# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=649

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 650

---

## [Runtime conditional](https://discuss.elastic.co/t/runtime-conditional/324210)

<div class="topic-metadata">

**Author:** [@LorensiusOksigii](https://discuss.elastic.co/u/LorensiusOksigii)\
**Replies:** 7\
**Last updated:** [January 31, 2023, 6:39pm UTC](https://discuss.elastic.co/t/runtime-conditional/324210 "2023-01-31T18:39:59Z")

</div>

Hi, i get confuse how to set a new value for msg value from message field. i want set if message value == { "msg" : "ICMP flood" }, msg value will show only ICMP flood i have try this but getting error

---

## [TCP input and answer to client](https://discuss.elastic.co/t/tcp-input-and-answer-to-client/324338)

<div class="topic-metadata">

**Author:** [@M\_K1](https://discuss.elastic.co/u/M_K1)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 6:01pm UTC](https://discuss.elastic.co/t/tcp-input-and-answer-to-client/324338 "2023-01-31T18:01:22Z")

</div>

Hello! is it possible to do in logstash? i need to receive strings throuth tcp input and after succssesful recievment i need to answer the client with string for example "ok" or "bad format"

---

## [Elasticsearch and Kibana certificate expired](https://discuss.elastic.co/t/elasticsearch-and-kibana-certificate-expired/323800)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 2\
**Last updated:** [January 31, 2023, 5:29pm UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-certificate-expired/323800 "2023-01-31T17:29:49Z")

</div>

Hi folks, We have 2 Elasticsearch servers and 1 Kibana server. Seem like the certificate has been expired in every servers, so can you help me to how to renew them. Seem like servers already having self sign certificat…

---

## [Solving error 413 when using BulkAllObserver (NEST)](https://discuss.elastic.co/t/solving-error-413-when-using-bulkallobserver-nest/324356)

<div class="topic-metadata">

**Author:** [@Emil](https://discuss.elastic.co/u/Emil)\
**Replies:** 0\
**Last updated:** [January 31, 2023, 4:03pm UTC](https://discuss.elastic.co/t/solving-error-413-when-using-bulkallobserver-nest/324356 "2023-01-31T16:03:51Z")

</div>

I'm using the C# NEST-api to index documents to elastic, with BulkAllObserver as described here: Indexing documents | Elasticsearch .NET Clients \[7.17\] | Elastic My documents are generally a few kB, but can sometimes be…

---

## [Data too large indices:data/read/search\[phase/query](https://discuss.elastic.co/t/data-too-large-indices-data-read-search-phase-query/323770)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 10\
**Last updated:** [January 31, 2023, 3:53pm UTC](https://discuss.elastic.co/t/data-too-large-indices-data-read-search-phase-query/323770 "2023-01-31T15:53:51Z")

</div>

Hi How I can increase such value ? for avoid any disturbance in read data over kibana \[parent\] Data too large, data for \[indices:data/read/search\[phase/query\]\] would be \[4093997030/3.8gb\], which is larger than the …

---

## [Disable fleet setting](https://discuss.elastic.co/t/disable-fleet-setting/323526)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 3:04pm UTC](https://discuss.elastic.co/t/disable-fleet-setting/323526 "2023-01-31T15:04:24Z")

</div>

I have following in my configuration xpack.fleet.agents.enabled: false but log on kibana shows this. why is it still does fleet setup. Am I missing something. \[2023-01-19T14:16:08.293+00:00\]\[INFO \]\[status\] Kibana is n…

---

## [Elastic Platinum License Pricing](https://discuss.elastic.co/t/elastic-platinum-license-pricing/324317)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 2:21pm UTC](https://discuss.elastic.co/t/elastic-platinum-license-pricing/324317 "2023-01-31T14:21:23Z")

</div>

Hello Can someone please help me with info on how to determine the pricing associated with the Platinum license using self-managed ELK instance and how that will vary with the volume of the data or the resources consump…

---

## [Logstash filter split array of json into individual objects](https://discuss.elastic.co/t/logstash-filter-split-array-of-json-into-individual-objects/324245)

<div class="topic-metadata">

**Author:** [@sajjad\_akram](https://discuss.elastic.co/u/sajjad_akram)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 1:43pm UTC](https://discuss.elastic.co/t/logstash-filter-split-array-of-json-into-individual-objects/324245 "2023-01-31T13:43:34Z")

</div>

Hi , iam trying to ingest each json object of array as a new entry/event in dynatrace using logstash. This is my json array {"RequestEventList":\[{"Instant":"2023-01-27T09:00:01.16141Z","RequestKey":"3fcbef69-9-10a608…

---

## [Not able to skip reading oids for down host in logstash Snmp file](https://discuss.elastic.co/t/not-able-to-skip-reading-oids-for-down-host-in-logstash-snmp-file/324335)

<div class="topic-metadata">

**Author:** [@himanshu\_rajput2](https://discuss.elastic.co/u/himanshu_rajput2)\
**Replies:** 0\
**Last updated:** [January 31, 2023, 1:20pm UTC](https://discuss.elastic.co/t/not-able-to-skip-reading-oids-for-down-host-in-logstash-snmp-file/324335 "2023-01-31T13:20:11Z")

</div>

I am using 7.6.2 version of logstash. We are fetching snmp data using walk in logstash conf file. I have used feature of multiple hosts. It is working fine but if any one host is down then it reads all oid for that host …

---

## [Best configuration for 3 Node Cluster](https://discuss.elastic.co/t/best-configuration-for-3-node-cluster/324318)

<div class="topic-metadata">

**Author:** [@sidchaug](https://discuss.elastic.co/u/sidchaug)\
**Replies:** 5\
**Last updated:** [January 31, 2023, 12:55pm UTC](https://discuss.elastic.co/t/best-configuration-for-3-node-cluster/324318 "2023-01-31T12:55:35Z")

</div>

HI There, Currently we having 3 ES nodes(node-1, node-2 and node-3 each of 3TB) , we are creating indexex on daily basic. When we run the command we note that we have 3 PRI & 3 Replicas, is this the best configuration? …

---

## [Kibana control v 8.5.3 does not support scripted fields neither field created in data view](https://discuss.elastic.co/t/kibana-control-v-8-5-3-does-not-support-scripted-fields-neither-field-created-in-data-view/324257)

<div class="topic-metadata">

**Author:** [@monica.brandao](https://discuss.elastic.co/u/monica.brandao)\
**Replies:** 3\
**Last updated:** [January 31, 2023, 12:48pm UTC](https://discuss.elastic.co/t/kibana-control-v-8-5-3-does-not-support-scripted-fields-neither-field-created-in-data-view/324257 "2023-01-31T12:48:29Z")

</div>

In a previous version of Kibana I had some controls that in the new version are deprecated. As I imported the visualizatiosn to the new version, I changed the control to the new verson funcionality,. One of my fields w…

---

## [Dynamical way of getting name and path of Logstash config file](https://discuss.elastic.co/t/dynamical-way-of-getting-name-and-path-of-logstash-config-file/324324)

<div class="topic-metadata">

**Author:** [@sigbo](https://discuss.elastic.co/u/sigbo)\
**Replies:** 0\
**Last updated:** [January 31, 2023, 12:22pm UTC](https://discuss.elastic.co/t/dynamical-way-of-getting-name-and-path-of-logstash-config-file/324324 "2023-01-31T12:22:23Z")

</div>

We have a lot of Logstash configuration files and some handle almost the same data. Along with Logstash we have several other scripts ingesting data into Elasticsearch. Because of the sheer amount, we'd like to be able …

---

## [Error on Running Logstash](https://discuss.elastic.co/t/error-on-running-logstash/324299)

<div class="topic-metadata">

**Author:** [@Meghana1](https://discuss.elastic.co/u/Meghana1)\
**Replies:** 2\
**Last updated:** [January 31, 2023, 11:38am UTC](https://discuss.elastic.co/t/error-on-running-logstash/324299 "2023-01-31T11:38:12Z")

</div>

When I run the following command bin/logstash -f /etc/logstash/logstash-sample.conf . I get the following error runner - An unexpected error occurred! {:error=\>java.nio.file.AccessDeniedException: /usr/share/logstash/…

---

## [Logstash csv export =\> export of unwanted documents multiple times](https://discuss.elastic.co/t/logstash-csv-export-export-of-unwanted-documents-multiple-times/324315)

<div class="topic-metadata">

**Author:** [@SKiD](https://discuss.elastic.co/u/SKiD)\
**Replies:** 0\
**Last updated:** [January 31, 2023, 10:26am UTC](https://discuss.elastic.co/t/logstash-csv-export-export-of-unwanted-documents-multiple-times/324315 "2023-01-31T10:26:44Z")

</div>

Hello, I'm currently experiencing weird behavior of my logstash pipeline. Maybe someone has an idea what I'm currently doing wrong. What I'm trying to do I use a logstash pipeline to extract data from elasticsearch an…

---

## [Logstash unable to process more no of documents](https://discuss.elastic.co/t/logstash-unable-to-process-more-no-of-documents/324213)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [January 31, 2023, 9:44am UTC](https://discuss.elastic.co/t/logstash-unable-to-process-more-no-of-documents/324213 "2023-01-31T09:44:01Z")

</div>

Hello All, I'm tyring to process 40000 documents by running perl script.The issue faced is that in stack management I can see the index being get cereated but the documents are not inserting the index. For a seperate u…

---

## [Elastic Search 8.3 integration Issue with Rest High Client 7.17.6](https://discuss.elastic.co/t/elastic-search-8-3-integration-issue-with-rest-high-client-7-17-6/323035)

<div class="topic-metadata">

**Author:** [@sidchaug](https://discuss.elastic.co/u/sidchaug)\
**Replies:** 6\
**Last updated:** [January 31, 2023, 9:34am UTC](https://discuss.elastic.co/t/elastic-search-8-3-integration-issue-with-rest-high-client-7-17-6/323035 "2023-01-31T09:34:08Z")

</div>

Hi Team, We are currently working on 6.3 Version of ES and 6.4v of RestHighLevelClient we are upgrading to ES 8.3v so the code written in earlier version of ES with RestHigh client we are facing challenges to upgrade. C…

---

## [Why does the query response time optimized significantly after disabling indices.queries.cache.size](https://discuss.elastic.co/t/why-does-the-query-response-time-optimized-significantly-after-disabling-indices-queries-cache-size/324204)

<div class="topic-metadata">

**Author:** [@xiaodid](https://discuss.elastic.co/u/xiaodid)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 8:18am UTC](https://discuss.elastic.co/t/why-does-the-query-response-time-optimized-significantly-after-disabling-indices-queries-cache-size/324204 "2023-01-31T08:18:17Z")

</div>

We have a ES 7.9.16 cluster which has 1 master node and 3 data nodes. Each data node has 31 Gb heap size. We created 2 indexes, each index contains 2.5 billion docs. The query response time is about 1 second while query…

---

## [What is the implication of making a large text field as keyword (using multi-fields)?](https://discuss.elastic.co/t/what-is-the-implication-of-making-a-large-text-field-as-keyword-using-multi-fields/324224)

<div class="topic-metadata">

**Author:** [@DarwinGoyal](https://discuss.elastic.co/u/DarwinGoyal)\
**Replies:** 4\
**Last updated:** [January 31, 2023, 8:07am UTC](https://discuss.elastic.co/t/what-is-the-implication-of-making-a-large-text-field-as-keyword-using-multi-fields/324224 "2023-01-31T08:07:55Z")

</div>

What are the considerations that I should take into account while making a field as keyword? To provide some search capabilities I need to make a text field as keyword. I am not sure if there are any performance implica…

---

## [How to add password authorization](https://discuss.elastic.co/t/how-to-add-password-authorization/323713)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 14\
**Last updated:** [January 31, 2023, 7:52am UTC](https://discuss.elastic.co/t/how-to-add-password-authorization/323713 "2023-01-31T07:52:15Z")

</div>

Hi I've setup elk stack version 8.6.0. I've disabled authorization initially because ive installed it using a ansible playbook. by any way can i setup authorization from front end after i access kibana from front end?

---

## [Cluster\_block\_exception does not allow me to delete an index](https://discuss.elastic.co/t/cluster-block-exception-does-not-allow-me-to-delete-an-index/324218)

<div class="topic-metadata">

**Author:** [@DarwinGoyal](https://discuss.elastic.co/u/DarwinGoyal)\
**Replies:** 6\
**Last updated:** [January 31, 2023, 7:50am UTC](https://discuss.elastic.co/t/cluster-block-exception-does-not-allow-me-to-delete-an-index/324218 "2023-01-31T07:50:46Z")

</div>

I created one index with "blocks.metadata": true. PUT darwin-test-shard/\_settings { "blocks.metadata": true } Now whenever I try to access \_cat/indices, I get { "error" : { "root\_cause" : \[ { "ty…

---

## [Issue about starting beats](https://discuss.elastic.co/t/issue-about-starting-beats/324176)

<div class="topic-metadata">

**Author:** [@chris3](https://discuss.elastic.co/u/chris3)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 7:30am UTC](https://discuss.elastic.co/t/issue-about-starting-beats/324176 "2023-01-31T07:30:35Z")

</div>

Hi All, I was wondering if you can advise on this issue I am getting with starting the beats or if anyone has seen this issue before. I have created a virtual machine on virtual box with an Ubuntu OS. I have tried to s…

---

## [Elasticsearch Question, Disable nesting](https://discuss.elastic.co/t/elasticsearch-question-disable-nesting/324207)

<div class="topic-metadata">

**Author:** [@tglanz](https://discuss.elastic.co/u/tglanz)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 7:02am UTC](https://discuss.elastic.co/t/elasticsearch-question-disable-nesting/324207 "2023-01-31T07:02:19Z")

</div>

Hi, I have a scenario with documents of the form: { "field": "some value", "properties": { "a": "some value of a", "a.b": "some value of a.b" } } I would like to have the following capabilities: Search…

---

## [Migration via snapshot from ELK to ECK 7.17](https://discuss.elastic.co/t/migration-via-snapshot-from-elk-to-eck-7-17/324046)

<div class="topic-metadata">

**Author:** [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Replies:** 2\
**Last updated:** [January 31, 2023, 6:52am UTC](https://discuss.elastic.co/t/migration-via-snapshot-from-elk-to-eck-7-17/324046 "2023-01-31T06:52:01Z")

</div>

We are in the process of migrating our indices from an ELK version to an ECK version on k8. We took a snapshot of the indices and when we restored them on ECK all the indices were in red state and the error was no\_shard\_…

---

## [Which is faster? Redis or Elastic](https://discuss.elastic.co/t/which-is-faster-redis-or-elastic/323779)

<div class="topic-metadata">

**Author:** [@MaralErdene\_Tumursuh](https://discuss.elastic.co/u/MaralErdene_Tumursuh)\
**Replies:** 2\
**Last updated:** [January 31, 2023, 6:50am UTC](https://discuss.elastic.co/t/which-is-faster-redis-or-elastic/323779 "2023-01-31T06:50:26Z")

</div>

This is weird question. But I want to clear my confusion. Currently, my app using elastic for displaying list. if i use Redis when user first time fetching data, will my performance is speed up? Thanks in advance.

---

## [Kibana watcher help](https://discuss.elastic.co/t/kibana-watcher-help/323844)

<div class="topic-metadata">

**Author:** [@furkano](https://discuss.elastic.co/u/furkano)\
**Replies:** 19\
**Last updated:** [January 31, 2023, 6:25am UTC](https://discuss.elastic.co/t/kibana-watcher-help/323844 "2023-01-31T06:25:54Z")

</div>

Hi, I want to create watcher and the condition if there is same at least 10 messages in the field X for 10 minutes i need an alert, I couldn't find any documentary for this sample, should it been done with script? Tha…

---

## [Join queries or filter queries across indices](https://discuss.elastic.co/t/join-queries-or-filter-queries-across-indices/324275)

<div class="topic-metadata">

**Author:** [@H-Soni](https://discuss.elastic.co/u/H-Soni)\
**Replies:** 12\
**Last updated:** [January 31, 2023, 6:19am UTC](https://discuss.elastic.co/t/join-queries-or-filter-queries-across-indices/324275 "2023-01-31T06:19:44Z")

</div>

Hi, We are thinking of a document model, where we have data in multiple indices. However, when querying that data, we have to perform a join operation on these indices or to be more precise, filter an index's data using…

---

## [RemoteTransportException](https://discuss.elastic.co/t/remotetransportexception/324083)

<div class="topic-metadata">

**Author:** [@Abhinav\_Raj](https://discuss.elastic.co/u/Abhinav_Raj)\
**Replies:** 11\
**Last updated:** [January 31, 2023, 6:09am UTC](https://discuss.elastic.co/t/remotetransportexception/324083 "2023-01-31T06:09:58Z")

</div>

Hi , what is this error saying. I am getting it multiple times . org.elasticsearch.transport.RemoteTransportException: \[indices:data/read/search\[phase/query\]\] Caused by: org.elasticsearch.search.query.QueryPhaseExecuti…

---

## [Lifecycle action \[migrate\] waiting for \[1\] shards to be moved to the \[data\_warm\] tier (tier migration preference configuration is \[data\_warm, data\_hot\])](https://discuss.elastic.co/t/lifecycle-action-migrate-waiting-for-1-shards-to-be-moved-to-the-data-warm-tier-tier-migration-preference-configuration-is-data-warm-data-hot/323915)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 2\
**Last updated:** [January 31, 2023, 5:40am UTC](https://discuss.elastic.co/t/lifecycle-action-migrate-waiting-for-1-shards-to-be-moved-to-the-data-warm-tier-tier-migration-preference-configuration-is-data-warm-data-hot/323915 "2023-01-31T05:40:25Z")

</div>

I have set ILM policy as { "aggregations-lifecycle-policy":{ "version":2, "modified\_date":"2023-01-25T08:51:42.054Z", "policy":{ "phases":{ "warm":{ …

---

## [Heartbeat Ping](https://discuss.elastic.co/t/heartbeat-ping/324132)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 1\
**Last updated:** [January 31, 2023, 5:22am UTC](https://discuss.elastic.co/t/heartbeat-ping/324132 "2023-01-31T05:22:57Z")

</div>

Hi Team, I have installed heartbeat on few VMs to monitor icmp. However, if the agent stops the data stops coming from the node. However, i want to get notified that the host is down. How can i achieve the same? Kindly…

---

## [How to use FSCrawler with Azure Blob Storage?](https://discuss.elastic.co/t/how-to-use-fscrawler-with-azure-blob-storage/324163)

<div class="topic-metadata">

**Author:** [@AbderrahimAl](https://discuss.elastic.co/u/AbderrahimAl)\
**Replies:** 3\
**Last updated:** [January 29, 2023, 1:30pm UTC](https://discuss.elastic.co/t/how-to-use-fscrawler-with-azure-blob-storage/324163 "2023-01-29T13:30:49Z")

</div>

I want to index the documents stored in Azure Blob Storage into Elasticsearch. Is it possible to use FSCrawler in this case by providing the blob container URL?

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=648)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=650)
