# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=630

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 631

---

## [Automatically closing indices older than x days using ILP](https://discuss.elastic.co/t/automatically-closing-indices-older-than-x-days-using-ilp/325765)

<div class="topic-metadata">

**Author:** [@Monica\_majua](https://discuss.elastic.co/u/Monica_majua)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 8:21pm UTC](https://discuss.elastic.co/t/automatically-closing-indices-older-than-x-days-using-ilp/325765 "2023-02-16T20:21:17Z")

</div>

I was wondering if it is possible to configure a lifecycle policy so that nodes older than 300 days are automatically closing? I would like to know if I am on the right way or am I really trying something that I will nev…

---

## [Error while uploading bulk json to elasticsearch domain](https://discuss.elastic.co/t/error-while-uploading-bulk-json-to-elasticsearch-domain/325774)

<div class="topic-metadata">

**Author:** [@truptivala](https://discuss.elastic.co/u/truptivala)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 8:18pm UTC](https://discuss.elastic.co/t/error-while-uploading-bulk-json-to-elasticsearch-domain/325774 "2023-02-16T20:18:36Z")

</div>

I am trying to upload the below json file to the elasticsearch domain I have on aws and getting the below error: Input json file: {"index": {"\_index": "ods-pcd-poc","\_id": "1"}}{"Page": 0,"Path": "//Document/Figure","T…

---

## [Reindex debuging](https://discuss.elastic.co/t/reindex-debuging/325772)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 8:01pm UTC](https://discuss.elastic.co/t/reindex-debuging/325772 "2023-02-16T20:01:41Z")

</div>

Hi I'm going through some of troubleshooting for reindex process by bulkprocessor Under that proc Failed to execute bulk request. Reason: \<mark\>java.net.SocketTimeoutException\</mark\>: 8,000 milliseconds \<mark\>timeout\</…

---

## [Migrating from self hosted to elastic service, how to change our ingest flow from kafka/logstash?](https://discuss.elastic.co/t/migrating-from-self-hosted-to-elastic-service-how-to-change-our-ingest-flow-from-kafka-logstash/325766)

<div class="topic-metadata">

**Author:** [@tymercer](https://discuss.elastic.co/u/tymercer)\
**Replies:** 7\
**Last updated:** [February 16, 2023, 7:14pm UTC](https://discuss.elastic.co/t/migrating-from-self-hosted-to-elastic-service-how-to-change-our-ingest-flow-from-kafka-logstash/325766 "2023-02-16T19:14:48Z")

</div>

We are in the process of migrating our self hosted ELK stack to the hosted Elastic Services in Azure. Currently we have our servers running filebeat configured to push their logs to Kafka/zookeeper which then pushes to …

---

## [ELK CCR Setup](https://discuss.elastic.co/t/elk-ccr-setup/324719)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 7\
**Last updated:** [February 16, 2023, 6:36pm UTC](https://discuss.elastic.co/t/elk-ccr-setup/324719 "2023-02-16T18:36:00Z")

</div>

Hello, I want to test the CCR feature, and I understand these two limitations exist: A follower can only follow one leader. No way to directly write events from the client side to the follower index. with these two l…

---

## [Compare 2 days Data and conditional formatting](https://discuss.elastic.co/t/compare-2-days-data-and-conditional-formatting/324860)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 5:25pm UTC](https://discuss.elastic.co/t/compare-2-days-data-and-conditional-formatting/324860 "2023-02-16T17:25:48Z")

</div>

Hi, I am new to Kibana, I have a requirement to compare 2 days of data and create visualization. (Kibana Version 7.10) Day 1 Data Nam Col1 Col2 AAA 500 600 BBB 700 800 Day 2 Data Nam Col1 Col2 AAA…

---

## [Use of aggregations with multiple queries](https://discuss.elastic.co/t/use-of-aggregations-with-multiple-queries/325763)

<div class="topic-metadata">

**Author:** [@usergbgc](https://discuss.elastic.co/u/usergbgc)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 4:31pm UTC](https://discuss.elastic.co/t/use-of-aggregations-with-multiple-queries/325763 "2023-02-16T16:31:24Z")

</div>

Hello, I've been having trouble getting some results for a while, and I'm starting to wonder if my query is even feasible. I have a set of documents collecting articles, with fields like date, title, and a nested autho…

---

## [Maps visualization can't recognize geospatial field](https://discuss.elastic.co/t/maps-visualization-cant-recognize-geospatial-field/325103)

<div class="topic-metadata">

**Author:** [@Evgenii\_X](https://discuss.elastic.co/u/Evgenii_X)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 7:27am UTC](https://discuss.elastic.co/t/maps-visualization-cant-recognize-geospatial-field/325103 "2023-02-09T07:27:39Z")

</div>

Maps visualization can't recognize geospatial (geo\_point ) field (source.geo.location). Field source.geo.location having type geo\_point, is searchable and aggregatable. Trying to check everything according to: T…

---

## [How to define multiple keys in index (Y Axis) to sort by clicks against date (X Axis)](https://discuss.elastic.co/t/how-to-define-multiple-keys-in-index-y-axis-to-sort-by-clicks-against-date-x-axis/325323)

<div class="topic-metadata">

**Author:** [@Sahil\_Sharma1](https://discuss.elastic.co/u/Sahil_Sharma1)\
**Replies:** 0\
**Last updated:** [February 11, 2023, 7:04pm UTC](https://discuss.elastic.co/t/how-to-define-multiple-keys-in-index-y-axis-to-sort-by-clicks-against-date-x-axis/325323 "2023-02-11T19:04:44Z")

</div>

Hi, I have an issue with kibana dashboards. I want multiple fields in index (Entity1.keyword, Entity2.keyword and Entity3.keyword) to be sorted by max clicks against date. Entities will be in Y axis and Date will in …

---

## [Convert values from string to int](https://discuss.elastic.co/t/convert-values-from-string-to-int/325164)

<div class="topic-metadata">

**Author:** [@Law\_Rence](https://discuss.elastic.co/u/Law_Rence)\
**Replies:** 6\
**Last updated:** [February 16, 2023, 2:31pm UTC](https://discuss.elastic.co/t/convert-values-from-string-to-int/325164 "2023-02-16T14:31:23Z")

</div>

How can I convert all the keys that have numbers from strings to int using ruby? example: "x": "hello", "a": "1", "b": "2", "c": "3", "d": "bye" to: "x": "hello", "a": 1, "b": 2, "c": 3, e.t.c here's my ruby…

---

## [Change how Kibana interprets dates as datetimes](https://discuss.elastic.co/t/change-how-kibana-interprets-dates-as-datetimes/325616)

<div class="topic-metadata">

**Author:** [@catrexis](https://discuss.elastic.co/u/catrexis)\
**Replies:** 6\
**Last updated:** [February 16, 2023, 2:17pm UTC](https://discuss.elastic.co/t/change-how-kibana-interprets-dates-as-datetimes/325616 "2023-02-16T14:17:44Z")

</div>

One of my indices uses a date (yyyy-MM-dd) instead of a datetime as timstamp-field. Kibana interprets that as a datetime, by setting the time to 01:00. As the document contains data of the whole day, I would like to set …

---

## [Migrate indices from elasticsearsh 6.8 to 7.17](https://discuss.elastic.co/t/migrate-indices-from-elasticsearsh-6-8-to-7-17/325745)

<div class="topic-metadata">

**Author:** [@Parvatayya\_Malimath](https://discuss.elastic.co/u/Parvatayya_Malimath)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 2:02pm UTC](https://discuss.elastic.co/t/migrate-indices-from-elasticsearsh-6-8-to-7-17/325745 "2023-02-16T14:02:29Z")

</div>

We have Elasticsearch 6.8 running at the moment and want to migrate it to 7.17. I have created another cluster with 7.17 running and we would like migrate the indices from 6.8. what is the best way to do it, I would li…

---

## [Elasticsearch 5 vs 8 performance and index size](https://discuss.elastic.co/t/elasticsearch-5-vs-8-performance-and-index-size/325601)

<div class="topic-metadata">

**Author:** [@Idorasi\_Paul](https://discuss.elastic.co/u/Idorasi_Paul)\
**Replies:** 9\
**Last updated:** [February 16, 2023, 1:45pm UTC](https://discuss.elastic.co/t/elasticsearch-5-vs-8-performance-and-index-size/325601 "2023-02-16T13:45:18Z")

</div>

Hello. I've updated from elasticsearch 5.6 to 8.1 and following load tests I can see a decrease in performance, between 20-40%. I was expecting 8.1 to be faster 5.6, I'm assuming we're doing something wrong. Another weir…

---

## [Performance during Snapshot Backups/Cross-Cluster replication](https://discuss.elastic.co/t/performance-during-snapshot-backups-cross-cluster-replication/325560)

<div class="topic-metadata">

**Author:** [@x00m](https://discuss.elastic.co/u/x00m)\
**Replies:** 3\
**Last updated:** [February 16, 2023, 1:15pm UTC](https://discuss.elastic.co/t/performance-during-snapshot-backups-cross-cluster-replication/325560 "2023-02-16T13:15:59Z")

</div>

Assume the cumulative Index Size is approximately 200GB. Is taking snapshot backup every 30 minutes advisable? Will it cause any performance impact on the cluster for any active read/writes happening to the cluster duri…

---

## [Cant do case insensitive search in elastic search](https://discuss.elastic.co/t/cant-do-case-insensitive-search-in-elastic-search/325680)

<div class="topic-metadata">

**Author:** [@Dang\_Hai](https://discuss.elastic.co/u/Dang_Hai)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 12:58pm UTC](https://discuss.elastic.co/t/cant-do-case-insensitive-search-in-elastic-search/325680 "2023-02-16T12:58:35Z")

</div>

I'm new to Elasticsearch and trying to do this query right. So I'm having a document like this: { "id": 1, "name": "Văn Hiến" } I want to get that document in 3 cases: 1/ User input is: "v" or "h" or "i",... …

---

## [Filebeat. Read each time from the beginning of the file. How?](https://discuss.elastic.co/t/filebeat-read-each-time-from-the-beginning-of-the-file-how/325693)

<div class="topic-metadata">

**Author:** [@cheburasshka](https://discuss.elastic.co/u/cheburasshka)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 7:26am UTC](https://discuss.elastic.co/t/filebeat-read-each-time-from-the-beginning-of-the-file-how/325693 "2023-02-16T07:26:04Z")

</div>

Hi. Faced with such a need: I need to read the file every time from the beginning of the file and send events. I have a file that is completely updated every 10 seconds, that is, the old content is overwritten with new …

---

## [Customize panel time range - Last week, and Next week](https://discuss.elastic.co/t/customize-panel-time-range-last-week-and-next-week/325734)

<div class="topic-metadata">

**Author:** [@fengen](https://discuss.elastic.co/u/fengen)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 12:26pm UTC](https://discuss.elastic.co/t/customize-panel-time-range-last-week-and-next-week/325734 "2023-02-16T12:26:19Z")

</div>

Hi, Does anyone know how to set the Customize panel time range to "Last week", and "Next week". It is possible to set it to "This week" which i think means that it chooses the week that you are currently in and updates…

---

## [Elastic Search:Update of existing Record (which has custom routing param set) results in duplicate record, if custom routing is not set during update](https://discuss.elastic.co/t/elastic-search-update-of-existing-record-which-has-custom-routing-param-set-results-in-duplicate-record-if-custom-routing-is-not-set-during-update/325730)

<div class="topic-metadata">

**Author:** [@Bhushan\_Shelke](https://discuss.elastic.co/u/Bhushan_Shelke)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 11:55am UTC](https://discuss.elastic.co/t/elastic-search-update-of-existing-record-which-has-custom-routing-param-set-results-in-duplicate-record-if-custom-routing-is-not-set-during-update/325730 "2023-02-16T11:55:51Z")

</div>

Env Details: Elastic Search version 7.8.1 routing param is an optional in Index settings. As per Elasticsearch docs - \_routing field | Elasticsearch Guide \[8.6\] | Elastic When indexing documents specifying a custom \_…

---

## [Elastic-Agent autodiscovery for Kubernetes pod logs not working after upgrading to 8.6.x](https://discuss.elastic.co/t/elastic-agent-autodiscovery-for-kubernetes-pod-logs-not-working-after-upgrading-to-8-6-x/325227)

<div class="topic-metadata">

**Author:** [@clewo](https://discuss.elastic.co/u/clewo)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 10:43am UTC](https://discuss.elastic.co/t/elastic-agent-autodiscovery-for-kubernetes-pod-logs-not-working-after-upgrading-to-8-6-x/325227 "2023-02-16T10:43:33Z")

</div>

Hi all, I noticed an issue with the standalone Elastic Agent shipping Kubernetes pod logs after upgrading the Agent version from 8.5.3 to 8.6.x. We run the Elastic-Agent standalone on Kubernetes as a DaemonSet. After …

---

## [Elastic On-Premise license buy,contact sales](https://discuss.elastic.co/t/elastic-on-premise-license-buy-contact-sales/325704)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 10:33am UTC](https://discuss.elastic.co/t/elastic-on-premise-license-buy-contact-sales/325704 "2023-02-16T10:33:09Z")

</div>

Hello Elastic Team, I have a question regarding Elasticsearch on premise licensing,I would like to get in contact with Sales or any representative who could guide out how licensing works.Currently I'm using elk 7.9.1 …

---

## [Writing queries with Search UI](https://discuss.elastic.co/t/writing-queries-with-search-ui/325712)

<div class="topic-metadata">

**Author:** [@Pierre-Olivier\_BEAU](https://discuss.elastic.co/u/Pierre-Olivier_BEAU)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 10:01am UTC](https://discuss.elastic.co/t/writing-queries-with-search-ui/325712 "2023-02-16T10:01:23Z")

</div>

Hello all, I am currently researching the best way to send complex queries from a front-end interface to a custom api which will then send the query to Elasticsearch (using search UI-ES-connector). Search UI seems the …

---

## [Unkown script compilations for template-context in script-cache](https://discuss.elastic.co/t/unkown-script-compilations-for-template-context-in-script-cache/325707)

<div class="topic-metadata">

**Author:** [@The\_Hans](https://discuss.elastic.co/u/The_Hans)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 9:43am UTC](https://discuss.elastic.co/t/unkown-script-compilations-for-template-context-in-script-cache/325707 "2023-02-16T09:43:02Z")

</div>

Hi, from time to time we are facing a 'circuit\_breaking\_exception' caused by 'Too many dynamic script compilations within, max: \[75/5m\]' We only use 2 score\_scripts to re-rank the score of documents. These 2 scripts us…

---

## [How to prevent "Too many dynamic script compilations within" error with search templates?](https://discuss.elastic.co/t/how-to-prevent-too-many-dynamic-script-compilations-within-error-with-search-templates/325482)

<div class="topic-metadata">

**Author:** [@Ricou13](https://discuss.elastic.co/u/Ricou13)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 8:40am UTC](https://discuss.elastic.co/t/how-to-prevent-too-many-dynamic-script-compilations-within-error-with-search-templates/325482 "2023-02-16T08:40:07Z")

</div>

I use a search template with "mustache" language to build dynamic queries according to different parameters. When I often modify the values ​​of the parameters of this request, I get this error message : \[script\] Too m…

---

## [ESRally version 2.7.0 is throwing version mismatch h error with elasticsearch server 7.6.1](https://discuss.elastic.co/t/esrally-version-2-7-0-is-throwing-version-mismatch-h-error-with-elasticsearch-server-7-6-1/324723)

<div class="topic-metadata">

**Author:** [@Rahul\_Prajapati](https://discuss.elastic.co/u/Rahul_Prajapati)\
**Replies:** 3\
**Last updated:** [February 16, 2023, 8:00am UTC](https://discuss.elastic.co/t/esrally-version-2-7-0-is-throwing-version-mismatch-h-error-with-elasticsearch-server-7-6-1/324723 "2023-02-16T08:00:01Z")

</div>

elasticsearch.exceptions.UnsupportedProductError: The client noticed that the server is not a supported distribution of Elasticsearch I have installed esrally 2.7.0 on my local mac machine in a separate python virtual e…

---

## [Fail to add second fleet server with error missing enrollment api key](https://discuss.elastic.co/t/fail-to-add-second-fleet-server-with-error-missing-enrollment-api-key/325698)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 7:41am UTC](https://discuss.elastic.co/t/fail-to-add-second-fleet-server-with-error-missing-enrollment-api-key/325698 "2023-02-16T07:41:15Z")

</div>

Hi all, I have a weird case that i dont know how to fix. I've already setup a fleet server successfully and already enrolling agent to that fleet. But now i want to add another fleet server to the cluster to ensure hig…

---

## [Elastic decay function not working on nested field](https://discuss.elastic.co/t/elastic-decay-function-not-working-on-nested-field/324517)

<div class="topic-metadata">

**Author:** [@AthanatiusC](https://discuss.elastic.co/u/AthanatiusC)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 6:58am UTC](https://discuss.elastic.co/t/elastic-decay-function-not-working-on-nested-field/324517 "2023-02-16T06:58:19Z")

</div>

I have the following configuration: mapping put geo\_test { "mappings":{ "properties":{ "name":{ "type":"text" }, "location":{ "type":"nested", "properties":{ "n…

---

## [Elasticsearch cluster automatically adds transient settings...How do I remove this?](https://discuss.elastic.co/t/elasticsearch-cluster-automatically-adds-transient-settings-how-do-i-remove-this/325353)

<div class="topic-metadata">

**Author:** [@prabhash\_mohanty](https://discuss.elastic.co/u/prabhash_mohanty)\
**Replies:** 4\
**Last updated:** [February 16, 2023, 6:27am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-automatically-adds-transient-settings-how-do-i-remove-this/325353 "2023-02-16T06:27:29Z")

</div>

I have 2 nodes in the cluster log-es-default-0 and log-es-default-1. log-es-default-0 - master node log-es-default-1 - data node I tried running the below command but it still adds it. PUT /\_cluster/settings?pretty {…

---

## [ELK for Jasper](https://discuss.elastic.co/t/elk-for-jasper/325579)

<div class="topic-metadata">

**Author:** [@ELK\_USR1](https://discuss.elastic.co/u/ELK_USR1)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 6:18am UTC](https://discuss.elastic.co/t/elk-for-jasper/325579 "2023-02-16T06:18:11Z")

</div>

I need elk on Jasper application. Can someone guide me to configure.

---

## [Index is not moving to warm phase](https://discuss.elastic.co/t/index-is-not-moving-to-warm-phase/325677)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 5:56am UTC](https://discuss.elastic.co/t/index-is-not-moving-to-warm-phase/325677 "2023-02-16T05:56:09Z")

</div>

I have an index, i have implemented ILM on that. I am not seeing index is not moving to warm phase after reaching out 8 days old. There are no errors to. { "emailer-lifecycle-policy" : { "version" : 1, "modifi…

---

## [One rsyslog port vs multiple syslog ports](https://discuss.elastic.co/t/one-rsyslog-port-vs-multiple-syslog-ports/325668)

<div class="topic-metadata">

**Author:** [@Tiharqa](https://discuss.elastic.co/u/Tiharqa)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 12:24am UTC](https://discuss.elastic.co/t/one-rsyslog-port-vs-multiple-syslog-ports/325668 "2023-02-16T00:24:56Z")

</div>

Trying to decide if I can direct all syslog data from cisco and vmware and f5 to a centralized location running elastic agent as syslog and if elastic supports having multiple integration used would that be ideal set…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=629)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=631)
