# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=622

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 623

---

## [Elasticsearch document update and insertio using update api](https://discuss.elastic.co/t/elasticsearch-document-update-and-insertio-using-update-api/326401)

<div class="topic-metadata">

**Author:** [@murli\_krishna](https://discuss.elastic.co/u/murli_krishna)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 5:20am UTC](https://discuss.elastic.co/t/elasticsearch-document-update-and-insertio-using-update-api/326401 "2023-02-24T05:20:58Z")

</div>

I want to ingest data using Python code, and if data is already available, I just want to update it with the given document for that ID. So far, I have tried this. Using Elasticsearch 8.6.1 import elasticsearch from …

---

## [Unable to change "elastic" user password](https://discuss.elastic.co/t/unable-to-change-elastic-user-password/326364)

<div class="topic-metadata">

**Author:** [@SUNA](https://discuss.elastic.co/u/SUNA)\
**Replies:** 4\
**Last updated:** [February 24, 2023, 5:18am UTC](https://discuss.elastic.co/t/unable-to-change-elastic-user-password/326364 "2023-02-24T05:18:51Z")

</div>

Team, Can you please help to change \*\*elastic\*\* user password. root@elk:/usr/share/elasticsearch/bin# ls -lrt total 20812 -rwxr-xr-x 1 root root 21220982 Jan 13 2021 elasticsearch-sql-cli-7.10.2.jar -rwxr-xr-x 1 root …

---

## [Get the matched and unmatched result based on fields inside an index](https://discuss.elastic.co/t/get-the-matched-and-unmatched-result-based-on-fields-inside-an-index/326397)

<div class="topic-metadata">

**Author:** [@Prashant\_Pandey1](https://discuss.elastic.co/u/Prashant_Pandey1)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 4:06am UTC](https://discuss.elastic.co/t/get-the-matched-and-unmatched-result-based-on-fields-inside-an-index/326397 "2023-02-24T04:06:21Z")

</div>

Hi All , I'm new to Elasticsearch, please can someone help on this I want to matched and unmatched data based on fields from index. Sample of Data Schema of index : { "\_index": "comparebyid", "\_id": "MPGsra40AGzOIw1…

---

## [Autocomplete - Completion Suggester Or Search as you type filed type](https://discuss.elastic.co/t/autocomplete-completion-suggester-or-search-as-you-type-filed-type/326393)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 3:18am UTC](https://discuss.elastic.co/t/autocomplete-completion-suggester-or-search-as-you-type-filed-type/326393 "2023-02-24T03:18:02Z")

</div>

We need to create an autocomplete functionality so that as the user is typing suggestions are shown from the backend elasticsearch indices. Which is the better option for indiex that has 10 million plus records and the …

---

## [How to create readonly public API Key?](https://discuss.elastic.co/t/how-to-create-readonly-public-api-key/326270)

<div class="topic-metadata">

**Author:** [@indicozy](https://discuss.elastic.co/u/indicozy)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 2:15am UTC](https://discuss.elastic.co/t/how-to-create-readonly-public-api-key/326270 "2023-02-24T02:15:20Z")

</div>

I'm trying to create an API Key for users to search on my frontend, however, I cannot find configuration example for readonly users to specific indices. Could you please share your config for this setting?

---

## [Get request taking much time in elasticsearch](https://discuss.elastic.co/t/get-request-taking-much-time-in-elasticsearch/326391)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 1\
**Last updated:** [February 24, 2023, 2:12am UTC](https://discuss.elastic.co/t/get-request-taking-much-time-in-elasticsearch/326391 "2023-02-24T02:12:59Z")

</div>

Hi Team, For elasticsearch using transport client 9kb record it takes to 3 seconds. sometimes it will take the 100 ms.

---

## [Error when trying to install Fleet Server to a centralized host](https://discuss.elastic.co/t/error-when-trying-to-install-fleet-server-to-a-centralized-host/326387)

<div class="topic-metadata">

**Author:** [@Stephen\_Johnston](https://discuss.elastic.co/u/Stephen_Johnston)\
**Replies:** 0\
**Last updated:** [February 24, 2023, 1:18am UTC](https://discuss.elastic.co/t/error-when-trying-to-install-fleet-server-to-a-centralized-host/326387 "2023-02-24T01:18:00Z")

</div>

Hi, I'm trying to add a new fleet server in kibana. When I try to install the Fleet Server Agent on a centralized host, I'm getting errors after I input the following code: curl -L -O https://artifacts.elastic.co/downlo…

---

## [Storing only pointer to source field?](https://discuss.elastic.co/t/storing-only-pointer-to-source-field/326368)

<div class="topic-metadata">

**Author:** [@XD\_Captain](https://discuss.elastic.co/u/XD_Captain)\
**Replies:** 3\
**Last updated:** [February 24, 2023, 12:21am UTC](https://discuss.elastic.co/t/storing-only-pointer-to-source-field/326368 "2023-02-24T00:21:19Z")

</div>

Hi, I'm new to Elasticsearch and am wondering about this: is there a handy way to not store the \_source field (original json file), but instead store just a pointer (ID) to the source field items? For instance if the …

---

## [Tag events based in words in different fields](https://discuss.elastic.co/t/tag-events-based-in-words-in-different-fields/326382)

<div class="topic-metadata">

**Author:** [@xalmer](https://discuss.elastic.co/u/xalmer)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 11:35pm UTC](https://discuss.elastic.co/t/tag-events-based-in-words-in-different-fields/326382 "2023-02-23T23:35:04Z")

</div>

Hello everybody, I want to make a better code, but i try a lot of thing and nothing works. I need to tag the input based in many words in 4 different fields. Im doing like this, but need to replicate all the filter fo…

---

## [Error running Repository Analysis API on AWS S3](https://discuss.elastic.co/t/error-running-repository-analysis-api-on-aws-s3/326381)

<div class="topic-metadata">

**Author:** [@ben.clifford](https://discuss.elastic.co/u/ben.clifford)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 11:24pm UTC](https://discuss.elastic.co/t/error-running-repository-analysis-api-on-aws-s3/326381 "2023-02-23T23:24:36Z")

</div>

I am running a 4 node cluster in AWS trying to use the Repository Analysis API to validate S3 compatible storage. The cluster is healthy and well provisioned, and doing nothing but running this API test. After continuous…

---

## [Runtime Field Convert String to Number](https://discuss.elastic.co/t/runtime-field-convert-string-to-number/326370)

<div class="topic-metadata">

**Author:** [@sparker22](https://discuss.elastic.co/u/sparker22)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 10:49pm UTC](https://discuss.elastic.co/t/runtime-field-convert-string-to-number/326370 "2023-02-23T22:49:05Z")

</div>

Is there a way to convert string / text to a number in a runtime field script? We have data that is getting ingested into Elastic as keyword / text fields, but I need to convert that data at runtime from a string to numb…

---

## [Upload of multiple CSV files into same index](https://discuss.elastic.co/t/upload-of-multiple-csv-files-into-same-index/326156)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 4\
**Last updated:** [February 23, 2023, 10:07pm UTC](https://discuss.elastic.co/t/upload-of-multiple-csv-files-into-same-index/326156 "2023-02-23T22:07:07Z")

</div>

Hi, Please advise me on the below. I want to upload CSV file into the same index name on daily basis and need to create Kibana dashboard. Is it possible for me to upload the CSV file directly into Elasticsearch autom…

---

## [Feature Request: minimum\_should\_match support for Terms Set query](https://discuss.elastic.co/t/feature-request-minimum-should-match-support-for-terms-set-query/326374)

<div class="topic-metadata">

**Author:** [@kulinsj](https://discuss.elastic.co/u/kulinsj)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 9:32pm UTC](https://discuss.elastic.co/t/feature-request-minimum-should-match-support-for-terms-set-query/326374 "2023-02-23T21:32:36Z")

</div>

The Terms Set Query lets you match documents that have some minimum number of matches to a given array of input search terms. The minimum number of matches however can only be specified by referencing another field on th…

---

## [DakMode in kibana spaces](https://discuss.elastic.co/t/dakmode-in-kibana-spaces/326343)

<div class="topic-metadata">

**Author:** [@thomas4](https://discuss.elastic.co/u/thomas4)\
**Replies:** 8\
**Last updated:** [February 23, 2023, 8:38pm UTC](https://discuss.elastic.co/t/dakmode-in-kibana-spaces/326343 "2023-02-23T20:38:14Z")

</div>

Hi all, new to Kibana and setting up new spaces, but i want them in darkMode but can't figure out how to do it, any help would be appreciated. I'm using Kibana 7.6.1

---

## [Elasticsearch 8.6 - enrich processor is not behaving as expected](https://discuss.elastic.co/t/elasticsearch-8-6-enrich-processor-is-not-behaving-as-expected/326371)

<div class="topic-metadata">

**Author:** [@BlueNoteBird](https://discuss.elastic.co/u/BlueNoteBird)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 7:44pm UTC](https://discuss.elastic.co/t/elasticsearch-8-6-enrich-processor-is-not-behaving-as-expected/326371 "2023-02-23T19:44:23Z")

</div>

Hello, I am new to Elasticsearch and I am probably missing something. It seems that enrich processor is not using custom normalizer. // My custom Normalizer PUT /\_component\_template/comptpl\_norm\_letters { "template"…

---

## [How to Set Default Integer Value in Search Template](https://discuss.elastic.co/t/how-to-set-default-integer-value-in-search-template/325279)

<div class="topic-metadata">

**Author:** [@krmathieu](https://discuss.elastic.co/u/krmathieu)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 6:58pm UTC](https://discuss.elastic.co/t/how-to-set-default-integer-value-in-search-template/325279 "2023-02-23T18:58:53Z")

</div>

I am getting a number\_format\_exception when trying to run a search against a search template containing this snippet of code. It defines a CityID variable and tries to set a wildcard default and the CityID field is defin…

---

## [Elasticsearch rolling restart without indexing down time](https://discuss.elastic.co/t/elasticsearch-rolling-restart-without-indexing-down-time/326358)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 6:50pm UTC](https://discuss.elastic.co/t/elasticsearch-rolling-restart-without-indexing-down-time/326358 "2023-02-23T18:50:06Z")

</div>

We run an elasticsearch cluster 7.17, with 3 data nodes and 3 master nodes. The use case is for monitoring with elasticAPM. We follow official documentation at Full cluster restart upgrade | Elasticsearch Guide \[7.17\] |…

---

## [Logs reflecting late in kibana](https://discuss.elastic.co/t/logs-reflecting-late-in-kibana/326291)

<div class="topic-metadata">

**Author:** [@Haneesha](https://discuss.elastic.co/u/Haneesha)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 6:39pm UTC](https://discuss.elastic.co/t/logs-reflecting-late-in-kibana/326291 "2023-02-23T18:39:42Z")

</div>

Hi Team, Logs are reflecting after 20 min after the generation for a particular service. How can I sort this out.

---

## [Kibana Search on field endTime not working](https://discuss.elastic.co/t/kibana-search-on-field-endtime-not-working/326318)

<div class="topic-metadata">

**Author:** [@garmy](https://discuss.elastic.co/u/garmy)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 6:04pm UTC](https://discuss.elastic.co/t/kibana-search-on-field-endtime-not-working/326318 "2023-02-23T18:04:56Z")

</div>

Hi gang, Trying to identify documents that have a time field called "endTime" \>= future times..... since this field is a UTC Time field, some may, and do have 'Future' dates and those are what I want to see (as well as …

---

## [Reindex w/ a regex](https://discuss.elastic.co/t/reindex-w-a-regex/326348)

<div class="topic-metadata">

**Author:** [@vfeydel](https://discuss.elastic.co/u/vfeydel)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 5:44pm UTC](https://discuss.elastic.co/t/reindex-w-a-regex/326348 "2023-02-23T17:44:51Z")

</div>

I have lot of indices with same prefix. In those indices, I need to keep only document that have for example the field "abc" with 7 numbers only. My indices are already index in Elastic. It is possible , with a query or…

---

## [How to analyse nested fields?](https://discuss.elastic.co/t/how-to-analyse-nested-fields/325944)

<div class="topic-metadata">

**Author:** [@Amine16](https://discuss.elastic.co/u/Amine16)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 3:28pm UTC](https://discuss.elastic.co/t/how-to-analyse-nested-fields/325944 "2023-02-23T15:28:45Z")

</div>

I am working in e-health project and we have a lot of clinical data (JSON format) stored in our data base. We want to do some research in these data, that’s why we think that Elastic Search tool can help us in this proj…

---

## [Copy Dashboard th onther space](https://discuss.elastic.co/t/copy-dashboard-th-onther-space/326194)

<div class="topic-metadata">

**Author:** [@hiba](https://discuss.elastic.co/u/hiba)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 2:26pm UTC](https://discuss.elastic.co/t/copy-dashboard-th-onther-space/326194 "2023-02-23T14:26:36Z")

</div>

Hi, I copied a dashboard to another space, but I noticed that there are visualizations whose X axis is not the same For example : i copy this dashboard (original) But i get this

---

## [How to grab the trace for bulkprocessor](https://discuss.elastic.co/t/how-to-grab-the-trace-for-bulkprocessor/326149)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 2:19pm UTC](https://discuss.elastic.co/t/how-to-grab-the-trace-for-bulkprocessor/326149 "2023-02-23T14:19:41Z")

</div>

Hi I need to trace same stack for bulkprocessor for tracing the cause of the error on elastic, why does the application get a timeout ERROR e.i.u.r.i.BulkIndexingProcessorConfig - - Failed to execute bulk request. Reas…

---

## [Kibana Visualizations](https://discuss.elastic.co/t/kibana-visualizations/326251)

<div class="topic-metadata">

**Author:** [@joelle\_umutoni](https://discuss.elastic.co/u/joelle_umutoni)\
**Replies:** 6\
**Last updated:** [February 23, 2023, 2:05pm UTC](https://discuss.elastic.co/t/kibana-visualizations/326251 "2023-02-23T14:05:29Z")

</div>

What to do when you click on visualization for filtering purpose but the other visualization does not update to show the data related to the one clicked.

---

## [Logstash is taking high cpu](https://discuss.elastic.co/t/logstash-is-taking-high-cpu/326316)

<div class="topic-metadata">

**Author:** [@divya.m](https://discuss.elastic.co/u/divya.m)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 2:00pm UTC](https://discuss.elastic.co/t/logstash-is-taking-high-cpu/326316 "2023-02-23T14:00:24Z")

</div>

Without any load consistently logstash is using 46% of CPU, after performance load testing logstash cpu is high root@::~ $ docker logs XXXXX | grep -i "2023-02-23 10:57" | wc 86 1238 18546

---

## [Kibana Vega : Sum of field of latest unique values](https://discuss.elastic.co/t/kibana-vega-sum-of-field-of-latest-unique-values/326047)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 9\
**Last updated:** [February 23, 2023, 1:57pm UTC](https://discuss.elastic.co/t/kibana-vega-sum-of-field-of-latest-unique-values/326047 "2023-02-23T13:57:07Z")

</div>

Problem statement : I have written a Kibana Vega script to show sum of latest balanceusd field having a unique orgid. I am getting balance logs frequently and every latest log has the updated balance. There can be a numb…

---

## [Vega kibana tag cloud](https://discuss.elastic.co/t/vega-kibana-tag-cloud/326265)

<div class="topic-metadata">

**Author:** [@uae\_user](https://discuss.elastic.co/u/uae_user)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 1:50pm UTC](https://discuss.elastic.co/t/vega-kibana-tag-cloud/326265 "2023-02-23T13:50:24Z")

</div>

Hi, I'm trying to build a tag cloud using custom visualization, I tried to follow Vega tag cloud format and replaced the value part with url , I'm sure about the query as I tried it on the dev tool and it worked. ' I'm…

---

## [Unable to search data containing math expression](https://discuss.elastic.co/t/unable-to-search-data-containing-math-expression/326287)

<div class="topic-metadata">

**Author:** [@Hassan\_zaib\_Hayat](https://discuss.elastic.co/u/Hassan_zaib_Hayat)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 1:39pm UTC](https://discuss.elastic.co/t/unable-to-search-data-containing-math-expression/326287 "2023-02-23T13:39:14Z")

</div>

Hi ES folks, Hope everyone is doing fine. I am facing a problem when querying data containing mathematical expressions. For example I have following data indexed in my ES what is 3+4 what is 3-4 what is 3\*4 what is 3/…

---

## [Elastic Cloud SAML SSO in 'trial' environment](https://discuss.elastic.co/t/elastic-cloud-saml-sso-in-trial-environment/325509)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 14\
**Last updated:** [February 23, 2023, 1:07pm UTC](https://discuss.elastic.co/t/elastic-cloud-saml-sso-in-trial-environment/325509 "2023-02-23T13:07:40Z")

</div>

Hello, I'm looking for some insight with configuring SAML SSO in a trial Elastic Cloud environment. The deployment is on v8.6.1. Using Elasticsearch, Kibana, Enterprise Search. The idP provider is SAML 2.0. I have be…

---

## [Custom Logs, fleet pre processor to keep on field as json itself](https://discuss.elastic.co/t/custom-logs-fleet-pre-processor-to-keep-on-field-as-json-itself/326327)

<div class="topic-metadata">

**Author:** [@coderhs](https://discuss.elastic.co/u/coderhs)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 12:59pm UTC](https://discuss.elastic.co/t/custom-logs-fleet-pre-processor-to-keep-on-field-as-json-itself/326327 "2023-02-23T12:59:47Z")

</div>

I have setup a self hosted elastic stack with kibana to track logs for a web application (ruby on rails). I am pushing the production logs to elastic using fleet. I am creating the log in JSON fromat from the application…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=621)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=623)
