# Elasticsearch

**URL:** https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=302

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 303

---

## [Why I am getting two fields (label & metrics) for Prometheus data in Elasticsearch](https://discuss.elastic.co/t/why-i-am-getting-two-fields-label-metrics-for-prometheus-data-in-elasticsearch/325280)

<div class="topic-metadata">

**Author:** [@Maruthappan\_Muthu](https://discuss.elastic.co/u/Maruthappan_Muthu)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 3:41pm UTC](https://discuss.elastic.co/t/why-i-am-getting-two-fields-label-metrics-for-prometheus-data-in-elasticsearch/325280 "2023-02-10T15:41:00Z")

</div>

I am sending the Prometheus scraped data to Elasticsearch through Metricbeat on 'remote write' option. However I am getting two fields as prometheus.labels.\* and prometheus.metrics.\* for every different fields. Is my con…

---

## [Is there a way to get a nested field in not flattened format?](https://discuss.elastic.co/t/is-there-a-way-to-get-a-nested-field-in-not-flattened-format/325276)

<div class="topic-metadata">

**Author:** [@MohammedZia](https://discuss.elastic.co/u/MohammedZia)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 3:00pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-a-nested-field-in-not-flattened-format/325276 "2023-02-10T15:00:54Z")

</div>

I've a document that contains a field called json\_field. This field contains nested object (a dictionary as complex as it can get, as I can't fix the shape at the moment). When I search for this field using json\_field, I…

---

## [Migration path from embedded 2.x to current](https://discuss.elastic.co/t/migration-path-from-embedded-2-x-to-current/325080)

<div class="topic-metadata">

**Author:** [@Cyntech](https://discuss.elastic.co/u/Cyntech)\
**Replies:** 5\
**Last updated:** [February 10, 2023, 1:41pm UTC](https://discuss.elastic.co/t/migration-path-from-embedded-2-x-to-current/325080 "2023-02-10T13:41:35Z")

</div>

I'm the developer of a Grails web application that had embedded Elastic Search 1.x implemented more around 10 years ago (not by me, I've only been the developer for the last 2 yrs). In the process of upgrading to Grails…

---

## [Heap memory full? new documents just disappeared!](https://discuss.elastic.co/t/heap-memory-full-new-documents-just-disappeared/325037)

<div class="topic-metadata">

**Author:** [@Pete\_Watcharawit1](https://discuss.elastic.co/u/Pete_Watcharawit1)\
**Replies:** 5\
**Last updated:** [February 10, 2023, 6:07am UTC](https://discuss.elastic.co/t/heap-memory-full-new-documents-just-disappeared/325037 "2023-02-10T06:07:59Z")

</div>

Hello, some of our new batch of documents disappeared lately and I tried checking the heap memory usage of the cluster of 2 nodes by running: curl -XGET 'http://\<address\>:9200/\_nodes/stats/jvm?pretty' Our cluster is usi…

---

## [View cost breakdown of Elasticsearch in Azure](https://discuss.elastic.co/t/view-cost-breakdown-of-elasticsearch-in-azure/325266)

<div class="topic-metadata">

**Author:** [@matthew\_gen](https://discuss.elastic.co/u/matthew_gen)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 1:01pm UTC](https://discuss.elastic.co/t/view-cost-breakdown-of-elasticsearch-in-azure/325266 "2023-02-10T13:01:37Z")

</div>

Is there a way to extract the billing details of Elastic from the Elastic console (https://cloud.elastic.co/billing/usage) to the azure cost management page (Microsoft Azure)? I followed the links from the elastic cloud …

---

## [Elasticsearch, kibana y logstash y filebeat](https://discuss.elastic.co/t/elasticsearch-kibana-y-logstash-y-filebeat/325228)

<div class="topic-metadata">

**Author:** [@jomaguca](https://discuss.elastic.co/u/jomaguca)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 12:46pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-y-logstash-y-filebeat/325228 "2023-02-10T12:46:06Z")

</div>

Hello everybody My name is José Manuel and I am testing this solution to be use in logs managment so I hope you can help to work with this. My idea is install this in a debian 11 and elasticsearch 8.6.1 with kibana 8.6…

---

## [GCSToElasticsearch Template](https://discuss.elastic.co/t/gcstoelasticsearch-template/323834)

<div class="topic-metadata">

**Author:** [@Roque\_Moyano](https://discuss.elastic.co/u/Roque_Moyano)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 11:31am UTC](https://discuss.elastic.co/t/gcstoelasticsearch-template/323834 "2023-02-10T11:31:12Z")

</div>

Hi, I'm following this tutorial: Ingest data directly from Google Cloud Storage into Elastic using Google Dataflow | Elastic Blog but when the dataflow job is running I got this error: {"severity":"INFO","time":"2023/0…

---

## [Pass Multiple Fields in span term query](https://discuss.elastic.co/t/pass-multiple-fields-in-span-term-query/325213)

<div class="topic-metadata">

**Author:** [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 11:26am UTC](https://discuss.elastic.co/t/pass-multiple-fields-in-span-term-query/325213 "2023-02-10T11:26:25Z")

</div>

Hi Team, Can anyone please help how to pass multiple fields for searching in span\_term query? Example for span\_term query { "span\_term": { "field1": "value1" } } I want to pass something like this { "span\_term": { \[…

---

## [Installed ElasticSearch on linux, service is running but curl to elasticsearch url is failing](https://discuss.elastic.co/t/installed-elasticsearch-on-linux-service-is-running-but-curl-to-elasticsearch-url-is-failing/324937)

<div class="topic-metadata">

**Author:** [@Devanshu](https://discuss.elastic.co/u/Devanshu)\
**Replies:** 3\
**Last updated:** [February 10, 2023, 9:37am UTC](https://discuss.elastic.co/t/installed-elasticsearch-on-linux-service-is-running-but-curl-to-elasticsearch-url-is-failing/324937 "2023-02-10T09:37:55Z")

</div>

Installed Elasticsearch on linux, service is running but curl to elasticsearch url is failing. Getting below error curl: (52) Empty reply from server

---

## [I use the SLM policy, and the start time of the snapshot is inconsistent with the scheduled time](https://discuss.elastic.co/t/i-use-the-slm-policy-and-the-start-time-of-the-snapshot-is-inconsistent-with-the-scheduled-time/325082)

<div class="topic-metadata">

**Author:** [@lijianzhi](https://discuss.elastic.co/u/lijianzhi)\
**Replies:** 8\
**Last updated:** [February 10, 2023, 8:59am UTC](https://discuss.elastic.co/t/i-use-the-slm-policy-and-the-start-time-of-the-snapshot-is-inconsistent-with-the-scheduled-time/325082 "2023-02-10T08:59:49Z")

</div>

I use slm policy to create a snapshot policy plan 0 0 \* \* \*?, The next plan is 12:00, but the actual start time of the snapshot is 11:59:59, one second ahead of schedule. Or 12:00:01, delay 1 second. There are three repl…

---

## [Split Alert Message in Elasticsearch Query type Alert](https://discuss.elastic.co/t/split-alert-message-in-elasticsearch-query-type-alert/325226)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 8:56am UTC](https://discuss.elastic.co/t/split-alert-message-in-elasticsearch-query-type-alert/325226 "2023-02-10T08:56:38Z")

</div>

Hi there, i want to ask about alerting message. i was created an alert using elasticsearch query to find some cert that close to it's expire date and i used server log connector. the alert is running as well, but the pr…

---

## [Elastic agent random shutdown/goes offline](https://discuss.elastic.co/t/elastic-agent-random-shutdown-goes-offline/325223)

<div class="topic-metadata">

**Author:** [@fontexD](https://discuss.elastic.co/u/fontexD)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 8:27am UTC](https://discuss.elastic.co/t/elastic-agent-random-shutdown-goes-offline/325223 "2023-02-10T08:27:41Z")

</div>

Ive deployed a elk stack with elastic kibana and fleet server, all going smooth using self-gen self-created certs for transport all the way and my own ssl in front via ingress version 6.2.1 created with elk operator in…

---

## [Solace/Jagger integration with Elasticsearch](https://discuss.elastic.co/t/solace-jagger-integration-with-elasticsearch/325215)

<div class="topic-metadata">

**Author:** [@akhil](https://discuss.elastic.co/u/akhil)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 7:43am UTC](https://discuss.elastic.co/t/solace-jagger-integration-with-elasticsearch/325215 "2023-02-10T07:43:55Z")

</div>

We are getting below exception while connecting elk through Jagger, please help us to fix the issue. HTTP Error: search services failed: elastic: Error 400 (Bad Request): all shards failed \[type=search\_phase\_execution\_e…

---

## [ILM deleted after run](https://discuss.elastic.co/t/ilm-deleted-after-run/325130)

<div class="topic-metadata">

**Author:** [@laurijssen](https://discuss.elastic.co/u/laurijssen)\
**Replies:** 2\
**Last updated:** [February 10, 2023, 7:42am UTC](https://discuss.elastic.co/t/ilm-deleted-after-run/325130 "2023-02-10T07:42:41Z")

</div>

I've created an ILM that deletes data after x days. PUT idx\*/\_settings { "index": { "lifecycle": { "name": "x-days-policy" } } } The data gets deleted only once and then the ILM is removed. GET idx/\_…

---

## [Elasticsearch, Logstash, Kibana Scale-out Architecture](https://discuss.elastic.co/t/elasticsearch-logstash-kibana-scale-out-architecture/325206)

<div class="topic-metadata">

**Author:** [@haikal.azaim](https://discuss.elastic.co/u/haikal.azaim)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 7:04am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-kibana-scale-out-architecture/325206 "2023-02-10T07:04:54Z")

</div>

Hi Elastic Community, please need your advice. I have 2 logstash, 3 elasticsearch nodes, and 1 kibana for one office. I want to scale out the architecture, because there is new office with 300GB/day. My goal is to stick…

---

## [Create an index with 0 replicas using terraform](https://discuss.elastic.co/t/create-an-index-with-0-replicas-using-terraform/324707)

<div class="topic-metadata">

**Author:** [@james-world](https://discuss.elastic.co/u/james-world)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 11:42pm UTC](https://discuss.elastic.co/t/create-an-index-with-0-replicas-using-terraform/324707 "2023-02-09T23:42:26Z")

</div>

I am trying to use the latest terraform provider, currently 0.5.0 to create an index with no replicas into an existing Azure managed deployment. I can successfully create the index, but I always get 1 replica, even thou…

---

## ["missing authentication credentials for REST request \[/\]"](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/325177)

<div class="topic-metadata">

**Author:** [@vijaybala](https://discuss.elastic.co/u/vijaybala)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 10:48pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/325177 "2023-02-09T22:48:36Z")

</div>

Hi, I'm new to ELK Stack .I'm using 8.6.1 I have configured elasticsearch and kibana, and failed to configure logstash. After shutting down the system and running elasticsearch.bat, and connection to the local port it is…

---

## [Elasticsearch service does not start on Windows](https://discuss.elastic.co/t/elasticsearch-service-does-not-start-on-windows/325165)

<div class="topic-metadata">

**Author:** [@ludovic.denee](https://discuss.elastic.co/u/ludovic.denee)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 9:42pm UTC](https://discuss.elastic.co/t/elasticsearch-service-does-not-start-on-windows/325165 "2023-02-09T21:42:28Z")

</div>

Hi all, In the context of an upgrade of Azure DevOps Server from 2020 to 2022, I needed to upgrade the ES service. from 6 to 7. Update is ok but impossible to start the service. I tried to uninstall and reinstall the …

---

## [Runtime field query performance](https://discuss.elastic.co/t/runtime-field-query-performance/325193)

<div class="topic-metadata">

**Author:** [@vlasami](https://discuss.elastic.co/u/vlasami)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 8:38pm UTC](https://discuss.elastic.co/t/runtime-field-query-performance/325193 "2023-02-09T20:38:27Z")

</div>

Hi, We're evaluating the use runtime fields vs indexed fields (keyword). We have an object field (let's call it X) under which we can have arbitrary amount of fields. Unfortunately we cannot control the sending party, …

---

## [Prefer matching search text in beginning of result using elasticsearch in ElasticSearch Match Query](https://discuss.elastic.co/t/prefer-matching-search-text-in-beginning-of-result-using-elasticsearch-in-elasticsearch-match-query/325178)

<div class="topic-metadata">

**Author:** [@pavel4008](https://discuss.elastic.co/u/pavel4008)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 4:44pm UTC](https://discuss.elastic.co/t/prefer-matching-search-text-in-beginning-of-result-using-elasticsearch-in-elasticsearch-match-query/325178 "2023-02-09T16:44:22Z")

</div>

I have a query and sometimes I can't get to return the most relevant answer: GET /items2/\_search { "query": { "match": { "description": { "query": "query\_value", "fuzzines…

---

## [How is filter processed in query/fetch phases?](https://discuss.elastic.co/t/how-is-filter-processed-in-query-fetch-phases/325174)

<div class="topic-metadata">

**Author:** [@Robin\_Zimmerman](https://discuss.elastic.co/u/Robin_Zimmerman)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 4:18pm UTC](https://discuss.elastic.co/t/how-is-filter-processed-in-query-fetch-phases/325174 "2023-02-09T16:18:05Z")

</div>

I'm trying to understand how a filter is processed by the cluster. In particular, I have a metric that gives me the average time queries spend in the "query phase", and using the "took" time I can get an understanding of…

---

## [\[bool\] failed to parse field \[filter\]"](https://discuss.elastic.co/t/bool-failed-to-parse-field-filter/325131)

<div class="topic-metadata">

**Author:** [@Test\_Acc](https://discuss.elastic.co/u/Test_Acc)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 3:42pm UTC](https://discuss.elastic.co/t/bool-failed-to-parse-field-filter/325131 "2023-02-09T15:42:37Z")

</div>

Hi i am pretty new to kibana and elastisearch, we upgraded from kibana/elastisearch 7.16.3 to 8.5.2 and since then the dashboard has been less than friendly here is a error that has stumped us ///////////////////////…

---

## [Select all facets](https://discuss.elastic.co/t/select-all-facets/325149)

<div class="topic-metadata">

**Author:** [@athiraaravindan](https://discuss.elastic.co/u/athiraaravindan)\
**Replies:** 4\
**Last updated:** [February 9, 2023, 3:40pm UTC](https://discuss.elastic.co/t/select-all-facets/325149 "2023-02-09T15:40:20Z")

</div>

how can a select all facets values on a page load using the config

---

## [Initializing ELK stack in production environment (AWS EC2)](https://discuss.elastic.co/t/initializing-elk-stack-in-production-environment-aws-ec2/325160)

<div class="topic-metadata">

**Author:** [@st3fus](https://discuss.elastic.co/u/st3fus)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 3:11pm UTC](https://discuss.elastic.co/t/initializing-elk-stack-in-production-environment-aws-ec2/325160 "2023-02-09T15:11:23Z")

</div>

Hey there, just have a general question about initializing ELK stack, I'm launching it with docker, following deviantony/docker-elk guide and his repository. I'm just wondering should i change '0.0.0.0' values for hosts …

---

## [How to completely uninstall ELK?](https://discuss.elastic.co/t/how-to-completely-uninstall-elk/325112)

<div class="topic-metadata">

**Author:** [@usr4](https://discuss.elastic.co/u/usr4)\
**Replies:** 3\
**Last updated:** [February 9, 2023, 2:56pm UTC](https://discuss.elastic.co/t/how-to-completely-uninstall-elk/325112 "2023-02-09T14:56:41Z")

</div>

Hi everyone, I hastily installed ELK and x-pack on a Mac many years ago, the version is 5.6.3. I forgot how it was installed in the first place, now I wanted to uninstall them all clean and install a different version …

---

## [Can I use grok patterns inside of transform for a watcher?](https://discuss.elastic.co/t/can-i-use-grok-patterns-inside-of-transform-for-a-watcher/325063)

<div class="topic-metadata">

**Author:** [@ksobon](https://discuss.elastic.co/u/ksobon)\
**Replies:** 3\
**Last updated:** [February 9, 2023, 2:51pm UTC](https://discuss.elastic.co/t/can-i-use-grok-patterns-inside-of-transform-for-a-watcher/325063 "2023-02-09T14:51:36Z")

</div>

I got this transform for a watcher, and it's failing at the "grok" point: "transform": { "script": { "source": """ def finalMessage = "A new workset has been created in a Revit model. \\\\n\\\\n"…

---

## [Index to file (.json)](https://discuss.elastic.co/t/index-to-file-json/324683)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 2:50pm UTC](https://discuss.elastic.co/t/index-to-file-json/324683 "2023-02-09T14:50:53Z")

</div>

Hi, I have a running Elastic node with an index. I'm constantly inserting documents into the index in a process that I can't stop. I need to 'export' the index to a file (e.g., a .json). I've check alternatives to do th…

---

## [Replacing Self-Signed Certificates with Corporate CA Certificates](https://discuss.elastic.co/t/replacing-self-signed-certificates-with-corporate-ca-certificates/324140)

<div class="topic-metadata">

**Author:** [@jceddy](https://discuss.elastic.co/u/jceddy)\
**Replies:** 6\
**Last updated:** [February 9, 2023, 2:23pm UTC](https://discuss.elastic.co/t/replacing-self-signed-certificates-with-corporate-ca-certificates/324140 "2023-02-09T14:23:21Z")

</div>

I am working on changing over the certificates used for communication between elasticsearch nodes, and for communication between other applications and elasticsearch, from self-signed certificates generated by elasticsea…

---

## [How to use boxplot buckets for plotly?](https://discuss.elastic.co/t/how-to-use-boxplot-buckets-for-plotly/325148)

<div class="topic-metadata">

**Author:** [@Emporea](https://discuss.elastic.co/u/Emporea)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 2:16pm UTC](https://discuss.elastic.co/t/how-to-use-boxplot-buckets-for-plotly/325148 "2023-02-09T14:16:02Z")

</div>

I want to create a boxplot graph using plotly.js and elasticsearch. Elasticsearch has an inbuild boxplot aggregation that returns this for each trace: { "aggregations": { "load\_time\_boxplot": { "min": 0.0, …

---

## [How platinum licensing work with Elasticsearch. Is it node based or cluster based?](https://discuss.elastic.co/t/how-platinum-licensing-work-with-elasticsearch-is-it-node-based-or-cluster-based/325144)

<div class="topic-metadata">

**Author:** [@kommineni24](https://discuss.elastic.co/u/kommineni24)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 1:42pm UTC](https://discuss.elastic.co/t/how-platinum-licensing-work-with-elasticsearch-is-it-node-based-or-cluster-based/325144 "2023-02-09T13:42:11Z")

</div>

Currently, we are a little confused about how platinum licensing work with Elasticsearch. Is it node-based or cluster-based? For example, we have two six nodes clusters(Each Cluster - Three masters with 16 GB RAM each+ …

[Previous page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=301)

[Next page](https://discuss.elastic.co/c/elastic-stack/elasticsearch/6.md?page=303)
