# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=619

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 620

---

## [Actual Size of a document - Mapper Size Plugin](https://discuss.elastic.co/t/actual-size-of-a-document-mapper-size-plugin/326631)

<div class="topic-metadata">

**Author:** [@prateek\_shekhar](https://discuss.elastic.co/u/prateek_shekhar)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 8:48pm UTC](https://discuss.elastic.co/t/actual-size-of-a-document-mapper-size-plugin/326631 "2023-02-27T20:48:37Z")

</div>

Hi All, Recently we have enabled the mapper-size plugin on our ES cluster. We have also added the index mapping \_size as per the recommendations at this link: Using the \_size field | Elasticsearch Plugins and Integratio…

---

## [Manual Alias vs ILM read performance](https://discuss.elastic.co/t/manual-alias-vs-ilm-read-performance/326627)

<div class="topic-metadata">

**Author:** [@Chirag\_Poddar](https://discuss.elastic.co/u/Chirag_Poddar)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 8:31pm UTC](https://discuss.elastic.co/t/manual-alias-vs-ilm-read-performance/326627 "2023-02-27T20:31:06Z")

</div>

I want to know about read performance between the following 2 Creating monthly indices on my own and pointing them to an alias Creating monthly indices using ILM Will they have any difference in search performance for…

---

## [Kibana API output](https://discuss.elastic.co/t/kibana-api-output/325776)

<div class="topic-metadata">

**Author:** [@branden.heifner](https://discuss.elastic.co/u/branden.heifner)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 8:16pm UTC](https://discuss.elastic.co/t/kibana-api-output/325776 "2023-02-27T20:16:36Z")

</div>

Hello everyone, I am using the Kibana API to output the list of agent for auditing purposes. Is there a built-in way to output the list of agents in CSV format instead of JSON? Below is the current API call I am using. …

---

## [Using ILM for huge size of indexes](https://discuss.elastic.co/t/using-ilm-for-huge-size-of-indexes/326496)

<div class="topic-metadata">

**Author:** [@Chirag\_Poddar](https://discuss.elastic.co/u/Chirag_Poddar)\
**Replies:** 16\
**Last updated:** [February 27, 2023, 8:11pm UTC](https://discuss.elastic.co/t/using-ilm-for-huge-size-of-indexes/326496 "2023-02-27T20:11:22Z")

</div>

Use case: We have a few indexes which have huge amounts of data and they are growing. We need to figure out a way to optimize the search time. We are thinking of using ILM to manage the indexes. But there are a few roadb…

---

## [Kibana Dashboard - Pie chart from two dependent fields](https://discuss.elastic.co/t/kibana-dashboard-pie-chart-from-two-dependent-fields/326625)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 6:55pm UTC](https://discuss.elastic.co/t/kibana-dashboard-pie-chart-from-two-dependent-fields/326625 "2023-02-27T18:55:18Z")

</div>

Hi Team, I am newbie to Elasticsearch, but trying to make hand dirty. Trying to develop a pie chart in Kibana dashboard. Want to know how we can link two fields for generating a pie chart. Sample problem statement: W…

---

## [After parsing in logstash got error](https://discuss.elastic.co/t/after-parsing-in-logstash-got-error/326560)

<div class="topic-metadata">

**Author:** [@neeldey](https://discuss.elastic.co/u/neeldey)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 5:09pm UTC](https://discuss.elastic.co/t/after-parsing-in-logstash-got-error/326560 "2023-02-27T17:09:49Z")

</div>

Hi all, i getting error, while to start logstash. logstash log is as bellow. \[2023-02-27T15:18:50,526\]\[FATAL\]\[org.logstash.Logstash \] Logstash stopped processing because of an error: (SystemExit) exit org.jruby.ex…

---

## [Correct parsing Syslog message to json](https://discuss.elastic.co/t/correct-parsing-syslog-message-to-json/326564)

<div class="topic-metadata">

**Author:** [@poky](https://discuss.elastic.co/u/poky)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 5:07pm UTC](https://discuss.elastic.co/t/correct-parsing-syslog-message-to-json/326564 "2023-02-27T17:07:34Z")

</div>

Hi Folks! I'm trying to parse the following message from mcafee proxy syslog inside my logstash pipeline: \<30\>Feb 24 9:33:45 mwg-n3 mwg-n3: x-message="{"DateTime":"2023-02-22 14:03:44.927","MWG\_Source":"mwg-n3.foo.de",…

---

## [About Kibana's "Color mapping" in 8.X](https://discuss.elastic.co/t/about-kibanas-color-mapping-in-8-x/326607)

<div class="topic-metadata">

**Author:** [@Juanma](https://discuss.elastic.co/u/Juanma)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 5:04pm UTC](https://discuss.elastic.co/t/about-kibanas-color-mapping-in-8-x/326607 "2023-02-27T17:04:25Z")

</div>

Hi! I was looking throught my kibana 7.17 advanced options, and I've notice that "color mapping" is deprecated and removed from 8.0... Is it deprecated/removed in favor of any other thing that gives the same functional…

---

## [Synonym graph token filter backed by Elastic index](https://discuss.elastic.co/t/synonym-graph-token-filter-backed-by-elastic-index/326616)

<div class="topic-metadata">

**Author:** [@jnioche](https://discuss.elastic.co/u/jnioche)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 4:35pm UTC](https://discuss.elastic.co/t/synonym-graph-token-filter-backed-by-elastic-index/326616 "2023-02-27T16:35:20Z")

</div>

Hi, I want to use the synonym graph token filter but ideally have the data stored in an Elasticsearch index so that it can be easily updated and modified. My understanding of the code is that it reads the data from a f…

---

## [Start elasticsearch that used to be in a cluster as a single-node or in a different cluster](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 8\
**Last updated:** [February 27, 2023, 4:22pm UTC](https://discuss.elastic.co/t/start-elasticsearch-that-used-to-be-in-a-cluster-as-a-single-node-or-in-a-different-cluster/326568 "2023-02-27T16:22:24Z")

</div>

Hey Everyone, Due to some stuff that happened, I have an Elasticsearch node with a lot of data, that isn't up to date with the cluster. What I need to do is somehow start this node as a separate cluster, without it nee…

---

## [Using metricbeat in a CRC Instalation of Openshift](https://discuss.elastic.co/t/using-metricbeat-in-a-crc-instalation-of-openshift/326346)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 3:22pm UTC](https://discuss.elastic.co/t/using-metricbeat-in-a-crc-instalation-of-openshift/326346 "2023-02-27T15:22:56Z")

</div>

Hi Im having problems with the instalation of metricbeat using the manifest in the documentation https://raw.githubusercontent.com/elastic/beats/7.17/deploy/kubernetes/metricbeat-kubernetes.yaml this path doesnt exist …

---

## [Filebeat log not in elastic when matching parser](https://discuss.elastic.co/t/filebeat-log-not-in-elastic-when-matching-parser/326609)

<div class="topic-metadata">

**Author:** [@NL-kk](https://discuss.elastic.co/u/NL-kk)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 3:16pm UTC](https://discuss.elastic.co/t/filebeat-log-not-in-elastic-when-matching-parser/326609 "2023-02-27T15:16:24Z")

</div>

I just setup a multiline parser because of the multiline error logs of nginx. Before the logs were visible in kibana as seperate log enteries, now they are not visible at all. The single line logs are being logged corr…

---

## [Create "Flop 10" with 0 values](https://discuss.elastic.co/t/create-flop-10-with-0-values/326572)

<div class="topic-metadata">

**Author:** [@StadtGE](https://discuss.elastic.co/u/StadtGE)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 2:50pm UTC](https://discuss.elastic.co/t/create-flop-10-with-0-values/326572 "2023-02-27T14:50:52Z")

</div>

Hi, I hope you can help me. I want to create a visualisation (bar, metric, bucket etc.) for flop 10. It works, but I want show 0 values, areas that have not been selected. I have added {"min\_doc\_count":0} for the JSON …

---

## [Elastic enrich data based on two matching fields](https://discuss.elastic.co/t/elastic-enrich-data-based-on-two-matching-fields/325561)

<div class="topic-metadata">

**Author:** [@maggo](https://discuss.elastic.co/u/maggo)\
**Replies:** 8\
**Last updated:** [February 27, 2023, 2:35pm UTC](https://discuss.elastic.co/t/elastic-enrich-data-based-on-two-matching-fields/325561 "2023-02-27T14:35:42Z")

</div>

Hello guys, i'm pretty new to ELK and want to implement a vulnerability enrichment for incoming osquery data. I have one index with vulnerability data with fields like: "affected\_product": "chrome" "affected\_version":…

---

## [Trusting remote clusters' CA](https://discuss.elastic.co/t/trusting-remote-clusters-ca/326465)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 2:33pm UTC](https://discuss.elastic.co/t/trusting-remote-clusters-ca/326465 "2023-02-27T14:33:53Z")

</div>

Hi, I have two scenarios and would like a solution for both. I created a new cluster (8.6.X) with the self-generated certificates and enrolling new nodes. After that, I want to create a separate cluster, but I'd like …

---

## [Ingest issue during re-indexing/cloning?](https://discuss.elastic.co/t/ingest-issue-during-re-indexing-cloning/326466)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 5\
**Last updated:** [February 27, 2023, 2:17pm UTC](https://discuss.elastic.co/t/ingest-issue-during-re-indexing-cloning/326466 "2023-02-27T14:17:29Z")

</div>

Hello ! I need to re-index multiple indices prior to an update of our stack. In order to test the reindexing process, I am cloning an index. However, the index needs to be read-only. My question is...what if data is in…

---

## [Elastic Search query](https://discuss.elastic.co/t/elastic-search-query/326430)

<div class="topic-metadata">

**Author:** [@ashish.akm](https://discuss.elastic.co/u/ashish.akm)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 1:39pm UTC](https://discuss.elastic.co/t/elastic-search-query/326430 "2023-02-27T13:39:06Z")

</div>

how to create one query with match sort by newer report date and martch\_phrase sort by newer report and combine both result

---

## [Only one of the data nodes has a significantly higher cpu usage than other data nodes](https://discuss.elastic.co/t/only-one-of-the-data-nodes-has-a-significantly-higher-cpu-usage-than-other-data-nodes/326589)

<div class="topic-metadata">

**Author:** [@wangxr1985](https://discuss.elastic.co/u/wangxr1985)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 1:07pm UTC](https://discuss.elastic.co/t/only-one-of-the-data-nodes-has-a-significantly-higher-cpu-usage-than-other-data-nodes/326589 "2023-02-27T13:07:23Z")

</div>

ES version: elasticsearch-5.6.3-1.noarch OS version: CentOS Linux release 7.6.1810 (Core) Linux version 3.10.0-1160.31.1.el7.x86\_64 (mockbuild@kbuilder.bsys.centos.org) (gcc version 4.8.5 20150623 (Red Hat 4.8.5-44) (…

---

## [Two Node Cluster Failover did not work](https://discuss.elastic.co/t/two-node-cluster-failover-did-not-work/326583)

<div class="topic-metadata">

**Author:** [@sven\_begis](https://discuss.elastic.co/u/sven_begis)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 12:32pm UTC](https://discuss.elastic.co/t/two-node-cluster-failover-did-not-work/326583 "2023-02-27T12:32:26Z")

</div>

Two Node Cluster Failover did not work Hello, I'm trying to set up a two node cluster. VST-ELA01 -- RAM = 8 GB -- CPU = 8 -- HD = 100 GB -- OS = Ubuntu 22.04 LTS VST-ELA02 -- RAM = 8 GB -- CPU = 8 -- HD = 1…

---

## [How to Ingest MultiLine Json file into ElasticSearch using Logstash Pipeline](https://discuss.elastic.co/t/how-to-ingest-multiline-json-file-into-elasticsearch-using-logstash-pipeline/326580)

<div class="topic-metadata">

**Author:** [@prabhakar\_kamath](https://discuss.elastic.co/u/prabhakar_kamath)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 12:15pm UTC](https://discuss.elastic.co/t/how-to-ingest-multiline-json-file-into-elasticsearch-using-logstash-pipeline/326580 "2023-02-27T12:15:29Z")

</div>

I have a json file similar to following: { "Key1": "value1", "Key2": "value2" ....... } I want to ingest it as it is into logstash, The Keys should be fields and values should be values to the field, value can be a…

---

## [Kibana error connecting to package registry getaddrinfo EAI error](https://discuss.elastic.co/t/kibana-error-connecting-to-package-registry-getaddrinfo-eai-error/326579)

<div class="topic-metadata">

**Author:** [@Timo\_Anzalone](https://discuss.elastic.co/u/Timo_Anzalone)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 12:14pm UTC](https://discuss.elastic.co/t/kibana-error-connecting-to-package-registry-getaddrinfo-eai-error/326579 "2023-02-27T12:14:15Z")

</div>

2023-02-27T12:01:09.365155555Z \[2023-02-27T12:01:09.364+00:00\]\[ERROR\]\[plugins.fleet\] Failed to fetch latest version of endpoint from registry: Error connecting to package registry: request to https://epr.elastic.co/searc…

---

## [Get sum of record count for inner bucket key in two level term aggregation](https://discuss.elastic.co/t/get-sum-of-record-count-for-inner-bucket-key-in-two-level-term-aggregation/326575)

<div class="topic-metadata">

**Author:** [@Baekjun-Kim](https://discuss.elastic.co/u/Baekjun-Kim)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 12:01pm UTC](https://discuss.elastic.co/t/get-sum-of-record-count-for-inner-bucket-key-in-two-level-term-aggregation/326575 "2023-02-27T12:01:45Z")

</div>

I have records with two keyword type field user\_id: String that identifies individual user, result: String such as "success", "failure" or "pending" etc. These are what I want to do: Get record count for each result…

---

## [Compare two indexes based on more than two fields](https://discuss.elastic.co/t/compare-two-indexes-based-on-more-than-two-fields/325464)

<div class="topic-metadata">

**Author:** [@Prashant\_Pandey1](https://discuss.elastic.co/u/Prashant_Pandey1)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 11:56am UTC](https://discuss.elastic.co/t/compare-two-indexes-based-on-more-than-two-fields/325464 "2023-02-27T11:56:24Z")

</div>

I have two Indexes. I want to get the list of matched and unmatched data based on field(s). I had tried to use Preview transform Api , but it's showing data only up to 100 records. Please let me know ,is there any oth…

---

## [\[ERROR\]\[elasticsearch-service\] Unable to retrieve version information from Elasticsearch nodes](https://discuss.elastic.co/t/error-elasticsearch-service-unable-to-retrieve-version-information-from-elasticsearch-nodes/325827)

<div class="topic-metadata">

**Author:** [@Mausam\_Singh](https://discuss.elastic.co/u/Mausam_Singh)\
**Replies:** 5\
**Last updated:** [February 27, 2023, 11:49am UTC](https://discuss.elastic.co/t/error-elasticsearch-service-unable-to-retrieve-version-information-from-elasticsearch-nodes/325827 "2023-02-27T11:49:21Z")

</div>

Hi Team, I have locally installed elasticsearch and kibana on Mac OS. it was working fine from last 1.5 months . However I am getting below error (while starting kibana) from last week: Below is elasticsearch detail : …

---

## [Internal index process merging records into arrays of objects based on a parent common key](https://discuss.elastic.co/t/internal-index-process-merging-records-into-arrays-of-objects-based-on-a-parent-common-key/326451)

<div class="topic-metadata">

**Author:** [@MartinGarcia](https://discuss.elastic.co/u/MartinGarcia)\
**Replies:** 4\
**Last updated:** [February 27, 2023, 10:59am UTC](https://discuss.elastic.co/t/internal-index-process-merging-records-into-arrays-of-objects-based-on-a-parent-common-key/326451 "2023-02-27T10:59:41Z")

</div>

Hi, I have a doubt about a feature. I'm trying to run an internal process in Elastic where I create superseed objects based on an index that contains more flat and granular objects. For example: The source index contai…

---

## [How to Transpose Tabular Dashboard in Kibana](https://discuss.elastic.co/t/how-to-transpose-tabular-dashboard-in-kibana/326538)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 11:25am UTC](https://discuss.elastic.co/t/how-to-transpose-tabular-dashboard-in-kibana/326538 "2023-02-27T11:25:02Z")

</div>

Hello team, I wanted to transpose columns into row for better required visualization. Can you please suggest me how to do so. Note - I have used Lens for preparing Tabular dashboard Attaching screenshot for reference. …

---

## [Improve indexing performance speed by routing to a specific shard](https://discuss.elastic.co/t/improve-indexing-performance-speed-by-routing-to-a-specific-shard/326552)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 7\
**Last updated:** [February 27, 2023, 10:16am UTC](https://discuss.elastic.co/t/improve-indexing-performance-speed-by-routing-to-a-specific-shard/326552 "2023-02-27T10:16:47Z")

</div>

Hi, Let's say I have a 100GB of data that need to be indexed into a specific index with 5 shards. I don't have reads during indexing time and I want to speed up the process as much as possible. I have 5 (python) worke…

---

## [Logstash input elasticsearch](https://discuss.elastic.co/t/logstash-input-elasticsearch/326561)

<div class="topic-metadata">

**Author:** [@almteref](https://discuss.elastic.co/u/almteref)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 9:59am UTC](https://discuss.elastic.co/t/logstash-input-elasticsearch/326561 "2023-02-27T09:59:55Z")

</div>

Hi all I have question about the logstash in elasticsearch input plugin can I use the search template ID that I created in my cluster ? rether than pass query ?

---

## [An index that inflates](https://discuss.elastic.co/t/an-index-that-inflates/326517)

<div class="topic-metadata">

**Author:** [@boazBD](https://discuss.elastic.co/u/boazBD)\
**Replies:** 4\
**Last updated:** [February 27, 2023, 9:27am UTC](https://discuss.elastic.co/t/an-index-that-inflates/326517 "2023-02-27T09:27:23Z")

</div>

Hello, I have an index that inflates more until the node crashes with a full disk error. For now, I delete the index directly from the VM because Elastic is unhealthy when it happens. It is helpful for a short period,…

---

## [Add a csv input for every batch](https://discuss.elastic.co/t/add-a-csv-input-for-every-batch/326553)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 8:23am UTC](https://discuss.elastic.co/t/add-a-csv-input-for-every-batch/326553 "2023-02-27T08:23:19Z")

</div>

Hello, I am using http\_poller input plugin and elasticsearch output plugin.. I want to use CSV output plugin also for logging logstash success in a CSV file..But in my CSV all the events are noted but not only once. I …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=618)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=620)
