# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=620

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 621

---

## [Running \_forcemerge on an index that is being write on](https://discuss.elastic.co/t/running-forcemerge-on-an-index-that-is-being-write-on/326492)

<div class="topic-metadata">

**Author:** [@Tudor\_Plugaru](https://discuss.elastic.co/u/Tudor_Plugaru)\
**Replies:** 18\
**Last updated:** [February 27, 2023, 8:22am UTC](https://discuss.elastic.co/t/running-forcemerge-on-an-index-that-is-being-write-on/326492 "2023-02-27T08:22:27Z")

</div>

Hi, we are having an index with heavy updates on the documents. This leads us to having a lot of uncleaned deleted documents, for example, we can have around 400M searchable documents and around 150M of uncleaned docume…

---

## [How can I add field by a same field when across event](https://discuss.elastic.co/t/how-can-i-add-field-by-a-same-field-when-across-event/326551)

<div class="topic-metadata">

**Author:** [@OICAn](https://discuss.elastic.co/u/OICAn)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 8:09am UTC](https://discuss.elastic.co/t/how-can-i-add-field-by-a-same-field-when-across-event/326551 "2023-02-27T08:09:02Z")

</div>

A user access our system will trigger many transcations. A transaction will generate some log, which are serval event in es and they have a same field called "globalNo". One event will log the name of the transaction and…

---

## [Particular word count in particular file](https://discuss.elastic.co/t/particular-word-count-in-particular-file/326181)

<div class="topic-metadata">

**Author:** [@smitak](https://discuss.elastic.co/u/smitak)\
**Replies:** 5\
**Last updated:** [February 27, 2023, 7:10am UTC](https://discuss.elastic.co/t/particular-word-count-in-particular-file/326181 "2023-02-27T07:10:50Z")

</div>

Hello Sir, I want count of keyword occurance in a particular file in elaticsearch .

---

## [Interactive table in kibana with aggregation](https://discuss.elastic.co/t/interactive-table-in-kibana-with-aggregation/326505)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 7:03am UTC](https://discuss.elastic.co/t/interactive-table-in-kibana-with-aggregation/326505 "2023-02-27T07:03:29Z")

</div>

Hello, I'm using Kibana 8.6.1 . For a dashboard I want to create an interactive table in Kibana that contains a timestamd and a ID. The most of the loglines starts with the timestamp and the ID, but you have the simi…

---

## [Too many tcp connection established issue](https://discuss.elastic.co/t/too-many-tcp-connection-established-issue/326545)

<div class="topic-metadata">

**Author:** [@manzoor77](https://discuss.elastic.co/u/manzoor77)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 7:01am UTC](https://discuss.elastic.co/t/too-many-tcp-connection-established-issue/326545 "2023-02-27T07:01:56Z")

</div>

Hi, I have enable elasticsearch in my production chat application. There was total 500+ users that uses this application on daily bases for communication purpose. I have initialize ELS newclient once when server start …

---

## [Is my ILM policy stuck?](https://discuss.elastic.co/t/is-my-ilm-policy-stuck/326543)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 6:36am UTC](https://discuss.elastic.co/t/is-my-ilm-policy-stuck/326543 "2023-02-27T06:36:44Z")

</div>

Hi Team , I have set my ILM policy to move from hot to frozen node when it reach 45 GB size in primary shard. Howver it is not yet moved and not showing any errors. But if I do Preformatted textGET /metricbeat-\*/\_ilm/e…

---

## [Import kibana dashboard using ansible](https://discuss.elastic.co/t/import-kibana-dashboard-using-ansible/325685)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 6:04am UTC](https://discuss.elastic.co/t/import-kibana-dashboard-using-ansible/325685 "2023-02-27T06:04:01Z")

</div>

Hi, I have exported kibana dashboard in ndjson format. now i want to import it to another instance of kibana. I am doing this using ansible playbook. This is my command curl -X POST "\*Reverse\_PROXY\_IP/kibana\*/api/saved\_…

---

## [How to list all scripts/templates when GET \_cat/templates doesn't return them](https://discuss.elastic.co/t/how-to-list-all-scripts-templates-when-get-cat-templates-doesnt-return-them/326476)

<div class="topic-metadata">

**Author:** [@Cal\_L](https://discuss.elastic.co/u/Cal_L)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 3:44am UTC](https://discuss.elastic.co/t/how-to-list-all-scripts-templates-when-get-cat-templates-doesnt-return-them/326476 "2023-02-27T03:44:16Z")

</div>

I am new to ES ... I am looking at the existing codes which my team is using es.put\_script("my\_custom\_template\_1\_id", my\_custom\_template\_1\_query) I can retrieve the the template info by using the SPECIFIC template id li…

---

## [My ela cluster failed to load metadata when running, but I can't see the other problem. If there is the same problem, please help to take a look](https://discuss.elastic.co/t/my-ela-cluster-failed-to-load-metadata-when-running-but-i-cant-see-the-other-problem-if-there-is-the-same-problem-please-help-to-take-a-look/326286)

<div class="topic-metadata">

**Author:** [@limedong1](https://discuss.elastic.co/u/limedong1)\
**Replies:** 8\
**Last updated:** [February 27, 2023, 3:17am UTC](https://discuss.elastic.co/t/my-ela-cluster-failed-to-load-metadata-when-running-but-i-cant-see-the-other-problem-if-there-is-the-same-problem-please-help-to-take-a-look/326286 "2023-02-27T03:17:01Z")

</div>

Here is the error message： {"@timestamp":"2023-02-23T08:43:40.767Z", "log.level":"ERROR", "message":"fatal exception while booting Elasticsearch", "ecs.version": "1.2.0","service.name":"ES\_ECS","event.dataset":"elastic…

---

## [Monitoring postgres y sql server on AWS with an elastic on premises](https://discuss.elastic.co/t/monitoring-postgres-y-sql-server-on-aws-with-an-elastic-on-premises/325660)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 3:00am UTC](https://discuss.elastic.co/t/monitoring-postgres-y-sql-server-on-aws-with-an-elastic-on-premises/325660 "2023-02-27T03:00:33Z")

</div>

It is posible to monitor postgres y sql server on aws? if it is, with wich tool? our elastic is on premises. thanks.

---

## [Find: 'elasticsearch-translog': No such file or directory](https://discuss.elastic.co/t/find-elasticsearch-translog-no-such-file-or-directory/326518)

<div class="topic-metadata">

**Author:** [@ACoder](https://discuss.elastic.co/u/ACoder)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 2:10am UTC](https://discuss.elastic.co/t/find-elasticsearch-translog-no-such-file-or-directory/326518 "2023-02-27T02:10:39Z")

</div>

I think my translog is corrupted, so I'm trying to solve the problem by following this tutorial: But this tool doesn't exist in the docker image for elasticsearch at all: $ find / elasticsearch-translog ... find: 'ela…

---

## [Collect everything from a host](https://discuss.elastic.co/t/collect-everything-from-a-host/326532)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 1:16am UTC](https://discuss.elastic.co/t/collect-everything-from-a-host/326532 "2023-02-27T01:16:36Z")

</div>

Hi, It seems that there is no config which will allow winlogbeat to collect everything available on a given host. event.log: \* I want to deploy winlogbeat across my environment, but hosts have differing roles and ther…

---

## [The Kibana graph label of the date can't be changed in its format](https://discuss.elastic.co/t/the-kibana-graph-label-of-the-date-cant-be-changed-in-its-format/326409)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 12:34am UTC](https://discuss.elastic.co/t/the-kibana-graph-label-of-the-date-cant-be-changed-in-its-format/326409 "2023-02-27T00:34:45Z")

</div>

I use Elastic Cloud with v.8.6.2 of ES and Kibana. I used to change the Date format like this YYYY/MM/DD HH:mm:ss of the advanced settings at v.7 for the graph's date format of Kibana. After the version of Kibana grade…

---

## [Update existing record shuffles the data](https://discuss.elastic.co/t/update-existing-record-shuffles-the-data/326400)

<div class="topic-metadata">

**Author:** [@srb.saurabhjain](https://discuss.elastic.co/u/srb.saurabhjain)\
**Replies:** 3\
**Last updated:** [February 26, 2023, 9:42pm UTC](https://discuss.elastic.co/t/update-existing-record-shuffles-the-data/326400 "2023-02-26T21:42:11Z")

</div>

Hi team, I am trying to update a field in the below data B.B1 but the result data is randomly shuffled when I fetch again. Original { "A": { "A1": "test" }, "B": { "B1": "approved" }, …

---

## [Grep-like results on elasticsearch index](https://discuss.elastic.co/t/grep-like-results-on-elasticsearch-index/326524)

<div class="topic-metadata">

**Author:** [@John10](https://discuss.elastic.co/u/John10)\
**Replies:** 1\
**Last updated:** [February 26, 2023, 7:42pm UTC](https://discuss.elastic.co/t/grep-like-results-on-elasticsearch-index/326524 "2023-02-26T19:42:45Z")

</div>

If you have 5,000 pdf documents and you want to return every instance of the word "dog" across all of those documents (including the context where it occurs -- page number, the line before and after the match, etc.), you…

---

## [Elasticsearch filter to parse all date types in the logs?](https://discuss.elastic.co/t/elasticsearch-filter-to-parse-all-date-types-in-the-logs/326520)

<div class="topic-metadata">

**Author:** [@sid2014](https://discuss.elastic.co/u/sid2014)\
**Replies:** 1\
**Last updated:** [February 26, 2023, 3:41pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-to-parse-all-date-types-in-the-logs/326520 "2023-02-26T15:41:41Z")

</div>

I have to read multiple service logs which contain different time formats to the microseconds precision. Logstash is able to parse all the timestamps from "%{TIMESTAMP\_ISO8601:timestamp} filter but I get 400 for some log…

---

## [Nodes not syncing due to: master not discovered or elected yet](https://discuss.elastic.co/t/nodes-not-syncing-due-to-master-not-discovered-or-elected-yet/326434)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 1\
**Last updated:** [February 26, 2023, 6:28am UTC](https://discuss.elastic.co/t/nodes-not-syncing-due-to-master-not-discovered-or-elected-yet/326434 "2023-02-26T06:28:02Z")

</div>

Hello, I have a 3-node cluster with two nodes holding data and one as the voting node thastorees not hold any data. All virtual nodes run on ESXi 8.0 with Ubuntu 22.04.1 & Elasticsearch 8.6.2. OS and data are on…

---

## [Searchable Snapshot/Cold Nodes much slower to recover 8.5+?](https://discuss.elastic.co/t/searchable-snapshot-cold-nodes-much-slower-to-recover-8-5/326458)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 1\
**Last updated:** [February 25, 2023, 8:58pm UTC](https://discuss.elastic.co/t/searchable-snapshot-cold-nodes-much-slower-to-recover-8-5/326458 "2023-02-25T20:58:28Z")

</div>

Hi All, I was wondering if anyone else has noticed that since upgrading to 8.5.x (and 8.6.x), that the recovery of Searchable Snapshot/Cold nodes from a rolling restart is much slower than in lower versions? A cold nod…

---

## [Should I be copying the \`/etc/elasticsearch/service\_tokens\` to several elastic nodes?](https://discuss.elastic.co/t/should-i-be-copying-the-etc-elasticsearch-service-tokens-to-several-elastic-nodes/326185)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [February 25, 2023, 8:37pm UTC](https://discuss.elastic.co/t/should-i-be-copying-the-etc-elasticsearch-service-tokens-to-several-elastic-nodes/326185 "2023-02-25T20:37:15Z")

</div>

I have an elastic cluster with three nodes: n1, n2 and n3. And I have a new kibana instance on a separate linux server. On n1, I ran this command /usr/share/elasticsearch/bin/elasticsearch-service-token elastic/kibana …

---

## [Logstash not shipping data to Elasticsearch](https://discuss.elastic.co/t/logstash-not-shipping-data-to-elasticsearch/326376)

<div class="topic-metadata">

**Author:** [@Technolust](https://discuss.elastic.co/u/Technolust)\
**Replies:** 2\
**Last updated:** [February 25, 2023, 7:50pm UTC](https://discuss.elastic.co/t/logstash-not-shipping-data-to-elasticsearch/326376 "2023-02-25T19:50:43Z")

</div>

How do I get logstash to ship data to Elasticsearch? I'm not sure what to change in the logstash.yml file or what section I should change for that matter. My pipelines.yml points to /etc/logstash/conf.d/syslog.conf... Th…

---

## [Unable to enable Vnet or traffic filter for Elastic cloud](https://discuss.elastic.co/t/unable-to-enable-vnet-or-traffic-filter-for-elastic-cloud/325965)

<div class="topic-metadata">

**Author:** [@zameer712](https://discuss.elastic.co/u/zameer712)\
**Replies:** 4\
**Last updated:** [February 25, 2023, 4:14pm UTC](https://discuss.elastic.co/t/unable-to-enable-vnet-or-traffic-filter-for-elastic-cloud/325965 "2023-02-25T16:14:03Z")

</div>

Hi Team, Hope you are doing well & Safe. I have followed documentation to enabled our elastic cloud from public internet to azure networking boundaries as per the step granted as below documentation. But still we coul…

---

## [\[ML\] Custom function in anomaly detection job](https://discuss.elastic.co/t/ml-custom-function-in-anomaly-detection-job/326332)

<div class="topic-metadata">

**Author:** [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Replies:** 6\
**Last updated:** [February 25, 2023, 12:58pm UTC](https://discuss.elastic.co/t/ml-custom-function-in-anomaly-detection-job/326332 "2023-02-25T12:58:38Z")

</div>

Dear community, I'm feeding documents directly from a source index to an ML anomaly job detection, using population analysis for a high cardinality use case (I don't want to feed aggregated data directly or using transf…

---

## [Kibana quick select value](https://discuss.elastic.co/t/kibana-quick-select-value/326490)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 2\
**Last updated:** [February 25, 2023, 9:39am UTC](https://discuss.elastic.co/t/kibana-quick-select-value/326490 "2023-02-25T09:39:52Z")

</div>

Hi, Is there a way to get a value from quick select (time range picker) in Kibana Lens , to be able to use this value into additional KQL filtering. My data is having two time fields. A user should be able to select/sl…

---

## [To view the index details using canvas dashboard](https://discuss.elastic.co/t/to-view-the-index-details-using-canvas-dashboard/325967)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 2\
**Last updated:** [February 25, 2023, 8:44am UTC](https://discuss.elastic.co/t/to-view-the-index-details-using-canvas-dashboard/325967 "2023-02-25T08:44:57Z")

</div>

Hi Team, We are trying to create the canvas dashboard which will display the index details using the command "GET \_cat/indices". Could you please suggest any approach to proceed with this activity. Regards Anushya

---

## [Range with script fields](https://discuss.elastic.co/t/range-with-script-fields/326487)

<div class="topic-metadata">

**Author:** [@TECHNOID](https://discuss.elastic.co/u/TECHNOID)\
**Replies:** 0\
**Last updated:** [February 25, 2023, 7:41am UTC](https://discuss.elastic.co/t/range-with-script-fields/326487 "2023-02-25T07:41:50Z")

</div>

Hello, tell me if it's possible to filter aggregation by scriptfield range search result \[hits\] =\> Array ( ... \[hits\] =\> Array ( \[0\] =\> Array …

---

## [How load big data from database using Logstash in elasticsearch index?](https://discuss.elastic.co/t/how-load-big-data-from-database-using-logstash-in-elasticsearch-index/326489)

<div class="topic-metadata">

**Author:** [@boliwe](https://discuss.elastic.co/u/boliwe)\
**Replies:** 0\
**Last updated:** [February 25, 2023, 8:06am UTC](https://discuss.elastic.co/t/how-load-big-data-from-database-using-logstash-in-elasticsearch-index/326489 "2023-02-25T08:06:52Z")

</div>

I want to learn how to load big data from database to elasticsearch using logstash jdbc input plugin. I could not find my answer from other forums. I have 1billion data in databse. Logstash settings has 8 workers, 15000…

---

## [Querying data using script query with lang=expression for remainder operation](https://discuss.elastic.co/t/querying-data-using-script-query-with-lang-expression-for-remainder-operation/325895)

<div class="topic-metadata">

**Author:** [@Rachana\_Maniyar](https://discuss.elastic.co/u/Rachana_Maniyar)\
**Replies:** 16\
**Last updated:** [February 25, 2023, 7:20am UTC](https://discuss.elastic.co/t/querying-data-using-script-query-with-lang-expression-for-remainder-operation/325895 "2023-02-25T07:20:25Z")

</div>

hi Folks, We store a field of type "long" in elastic which has value of this nature = 9048716794795431 Need to retrieve these records based on modulus expression. So the query looks like this query: {'query': {'bool':…

---

## [PDF/PNG Reporting chromium error](https://discuss.elastic.co/t/pdf-png-reporting-chromium-error/326121)

<div class="topic-metadata">

**Author:** [@furkano](https://discuss.elastic.co/u/furkano)\
**Replies:** 6\
**Last updated:** [February 24, 2023, 11:04pm UTC](https://discuss.elastic.co/t/pdf-png-reporting-chromium-error/326121 "2023-02-24T23:04:40Z")

</div>

Hi, I'm getting this error when i try to download some dashboards as PDF/PNG, I increased my timeout time and byte for reporting. By the way i've got platinium license

---

## [What is the difference between xpack.security.http.ssl.verification\_mode and xpack.http.ssl.verification\_mode](https://discuss.elastic.co/t/what-is-the-difference-between-xpack-security-http-ssl-verification-mode-and-xpack-http-ssl-verification-mode/326474)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 9:39pm UTC](https://discuss.elastic.co/t/what-is-the-difference-between-xpack-security-http-ssl-verification-mode-and-xpack-http-ssl-verification-mode/326474 "2023-02-24T21:39:38Z")

</div>

I want to know what is the difference between xpack.security.http.ssl.verification\_mode: certificate and xpack.http.ssl.verification\_mode: certificate Also, can I use both setting at same time...? Thank you..! Hiruni

---

## [How to create many small separate indices](https://discuss.elastic.co/t/how-to-create-many-small-separate-indices/326459)

<div class="topic-metadata">

**Author:** [@tim28](https://discuss.elastic.co/u/tim28)\
**Replies:** 5\
**Last updated:** [February 24, 2023, 7:27pm UTC](https://discuss.elastic.co/t/how-to-create-many-small-separate-indices/326459 "2023-02-24T19:27:48Z")

</div>

Hi! I want to create many (~10k) indices each having a couple of hundred documents. I have read in other places that that's discouraged as it creates a shard per index which is a lot of overhead. However, I have the req…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=619)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=621)
