# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=628

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 629

---

## [Is there a recommendation on the number of Indices that can be created using ILM](https://discuss.elastic.co/t/is-there-a-recommendation-on-the-number-of-indices-that-can-be-created-using-ilm/325716)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 9\
**Last updated:** [February 20, 2023, 2:13am UTC](https://discuss.elastic.co/t/is-there-a-recommendation-on-the-number-of-indices-that-can-be-created-using-ilm/325716 "2023-02-20T02:13:19Z")

</div>

Hi Team, I am quite new to Elasticsearch. We are migrating Data from a Licensed Product to Elastic. But the amount of data is huge, its about 100 TB/month. And we have to index data for 10 years. So effectively 1 Pet…

---

## [Does Elastic Cloud service support SDK to access its APIs](https://discuss.elastic.co/t/does-elastic-cloud-service-support-sdk-to-access-its-apis/325719)

<div class="topic-metadata">

**Author:** [@vaibhav\_b](https://discuss.elastic.co/u/vaibhav_b)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 1:15am UTC](https://discuss.elastic.co/t/does-elastic-cloud-service-support-sdk-to-access-its-apis/325719 "2023-02-20T01:15:49Z")

</div>

I have question related to SDK support to provision Elasticsearch service on elastic cloud. I am going through the documentation where I am seeing, "how can I consume the API", here I am not seeing anything mentioned r…

---

## [Easy way to monitor ElasticSearch](https://discuss.elastic.co/t/easy-way-to-monitor-elasticsearch/324404)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 1:08am UTC](https://discuss.elastic.co/t/easy-way-to-monitor-elasticsearch/324404 "2023-02-20T01:08:15Z")

</div>

I want a easy way to monitor Elasticsearch. What I found is Metricbeat. But it seems to be very extensive. For my purpose it is enough to see green, yellow, red and it would be nice to have if the administrator gets a …

---

## [Unassigned Shards - issue](https://discuss.elastic.co/t/unassigned-shards-issue/325692)

<div class="topic-metadata">

**Author:** [@azuramazda](https://discuss.elastic.co/u/azuramazda)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 9:00pm UTC](https://discuss.elastic.co/t/unassigned-shards-issue/325692 "2023-02-19T21:00:59Z")

</div>

I am facing an issue with ES where it shows 174 shards are unassigned. and allocate\_explanation is :"cannot allocate because all found copies of the shard are there stale or corrupt". This issue is arising since yesterd…

---

## [Systemctl reload elasticsearch.service or systemctl restart elasticsearch.service](https://discuss.elastic.co/t/systemctl-reload-elasticsearch-service-or-systemctl-restart-elasticsearch-service/325703)

<div class="topic-metadata">

**Author:** [@firdaussaad](https://discuss.elastic.co/u/firdaussaad)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 8:59pm UTC](https://discuss.elastic.co/t/systemctl-reload-elasticsearch-service-or-systemctl-restart-elasticsearch-service/325703 "2023-02-19T20:59:33Z")

</div>

Hi all, I am currently working on a bash script. Whenever i make changes to elasticsearch.yml file, should i perform systemctl reload elascticsearch.service or systemctl restart elasticsearch.service? Any difference be…

---

## [Is it possible to configure SAML authentication in kibana 7.17 version without changing the elasticsearch.yml](https://discuss.elastic.co/t/is-it-possible-to-configure-saml-authentication-in-kibana-7-17-version-without-changing-the-elasticsearch-yml/325727)

<div class="topic-metadata">

**Author:** [@Vlada\_Homyakova](https://discuss.elastic.co/u/Vlada_Homyakova)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 8:57pm UTC](https://discuss.elastic.co/t/is-it-possible-to-configure-saml-authentication-in-kibana-7-17-version-without-changing-the-elasticsearch-yml/325727 "2023-02-19T20:57:06Z")

</div>

Hi I'm trying to integrate kibana with okta saml, I try to get constantly FATAL Error: \[config validation of \[xpack.security\].authc.realm\]: Epexted a String but got an object xpack.security.authc.providers: - saml …

---

## [LogDriver.StartLogging: error creating client config: A hosts flag is required](https://discuss.elastic.co/t/logdriver-startlogging-error-creating-client-config-a-hosts-flag-is-required/325800)

<div class="topic-metadata">

**Author:** [@cavarzan](https://discuss.elastic.co/u/cavarzan)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 8:54pm UTC](https://discuss.elastic.co/t/logdriver-startlogging-error-creating-client-config-a-hosts-flag-is-required/325800 "2023-02-19T20:54:15Z")

</div>

I'm receiving the following error when I try to start a docker-compose service with elastic-apm.jar configured. LogDriver.StartLogging: error creating client config: A hosts flag is required I've looked at this answer,…

---

## [Is "http://localhost:9200/\_all/\_stats/\_all" an expensive call?](https://discuss.elastic.co/t/is-http-localhost-9200-all-stats-all-an-expensive-call/325907)

<div class="topic-metadata">

**Author:** [@junhuangli](https://discuss.elastic.co/u/junhuangli)\
**Replies:** 6\
**Last updated:** [February 19, 2023, 8:43pm UTC](https://discuss.elastic.co/t/is-http-localhost-9200-all-stats-all-an-expensive-call/325907 "2023-02-19T20:43:02Z")

</div>

We are using open-telemetry to monitor the es cluster. And I found the open-telemetry receiver is sending request to "http://localhost:9200/\_all/\_stats/\_all" to pull the metrics. One issue I notice is if the receiver is …

---

## ["Elasticsearch Unreachable: \[http://localhost:9200/\]\[Manticore::ClientProtocolException\] localhost:9200 failed to respond"}](https://discuss.elastic.co/t/elasticsearch-unreachable-http-localhost-9200-manticore-clientprotocolexception-localhost-9200-failed-to-respond/325897)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 10\
**Last updated:** [February 19, 2023, 7:20pm UTC](https://discuss.elastic.co/t/elasticsearch-unreachable-http-localhost-9200-manticore-clientprotocolexception-localhost-9200-failed-to-respond/325897 "2023-02-19T19:20:51Z")

</div>

Hi. I'm trying to follow the "Parsing Logs with Logstash" (Tutorial), and I am having trouble when I try to connect my pipeline to Elasticsearch. My first-pipeline.conf file looks like this: input { beats { …

---

## [Closing node](https://discuss.elastic.co/t/closing-node/325913)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 7\
**Last updated:** [February 19, 2023, 3:53pm UTC](https://discuss.elastic.co/t/closing-node/325913 "2023-02-19T15:53:31Z")

</div>

Hi, I want to close node, and want elastic to move his to different node. What is the procedure for closing node? How it can be done automatically? Thanks.

---

## [Very slow on-prem Elasticsearch 8.6.0 cluster](https://discuss.elastic.co/t/very-slow-on-prem-elasticsearch-8-6-0-cluster/325307)

<div class="topic-metadata">

**Author:** [@tibbers38](https://discuss.elastic.co/u/tibbers38)\
**Replies:** 6\
**Last updated:** [February 19, 2023, 3:29pm UTC](https://discuss.elastic.co/t/very-slow-on-prem-elasticsearch-8-6-0-cluster/325307 "2023-02-19T15:29:37Z")

</div>

Hi everyone, I'm having a very slow ES cluster despite I'm not making any change with data volume or number of shards. Our ES cluster is version 8.6.0 with these node: es01: "data\_content","data\_hot","ingest","master…

---

## [Elasticsearch production deployment to docker keeps exiting without any indication to why](https://discuss.elastic.co/t/elasticsearch-production-deployment-to-docker-keeps-exiting-without-any-indication-to-why/325916)

<div class="topic-metadata">

**Author:** [@m.jaafar](https://discuss.elastic.co/u/m.jaafar)\
**Replies:** 0\
**Last updated:** [February 19, 2023, 2:59pm UTC](https://discuss.elastic.co/t/elasticsearch-production-deployment-to-docker-keeps-exiting-without-any-indication-to-why/325916 "2023-02-19T14:59:48Z")

</div>

After tinkering with elasticsearch in development, I am now ready to deploy it to production on docker on my own server, so, I was reading what practices should be followed, this documentation: Install Elasticsearch with…

---

## [Joining two indexes](https://discuss.elastic.co/t/joining-two-indexes/325876)

<div class="topic-metadata">

**Author:** [@etp](https://discuss.elastic.co/u/etp)\
**Replies:** 2\
**Last updated:** [February 19, 2023, 2:57pm UTC](https://discuss.elastic.co/t/joining-two-indexes/325876 "2023-02-19T14:57:06Z")

</div>

Hi, I have two indices A and B. I wanted to perform inner join on the two indices using a common field such that I can collect the fields(spread across both indices) into another index using transforms. What aggregatio…

---

## [Beat-exporter sending the metrics of filebeat to prometheus even pod gets deleted](https://discuss.elastic.co/t/beat-exporter-sending-the-metrics-of-filebeat-to-prometheus-even-pod-gets-deleted/325914)

<div class="topic-metadata">

**Author:** [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 2:10pm UTC](https://discuss.elastic.co/t/beat-exporter-sending-the-metrics-of-filebeat-to-prometheus-even-pod-gets-deleted/325914 "2023-02-19T14:10:56Z")

</div>

Hi Team, I am running filebeat as a deamonset in k8s also running beat-exporter as a side car container. one weird thing i am observing is after pod get's deleted \[ pod deleted almost 1 week ago \] still i am getting th…

---

## [Improve search performance beyond 2x](https://discuss.elastic.co/t/improve-search-performance-beyond-2x/325537)

<div class="topic-metadata">

**Author:** [@pathaniaamn](https://discuss.elastic.co/u/pathaniaamn)\
**Replies:** 3\
**Last updated:** [February 19, 2023, 10:15am UTC](https://discuss.elastic.co/t/improve-search-performance-beyond-2x/325537 "2023-02-19T10:15:22Z")

</div>

Question on replica shard: Node1 P0 Node2 P1 Node3 R0 Node4 R1 So, overall search performance can get 2x as Primary and Replica shards will share the search load. But what is next if search load increases to 5 f…

---

## [ICU Tokenizer to keep tags and hashtags in token](https://discuss.elastic.co/t/icu-tokenizer-to-keep-tags-and-hashtags-in-token/325909)

<div class="topic-metadata">

**Author:** [@kaanebv](https://discuss.elastic.co/u/kaanebv)\
**Replies:** 0\
**Last updated:** [February 19, 2023, 9:07am UTC](https://discuss.elastic.co/t/icu-tokenizer-to-keep-tags-and-hashtags-in-token/325909 "2023-02-19T09:07:56Z")

</div>

I'm using ICU tokenizer with a custom analyzer but it doesn't keep hashtag in token. I have tried word\_delimiter and icu\_normalizer but they didn't work. Is there any solution to this?

---

## [Restoring Dashboards](https://discuss.elastic.co/t/restoring-dashboards/325738)

<div class="topic-metadata">

**Author:** [@Faisaljodayn](https://discuss.elastic.co/u/Faisaljodayn)\
**Replies:** 6\
**Last updated:** [February 19, 2023, 5:39am UTC](https://discuss.elastic.co/t/restoring-dashboards/325738 "2023-02-19T05:39:17Z")

</div>

Hi everyone, Today while we were working on dashboards. We deleted a model package by mistake and it affected all the dashboards. Basically, all the indices are present but with no data. All the configurations and every…

---

## [Can elasticsearch/kibana/... export trace/span log as datasets?](https://discuss.elastic.co/t/can-elasticsearch-kibana-export-trace-span-log-as-datasets/325855)

<div class="topic-metadata">

**Author:** [@elkLearner](https://discuss.elastic.co/u/elkLearner)\
**Replies:** 3\
**Last updated:** [February 19, 2023, 4:07am UTC](https://discuss.elastic.co/t/can-elasticsearch-kibana-export-trace-span-log-as-datasets/325855 "2023-02-19T04:07:09Z")

</div>

I'm a freshman here. I'm using skywalking+elasticsearch monitoring a microservice application in k8s. l know skywalking can collect trace/span logs from microservice and store the data in elasticsearch, and then display …

---

## [How to use mutli\_match with same value](https://discuss.elastic.co/t/how-to-use-mutli-match-with-same-value/325882)

<div class="topic-metadata">

**Author:** [@anhhungxdieu](https://discuss.elastic.co/u/anhhungxdieu)\
**Replies:** 4\
**Last updated:** [February 19, 2023, 2:49am UTC](https://discuss.elastic.co/t/how-to-use-mutli-match-with-same-value/325882 "2023-02-19T02:49:35Z")

</div>

I'm using elastic ver7.17 My sample documents : { "title" : "Firmly stepping forward under the glorious banner of the Party", "intro": "In celebration of the Party’s founding anniversary and the new spring, we proudl…

---

## [What happens when the document data has special characters like "party-planning" or "Michelle\_obama" ? I see that Elasticsearch includes them in the hit. how do we ignore such documents? Is Elasticsearch case sensitive?](https://discuss.elastic.co/t/what-happens-when-the-document-data-has-special-characters-like-party-planning-or-michelle-obama-i-see-that-elasticsearch-includes-them-in-the-hit-how-do-we-ignore-such-documents-is-elasticsearch-case-sensitive/325901)

<div class="topic-metadata">

**Author:** [@pathaniaamn](https://discuss.elastic.co/u/pathaniaamn)\
**Replies:** 0\
**Last updated:** [February 19, 2023, 1:17am UTC](https://discuss.elastic.co/t/what-happens-when-the-document-data-has-special-characters-like-party-planning-or-michelle-obama-i-see-that-elasticsearch-includes-them-in-the-hit-how-do-we-ignore-such-documents-is-elasticsearch-case-sensitive/325901 "2023-02-19T01:17:32Z")

</div>

Two questions: What happens when the document data has special characters like "party-planning" or "Michelle\_obama" ? I see that Elasticsearch includes them in the hit. how do we ignore such documents? Is Elasticsearch…

---

## [Alerting via email when new value is inserted](https://discuss.elastic.co/t/alerting-via-email-when-new-value-is-inserted/325890)

<div class="topic-metadata">

**Author:** [@camay123](https://discuss.elastic.co/u/camay123)\
**Replies:** 0\
**Last updated:** [February 18, 2023, 3:47pm UTC](https://discuss.elastic.co/t/alerting-via-email-when-new-value-is-inserted/325890 "2023-02-18T15:47:27Z")

</div>

Hello, I have some data that enters my elk stack every four hours. I want to be alerted by email when data is inserted and a specific field contains a never seen before value. I am wondering of this is possible and if…

---

## [Elasticsearch node HTTP layer SSL configuration Keystore doesn't contain any PrivateKey entries where the associated certificate is a CA certificate](https://discuss.elastic.co/t/elasticsearch-node-http-layer-ssl-configuration-keystore-doesnt-contain-any-privatekey-entries-where-the-associated-certificate-is-a-ca-certificate/325713)

<div class="topic-metadata">

**Author:** [@Behzad\_Nazemi](https://discuss.elastic.co/u/Behzad_Nazemi)\
**Replies:** 4\
**Last updated:** [February 18, 2023, 11:37am UTC](https://discuss.elastic.co/t/elasticsearch-node-http-layer-ssl-configuration-keystore-doesnt-contain-any-privatekey-entries-where-the-associated-certificate-is-a-ca-certificate/325713 "2023-02-18T11:37:06Z")

</div>

Dear Elastic Team, Would you please help us with this issue? The new nodes could not join the cluster since we can not create a token for nodes. The http.p12 is already created and contained a PrivateKey but the error i…

---

## [Question about minimum requirements per zone on Elastic Cloud](https://discuss.elastic.co/t/question-about-minimum-requirements-per-zone-on-elastic-cloud/325861)

<div class="topic-metadata">

**Author:** [@lengoyvaerts](https://discuss.elastic.co/u/lengoyvaerts)\
**Replies:** 1\
**Last updated:** [February 18, 2023, 6:38am UTC](https://discuss.elastic.co/t/question-about-minimum-requirements-per-zone-on-elastic-cloud/325861 "2023-02-18T06:38:35Z")

</div>

When setting up a new deployment on Elastic Cloud, it is recommended to use minimum hardware requirements per zone, depending on the chosen provider. Using less could affect the performance of your deployment. Why is…

---

## [Is cloudfront codec ever works before?](https://discuss.elastic.co/t/is-cloudfront-codec-ever-works-before/325879)

<div class="topic-metadata">

**Author:** [@stwang](https://discuss.elastic.co/u/stwang)\
**Replies:** 1\
**Last updated:** [February 18, 2023, 5:15am UTC](https://discuss.elastic.co/t/is-cloudfront-codec-ever-works-before/325879 "2023-02-18T05:15:56Z")

</div>

Hi There, I am try to parse cloudfront log in logstash, and I found there has a cloudfront codec can be used. but I never make it works. Can someone pointing me a vaild config, or this codec never works before? Cheers…

---

## [Shodan.io query return json mapping, nested dynamic mapping](https://discuss.elastic.co/t/shodan-io-query-return-json-mapping-nested-dynamic-mapping/325761)

<div class="topic-metadata">

**Author:** [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Replies:** 3\
**Last updated:** [February 17, 2023, 8:52pm UTC](https://discuss.elastic.co/t/shodan-io-query-return-json-mapping-nested-dynamic-mapping/325761 "2023-02-17T20:52:13Z")

</div>

hi, i'm using some python to query shodan.io, it returns a reasonably complex json that i'd like to push into Elasticsearch. i've got most mapped out and its work, but there is one field i just cant to map correctly. the…

---

## [How to Search word and digits](https://discuss.elastic.co/t/how-to-search-word-and-digits/325848)

<div class="topic-metadata">

**Author:** [@Mohamed\_Farshath](https://discuss.elastic.co/u/Mohamed_Farshath)\
**Replies:** 3\
**Last updated:** [February 17, 2023, 8:24pm UTC](https://discuss.elastic.co/t/how-to-search-word-and-digits/325848 "2023-02-17T20:24:39Z")

</div>

Hey guys, I need help searching this message's contents which has a word and a code that varies from 4 to 6 digits. examples are follows: enter this : 4567 enter this : 567893

---

## [Parse Date with RFC\_1123\_DATE\_TIME format](https://discuss.elastic.co/t/parse-date-with-rfc-1123-date-time-format/325863)

<div class="topic-metadata">

**Author:** [@valleram](https://discuss.elastic.co/u/valleram)\
**Replies:** 4\
**Last updated:** [February 17, 2023, 7:03pm UTC](https://discuss.elastic.co/t/parse-date-with-rfc-1123-date-time-format/325863 "2023-02-17T19:03:42Z")

</div>

Hi All, I'm ingesting documents to my ES cluster with a field called CREATION\_TIME with format Wed, 13 Oct 2021 13:04:54 GMT. I've tried to parse it using below mappings, but Kibana is still ignoring the value. { "p…

---

## [How does Anomaly Detection work?](https://discuss.elastic.co/t/how-does-anomaly-detection-work/325694)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 1\
**Last updated:** [February 17, 2023, 6:34pm UTC](https://discuss.elastic.co/t/how-does-anomaly-detection-work/325694 "2023-02-17T18:34:47Z")

</div>

I have a question about the Anomaly Detection module provided by elastic stack. As per my understanding of Machine Learning the more data being fed to the model the better learning it will do provided the data is proper.…

---

## [How do I sum the result of an aggregation and present it in a table?](https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 6\
**Last updated:** [February 17, 2023, 6:28pm UTC](https://discuss.elastic.co/t/how-do-i-sum-the-result-of-an-aggregation-and-present-it-in-a-table/324352 "2023-02-17T18:28:23Z")

</div>

I would like to take the results of this query, namely the values: 3683 3676 3574 3530 3706 3695 3663 3530 3586 3567 Sum them together, which would give: 36210, and display them in a table. I can't seem to …

---

## [Index/alias Filter(s)](https://discuss.elastic.co/t/index-alias-filter-s/325851)

<div class="topic-metadata">

**Author:** [@Talvaro](https://discuss.elastic.co/u/Talvaro)\
**Replies:** 3\
**Last updated:** [February 17, 2023, 5:52pm UTC](https://discuss.elastic.co/t/index-alias-filter-s/325851 "2023-02-17T17:52:59Z")

</div>

I'm researching an issue with a existing application I just got as responsible. I am not too familiar with Elastic/Kibana. The issue is the application reading docs from an Alias is not getting all expected results. I no…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=627)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=629)
