# Latest

**URL:** https://discuss.elastic.co/latest.md?page=417

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 418

---

## [Getting 403 from artifacts.elastic.co](https://discuss.elastic.co/t/getting-403-from-artifacts-elastic-co/352064)

<div class="topic-metadata">

**Author:** [@Bakar\_Chkhaidze](https://discuss.elastic.co/u/Bakar_Chkhaidze)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 10:24am UTC](https://discuss.elastic.co/t/getting-403-from-artifacts-elastic-co/352064 "2024-01-30T10:24:17Z")

</div>

Hello, We are running Elasticsearch on a GKE cluster in europe-west3 region (Frankfurt, Germany). Pods can't start because I'm getting an error from install-plugins container: Exception in thread "main" java.io.IOExce…

---

## [How do configure display field response time on kibana of integration nginx](https://discuss.elastic.co/t/how-do-configure-display-field-response-time-on-kibana-of-integration-nginx/351951)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 2\
**Last updated:** [January 30, 2024, 9:24am UTC](https://discuss.elastic.co/t/how-do-configure-display-field-response-time-on-kibana-of-integration-nginx/351951 "2024-01-30T09:24:17Z")

</div>

I have configured elastic-agent with integration nginx. However, it does not have a responsetime field on kibana like the following image: And I was tried configured prossessors pipelines but it is error Ple…

---

## [Ticket sales now open for Haystack US, the Search Relevance Conference week of April 22nd](https://discuss.elastic.co/t/ticket-sales-now-open-for-haystack-us-the-search-relevance-conference-week-of-april-22nd/352075)

<div class="topic-metadata">

**Author:** [@flaxsearch](https://discuss.elastic.co/u/flaxsearch)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 10:06am UTC](https://discuss.elastic.co/t/ticket-sales-now-open-for-haystack-us-the-search-relevance-conference-week-of-april-22nd/352075 "2024-01-30T10:06:23Z")

</div>

I'm very pleased to announce tickets are now on sale for Haystack US 2024! This year features two tracks, one focused on AI and one on traditional search relevance (get your submissions in before Feb 16th) and three amaz…

---

## [Only return nested child objects with deep nesting](https://discuss.elastic.co/t/only-return-nested-child-objects-with-deep-nesting/351799)

<div class="topic-metadata">

**Author:** [@iamlindoro](https://discuss.elastic.co/u/iamlindoro)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 10:02am UTC](https://discuss.elastic.co/t/only-return-nested-child-objects-with-deep-nesting/351799 "2024-01-30T10:02:31Z")

</div>

Hi, very new to Elasticsearch so please forgive the potentially stupid question which is surely related either to my query or to my mapping. In short, I have index "cases" which is the parent of nested object stages, wh…

---

## [Search Special char support](https://discuss.elastic.co/t/search-special-char-support/352058)

<div class="topic-metadata">

**Author:** [@Sankar\_S](https://discuss.elastic.co/u/Sankar_S)\
**Replies:** 2\
**Last updated:** [January 30, 2024, 9:35am UTC](https://discuss.elastic.co/t/search-special-char-support/352058 "2024-01-30T09:35:45Z")

</div>

Hello All, I have a field called title and it has value "title" : "Toddler- $kitkat @taste &roll ^yart !here #you %ice ^oops \*jam (pot) \[beat\] pep |old {jet} \`egg /lol" For given input i would like to match any term s…

---

## [Logstash XML file not parsing](https://discuss.elastic.co/t/logstash-xml-file-not-parsing/352048)

<div class="topic-metadata">

**Author:** [@Shawn\_Lim](https://discuss.elastic.co/u/Shawn_Lim)\
**Replies:** 2\
**Last updated:** [January 30, 2024, 9:31am UTC](https://discuss.elastic.co/t/logstash-xml-file-not-parsing/352048 "2024-01-30T09:31:03Z")

</div>

Hi guys, I'm very new to Elasticsearch stack, need some help over here... Currently I'm trying to parse XML file, output to Elasticsearch and use it on Grafana for visualization. Now I facing a problem is my XML files …

---

## [Adding a label to the dataset - Multiple entries (large scale)](https://discuss.elastic.co/t/adding-a-label-to-the-dataset-multiple-entries-large-scale/351817)

<div class="topic-metadata">

**Author:** [@kaganova](https://discuss.elastic.co/u/kaganova)\
**Replies:** 7\
**Last updated:** [January 30, 2024, 8:25am UTC](https://discuss.elastic.co/t/adding-a-label-to-the-dataset-multiple-entries-large-scale/351817 "2024-01-30T08:25:38Z")

</div>

Hey, I'm querying a large API dataset with ~200k different tokens. I'm trying to query a subset of the activity, by token - of about ~170k values. I've tried using a filter for multiple values ("not in 30k") but I get …

---

## [Elastic Performance for Spatial Queries Slows Down when Geometries are in Millions](https://discuss.elastic.co/t/elastic-performance-for-spatial-queries-slows-down-when-geometries-are-in-millions/351959)

<div class="topic-metadata">

**Author:** [@purijs](https://discuss.elastic.co/u/purijs)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 6:58am UTC](https://discuss.elastic.co/t/elastic-performance-for-spatial-queries-slows-down-when-geometries-are-in-millions/351959 "2024-01-30T06:58:36Z")

</div>

I have a usecase to query ES for spatial intersection query with a Multipolygon. I tried two approaches where I store documents in flat structure, where 1 Polygon represents 1 document and in another setup I aggregate do…

---

## [ Filebeat: 0 Documents After Index Rollover](https://discuss.elastic.co/t/filebeat-0-documents-after-index-rollover/352060)

<div class="topic-metadata">

**Author:** [@Megha\_Varshney](https://discuss.elastic.co/u/Megha_Varshney)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 6:37am UTC](https://discuss.elastic.co/t/filebeat-0-documents-after-index-rollover/352060 "2024-01-30T06:37:46Z")

</div>

I am experiencing an issue with Filebeat where, after an index rollover, the new index shows 0 documents, and no data seems to be indexed. Here are the details of my setup:' Filebeat Configuration: filebeat.inputs: - t…

---

## [\[ElasticSearch v.7.5\] How to delete all indexes older than 6 month automatically?](https://discuss.elastic.co/t/elasticsearch-v-7-5-how-to-delete-all-indexes-older-than-6-month-automatically/351036)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 18\
**Last updated:** [January 30, 2024, 6:28am UTC](https://discuss.elastic.co/t/elasticsearch-v-7-5-how-to-delete-all-indexes-older-than-6-month-automatically/351036 "2024-01-30T06:28:23Z")

</div>

How to delete all indexes older than 6 month automatically?

---

## [After Implementing Elastic Search in Oracle's WEb center content, we are seeing no enhancement in Performance](https://discuss.elastic.co/t/after-implementing-elastic-search-in-oracles-web-center-content-we-are-seeing-no-enhancement-in-performance/352055)

<div class="topic-metadata">

**Author:** [@Subhs](https://discuss.elastic.co/u/Subhs)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 5:50am UTC](https://discuss.elastic.co/t/after-implementing-elastic-search-in-oracles-web-center-content-we-are-seeing-no-enhancement-in-performance/352055 "2024-01-30T05:50:30Z")

</div>

I have implemented Elastic Search in Oracle Web Center content( a content management repository from Oracle) as Oracle supports Elastic Search. But we are seeing no enhancement in performance compared to Database search.…

---

## [URL templating - Is it possible to split the output of event.values?](https://discuss.elastic.co/t/url-templating-is-it-possible-to-split-the-output-of-event-values/351659)

<div class="topic-metadata">

**Author:** [@azulgrana](https://discuss.elastic.co/u/azulgrana)\
**Replies:** 1\
**Last updated:** [January 30, 2024, 5:29am UTC](https://discuss.elastic.co/t/url-templating-is-it-possible-to-split-the-output-of-event-values/351659 "2024-01-30T05:29:49Z")

</div>

Hi there! I'm working on a "Table row click" drill down for one of my Lens tables, my goal is to have a drill down off a hidden field (report Id) to make it easier for the users. the event.values variable return an arr…

---

## [Logstash cpu usage is very high](https://discuss.elastic.co/t/logstash-cpu-usage-is-very-high/351619)

<div class="topic-metadata">

**Author:** [@Manoj\_Sangwan](https://discuss.elastic.co/u/Manoj_Sangwan)\
**Replies:** 3\
**Last updated:** [January 30, 2024, 4:56am UTC](https://discuss.elastic.co/t/logstash-cpu-usage-is-very-high/351619 "2024-01-30T04:56:32Z")

</div>

Logstash CPU usage is up to 90% and assuming this would increase with data growth. From the Application side seems everything fine. How to solve this issue in my project?

---

## [EFK Deployment on Openshift](https://discuss.elastic.co/t/efk-deployment-on-openshift/352053)

<div class="topic-metadata">

**Author:** [@bkrraj](https://discuss.elastic.co/u/bkrraj)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 4:47am UTC](https://discuss.elastic.co/t/efk-deployment-on-openshift/352053 "2024-01-30T04:47:14Z")

</div>

Hi , We are planning to Implement EFK on our PROD RedHat OpenShift cluster. Can anyone help us with the steps. Thanks Bala

---

## [Increase number of shards for an existing data stream](https://discuss.elastic.co/t/increase-number-of-shards-for-an-existing-data-stream/352045)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 2:07am UTC](https://discuss.elastic.co/t/increase-number-of-shards-for-an-existing-data-stream/352045 "2024-01-30T02:07:19Z")

</div>

Hi, I have been using the \_split API to change the number of shards on an existing index. This has been a simple task and has worked as expected. I have not had much success doing the same for a data stream which may …

---

## [How can I get the wkB/s reported by iostat](https://discuss.elastic.co/t/how-can-i-get-the-wkb-s-reported-by-iostat/352043)

<div class="topic-metadata">

**Author:** [@aorona](https://discuss.elastic.co/u/aorona)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 1:02am UTC](https://discuss.elastic.co/t/how-can-i-get-the-wkb-s-reported-by-iostat/352043 "2024-01-30T01:02:52Z")

</div>

I am using elastic integrations to collect disk statistics https://docs.elastic.co/en/integrations/system#disk-io I would like to plot amount of data read and written (rkB/s , wkB/s ) but I am running into some issues…

---

## [Elastic search is missing a hit when returning inner hits but the hit shows in highlights](https://discuss.elastic.co/t/elastic-search-is-missing-a-hit-when-returning-inner-hits-but-the-hit-shows-in-highlights/352042)

<div class="topic-metadata">

**Author:** [@warrengoldman](https://discuss.elastic.co/u/warrengoldman)\
**Replies:** 0\
**Last updated:** [January 29, 2024, 11:34pm UTC](https://discuss.elastic.co/t/elastic-search-is-missing-a-hit-when-returning-inner-hits-but-the-hit-shows-in-highlights/352042 "2024-01-29T23:34:41Z")

</div>

I have verified this via java api connection to Elasticsearch AND via kibana console. inner hits is missing chapter 7 verse 7 (note: highlights DOES show this instance, but inner hits ONLY has 3 or the 4 hits). The text …

---

## [High level of storage usage onky for 3 servers](https://discuss.elastic.co/t/high-level-of-storage-usage-onky-for-3-servers/351948)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 2\
**Last updated:** [January 29, 2024, 9:35pm UTC](https://discuss.elastic.co/t/high-level-of-storage-usage-onky-for-3-servers/351948 "2024-01-29T21:35:01Z")

</div>

I have 40 servers in Elk cluster version 7.5. A majority of them have a stable storage usage of around 65%, but 3 of them always have a usage over 85% and they grow up continuously What could be the reason?

---

## [Trying to decrypt data but it is not working as expected](https://discuss.elastic.co/t/trying-to-decrypt-data-but-it-is-not-working-as-expected/351977)

<div class="topic-metadata">

**Author:** [@Pallavibhushan](https://discuss.elastic.co/u/Pallavibhushan)\
**Replies:** 4\
**Last updated:** [January 29, 2024, 7:22pm UTC](https://discuss.elastic.co/t/trying-to-decrypt-data-but-it-is-not-working-as-expected/351977 "2024-01-29T19:22:47Z")

</div>

Below is my config input { file { path =\> "C:/logstash-7.16.2/data/input/test\*.json" start\_position =\> "beginning" sincedb\_path =\> "null" } } filter { json { source =\> "message" target =\> "document" } mutate…

---

## [ECE licensing](https://discuss.elastic.co/t/ece-licensing/352005)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 2\
**Last updated:** [January 29, 2024, 6:20pm UTC](https://discuss.elastic.co/t/ece-licensing/352005 "2024-01-29T18:20:05Z")

</div>

Hello Elastic Team, if I buy X ERU of Enterprise licenses, Are the Proxy, Controllers.. going to consume License or only the Allocators will consume it.

---

## [How is elastic agent gathering statistics?](https://discuss.elastic.co/t/how-is-elastic-agent-gathering-statistics/352028)

<div class="topic-metadata">

**Author:** [@aorona](https://discuss.elastic.co/u/aorona)\
**Replies:** 0\
**Last updated:** [January 29, 2024, 6:11pm UTC](https://discuss.elastic.co/t/how-is-elastic-agent-gathering-statistics/352028 "2024-01-29T18:11:51Z")

</div>

Is elastic agent parsing the text output of observability tools or is it reading directly from the OS libraries and kernel interfaces?

---

## [Elastic Date Math Rounding](https://discuss.elastic.co/t/elastic-date-math-rounding/352027)

<div class="topic-metadata">

**Author:** [@AidenRourke](https://discuss.elastic.co/u/AidenRourke)\
**Replies:** 0\
**Last updated:** [January 29, 2024, 6:04pm UTC](https://discuss.elastic.co/t/elastic-date-math-rounding/352027 "2024-01-29T18:04:10Z")

</div>

The date\_histogram aggregation has a parameter called offset. This property can be used to change a weekly bucket to be Monday to Sunday (the default) to Sunday to Saturday. I'm wondering if there's a simliar solution f…

---

## [How to get the summation of inner\_hits hits total value](https://discuss.elastic.co/t/how-to-get-the-summation-of-inner-hits-hits-total-value/352022)

<div class="topic-metadata">

**Author:** [@warrengoldman](https://discuss.elastic.co/u/warrengoldman)\
**Replies:** 0\
**Last updated:** [January 29, 2024, 5:27pm UTC](https://discuss.elastic.co/t/how-to-get-the-summation-of-inner-hits-hits-total-value/352022 "2024-01-29T17:27:07Z")

</div>

Cannot figure out the syntax for aggregations per the doc for this. Would think this type of request is very common... { "bible-book": { "mappings": { "properties": { "book": { "type": "tex…

---

## ["Cropping" result string around matches?](https://discuss.elastic.co/t/cropping-result-string-around-matches/351998)

<div class="topic-metadata">

**Author:** [@Seb\_Jones](https://discuss.elastic.co/u/Seb_Jones)\
**Replies:** 2\
**Last updated:** [January 29, 2024, 4:43pm UTC](https://discuss.elastic.co/t/cropping-result-string-around-matches/351998 "2024-01-29T16:43:40Z")

</div>

Hi Folks, Meilisearch offers a "cropping" function that trims or shortens the result string while still including the matching term. So using an example from their docs (which this forum won't let me link to …

---

## [How to send JSON body in rule?](https://discuss.elastic.co/t/how-to-send-json-body-in-rule/351768)

<div class="topic-metadata">

**Author:** [@navin547](https://discuss.elastic.co/u/navin547)\
**Replies:** 3\
**Last updated:** [January 29, 2024, 3:45pm UTC](https://discuss.elastic.co/t/how-to-send-json-body-in-rule/351768 "2024-01-29T15:45:43Z")

</div>

Hi, I have created a webhook connector which uses servicenow api to send, then I have created a rule and used that webhook connector so whenever that rule trigger I need to send that alert data in body as a JSON as ser…

---

## [Filter array of nested object on App Search](https://discuss.elastic.co/t/filter-array-of-nested-object-on-app-search/352013)

<div class="topic-metadata">

**Author:** [@Rustin\_Spencer](https://discuss.elastic.co/u/Rustin_Spencer)\
**Replies:** 0\
**Last updated:** [January 29, 2024, 3:23pm UTC](https://discuss.elastic.co/t/filter-array-of-nested-object-on-app-search/352013 "2024-01-29T15:23:12Z")

</div>

I have a data structure where certain fields are nested objects. For example, in my 'events' engine, the 'event\_permission' field is an array of objects, with each object containing a 'user\_id'. I'm using @elastic/enter…

---

## [Write log category to field](https://discuss.elastic.co/t/write-log-category-to-field/352000)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 1\
**Last updated:** [January 29, 2024, 3:22pm UTC](https://discuss.elastic.co/t/write-log-category-to-field/352000 "2024-01-29T15:22:37Z")

</div>

Hello, if i have logs like this: 2024-01-29 15:09:43,102 - ERROR - DB:Test1 - Test Error 2024-01-29 15:09:48,653 - ERROR - DB:Test2 - Test Error 2024-01-29 15:09:49,041 - ERROR - DB:Test1 - Test Error 2024-01-29 15:09:…

---

## [ECK, coordinator pods rolling quickly on upgrade - Maybe?](https://discuss.elastic.co/t/eck-coordinator-pods-rolling-quickly-on-upgrade-maybe/351088)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 2\
**Last updated:** [January 29, 2024, 3:19pm UTC](https://discuss.elastic.co/t/eck-coordinator-pods-rolling-quickly-on-upgrade-maybe/351088 "2024-01-29T15:19:26Z")

</div>

Hey all, the ECK operator is doing amazing things for me. The only thing I'm noticing is that on upgrades, my 3 coordinator pods seem to roll one right after the other and I wind up with a non-responsive queries on my in…

---

## [Reindex multiple indices - missing data stream](https://discuss.elastic.co/t/reindex-multiple-indices-missing-data-stream/352002)

<div class="topic-metadata">

**Author:** [@Oscar\_Yerpes](https://discuss.elastic.co/u/Oscar_Yerpes)\
**Replies:** 0\
**Last updated:** [January 29, 2024, 2:45pm UTC](https://discuss.elastic.co/t/reindex-multiple-indices-missing-data-stream/352002 "2024-01-29T14:45:57Z")

</div>

Hello all, Elastic version is 8.1 I have daily indices from an ILM that I would like to reindex in a single monthly index. I've tried the following: POST \_reindex { "source": { "index": ".ds-hpc-slurm-2023.10.\*…

---

## [Normalizer lowercase not found](https://discuss.elastic.co/t/normalizer-lowercase-not-found/351882)

<div class="topic-metadata">

**Author:** [@M.Ronge](https://discuss.elastic.co/u/M.Ronge)\
**Replies:** 2\
**Last updated:** [January 29, 2024, 2:35pm UTC](https://discuss.elastic.co/t/normalizer-lowercase-not-found/351882 "2024-01-29T14:35:58Z")

</div>

We develop an open source Java EE web application that uses Elasticsearch. This works wonderfully productively and very stable on countless servers. I now updated a single server, where it had been running smoothly so fa…

[Previous page](https://discuss.elastic.co/latest.md?page=416)

[Next page](https://discuss.elastic.co/latest.md?page=418)
