# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=660

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 661

---

## [Discard non-letter characters during Completion Suggestor indexing](https://discuss.elastic.co/t/discard-non-letter-characters-during-completion-suggestor-indexing/323561)

<div class="topic-metadata">

**Author:** [@vikk](https://discuss.elastic.co/u/vikk)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 3:58am UTC](https://discuss.elastic.co/t/discard-non-letter-characters-during-completion-suggestor-indexing/323561 "2023-01-20T03:58:31Z")

</div>

Here's my index: PUT autocomplete-food { "mappings": { "properties": { "suggest": { "type": "completion" } } } } Adding a document to this index: PUT autocomplete-food/\_doc/1?refresh { …

---

## [How to get enrollment token when re-install Elasticsearch to Windows](https://discuss.elastic.co/t/how-to-get-enrollment-token-when-re-install-elasticsearch-to-windows/323314)

<div class="topic-metadata">

**Author:** [@oga](https://discuss.elastic.co/u/oga)\
**Replies:** 2\
**Last updated:** [January 20, 2023, 3:36am UTC](https://discuss.elastic.co/t/how-to-get-enrollment-token-when-re-install-elasticsearch-to-windows/323314 "2023-01-20T03:36:08Z")

</div>

When installing Elasticsarch8.6 on Windows, after runnning elasticsearch.bat I forgot to write down the enrollment token. To get the enrollment token,delete the elasticsearch directory and unzip the elasticsearch an…

---

## [In Docker swarm environment, Kibana not running](https://discuss.elastic.co/t/in-docker-swarm-environment-kibana-not-running/323559)

<div class="topic-metadata">

**Author:** [@hzdtony](https://discuss.elastic.co/u/hzdtony)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 2:35am UTC](https://discuss.elastic.co/t/in-docker-swarm-environment-kibana-not-running/323559 "2023-01-20T02:35:36Z")

</div>

My docker swarm have two node, follow as I has deploy elk in my dokcer swarm In the docker swarm, depends\_on not avaiable. so beyond control service start order. As a result kibana\_system user unable create.…

---

## [Vulnerabilities Related to Java (in January 2023.)](https://discuss.elastic.co/t/vulnerabilities-related-to-java-in-january-2023/323557)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 2\
**Last updated:** [January 20, 2023, 2:33am UTC](https://discuss.elastic.co/t/vulnerabilities-related-to-java-in-january-2023/323557 "2023-01-20T02:33:39Z")

</div>

Oracle released "Critical Patch Updates, Security Alerts and Bulletins" in January 2023. These include vulnerabilities involving Java. Is there any official word on the impact on Elastic products? cf.

---

## [How to do Calculation in Elasticsearch Query](https://discuss.elastic.co/t/how-to-do-calculation-in-elasticsearch-query/323496)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [January 20, 2023, 1:39am UTC](https://discuss.elastic.co/t/how-to-do-calculation-in-elasticsearch-query/323496 "2023-01-20T01:39:44Z")

</div>

Hi there, to continue discussion below, I decided to create a new topic. please read the topic below first so you can understand it. OK, so the next question is how if i use elasticsearch query to calculate expire dat…

---

## [Bool query with boost for should clause](https://discuss.elastic.co/t/bool-query-with-boost-for-should-clause/323555)

<div class="topic-metadata">

**Author:** [@seeminglee](https://discuss.elastic.co/u/seeminglee)\
**Replies:** 1\
**Last updated:** [January 20, 2023, 1:33am UTC](https://discuss.elastic.co/t/bool-query-with-boost-for-should-clause/323555 "2023-01-20T01:33:55Z")

</div>

How can you add boost to specific part of a should query. For example: { "query": { "bool": { "should": \[ {"term":{"fruit.keyword":"apple"}}, {"term":{"fruit.keyword":"banana"}}, {"te…

---

## [Reindexing the data from an existing index to new index with Completion fields](https://discuss.elastic.co/t/reindexing-the-data-from-an-existing-index-to-new-index-with-completion-fields/323471)

<div class="topic-metadata">

**Author:** [@Vaibhav\_Sinha](https://discuss.elastic.co/u/Vaibhav_Sinha)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 4:53am UTC](https://discuss.elastic.co/t/reindexing-the-data-from-an-existing-index-to-new-index-with-completion-fields/323471 "2023-01-19T04:53:38Z")

</div>

Hey Team, I need some help reindexing the data from an existing Index (keyword/string-based fields) to a new index with fields of type Completion. I have created the new index to be used for Completion Suggesters with …

---

## [Custom code for pagination in Logstash](https://discuss.elastic.co/t/custom-code-for-pagination-in-logstash/323474)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 11:00pm UTC](https://discuss.elastic.co/t/custom-code-for-pagination-in-logstash/323474 "2023-01-19T23:00:08Z")

</div>

Hello there ! I am fetching some data using the vRealize api, I want to add pagination using the custom code. which programming language can I use and how can I achieve this ? Can someone please help me with this !

---

## [Elastic fleet server fails to install after 8.6.0](https://discuss.elastic.co/t/elastic-fleet-server-fails-to-install-after-8-6-0/323063)

<div class="topic-metadata">

**Author:** [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Replies:** 6\
**Last updated:** [January 19, 2023, 10:39pm UTC](https://discuss.elastic.co/t/elastic-fleet-server-fails-to-install-after-8-6-0/323063 "2023-01-19T22:39:23Z")

</div>

"Fleet Server - Waiting on fleet-server input to be added to default policy","ecs.version":"1.6.0"} {"log.level":"info","@timestamp":"2023-01-12T12:57:55.988-0800","log.origin":{"file.name":"cmd/enroll\_cmd.go","file.lin…

---

## [My cluster frequently has shards on initializing\_shards](https://discuss.elastic.co/t/my-cluster-frequently-has-shards-on-initializing-shards/323446)

<div class="topic-metadata">

**Author:** [@Lohanna\_Sarah](https://discuss.elastic.co/u/Lohanna_Sarah)\
**Replies:** 12\
**Last updated:** [January 19, 2023, 9:57pm UTC](https://discuss.elastic.co/t/my-cluster-frequently-has-shards-on-initializing-shards/323446 "2023-01-19T21:57:03Z")

</div>

My cluster frequently has shards in the initializing\_shards state. The cluster is running on ks8. Exists any fix that I could do to fix it? The data nodes are restarted at least once a day

---

## [Fleet server stuck upgrading 8.5.3 -\> 8.6.0](https://discuss.elastic.co/t/fleet-server-stuck-upgrading-8-5-3-8-6-0/323204)

<div class="topic-metadata">

**Author:** [@rossw](https://discuss.elastic.co/u/rossw)\
**Replies:** 5\
**Last updated:** [January 19, 2023, 8:01pm UTC](https://discuss.elastic.co/t/fleet-server-stuck-upgrading-8-5-3-8-6-0/323204 "2023-01-19T20:01:33Z")

</div>

Our fleet server runs on our kibana server, with about 20 agents connected. We upgrade our Elastic cluster from 8.5.3 to 8.6.0 and the upgrade popped up in the fleet UI just fine. Selected the fleet server for the upgra…

---

## [Elastic Search for Frequent Location Updates](https://discuss.elastic.co/t/elastic-search-for-frequent-location-updates/323542)

<div class="topic-metadata">

**Author:** [@nsarvesh](https://discuss.elastic.co/u/nsarvesh)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 7:32pm UTC](https://discuss.elastic.co/t/elastic-search-for-frequent-location-updates/323542 "2023-01-19T19:32:03Z")

</div>

Hi Team, We are planning to build a calendar application with Location-based Search Capabilities. We want to store the user availability and the geolocation. Eg: { User: "foo" day: "Jan-19-2022…

---

## [Auditbeat 7.17.8 high cpu usage during data transfer with system socket dataset](https://discuss.elastic.co/t/auditbeat-7-17-8-high-cpu-usage-during-data-transfer-with-system-socket-dataset/323540)

<div class="topic-metadata">

**Author:** [@opoplawski](https://discuss.elastic.co/u/opoplawski)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 7:10pm UTC](https://discuss.elastic.co/t/auditbeat-7-17-8-high-cpu-usage-during-data-transfer-with-system-socket-dataset/323540 "2023-01-19T19:10:19Z")

</div>

I'm running auditbeat-7.17.8-1.x86\_64 on AlmaLinux release 8.7 on one of our file servers. I just noticed that while running an rsync transfer to that machine auditbeat is consuming between 100-200% cpu. It is not outp…

---

## [How to pipe results from one data view to other data view in KQL?](https://discuss.elastic.co/t/how-to-pipe-results-from-one-data-view-to-other-data-view-in-kql/323539)

<div class="topic-metadata">

**Author:** [@Arun\_Kulanthaivel](https://discuss.elastic.co/u/Arun_Kulanthaivel)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 6:48pm UTC](https://discuss.elastic.co/t/how-to-pipe-results-from-one-data-view-to-other-data-view-in-kql/323539 "2023-01-19T18:48:56Z")

</div>

Hi, i have two data views in kibana one logs-apigee-\* and other logs-epm-. we have a field "type" in logs-apigee- i want to get from logs-epm-\* for a given date range with all type from logs-apigee-\*. is there any way …

---

## [Reindex API: An unexpected authentication error occurred](https://discuss.elastic.co/t/reindex-api-an-unexpected-authentication-error-occurred/323538)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 6:39pm UTC](https://discuss.elastic.co/t/reindex-api-an-unexpected-authentication-error-occurred/323538 "2023-01-19T18:39:59Z")

</div>

Hello everyone, I'm trying to migrate an index from Cluster A to Cluster B using the Reindex from remote Add each ip segment in my whitelist in both cluster: reindex.remote.whitelist: \["123.176.49.\*:9200","123.188.49.…

---

## [Reliable way to see all hosts in environment?](https://discuss.elastic.co/t/reliable-way-to-see-all-hosts-in-environment/323530)

<div class="topic-metadata">

**Author:** [@Mahigs](https://discuss.elastic.co/u/Mahigs)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 4:51pm UTC](https://discuss.elastic.co/t/reliable-way-to-see-all-hosts-in-environment/323530 "2023-01-19T16:51:23Z")

</div>

I am trying to build out a dashboard showing all the hosts that are sending logs in our environment while also having a panel that shows when a host stops sending logs and the last time they sent a log. I took a look at…

---

## [Elasticsearch windows server high split i/o and service restart](https://discuss.elastic.co/t/elasticsearch-windows-server-high-split-i-o-and-service-restart/323147)

<div class="topic-metadata">

**Author:** [@elastic101](https://discuss.elastic.co/u/elastic101)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 4:39pm UTC](https://discuss.elastic.co/t/elasticsearch-windows-server-high-split-i-o-and-service-restart/323147 "2023-01-19T16:39:08Z")

</div>

Hello, We are using an app that has Elasticsearch database. The version is old and we are seeing a lot of issues lately. The split I/O increases to 50% + and the service becomes unresponsive. Below are the cluster detai…

---

## [Incorrect JSON logs parsing](https://discuss.elastic.co/t/incorrect-json-logs-parsing/323447)

<div class="topic-metadata">

**Author:** [@ira-zaya](https://discuss.elastic.co/u/ira-zaya)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 3:46pm UTC](https://discuss.elastic.co/t/incorrect-json-logs-parsing/323447 "2023-01-19T15:46:25Z")

</div>

Hi. I have json format logs, looks like this: { "dt":"2023-01-18T17:41:04.8723262+00:00", "tz":"Etc/UTC", "host":"host-name", "containerName":"container-name", "level":"INFO", "scope":"Web API", "message":"exitin…

---

## [Importing dashboards using kibana api through curl](https://discuss.elastic.co/t/importing-dashboards-using-kibana-api-through-curl/323320)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 3\
**Last updated:** [January 19, 2023, 3:29pm UTC](https://discuss.elastic.co/t/importing-dashboards-using-kibana-api-through-curl/323320 "2023-01-19T15:29:14Z")

</div>

Hi Community, I want to import metricbeat dashboard , but i can't find the id. ELK version 7.17 command used curl -u user:pass -k -X POST "https://localhost:5601/api/saved\_objects/\_export -H 'kbn-xsrf: true' -H 'Cont…

---

## [Can't connect to node (ECONNREFUSED) - Multi cluster setup](https://discuss.elastic.co/t/cant-connect-to-node-econnrefused-multi-cluster-setup/323334)

<div class="topic-metadata">

**Author:** [@Onezy](https://discuss.elastic.co/u/Onezy)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 3:27pm UTC](https://discuss.elastic.co/t/cant-connect-to-node-econnrefused-multi-cluster-setup/323334 "2023-01-19T15:27:25Z")

</div>

Hi, I'm new to both ES and docker so I may not be doing something right and maybe somebody could help I am currently trying to create a multi cluster setup with 3 nodes and 2 kibanas: Cluster1 (2 nodes 1 kibana) / Clu…

---

## [Vega Tree graph - Binding Custom Icon](https://discuss.elastic.co/t/vega-tree-graph-binding-custom-icon/323443)

<div class="topic-metadata">

**Author:** [@Dimple.P](https://discuss.elastic.co/u/Dimple.P)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 2:56pm UTC](https://discuss.elastic.co/t/vega-tree-graph-binding-custom-icon/323443 "2023-01-19T14:56:44Z")

</div>

Is it feasible to attach customized icons in the Vega V5 Tree graph? If yes, how should each node be modified?

---

## [No config file found - help me pleaseee](https://discuss.elastic.co/t/no-config-file-found-help-me-pleaseee/323521)

<div class="topic-metadata">

**Author:** [@Jonathan\_Or](https://discuss.elastic.co/u/Jonathan_Or)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 2:33pm UTC](https://discuss.elastic.co/t/no-config-file-found-help-me-pleaseee/323521 "2023-01-19T14:33:01Z")

</div>

hey , i have a problem with my logstash thats running on my ubuntu 18.04 machine. when i run journalctl -u logstash it presents one error that says that no config file found in path etc/log..... but when i go to conf…

---

## [Infinite extent for field "\<field name\>" : \[Infinity, -Infinity\]](https://discuss.elastic.co/t/infinite-extent-for-field-field-name-infinity-infinity/323523)

<div class="topic-metadata">

**Author:** [@Kamil\_BdBelfort](https://discuss.elastic.co/u/Kamil_BdBelfort)\
**Replies:** 5\
**Last updated:** [January 19, 2023, 2:26pm UTC](https://discuss.elastic.co/t/infinite-extent-for-field-field-name-infinity-infinity/323523 "2023-01-19T14:26:55Z")

</div>

Hi there, I am using elasticsearch & kibana version 8.5.3 This is how my data look like when I run my script: Inspect \> View Request \> Vega debug \> Spec: { "$schema": "https://vega.github.io/schema/vega-lite/v5.j…

---

## [How i can rename dynamical fields](https://discuss.elastic.co/t/how-i-can-rename-dynamical-fields/323321)

<div class="topic-metadata">

**Author:** [@Glad](https://discuss.elastic.co/u/Glad)\
**Replies:** 3\
**Last updated:** [January 19, 2023, 1:55pm UTC](https://discuss.elastic.co/t/how-i-can-rename-dynamical-fields/323321 "2023-01-19T13:55:46Z")

</div>

Hello, I would like some help with my little problem. I would like to be able to automatically rename fields that I get with my snmp plugin in input. I obtain this result: "host" =\> \[ \[1\] { "iso...hrProcessorLoa…

---

## [Dsl Query - calculate incidence in percentage (%) or bucket\_script](https://discuss.elastic.co/t/dsl-query-calculate-incidence-in-percentage-or-bucket-script/323501)

<div class="topic-metadata">

**Author:** [@SalvoDM91](https://discuss.elastic.co/u/SalvoDM91)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 11:24am UTC](https://discuss.elastic.co/t/dsl-query-calculate-incidence-in-percentage-or-bucket-script/323501 "2023-01-19T11:24:21Z")

</div>

Hi guys, I've a sample dataset with 3 columns (ID, ACTION and AMOUNT): I would like to create a DSL query in order to check minute by minute: number of documents with ACTION = "purchase" (paramA) number of documen…

---

## [Multi-node cluster certificates](https://discuss.elastic.co/t/multi-node-cluster-certificates/323522)

<div class="topic-metadata">

**Author:** [@cdy5159](https://discuss.elastic.co/u/cdy5159)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 1:27pm UTC](https://discuss.elastic.co/t/multi-node-cluster-certificates/323522 "2023-01-19T13:27:52Z")

</div>

I have a 3 node cluster that was created using the defaults at installation. Elastic version is 8.4.2. Only the cert from the initial node has a host-name built in. Do I need to re-create the transport certs and/or th…

---

## [I get no data from Elastic via asp.net core](https://discuss.elastic.co/t/i-get-no-data-from-elastic-via-asp-net-core/323515)

<div class="topic-metadata">

**Author:** [@fozgul](https://discuss.elastic.co/u/fozgul)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 12:54pm UTC](https://discuss.elastic.co/t/i-get-no-data-from-elastic-via-asp-net-core/323515 "2023-01-19T12:54:57Z")

</div>

My Elastic server(7.16.2) is running on an on-prem server with certain Ip. (Free version) I have the following setup for client creation in asp.net core: var pool = new SingleNodeConnectionPool(new Uri("http://username…

---

## [Complex queries inside nested fields](https://discuss.elastic.co/t/complex-queries-inside-nested-fields/323514)

<div class="topic-metadata">

**Author:** [@Hemabh\_Ravee\_Fox](https://discuss.elastic.co/u/Hemabh_Ravee_Fox)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 12:51pm UTC](https://discuss.elastic.co/t/complex-queries-inside-nested-fields/323514 "2023-01-19T12:51:32Z")

</div>

I have some documents which contain a nested field planList which is an array of objects. It's length will always be 2 or 3. And the objects always have 3 keys - planName, planType, and planId. I want to write a query w…

---

## [How to use DTOs in new java client with ILM](https://discuss.elastic.co/t/how-to-use-dtos-in-new-java-client-with-ilm/323511)

<div class="topic-metadata">

**Author:** [@bilak](https://discuss.elastic.co/u/bilak)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 12:36pm UTC](https://discuss.elastic.co/t/how-to-use-dtos-in-new-java-client-with-ilm/323511 "2023-01-19T12:36:46Z")

</div>

I'm using 7.17 client and I'd like to build ILM from java. This is what I've tried: final RolloverConditions rollover = new RolloverConditions.Builder() .maxSize("4GB") .maxAge(t -\> t.time("1D")) …

---

## [Multiple logstash instances listening to the same redis channel](https://discuss.elastic.co/t/multiple-logstash-instances-listening-to-the-same-redis-channel/323506)

<div class="topic-metadata">

**Author:** [@trondhindenes](https://discuss.elastic.co/u/trondhindenes)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 12:33pm UTC](https://discuss.elastic.co/t/multiple-logstash-instances-listening-to-the-same-redis-channel/323506 "2023-01-19T12:33:21Z")

</div>

We're using redis to pass data between logstash instances. I have 2 logstash instances currently with the same config: input { redis { data\_type =\> "channel" host =\> "${REDIS\_HOST}" key =\> "l…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=659)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=661)
