat-version-8-4-1-event-category/327137)

<div class="topic-metadata">

**Author:** [@jjacksonrkk](https://discuss.elastic.co/u/jjacksonrkk)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 5:08am UTC](https://discuss.elastic.co/t/auditbeat-version-8-4-1-event-category/327137 "2023-03-07T05:08:18Z")

</div>

Auditbeat version 8.4.1 is in use. When debugging, event.category occurs as \["intrusion\_detection", "process"\] When running the auditbeat daemon service, event.category appears only as process, what should I set in audi…

---

## [Is there query char length limit of a match query](https://discuss.elastic.co/t/is-there-query-char-length-limit-of-a-match-query/327020)

<div class="topic-metadata">

**Author:** [@chenchuangc](https://discuss.elastic.co/u/chenchuangc)\
**Replies:** 2\
**Last updated:** [March 7, 2023, 1:49am UTC](https://discuss.elastic.co/t/is-there-query-char-length-limit-of-a-match-query/327020 "2023-03-07T01:49:34Z")

</div>

Thank you so much for having a look of my issue. ES Version 7.5.0 Query GET search\_vietnamese/\_search { "query": { "bool": { "should": \[ { "match": { "address": { …

---

## [Parsing an html inside a Json](https://discuss.elastic.co/t/parsing-an-html-inside-a-json/327104)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 11:06pm UTC](https://discuss.elastic.co/t/parsing-an-html-inside-a-json/327104 "2023-03-06T23:06:35Z")

</div>

Hi, \*\* a longer explanation of the problem is in the second response to @Badger \*\* I need to parse a log with a JSON that contain a field which contains an HTML document, ex : 2023-03-04 20:20:06,817 \[http-nio-8080-ex…

---

## [Is it possible to ignore failure while using the Reindex API?](https://discuss.elastic.co/t/is-it-possible-to-ignore-failure-while-using-the-reindex-api/327120)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 5\
**Last updated:** [March 6, 2023, 10:01pm UTC](https://discuss.elastic.co/t/is-it-possible-to-ignore-failure-while-using-the-reindex-api/327120 "2023-03-06T22:01:40Z")

</div>

Hello, I'm trying to run some reindex on an index and got a failure related to a mapping parsing exception, which is kinda of expected as on this data the field can change from object to text. For this reason, the dest…

---

## [Reindex document count does not match the source](https://discuss.elastic.co/t/reindex-document-count-does-not-match-the-source/327116)

<div class="topic-metadata">

**Author:** [@Parvatayya\_Malimath](https://discuss.elastic.co/u/Parvatayya_Malimath)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 8:41pm UTC](https://discuss.elastic.co/t/reindex-document-count-does-not-match-the-source/327116 "2023-03-06T20:41:46Z")

</div>

I am reindexing an index from one cluster (elastic 6.8) to another cluster (elastic 7.17) Source: GET \<index\_name\>/\_count { "count" : 827908, "\_shards" : { "total" : 5, "successful" : 5, "skipped" : 0, "failed" …

---

## [Simple Query to search within log text (not keyword)](https://discuss.elastic.co/t/simple-query-to-search-within-log-text-not-keyword/327095)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 6:51pm UTC](https://discuss.elastic.co/t/simple-query-to-search-within-log-text-not-keyword/327095 "2023-03-06T18:51:30Z")

</div>

I am trying to search within text that originates from log files. Am I using the correct query? Any suggestions on how to restrict results only to the exact match? (eg show only results with higher score?) I am using e…

---

## [Will influencer change the way a model might detect and anomaly?](https://discuss.elastic.co/t/will-influencer-change-the-way-a-model-might-detect-and-anomaly/326908)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 5:29pm UTC](https://discuss.elastic.co/t/will-influencer-change-the-way-a-model-might-detect-and-anomaly/326908 "2023-03-06T17:29:15Z")

</div>

Hello Team, I am working with the machine learning tools provided by elastic. I am detecting certain rare events over time. But now I have certain fields that I want the model to take in consideration while detecting th…

---

## [Failed to publish events](https://discuss.elastic.co/t/failed-to-publish-events/327090)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 5:18pm UTC](https://discuss.elastic.co/t/failed-to-publish-events/327090 "2023-03-06T17:18:56Z")

</div>

Hi All, We see the following error in filebeat log resulting in loss of data: pipeline/output.go:121 Failed to publish events: write tcp 19.14.25.26:42660-\>14.18.8.1:5044: write: connection reset by peer It seems tha…

---

## [Saving the content of a file in an elasticsearch index using springboot RESTAPI](https://discuss.elastic.co/t/saving-the-content-of-a-file-in-an-elasticsearch-index-using-springboot-restapi/327112)

<div class="topic-metadata">

**Author:** [@BEY\_MEHREZ](https://discuss.elastic.co/u/BEY_MEHREZ)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:14pm UTC](https://discuss.elastic.co/t/saving-the-content-of-a-file-in-an-elasticsearch-index-using-springboot-restapi/327112 "2023-03-06T17:14:53Z")

</div>

So I am building a Spring Boot rest api that it takes a file ( Multipart file ) ( and it is a log file ) as an argument and saves its content in a unique elasticsearch index ! Each line of the file will be in a document.…

---

## [Debugging lost data in logstash coming from filebeat](https://discuss.elastic.co/t/debugging-lost-data-in-logstash-coming-from-filebeat/327110)

<div class="topic-metadata">

**Author:** [@mayer](https://discuss.elastic.co/u/mayer)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:07pm UTC](https://discuss.elastic.co/t/debugging-lost-data-in-logstash-coming-from-filebeat/327110 "2023-03-06T17:07:51Z")

</div>

Dear All, I am running a central ELK stack 8.6.2 with logstash to collect data from some server around. More than 2 years ago I compiled filebeat by myself as it was not available on ARM architecture. With a minimal con…

---

## [Bufforing logs using ingest node](https://discuss.elastic.co/t/bufforing-logs-using-ingest-node/327103)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 4:50pm UTC](https://discuss.elastic.co/t/bufforing-logs-using-ingest-node/327103 "2023-03-06T16:50:27Z")

</div>

Hi, I need to create an Elastic SIEM cluster in which logs will be buffered in the event of a data node failure. When the data node is brought back to life, the logs from the period when the node was not functioning wil…

---

## [Elasticsearch Compilation issues on Linux](https://discuss.elastic.co/t/elasticsearch-compilation-issues-on-linux/327096)

<div class="topic-metadata">

**Author:** [@markchennai](https://discuss.elastic.co/u/markchennai)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 3:19pm UTC](https://discuss.elastic.co/t/elasticsearch-compilation-issues-on-linux/327096 "2023-03-06T15:19:47Z")

</div>

Team, I am facing issues while compiling Elasticsearch 8.5.1, the source code is allowed to pull the files from the in-house repo, FAILURE: Build failed with an exception. What went wrong: A problem occurred configu…

---

## [Logstash still holding onto deleted logstash application logs](https://discuss.elastic.co/t/logstash-still-holding-onto-deleted-logstash-application-logs/325479)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 3:09pm UTC](https://discuss.elastic.co/t/logstash-still-holding-onto-deleted-logstash-application-logs/325479 "2023-03-06T15:09:12Z")

</div>

Hello, It seems logstash refuses to let go of deleted logs (logstash's own logs) and this takes up all the space on disks , until a service restart takes place . Is there a way , we could fix this ? Is something need to…

---

## [Elastic Docker Integration - not collecting logs](https://discuss.elastic.co/t/elastic-docker-integration-not-collecting-logs/326947)

<div class="topic-metadata">

**Author:** [@sc1215](https://discuss.elastic.co/u/sc1215)\
**Replies:** 4\
**Last updated:** [March 6, 2023, 3:01pm UTC](https://discuss.elastic.co/t/elastic-docker-integration-not-collecting-logs/326947 "2023-03-06T15:01:20Z")

</div>

I had been using the 'System' integration agent to consume my docker logs which are saved in the path: /var/lib/docker/containers/\*/\*-json.log This has been working, but unfortunately, it was splitting up log lines whic…

---

## [Logstash Config File not running getting error: contains non-ascii characters but are not UTF-8 encoded](https://discuss.elastic.co/t/logstash-config-file-not-running-getting-error-contains-non-ascii-characters-but-are-not-utf-8-encoded/327080)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 2:24pm UTC](https://discuss.elastic.co/t/logstash-config-file-not-running-getting-error-contains-non-ascii-characters-but-are-not-utf-8-encoded/327080 "2023-03-06T14:24:27Z")

</div>

Hello All, I'm getting below error while running the logstash config,Unable to understand how it can be resolved.Eearlier it worked by now giving error. input { jdbc { jdbc\_connection\_string =\> "jdbc:oracle:thin…

---

## [Clone a space via API](https://discuss.elastic.co/t/clone-a-space-via-api/327041)

<div class="topic-metadata">

**Author:** [@oliverj](https://discuss.elastic.co/u/oliverj)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 2:23pm UTC](https://discuss.elastic.co/t/clone-a-space-via-api/327041 "2023-03-06T14:23:18Z")

</div>

We are standing up our first Cluster, and one of the things we have run into is that people have no "user context" for the artifcats they create. Everything is shared by space. So, our plan is to have 2 spaces for our us…

---

## [java.lang.RuntimeException when using client in Java API in Kotlin](https://discuss.elastic.co/t/java-lang-runtimeexception-when-using-client-in-java-api-in-kotlin/327013)

<div class="topic-metadata">

**Author:** [@GAETANO\_SIMONELLI](https://discuss.elastic.co/u/GAETANO_SIMONELLI)\
**Replies:** 6\
**Last updated:** [March 6, 2023, 1:05pm UTC](https://discuss.elastic.co/t/java-lang-runtimeexception-when-using-client-in-java-api-in-kotlin/327013 "2023-03-06T13:05:38Z")

</div>

I am trying to use the Elasticsearch Java API in a Kotlin application, following the official tutorial page (Connecting | Elasticsearch Java API Client \[8.6\] | Elastic). However, I am encountering a java.lang.RuntimeExce…

---

## [Calculate MTTR for jenkins builds](https://discuss.elastic.co/t/calculate-mttr-for-jenkins-builds/327067)

<div class="topic-metadata">

**Author:** [@khuongdp](https://discuss.elastic.co/u/khuongdp)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 1:44pm UTC](https://discuss.elastic.co/t/calculate-mttr-for-jenkins-builds/327067 "2023-03-06T13:44:20Z")

</div>

Hi I would like to calculate MTTR for some jenkins builds. I have these fields in multiple documents: Using Elasticsearch 8.3.0 input : name, type \[type1|type2\], status \[failure|success\], buildDateTime Output (somet…

---

## [High CPU Utilization in Elasticsearch Nodes](https://discuss.elastic.co/t/high-cpu-utilization-in-elasticsearch-nodes/327078)

<div class="topic-metadata">

**Author:** [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 1:12pm UTC](https://discuss.elastic.co/t/high-cpu-utilization-in-elasticsearch-nodes/327078 "2023-03-06T13:12:26Z")

</div>

Hi, We have been experiencing HIGH CPU USAGE in elasticsearch nodes for the last couple of days causing timeout exceptions for most of the search queries. We have dedicated nodes for ES, however, there is no defined mas…

---

## [Gauge ordering by value calculated in bucket script aggregation](https://discuss.elastic.co/t/gauge-ordering-by-value-calculated-in-bucket-script-aggregation/327077)

<div class="topic-metadata">

**Author:** [@tumbl3w33d](https://discuss.elastic.co/u/tumbl3w33d)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 1:07pm UTC](https://discuss.elastic.co/t/gauge-ordering-by-value-calculated-in-bucket-script-aggregation/327077 "2023-03-06T13:07:50Z")

</div>

Hello, I'm using elastic agent with its system integration to collect metrics and I want to display the disk use per host as gauges. It's achieved by calculating the percentual use in a bucket script: The ordering d…

---

## [Setup Elastic Watcher Alert to match two message strings in a log](https://discuss.elastic.co/t/setup-elastic-watcher-alert-to-match-two-message-strings-in-a-log/326804)

<div class="topic-metadata">

**Author:** [@scott.godfrey](https://discuss.elastic.co/u/scott.godfrey)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 1:09pm UTC](https://discuss.elastic.co/t/setup-elastic-watcher-alert-to-match-two-message-strings-in-a-log/326804 "2023-03-06T13:09:34Z")

</div>

I'm trying to setup an Elastic Watcher Alert that will scan a logfile and match 2 different messages in the log and then send an alert. Sample Log \[2023-02-13 09:00:10.749 -05:00 INF\] This is test 1 \[2023-02-13 09:10…

---

## [All the shards are being assigned to a single node](https://discuss.elastic.co/t/all-the-shards-are-being-assigned-to-a-single-node/326857)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 4\
**Last updated:** [March 6, 2023, 11:27am UTC](https://discuss.elastic.co/t/all-the-shards-are-being-assigned-to-a-single-node/326857 "2023-03-06T11:27:41Z")

</div>

Hi.. We have a 6 data node cluster and we have around 2000 indices with 9500 shards. We have the below cluster settings and have enabled all the shards to be re-balanced to distribute the shards across the cluster. { …

---

## [Elasticsearch deprecation issues](https://discuss.elastic.co/t/elasticsearch-deprecation-issues/325543)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 5\
**Last updated:** [March 6, 2023, 11:20am UTC](https://discuss.elastic.co/t/elasticsearch-deprecation-issues/325543 "2023-03-06T11:20:40Z")

</div>

I can't upgrade to 8.6.1 due to a deprecation issue. I can't update the elasticsearch.yml, because I have a cloud solution. Problem: setting \[cluster.routing.allocation.disk.watermark.enable\_for\_single\_data\_node\] is dep…

---

## [Make a grok pattern for a field that might be missing](https://discuss.elastic.co/t/make-a-grok-pattern-for-a-field-that-might-be-missing/327014)

<div class="topic-metadata">

**Author:** [@ira-zaya](https://discuss.elastic.co/u/ira-zaya)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 11:12am UTC](https://discuss.elastic.co/t/make-a-grok-pattern-for-a-field-that-might-be-missing/327014 "2023-03-06T11:12:38Z")

</div>

Hi! There are logs in the following format: 2023-03-05 17:07:01.586+0000 \[L: WARN\] \[O: A.b.c.d.e.FGScript\] \[I: \] \[U: email@example.com\] \[S: \] \[P: \] \[T: ABCProcessor-23 \] @@@ aboba=5 beboba=1 ceboba=4 So I have a correc…

---

## [To find top 5 values and All value on selection of radio button on the basis of same field in Vega-lite using Kibana](https://discuss.elastic.co/t/to-find-top-5-values-and-all-value-on-selection-of-radio-button-on-the-basis-of-same-field-in-vega-lite-using-kibana/327066)

<div class="topic-metadata">

**Author:** [@ysattvik](https://discuss.elastic.co/u/ysattvik)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 10:38am UTC](https://discuss.elastic.co/t/to-find-top-5-values-and-all-value-on-selection-of-radio-button-on-the-basis-of-same-field-in-vega-lite-using-kibana/327066 "2023-03-06T10:38:54Z")

</div>

Hi Team, I am trying to implement selection options using radio button to show the top 5 values and other radio button shows the all the values available in that field using Vega-lite. It can be easily explained by this…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=611)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=613)
