# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=632

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 633

---

## [Limit of total fields \[1000\] in index has been exceeded after changing case classes to maps](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded-after-changing-case-classes-to-maps/325635)

<div class="topic-metadata">

**Author:** [@markcitizen](https://discuss.elastic.co/u/markcitizen)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 3:19pm UTC](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded-after-changing-case-classes-to-maps/325635 "2023-02-15T15:19:34Z")

</div>

Hello, I have a Scala Spark job that's writing output data to ES index. I modified my code to recursively convert Scala classes into Maps before writing those to the index. Before (when using case classes) index write w…

---

## [When to clear es cache?](https://discuss.elastic.co/t/when-to-clear-es-cache/325428)

<div class="topic-metadata">

**Author:** [@elastic-db-user](https://discuss.elastic.co/u/elastic-db-user)\
**Replies:** 8\
**Last updated:** [February 15, 2023, 2:59pm UTC](https://discuss.elastic.co/t/when-to-clear-es-cache/325428 "2023-02-15T14:59:45Z")

</div>

Is it a good idea to proactively clear all cache with a daily cron job to avoid any circuit breaker or any other memory related issues? Api calls from app to Elasticsearch are the same query e.g. count, histogram, get, …

---

## [Bar horizontal percentage chart from boolean](https://discuss.elastic.co/t/bar-horizontal-percentage-chart-from-boolean/325619)

<div class="topic-metadata">

**Author:** [@fbaer](https://discuss.elastic.co/u/fbaer)\
**Replies:** 2\
**Last updated:** [February 15, 2023, 2:52pm UTC](https://discuss.elastic.co/t/bar-horizontal-percentage-chart-from-boolean/325619 "2023-02-15T14:52:48Z")

</div>

I am retrieving a boolean field from my logs. Now i want to show this field as horizontal bar in percent with two colors green for true and red for false. It would be great if there was one bar showing the percentage of …

---

## [Kibana does not log all lines as json](https://discuss.elastic.co/t/kibana-does-not-log-all-lines-as-json/325627)

<div class="topic-metadata">

**Author:** [@woodywoodsta](https://discuss.elastic.co/u/woodywoodsta)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 2:36pm UTC](https://discuss.elastic.co/t/kibana-does-not-log-all-lines-as-json/325627 "2023-02-15T14:36:24Z")

</div>

I have Kibana deployed as an ECK resource. Despite the following config: config: logging: appenders: json-layout: type: console layout: type: json root: appenders: \[json-…

---

## [Config Auditbeat](https://discuss.elastic.co/t/config-auditbeat/325519)

<div class="topic-metadata">

**Author:** [@CodeRed](https://discuss.elastic.co/u/CodeRed)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 10:37pm UTC](https://discuss.elastic.co/t/config-auditbeat/325519 "2023-02-14T22:37:07Z")

</div>

Currently i am experimenting with auditbeat the config process i want to collect the whole log due to the auditd rules i added but the log i get is no log auditd here is my config file auditbeat.modules: module: audi…

---

## [Some indexes stopped to rollover and are now created without alias](https://discuss.elastic.co/t/some-indexes-stopped-to-rollover-and-are-now-created-without-alias/325623)

<div class="topic-metadata">

**Author:** [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 2:08pm UTC](https://discuss.elastic.co/t/some-indexes-stopped-to-rollover-and-are-now-created-without-alias/325623 "2023-02-15T14:08:59Z")

</div>

Hello, Some weeks ago, I had a full disk problem on my dev cluster. I made some space, reactivated index writing with PUT /\_all/\_settings { "index.blocks.read\_only\_allow\_delete": null } Most of the indexes are doin…

---

## [Elastic agent on eks](https://discuss.elastic.co/t/elastic-agent-on-eks/324903)

<div class="topic-metadata">

**Author:** [@oded\_rafi](https://discuss.elastic.co/u/oded_rafi)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 1:48pm UTC](https://discuss.elastic.co/t/elastic-agent-on-eks/324903 "2023-02-15T13:48:27Z")

</div>

hey all i am trying to run an agent on my eks cluster and the pods wont run i am using the code from elastic as is. could anyone help? --- # For more information refer to https://www.elastic.co/guide/en/fleet/current…

---

## [Elastic Agent not shipping all logs from Kubernetes Cluster. Errors in logs](https://discuss.elastic.co/t/elastic-agent-not-shipping-all-logs-from-kubernetes-cluster-errors-in-logs/325620)

<div class="topic-metadata">

**Author:** [@slogger](https://discuss.elastic.co/u/slogger)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 1:44pm UTC](https://discuss.elastic.co/t/elastic-agent-not-shipping-all-logs-from-kubernetes-cluster-errors-in-logs/325620 "2023-02-15T13:44:55Z")

</div>

Hello I have Elastic Agent installed on 5 EKS clusters for logging and monitoring. Recently the agents have stopped shipping all logs to the cluster (Hosted with elastic.cloud). Im seeing some logs, but not all (usual…

---

## [Designing a visualisation for success/failure of processes](https://discuss.elastic.co/t/designing-a-visualisation-for-success-failure-of-processes/324634)

<div class="topic-metadata">

**Author:** [@PetervH](https://discuss.elastic.co/u/PetervH)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 1:38pm UTC](https://discuss.elastic.co/t/designing-a-visualisation-for-success-failure-of-processes/324634 "2023-02-15T13:38:39Z")

</div>

Hi Can someone suggest a way to achieve the following: I'm getting a constant stream of events from a source. These events include data that specifies whether a particular process has completed successfully, as indicat…

---

## [Fleet server lose agents at restart](https://discuss.elastic.co/t/fleet-server-lose-agents-at-restart/325477)

<div class="topic-metadata">

**Author:** [@K8pl3r](https://discuss.elastic.co/u/K8pl3r)\
**Replies:** 5\
**Last updated:** [February 15, 2023, 1:13pm UTC](https://discuss.elastic.co/t/fleet-server-lose-agents-at-restart/325477 "2023-02-15T13:13:52Z")

</div>

Hello I'm a student who's getting started with Elastic, I have configured my stack with elasticsearch and Kibana. I have an issue when I reboot my fleet server, all of my elastic-agents are offline (I have enabled the …

---

## [Elasticsearch.service craches (Active: failed) every 1,2 days](https://discuss.elastic.co/t/elasticsearch-service-craches-active-failed-every-1-2-days/325373)

<div class="topic-metadata">

**Author:** [@Ziad\_Khater](https://discuss.elastic.co/u/Ziad_Khater)\
**Replies:** 12\
**Last updated:** [February 15, 2023, 12:42pm UTC](https://discuss.elastic.co/t/elasticsearch-service-craches-active-failed-every-1-2-days/325373 "2023-02-15T12:42:09Z")

</div>

Hi Team, every 1,2 days elasticsearch.service failed on my ubunto machine. It has all memory/disk resources it needs. I'll attach logs here and below is the failed status of elasticsearch. ===========================…

---

## [Multiline filter is not working even after installing the plugin](https://discuss.elastic.co/t/multiline-filter-is-not-working-even-after-installing-the-plugin/325611)

<div class="topic-metadata">

**Author:** [@Balaguru\_Maruthamuth](https://discuss.elastic.co/u/Balaguru_Maruthamuth)\
**Replies:** 2\
**Last updated:** [February 15, 2023, 12:44pm UTC](https://discuss.elastic.co/t/multiline-filter-is-not-working-even-after-installing-the-plugin/325611 "2023-02-15T12:44:36Z")

</div>

Warning: Manual override - there are filters that might not work with multiple worker threads {:pipeline\_id=\>"exterro", :worker\_threads=\>3, :filters=\>\["multiline", "multiline", "multiline", "multiline", "multiline", "mul…

---

## [Change time zone using date filter](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [February 15, 2023, 12:37pm UTC](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461 "2023-02-15T12:37:36Z")

</div>

Hi there, i have a problem with timezone in date filter. so this is the situation: i have a field contain an epoch timestamp like this i try to convert it using date filter like this but it didn't work mutate{ …

---

## [Problems using search\_fields and weighting in queries](https://discuss.elastic.co/t/problems-using-search-fields-and-weighting-in-queries/325610)

<div class="topic-metadata">

**Author:** [@bar8s](https://discuss.elastic.co/u/bar8s)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 12:35pm UTC](https://discuss.elastic.co/t/problems-using-search-fields-and-weighting-in-queries/325610 "2023-02-15T12:35:34Z")

</div>

I am trying to query an Elasticsearch index with some dynamic weighting on specific fields, but the query parser is rejecting the query I am basing this on the documentation at Relevance Tuning Guide, Weights and Boosts…

---

## [Synonyms Exact match Multiword Search](https://discuss.elastic.co/t/synonyms-exact-match-multiword-search/325439)

<div class="topic-metadata">

**Author:** [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 12:34pm UTC](https://discuss.elastic.co/t/synonyms-exact-match-multiword-search/325439 "2023-02-15T12:34:42Z")

</div>

Hi Team, We are looking for solution to search synonyms with exact match. For Example User is searching string - abc xyz abc has synonyms - abc1 abc2 xyz has synonyms - xyz1 xyz2 Data in Index Article1 - test abc1 …

---

## [Column count doesn't match after doing alias](https://discuss.elastic.co/t/column-count-doesnt-match-after-doing-alias/325454)

<div class="topic-metadata">

**Author:** [@Rushikesh\_Dikey](https://discuss.elastic.co/u/Rushikesh_Dikey)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 10:37am UTC](https://discuss.elastic.co/t/column-count-doesnt-match-after-doing-alias/325454 "2023-02-15T10:37:23Z")

</div>

Hi Team, I am trying to merge two different index, so i used // POST /\_aliases { "actions": \[ { "add": { "index": "abc", "alias": "poc" } }, { "add": { "index": "xyz", …

---

## [Logs, metrics and APM on Solaris, HPUX - I know it's not supported - but related question anyway](https://discuss.elastic.co/t/logs-metrics-and-apm-on-solaris-hpux-i-know-its-not-supported-but-related-question-anyway/325598)

<div class="topic-metadata">

**Author:** [@Melee](https://discuss.elastic.co/u/Melee)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 10:30am UTC](https://discuss.elastic.co/t/logs-metrics-and-apm-on-solaris-hpux-i-know-its-not-supported-but-related-question-anyway/325598 "2023-02-15T10:30:29Z")

</div>

Hello together, we are using the elastic stack (elastic agent, APM agent, heartbeat, logstash, kibana). So far so fine. Now, we have some legacy systems esp. Solaris, HPUX and also RHEL 6. There were already multiple …

---

## [Vega-lite, create a forecast similar as lens visualization](https://discuss.elastic.co/t/vega-lite-create-a-forecast-similar-as-lens-visualization/323572)

<div class="topic-metadata">

**Author:** [@plus](https://discuss.elastic.co/u/plus)\
**Replies:** 7\
**Last updated:** [February 15, 2023, 10:05am UTC](https://discuss.elastic.co/t/vega-lite-create-a-forecast-similar-as-lens-visualization/323572 "2023-02-15T10:05:12Z")

</div>

Hello everyone I have a question with vega-lite and I don't know how to follow up. I checked on lens I can see data from last 2 hours and next 4 hours on the same graphic (a forecast job has been launched previously to …

---

## [Remote Linux logs](https://discuss.elastic.co/t/remote-linux-logs/325578)

<div class="topic-metadata">

**Author:** [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 9:48am UTC](https://discuss.elastic.co/t/remote-linux-logs/325578 "2023-02-15T09:48:42Z")

</div>

Is there no way to use Elastic Agent or Filebeat to accept TCP Syslog messages forwarded from Linux hosts? Will I need to use something like rsyslog or Logstash to write the files to disk first, then use the system inte…

---

## [Log4j add more fields](https://discuss.elastic.co/t/log4j-add-more-fields/325546)

<div class="topic-metadata">

**Author:** [@manusha\_karunathilak](https://discuss.elastic.co/u/manusha_karunathilak)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 6:18am UTC](https://discuss.elastic.co/t/log4j-add-more-fields/325546 "2023-02-15T06:18:53Z")

</div>

I have setup to write log4j logs to elasticsearch. However it only maps log4j default fields such as level, message and etc. Full log message contains session id in the console log but that part is not mapped by default…

---

## [Conflicting Field Elasticsearch host.ip in metrics\*-\* Index Pattern](https://discuss.elastic.co/t/conflicting-field-elasticsearch-host-ip-in-metrics-index-pattern/325539)

<div class="topic-metadata">

**Author:** [@OmFJ](https://discuss.elastic.co/u/OmFJ)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 8:27am UTC](https://discuss.elastic.co/t/conflicting-field-elasticsearch-host-ip-in-metrics-index-pattern/325539 "2023-02-15T08:27:32Z")

</div>

Hello Everyone, in this topic, i would like to ask about conflicting field. From all discussions and forum i visited most of them tell you to re-index your index. but i come across this problem where the conflicting fie…

---

## [How to develop Kibana custom plugin to add a custom agg type in Kibana Platform?](https://discuss.elastic.co/t/how-to-develop-kibana-custom-plugin-to-add-a-custom-agg-type-in-kibana-platform/325556)

<div class="topic-metadata">

**Author:** [@gnehcnij](https://discuss.elastic.co/u/gnehcnij)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 8:06am UTC](https://discuss.elastic.co/t/how-to-develop-kibana-custom-plugin-to-add-a-custom-agg-type-in-kibana-platform/325556 "2023-02-15T08:06:28Z")

</div>

I want to update Kibana from v6.8.23 to v7.17.8, but the plugin kibana-datasweet-formula that I want to migrate to Kibana Platform do not work (Installation failed). I found this place to register each agg type: but…

---

## [Elastic Upgrade Issue](https://discuss.elastic.co/t/elastic-upgrade-issue/325470)

<div class="topic-metadata">

**Author:** [@cobdeng](https://discuss.elastic.co/u/cobdeng)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 7:30am UTC](https://discuss.elastic.co/t/elastic-upgrade-issue/325470 "2023-02-15T07:30:44Z")

</div>

Hi We are currently using Elasticsearch 7.16.2 and are now looking at the upgrade process to 7.16.3 and upwards. When we initially installed Elasticsearch, we used the msi installers that were then available as we are …

---

## [Custom plugin and custom entries in /etc/default/logstash gets deleted after each update on ubuntu](https://discuss.elastic.co/t/custom-plugin-and-custom-entries-in-etc-default-logstash-gets-deleted-after-each-update-on-ubuntu/325549)

<div class="topic-metadata">

**Author:** [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 6:44am UTC](https://discuss.elastic.co/t/custom-plugin-and-custom-entries-in-etc-default-logstash-gets-deleted-after-each-update-on-ubuntu/325549 "2023-02-15T06:44:03Z")

</div>

Hello All, I wanted a to ask if anybody knows why after almost each apt-get update/upgrate on my server two output plugins always gets deleted and I need to reinstall them along with all custom Logstash entries in /etc/…

---

## [Bash: ./bin/elasticsearch: No such file or directory](https://discuss.elastic.co/t/bash-bin-elasticsearch-no-such-file-or-directory/325506)

<div class="topic-metadata">

**Author:** [@samidha\_dubey](https://discuss.elastic.co/u/samidha_dubey)\
**Replies:** 2\
**Last updated:** [February 15, 2023, 6:40am UTC](https://discuss.elastic.co/t/bash-bin-elasticsearch-no-such-file-or-directory/325506 "2023-02-15T06:40:11Z")

</div>

Hello i am facing issue while setting up users for my ELK stack, I setup ELK on docker so my ELK is running as a docker container i used sebp/elk image and my container is running fine i can access kibana dashboard, i …

---

## [Update\_by\_query - empty failures list in response when conflicts=proceed](https://discuss.elastic.co/t/update-by-query-empty-failures-list-in-response-when-conflicts-proceed/325100)

<div class="topic-metadata">

**Author:** [@Przemyslaw\_Mantaj](https://discuss.elastic.co/u/Przemyslaw_Mantaj)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 5:51am UTC](https://discuss.elastic.co/t/update-by-query-empty-failures-list-in-response-when-conflicts-proceed/325100 "2023-02-15T05:51:30Z")

</div>

Continuing the discussion from Update\_by\_query with proceed does not return failure: I repeat @Paul\_Le\_Tilly question. Is it possible to return the failures list when the conflicts option has been set to proceed? Than…

---

## [Incorrect Filebeat Metrics](https://discuss.elastic.co/t/incorrect-filebeat-metrics/325540)

<div class="topic-metadata">

**Author:** [@vinit0711](https://discuss.elastic.co/u/vinit0711)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 5:19am UTC](https://discuss.elastic.co/t/incorrect-filebeat-metrics/325540 "2023-02-15T05:19:34Z")

</div>

I have Netflow Input For Filebeat . Fiebeat is processing the flow and sending to Elastic. I am receiving following metric logs From filebeat which are generated after every 30s {"monitoring":{"metrics":{"beat":{"cgrou…

---

## [How to search file path field value in Kibana?](https://discuss.elastic.co/t/how-to-search-file-path-field-value-in-kibana/325538)

<div class="topic-metadata">

**Author:** [@First\_Last](https://discuss.elastic.co/u/First_Last)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 4:51am UTC](https://discuss.elastic.co/t/how-to-search-file-path-field-value-in-kibana/325538 "2023-02-15T04:51:59Z")

</div>

New to Kibana and need some help understanding escaping special characters. Basically what I'm trying to do is take what I know in splunk and wildcard searching substrings of eventlog fields. Below is what I tried but re…

---

## [Error importing Kibana dashboards: fail to import the dashboards in Kibana:](https://discuss.elastic.co/t/error-importing-kibana-dashboards-fail-to-import-the-dashboards-in-kibana/316015)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 6\
**Last updated:** [February 15, 2023, 4:16am UTC](https://discuss.elastic.co/t/error-importing-kibana-dashboards-fail-to-import-the-dashboards-in-kibana/316015 "2023-02-15T04:16:07Z")

</div>

I'm having errors when running the command to check the version information. To load dashboards when Logstash is enabled, you need to disable Logstash output and enable Elasticsearch output: Follow the command and error…

---

## [Elasticsearch + Java - Inconsistent Search/Query time](https://discuss.elastic.co/t/elasticsearch-java-inconsistent-search-query-time/325527)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 3:38am UTC](https://discuss.elastic.co/t/elasticsearch-java-inconsistent-search-query-time/325527 "2023-02-15T03:38:35Z")

</div>

We are searching over 10million documents with a simple query that contains bool and multiple shoulds. But query time is inconsistent- taking sometimes 100ms sometimes 4 seconds. How can we tune this so that query time …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=631)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=633)
