# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=613

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 614

---

## [Elastic ML Alert Mustache Syntax (Break Line)](https://discuss.elastic.co/t/elastic-ml-alert-mustache-syntax-break-line/327024)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 9:16am UTC](https://discuss.elastic.co/t/elastic-ml-alert-mustache-syntax-break-line/327024 "2023-03-06T09:16:18Z")

</div>

Hi, I would like to adjust my email alert to break to a new line. From above image, the upper context for (Environment Affected) is working as I used {{{foo}}} to break it. However, it does not work for the (Detect…

---

## [Searching non-indexed fields](https://discuss.elastic.co/t/searching-non-indexed-fields/327033)

<div class="topic-metadata">

**Author:** [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 8:40am UTC](https://discuss.elastic.co/t/searching-non-indexed-fields/327033 "2023-03-06T08:40:00Z")

</div>

Hi everyone, Contrary to popular opinion, I'm able to search non-indexed fields in Elasticsearch. I'm wondering if this is is a bug or a newly introduced feature. I'm on Elasticsearch 8.6.2. The documentation says "Fie…

---

## [File Descriptors count](https://discuss.elastic.co/t/file-descriptors-count/327043)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 8:15am UTC](https://discuss.elastic.co/t/file-descriptors-count/327043 "2023-03-06T08:15:17Z")

</div>

Hi, According to docs it is recommended to set File Descriptors to 65535 (ulimit -n). How it effect my node? What will be the behavior if I will set higher value? for instance: 500000 Thanks

---

## [Metricbeat sends timestamp as keyword type instead of date type to Elasticsearch, old template endpoints work instead of new one](https://discuss.elastic.co/t/metricbeat-sends-timestamp-as-keyword-type-instead-of-date-type-to-elasticsearch-old-template-endpoints-work-instead-of-new-one/326703)

<div class="topic-metadata">

**Author:** [@learner75](https://discuss.elastic.co/u/learner75)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 8:05am UTC](https://discuss.elastic.co/t/metricbeat-sends-timestamp-as-keyword-type-instead-of-date-type-to-elasticsearch-old-template-endpoints-work-instead-of-new-one/326703 "2023-03-06T08:05:05Z")

</div>

Current problem: Metricbeat sends timestamp as keyword type instead of date type. Have to use a separate command with the old index template api to update mapping. Background: Our ELK stack was upgraded from 6.8.23 to …

---

## [Metricbeat services restarted automatically](https://discuss.elastic.co/t/metricbeat-services-restarted-automatically/326822)

<div class="topic-metadata">

**Author:** [@ArpitChoudhary](https://discuss.elastic.co/u/ArpitChoudhary)\
**Replies:** 4\
**Last updated:** [March 6, 2023, 6:53am UTC](https://discuss.elastic.co/t/metricbeat-services-restarted-automatically/326822 "2023-03-06T06:53:36Z")

</div>

Hello Guys. Facing an issue , Metricbeat service is recursively getting restarting. Please find below status/log of service.

---

## [How to measure time it takes from elasticsearch pod to elasticsearch?](https://discuss.elastic.co/t/how-to-measure-time-it-takes-from-elasticsearch-pod-to-elasticsearch/327035)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 6:42am UTC](https://discuss.elastic.co/t/how-to-measure-time-it-takes-from-elasticsearch-pod-to-elasticsearch/327035 "2023-03-06T06:42:02Z")

</div>

We have a global search functionality that takes time to fetch data from Elasticsearch so we need to measure time it would take from elasticsearch pod to elasticsearch itself. Our technology uses java spring Elasticsearc…

---

## [Customization in line lens](https://discuss.elastic.co/t/customization-in-line-lens/327034)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 6:22am UTC](https://discuss.elastic.co/t/customization-in-line-lens/327034 "2023-03-06T06:22:15Z")

</div>

Hi, Can we create Line lens as per the attached snap with color?

---

## [Deleting \_recovery\_source](https://discuss.elastic.co/t/deleting-recovery-source/327028)

<div class="topic-metadata">

**Author:** [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:32am UTC](https://discuss.elastic.co/t/deleting-recovery-source/327028 "2023-03-06T05:32:45Z")

</div>

Hi everyone, I'm on Elasticsearch 8.6.2. I wanted to reduce disk usage of my indices, and noticed that the \_recovery\_source takes up quite some space. I tried setting index.soft\_deletes.enabled to false, but index cr…

---

## [How to prevent RestHighLevelClient from blacklisting the Host in Elasticsearch 8.6.2?](https://discuss.elastic.co/t/how-to-prevent-resthighlevelclient-from-blacklisting-the-host-in-elasticsearch-8-6-2/327027)

<div class="topic-metadata">

**Author:** [@\_ite\_iew](https://discuss.elastic.co/u/_ite_iew)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:27am UTC](https://discuss.elastic.co/t/how-to-prevent-resthighlevelclient-from-blacklisting-the-host-in-elasticsearch-8-6-2/327027 "2023-03-06T05:27:35Z")

</div>

I am using Elasticsearch client version 8.6 we use Elasticsearch as a service and other companies provided us an IP/port to connect to it. we run heavy, numerous, automated queries against this Elasticsearch and someti…

---

## [Installed elastic search on Window 11. I hit localhost:9200 and Asking for Username and Password?](https://discuss.elastic.co/t/installed-elastic-search-on-window-11-i-hit-localhost-9200-and-asking-for-username-and-password/327022)

<div class="topic-metadata">

**Author:** [@wsdevprogrammer](https://discuss.elastic.co/u/wsdevprogrammer)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 3:50am UTC](https://discuss.elastic.co/t/installed-elastic-search-on-window-11-i-hit-localhost-9200-and-asking-for-username-and-password/327022 "2023-03-06T03:50:35Z")

</div>

I have installed Latest Elastic search setup on Window 11 , as i type lcoalhost:9200 as i hit enter it says user name and password. i don't know which type of pass and username need to enter.

---

## [Filebeat consume high CPU usage](https://discuss.elastic.co/t/filebeat-consume-high-cpu-usage/326152)

<div class="topic-metadata">

**Author:** [@Jalin](https://discuss.elastic.co/u/Jalin)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 2:00am UTC](https://discuss.elastic.co/t/filebeat-consume-high-cpu-usage/326152 "2023-03-06T02:00:30Z")

</div>

Filebeat consume high CPU usage (about 25%) when processing logs and scanning files. Here is my environment: Windows 10 Pro 64-bit 4 core Here is my configuration: filebeat.inputs: - type: log id: log enab…

---

## [ELK stack config on docker](https://discuss.elastic.co/t/elk-stack-config-on-docker/325941)

<div class="topic-metadata">

**Author:** [@samidha\_dubey](https://discuss.elastic.co/u/samidha_dubey)\
**Replies:** 5\
**Last updated:** [March 6, 2023, 12:34am UTC](https://discuss.elastic.co/t/elk-stack-config-on-docker/325941 "2023-03-06T00:34:40Z")

</div>

Hello Team here i need some help in order to setup my ELK stack on docker, we laredy have cloud elk setup but now we decided to move from cloud to on prim setup which is weird though :stuck\_out\_tongue: as of now i have …

---

## [Deploying ELK cluster on production server - generated and existing server certificates not working](https://discuss.elastic.co/t/deploying-elk-cluster-on-production-server-generated-and-existing-server-certificates-not-working/326715)

<div class="topic-metadata">

**Author:** [@cookersjs](https://discuss.elastic.co/u/cookersjs)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 11:42pm UTC](https://discuss.elastic.co/t/deploying-elk-cluster-on-production-server-generated-and-existing-server-certificates-not-working/326715 "2023-03-05T23:42:45Z")

</div>

Hi there, I've followed the instructions found here Install Elasticsearch with Docker | Elasticsearch Guide \[8.6\] | Elastic and managed to get a docker-compose ES cluster + Kibana setup working locally. What's more, I'v…

---

## [Elasticsearch error, after xpack authencation enabled](https://discuss.elastic.co/t/elasticsearch-error-after-xpack-authencation-enabled/326743)

<div class="topic-metadata">

**Author:** [@k\_noor](https://discuss.elastic.co/u/k_noor)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 11:32pm UTC](https://discuss.elastic.co/t/elasticsearch-error-after-xpack-authencation-enabled/326743 "2023-03-05T23:32:41Z")

</div>

HI All, I have enabled the pack for authentication purpose, but error has reported as below. Cloud you please help in this. at org.elasticsearch.bootstrap.Elasticsearch.init(Elasticsearch.java:173) ~\[elasticsearch-7.…

---

## [SQL Query on ElasticSearch fails to parse a message, throws illegal\_argument\_exception](https://discuss.elastic.co/t/sql-query-on-elasticsearch-fails-to-parse-a-message-throws-illegal-argument-exception/326931)

<div class="topic-metadata">

**Author:** [@pedrodantas](https://discuss.elastic.co/u/pedrodantas)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 11:36am UTC](https://discuss.elastic.co/t/sql-query-on-elasticsearch-fails-to-parse-a-message-throws-illegal-argument-exception/326931 "2023-03-03T11:36:00Z")

</div>

Hello, I am trying to query my Elasticsearch environment using a Canvas dashboard on the Kibana App. I am getting a weird error when making a simple SQL query. The illegal\_argument\_exception says that it failed tryi…

---

## [SQL query on indices imported by OTEL Collector and Elastic APM](https://discuss.elastic.co/t/sql-query-on-indices-imported-by-otel-collector-and-elastic-apm/326711)

<div class="topic-metadata">

**Author:** [@ncvolt](https://discuss.elastic.co/u/ncvolt)\
**Replies:** 4\
**Last updated:** [March 5, 2023, 11:03pm UTC](https://discuss.elastic.co/t/sql-query-on-indices-imported-by-otel-collector-and-elastic-apm/326711 "2023-03-05T23:03:52Z")

</div>

When OTEL collector sends traces, logs and metrics to elastic APM It got stored with indices names like GET \_cat/indices yellow open .ds-logs-apm.app-default-2023.02.27-000001 ciiMrei8TLmJ1YilCaZy\_A 1 1 96 …

---

## [How to install Elastic stack (ELK) 8.6.2 in windows machine?](https://discuss.elastic.co/t/how-to-install-elastic-stack-elk-8-6-2-in-windows-machine/326933)

<div class="topic-metadata">

**Author:** [@sonu\_singh](https://discuss.elastic.co/u/sonu_singh)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 10:58pm UTC](https://discuss.elastic.co/t/how-to-install-elastic-stack-elk-8-6-2-in-windows-machine/326933 "2023-03-05T22:58:16Z")

</div>

Hi there, I am trying to install Elastic stack (ELK 8.6.2) in windows machine and Elasticsearch is not getting up. No luck on finding the Installation steps/tutorials/blogs online for Elastic stack 8.6.2. Any suggesti…

---

## [Logstash: HTTP Poller Formatting Issue](https://discuss.elastic.co/t/logstash-http-poller-formatting-issue/326844)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 4\
**Last updated:** [March 5, 2023, 10:53pm UTC](https://discuss.elastic.co/t/logstash-http-poller-formatting-issue/326844 "2023-03-05T22:53:08Z")

</div>

I am trying to use the HTTP poller to automate a curl command that I am able to run successfully in my environment. I am trying to run a query, put the results through a pipeline and then send the output to elasticsearch…

---

## [TLS Error in Logstash](https://discuss.elastic.co/t/tls-error-in-logstash/326962)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 5:25pm UTC](https://discuss.elastic.co/t/tls-error-in-logstash/326962 "2023-03-03T17:25:53Z")

</div>

Hello, We are trying to send logs from an application hosted in kubernetes cluster to logstash via fluentd. The logs are sent in syslog over TCP on an encrypted channel with TLS configuration. At the logstash end we ar…

---

## [ELK Searches from Splunk](https://discuss.elastic.co/t/elk-searches-from-splunk/326887)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 3\
**Last updated:** [March 5, 2023, 10:38pm UTC](https://discuss.elastic.co/t/elk-searches-from-splunk/326887 "2023-03-05T22:38:03Z")

</div>

Hello On a single server I have ELK(v 7.6.0) and Splunk. All sources that support syslog protocol are being ingested to ELK Taking advantage of some Splunk functionalities a query is made to ELK with this kind of code…

---

## [What's Python "best practice" for security certificates with ES8?](https://discuss.elastic.co/t/whats-python-best-practice-for-security-certificates-with-es8/327009)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 4:17pm UTC](https://discuss.elastic.co/t/whats-python-best-practice-for-security-certificates-with-es8/327009 "2023-03-05T16:17:08Z")

</div>

I just set up ES 8.6.2 on my machine. This is a single-machine setup. In fact I'm upgrading from 7.10.2, see previous question. I've managed to obtain a password for user "elastic"... this means I can get the "You know,…

---

## [How to configure the alert rule in Kibana for current date?](https://discuss.elastic.co/t/how-to-configure-the-alert-rule-in-kibana-for-current-date/325931)

<div class="topic-metadata">

**Author:** [@Shiva\_Subramaniyan](https://discuss.elastic.co/u/Shiva_Subramaniyan)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 11:39am UTC](https://discuss.elastic.co/t/how-to-configure-the-alert-rule-in-kibana-for-current-date/325931 "2023-03-05T11:39:14Z")

</div>

Hi, We have a alert rule configured in Kibana with the elasticsearch query to send email alerts based on "message keyword" that the logs receive in Kibana Now our requirement is to send the alert on the "current date" …

---

## [How to customise ICU Collation Keyword Field for sorting digits, symbols at last after the alphabets?](https://discuss.elastic.co/t/how-to-customise-icu-collation-keyword-field-for-sorting-digits-symbols-at-last-after-the-alphabets/327000)

<div class="topic-metadata">

**Author:** [@Karthik\_Amar](https://discuss.elastic.co/u/Karthik_Amar)\
**Replies:** 0\
**Last updated:** [March 5, 2023, 11:32am UTC](https://discuss.elastic.co/t/how-to-customise-icu-collation-keyword-field-for-sorting-digits-symbols-at-last-after-the-alphabets/327000 "2023-03-05T11:32:01Z")

</div>

The phonebook fields sort the symbols, currency and digits at the top grouped. Instead i want to give the alphabets (a-z) the most precedence and appears first in the sorting and all the above 3 below it. for example In…

---

## [Struggling to get ES 8.6.2 to work (on W10)](https://discuss.elastic.co/t/struggling-to-get-es-8-6-2-to-work-on-w10/326998)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 11:16am UTC](https://discuss.elastic.co/t/struggling-to-get-es-8-6-2-to-work-on-w10/326998 "2023-03-05T11:16:17Z")

</div>

This follows on from this question. I deliberately configured 8.6.2 to use port 9500. I appear to have got 8.6.2 running on this W10 OS. When I enter "https://localhost:9500" in my browser I am asked for a username and…

---

## [Fleet Cloud Integrations on multiple agents](https://discuss.elastic.co/t/fleet-cloud-integrations-on-multiple-agents/326940)

<div class="topic-metadata">

**Author:** [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Replies:** 2\
**Last updated:** [March 5, 2023, 10:33am UTC](https://discuss.elastic.co/t/fleet-cloud-integrations-on-multiple-agents/326940 "2023-03-05T10:33:25Z")

</div>

Hi all. How does cloud integration work if you apply them to multiples agents. For example if I have two servers (for redundancy) dedicated to collecting logs from let's say Cloudflare (log pull) If I have both serve…

---

## [Use terms\_set with nested array](https://discuss.elastic.co/t/use-terms-set-with-nested-array/326997)

<div class="topic-metadata">

**Author:** [@Ibrahem\_ismail](https://discuss.elastic.co/u/Ibrahem_ismail)\
**Replies:** 0\
**Last updated:** [March 5, 2023, 9:08am UTC](https://discuss.elastic.co/t/use-terms-set-with-nested-array/326997 "2023-03-05T09:08:22Z")

</div>

Is there a way to use terms\_set with nested array { "from": 0, "size": 10, "query": { "bool": { "filter": \[ { "nested": { "path…

---

## [Run two versions of ES on machine](https://discuss.elastic.co/t/run-two-versions-of-es-on-machine/326985)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 5\
**Last updated:** [March 5, 2023, 9:49am UTC](https://discuss.elastic.co/t/run-two-versions-of-es-on-machine/326985 "2023-03-05T09:49:51Z")

</div>

This is on a W10 box. ES (7.10.2) is currently running on localhost:9200. I need to upgrade. When I attempted to upgrade to 7.16.3 some time ago a regression occurred, reported by me and acknowledged by Elasticsearch HQ,…

---

## [How to define "target-throughput" in cmd line of custom track](https://discuss.elastic.co/t/how-to-define-target-throughput-in-cmd-line-of-custom-track/326831)

<div class="topic-metadata">

**Author:** [@dan\_kim](https://discuss.elastic.co/u/dan_kim)\
**Replies:** 2\
**Last updated:** [March 5, 2023, 6:29am UTC](https://discuss.elastic.co/t/how-to-define-target-throughput-in-cmd-line-of-custom-track/326831 "2023-03-05T06:29:54Z")

</div>

hello i'm trying to make new custom track and just found how to write basic custom track and i have question that how can i pass params from command line for example, i want to set target-throuput on command line like …

---

## [Executing update by query for a array of arrays](https://discuss.elastic.co/t/executing-update-by-query-for-a-array-of-arrays/326993)

<div class="topic-metadata">

**Author:** [@otaviom\_30](https://discuss.elastic.co/u/otaviom_30)\
**Replies:** 0\
**Last updated:** [March 5, 2023, 4:30am UTC](https://discuss.elastic.co/t/executing-update-by-query-for-a-array-of-arrays/326993 "2023-03-05T04:30:27Z")

</div>

Hello! So, one of the metadata I have indexed is a array of arrays. But, I'm having problems when I try to execute a update by query on it. Here is the sintax I'm using: "source":"ctx.\_source.Exemple ='\[\['foobar','10',…

---

## [Kibana tag cloud does not count frequency of words in a text field](https://discuss.elastic.co/t/kibana-tag-cloud-does-not-count-frequency-of-words-in-a-text-field/326982)

<div class="topic-metadata">

**Author:** [@Mehran\_Goodarzi](https://discuss.elastic.co/u/Mehran_Goodarzi)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 2:38am UTC](https://discuss.elastic.co/t/kibana-tag-cloud-does-not-count-frequency-of-words-in-a-text-field/326982 "2023-03-05T02:38:54Z")

</div>

Hi There, Kibana tag cloud does not count frequency of words in my text field let's say i have a field named : Ticket\_text.keyword and here are some examples: hello world here I am hello everybody this is blah in th…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=612)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=614)
