# Latest

**URL:** https://discuss.elastic.co/latest.md?page=449

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 450

---

## [Add uptime monitors to a dashboard](https://discuss.elastic.co/t/add-uptime-monitors-to-a-dashboard/349675)

<div class="topic-metadata">

**Author:** [@gnatola](https://discuss.elastic.co/u/gnatola)\
**Replies:** 4\
**Last updated:** [December 20, 2023, 11:58am UTC](https://discuss.elastic.co/t/add-uptime-monitors-to-a-dashboard/349675 "2023-12-20T11:58:40Z")

</div>

How can I add my uptime monitors to a dashboard? Thanks.

---

## [Using elastic client with latest version for various operations](https://discuss.elastic.co/t/using-elastic-client-with-latest-version-for-various-operations/349678)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 1\
**Last updated:** [December 20, 2023, 9:10am UTC](https://discuss.elastic.co/t/using-elastic-client-with-latest-version-for-various-operations/349678 "2023-12-20T09:10:17Z")

</div>

Hi, I am trying to migrate my java client to 8.11 stack from 7.17. Earlier, I had to pass auth token as request options in all requests. Now, there are so many incompatible methods where I dont see option to pass reque…

---

## [Delete (or retain) specific documents from ILM-frozen searchable snapshot](https://discuss.elastic.co/t/delete-or-retain-specific-documents-from-ilm-frozen-searchable-snapshot/349698)

<div class="topic-metadata">

**Author:** [@maxboone](https://discuss.elastic.co/u/maxboone)\
**Replies:** 0\
**Last updated:** [December 20, 2023, 8:54am UTC](https://discuss.elastic.co/t/delete-or-retain-specific-documents-from-ilm-frozen-searchable-snapshot/349698 "2023-12-20T08:54:30Z")

</div>

Hey ELKers, We're running logging through Elastic but weren't very specific on our log indexes and had Elastic Agent pump all the logs in logs-kubernetes.container\_logs. Most of these logs have by now rotated through to…

---

## [Self-managed gold licence](https://discuss.elastic.co/t/self-managed-gold-licence/349638)

<div class="topic-metadata">

**Author:** [@akrambouss](https://discuss.elastic.co/u/akrambouss)\
**Replies:** 2\
**Last updated:** [December 20, 2023, 8:02am UTC](https://discuss.elastic.co/t/self-managed-gold-licence/349638 "2023-12-20T08:02:48Z")

</div>

Hi all, Hope you're ok. Need your help, actually i'm working on a company and we have elk used for data anlysis. we want to move to a self managed gold licence to access to other features. I tried to join commercial te…

---

## [Dec 20th, 2023: \[EN\] Mastering Elastic Agent Scalability: Navigating the Holiday Surge with SQS, S3, and CloudWatch](https://discuss.elastic.co/t/dec-20th-2023-en-mastering-elastic-agent-scalability-navigating-the-holiday-surge-with-sqs-s3-and-cloudwatch/347299)

<div class="topic-metadata">

**Author:** [@Tamara\_Dancheva](https://discuss.elastic.co/u/Tamara_Dancheva)\
**Replies:** 0\
**Last updated:** [December 20, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-20th-2023-en-mastering-elastic-agent-scalability-navigating-the-holiday-surge-with-sqs-s3-and-cloudwatch/347299 "2023-12-20T08:00:09Z")

</div>

Tags: #logs, #beats, filebeat, #scale, #cloudwatch, #s3, #sqs Ever found yourself wondering how to scale your Agent or your standalone Beats implementation? Are you currently grappling with the challenge of ingesting…

---

## [Dec 20th, 2023: \[ES\] Cómo dominar la Escalabilidad del Elastic Agent: Afrontando la Oleada Navideña con SQS, S3 y CloudWatch](https://discuss.elastic.co/t/dec-20th-2023-es-como-dominar-la-escalabilidad-del-elastic-agent-afrontando-la-oleada-navidena-con-sqs-s3-y-cloudwatch/347301)

<div class="topic-metadata">

**Author:** [@Tamara\_Dancheva](https://discuss.elastic.co/u/Tamara_Dancheva)\
**Replies:** 0\
**Last updated:** [December 20, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-20th-2023-es-como-dominar-la-escalabilidad-del-elastic-agent-afrontando-la-oleada-navidena-con-sqs-s3-y-cloudwatch/347301 "2023-12-20T08:00:09Z")

</div>

¿Alguna vez te has preguntado cómo escalar tu Agente o tu implementación independiente de Beats? ¿Te estás enfrentando al desafío de ingestar datos de numerosos grupos de registros de CloudWatch, solo para descubrir q…

---

## [Relation between shard size and sum of its segments size](https://discuss.elastic.co/t/relation-between-shard-size-and-sum-of-its-segments-size/349671)

<div class="topic-metadata">

**Author:** [@Tommaso\_Parisi](https://discuss.elastic.co/u/Tommaso_Parisi)\
**Replies:** 1\
**Last updated:** [December 20, 2023, 7:35am UTC](https://discuss.elastic.co/t/relation-between-shard-size-and-sum-of-its-segments-size/349671 "2023-12-20T07:35:00Z")

</div>

Hello, I was under the assumption that the disk space used by a shard is the sum of the disk space of its segments. I have and index with 1 Million document and 3 shards and it seems to me that this is not true. Can so…

---

## [Elastic Search becomes unresponsive after some time](https://discuss.elastic.co/t/elastic-search-becomes-unresponsive-after-some-time/348311)

<div class="topic-metadata">

**Author:** [@EVINDX](https://discuss.elastic.co/u/EVINDX)\
**Replies:** 2\
**Last updated:** [December 20, 2023, 7:34am UTC](https://discuss.elastic.co/t/elastic-search-becomes-unresponsive-after-some-time/348311 "2023-12-20T07:34:22Z")

</div>

We are facing issues with the Elasticsearch in the production environment where Elasticsearch stops responding intermittently and service needs to be restarted in-order to recover from this state. Logs collected from El…

---

## [How do I add a custom dashboard with charts for latency, throughput, and transaction failure rate in APM Service?](https://discuss.elastic.co/t/how-do-i-add-a-custom-dashboard-with-charts-for-latency-throughput-and-transaction-failure-rate-in-apm-service/349635)

<div class="topic-metadata">

**Author:** [@Mang-Joo](https://discuss.elastic.co/u/Mang-Joo)\
**Replies:** 2\
**Last updated:** [December 20, 2023, 6:38am UTC](https://discuss.elastic.co/t/how-do-i-add-a-custom-dashboard-with-charts-for-latency-throughput-and-transaction-failure-rate-in-apm-service/349635 "2023-12-20T06:38:58Z")

</div>

Hello People. The version of elk stack is 8.8.0 I want to clone chart in apm service overview (Latency, Throughput, Failed transaction rate and Time spent by span type) Is there a way to add these metrics in a custom …

---

## [High CPU Utilization - Tune performance](https://discuss.elastic.co/t/high-cpu-utilization-tune-performance/349691)

<div class="topic-metadata">

**Author:** [@castroivan](https://discuss.elastic.co/u/castroivan)\
**Replies:** 0\
**Last updated:** [December 20, 2023, 5:37am UTC](https://discuss.elastic.co/t/high-cpu-utilization-tune-performance/349691 "2023-12-20T05:37:14Z")

</div>

Hi team, First time posting a topic in here. I have a 6-node cluster which look like this: heap.percent ram.percent cpu load\_1m load\_5m load\_15m node.role master name 31 92 18 9.53 8.86 8…

---

## [Sql query returns nothing , but output file udpated](https://discuss.elastic.co/t/sql-query-returns-nothing-but-output-file-udpated/349622)

<div class="topic-metadata">

**Author:** [@gayatri\_SN](https://discuss.elastic.co/u/gayatri_SN)\
**Replies:** 3\
**Last updated:** [December 20, 2023, 5:28am UTC](https://discuss.elastic.co/t/sql-query-returns-nothing-but-output-file-udpated/349622 "2023-12-20T05:28:21Z")

</div>

Hi, I'm using jdbc input streaming filter to get the data from query. but in some cases query returns empty or null value. \< last\_run\_metadata\_path =\> \<filepath/sql\_last\_value.yml statement\_filepath =\> \<filepath/quer…

---

## [Date Mapping Template Not Being Applied Correctly](https://discuss.elastic.co/t/date-mapping-template-not-being-applied-correctly/349469)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 6\
**Last updated:** [December 19, 2023, 11:28pm UTC](https://discuss.elastic.co/t/date-mapping-template-not-being-applied-correctly/349469 "2023-12-19T23:28:10Z")

</div>

Hi, I'm receiving the following data set into ES from Logstash: { "fields": { "date-code": "180502", "form-factor": "FORM1", "serial-no": "1122334455", "vendor": "VENDOR-PRE", "vendor-part": "PART…

---

## [Reindex after Shrink to rename index (to the original one)?](https://discuss.elastic.co/t/reindex-after-shrink-to-rename-index-to-the-original-one/349606)

<div class="topic-metadata">

**Author:** [@HyebinHong](https://discuss.elastic.co/u/HyebinHong)\
**Replies:** 2\
**Last updated:** [December 19, 2023, 11:45pm UTC](https://discuss.elastic.co/t/reindex-after-shrink-to-rename-index-to-the-original-one/349606 "2023-12-19T23:45:23Z")

</div>

Hello, Elastic! According to my former question, I realized I need to change my settings related to shards and replicas. (Huge thanks to @Christian\_Dahlqvist ) Here is my former question Reducing replica was easy with…

---

## [Error when start the elastics services](https://discuss.elastic.co/t/error-when-start-the-elastics-services/349682)

<div class="topic-metadata">

**Author:** [@Antonio\_Sanchez](https://discuss.elastic.co/u/Antonio_Sanchez)\
**Replies:** 1\
**Last updated:** [December 19, 2023, 10:54pm UTC](https://discuss.elastic.co/t/error-when-start-the-elastics-services/349682 "2023-12-19T22:54:28Z")

</div>

Hello I'm installing a elastics services on a server ubuntu 22.4 but when I start the services I recibet the next error: \[sudo\] password for toor: Job for elasticsearch.service failed because the control process exite…

---

## [Max Window Size is Set to 10000 but the Terms aggregations is giving single filter value larger than max window size.](https://discuss.elastic.co/t/max-window-size-is-set-to-10000-but-the-terms-aggregations-is-giving-single-filter-value-larger-than-max-window-size/348924)

<div class="topic-metadata">

**Author:** [@santhosh.linga](https://discuss.elastic.co/u/santhosh.linga)\
**Replies:** 11\
**Last updated:** [December 19, 2023, 10:30pm UTC](https://discuss.elastic.co/t/max-window-size-is-set-to-10000-but-the-terms-aggregations-is-giving-single-filter-value-larger-than-max-window-size/348924 "2023-12-19T22:30:18Z")

</div>

We have created an index and are querying the index to display the complete dataset. However, we have encountered performance issues, as we are dealing with 1 million records in response to user search queries. To addres…

---

## [Custom TCP integration with TLS](https://discuss.elastic.co/t/custom-tcp-integration-with-tls/349679)

<div class="topic-metadata">

**Author:** [@CodeMonky](https://discuss.elastic.co/u/CodeMonky)\
**Replies:** 4\
**Last updated:** [December 19, 2023, 10:10pm UTC](https://discuss.elastic.co/t/custom-tcp-integration-with-tls/349679 "2023-12-19T22:10:42Z")

</div>

Good day all. I hope this is a simple question, but I've not been able to find any info. For the custom TCP integration that can be used when there's not an Elastic provided integration to use for data ingestion: does i…

---

## [Can Elasticsearch automatically normalize vectors for dot\_product?](https://discuss.elastic.co/t/can-elasticsearch-automatically-normalize-vectors-for-dot-product/349151)

<div class="topic-metadata">

**Author:** [@mmaccou](https://discuss.elastic.co/u/mmaccou)\
**Replies:** 7\
**Last updated:** [December 19, 2023, 10:01pm UTC](https://discuss.elastic.co/t/can-elasticsearch-automatically-normalize-vectors-for-dot-product/349151 "2023-12-19T22:01:28Z")

</div>

Can Elasticsearch automatically normalize vectors for dot\_product? I haven't found it the docs yet, but wanted to double check here before I manually add the step in my code.

---

## [Fixing query for type ahead with more than one query term](https://discuss.elastic.co/t/fixing-query-for-type-ahead-with-more-than-one-query-term/349564)

<div class="topic-metadata">

**Author:** [@RodAndTom](https://discuss.elastic.co/u/RodAndTom)\
**Replies:** 2\
**Last updated:** [December 19, 2023, 9:20pm UTC](https://discuss.elastic.co/t/fixing-query-for-type-ahead-with-more-than-one-query-term/349564 "2023-12-19T21:20:34Z")

</div>

Hi, I'm currently using the following query to suggest terms for type ahead completion for a title field, and it suits me very well: GET transcricoes/\_search { "query": { "wildcard": { "name": { "va…

---

## [Expired trial license during training lab... i just started :-(](https://discuss.elastic.co/t/expired-trial-license-during-training-lab-i-just-started/349480)

<div class="topic-metadata">

**Author:** [@logmeup](https://discuss.elastic.co/u/logmeup)\
**Replies:** 5\
**Last updated:** [December 19, 2023, 8:57pm UTC](https://discuss.elastic.co/t/expired-trial-license-during-training-lab-i-just-started/349480 "2023-12-19T20:57:54Z")

</div>

Course: Monitoring modern applications using Elastic Version: \<And which particular version?\> Question: Trying to do my first lab and Kibana says the trail license expired: "Your license expired on October 28, 2022 7:…

---

## [What happens on shutdown if queue.drain is true but output is unavailable?](https://discuss.elastic.co/t/what-happens-on-shutdown-if-queue-drain-is-true-but-output-is-unavailable/349680)

<div class="topic-metadata">

**Author:** [@noobiewan](https://discuss.elastic.co/u/noobiewan)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 7:29pm UTC](https://discuss.elastic.co/t/what-happens-on-shutdown-if-queue-drain-is-true-but-output-is-unavailable/349680 "2023-12-19T19:29:44Z")

</div>

Hi there, I'm currently running Logstash on Kubernetes and have configured a pipeline with a Persistent Queue and the setting queue.drain: true. In this setup, I'm curious about Logstash's behavior when it receives a SI…

---

## [How do I get to know that reindexing has been completed in Elasticsearch python client?](https://discuss.elastic.co/t/how-do-i-get-to-know-that-reindexing-has-been-completed-in-elasticsearch-python-client/349670)

<div class="topic-metadata">

**Author:** [@Aditya\_Dubey](https://discuss.elastic.co/u/Aditya_Dubey)\
**Replies:** 1\
**Last updated:** [December 19, 2023, 7:22pm UTC](https://discuss.elastic.co/t/how-do-i-get-to-know-that-reindexing-has-been-completed-in-elasticsearch-python-client/349670 "2023-12-19T19:22:18Z")

</div>

Basically, I'm running a reindexing function, and immediately after that, I'm running a function to delete the source index. Python runs all lines of code for the first function and moves to the next function (delete ind…

---

## [IF Regex not working](https://discuss.elastic.co/t/if-regex-not-working/349648)

<div class="topic-metadata">

**Author:** [@marcowiskhy](https://discuss.elastic.co/u/marcowiskhy)\
**Replies:** 5\
**Last updated:** [December 19, 2023, 5:51pm UTC](https://discuss.elastic.co/t/if-regex-not-working/349648 "2023-12-19T17:51:51Z")

</div>

Hey guys, In my pipeline I use a dictionary to enrich internal IPs and, to capture, I use the following regex: if \[source\] =~ "^10\\." or \[source\] =~ "^127\\.0\\." or \[source\] =~ "^192\\.168\\." or \[source\] =~ "^172\\.(1\[678…

---

## [Get integration assets](https://discuss.elastic.co/t/get-integration-assets/349647)

<div class="topic-metadata">

**Author:** [@adrien\_moreau](https://discuss.elastic.co/u/adrien_moreau)\
**Replies:** 3\
**Last updated:** [December 19, 2023, 5:22pm UTC](https://discuss.elastic.co/t/get-integration-assets/349647 "2023-12-19T17:22:08Z")

</div>

Is there a way to get the list of elasticsearch assets for a given elastic integration (From kibana or from an API). I am trying to figure out the list of: index templates, component templates, transforms, pipelines ma…

---

## [Allowing long query to complete even if indexes are shriking](https://discuss.elastic.co/t/allowing-long-query-to-complete-even-if-indexes-are-shriking/349273)

<div class="topic-metadata">

**Author:** [@DidierB](https://discuss.elastic.co/u/DidierB)\
**Replies:** 4\
**Last updated:** [December 19, 2023, 5:14pm UTC](https://discuss.elastic.co/t/allowing-long-query-to-complete-even-if-indexes-are-shriking/349273 "2023-12-19T17:14:40Z")

</div>

Hello, I have a use case with up to two billions events a day that are injected into an Elasticsearch. I opimized by making one index per hour (4 primary shards with 1 replica per shard) and setting a index lifecycle po…

---

## [Storage size](https://discuss.elastic.co/t/storage-size/349505)

<div class="topic-metadata">

**Author:** [@Noam\_Huri](https://discuss.elastic.co/u/Noam_Huri)\
**Replies:** 5\
**Last updated:** [December 19, 2023, 5:09pm UTC](https://discuss.elastic.co/t/storage-size/349505 "2023-12-19T17:09:19Z")

</div>

Hi, How can I determine the storage usage for App Search in my deployment? Thank you, Noam

---

## [Elastic Agent Cisco ASA integration - timestamp issue](https://discuss.elastic.co/t/elastic-agent-cisco-asa-integration-timestamp-issue/349646)

<div class="topic-metadata">

**Author:** [@vuylstekeb](https://discuss.elastic.co/u/vuylstekeb)\
**Replies:** 5\
**Last updated:** [December 19, 2023, 5:01pm UTC](https://discuss.elastic.co/t/elastic-agent-cisco-asa-integration-timestamp-issue/349646 "2023-12-19T17:01:35Z")

</div>

Hi I've recently started experimenting with Elastic Agent integrations. I've added one for Cisco ASA logs. The problem I'm facing is that my data is coming in with wrong timestamps. The data gets added into the indice wi…

---

## [Failed to submit a listener notification task. Event loop shut down? java.util.concurrent.RejectedExecutionException: event executor terminated](https://discuss.elastic.co/t/failed-to-submit-a-listener-notification-task-event-loop-shut-down-java-util-concurrent-rejectedexecutionexception-event-executor-terminated/349623)

<div class="topic-metadata">

**Author:** [@Kelvin\_A\_Escobar\_Mor](https://discuss.elastic.co/u/Kelvin_A_Escobar_Mor)\
**Replies:** 2\
**Last updated:** [December 19, 2023, 4:28pm UTC](https://discuss.elastic.co/t/failed-to-submit-a-listener-notification-task-event-loop-shut-down-java-util-concurrent-rejectedexecutionexception-event-executor-terminated/349623 "2023-12-19T16:28:51Z")

</div>

Failed to submit a listener notification task. Event loop shut down? java.util.concurrent.RejectedExecutionException: event executor terminated at io.netty.util.concurrent.SingleThreadEventExecutor.reject(SingleThreadE…

---

## [Unstable operation of elasticsearch](https://discuss.elastic.co/t/unstable-operation-of-elasticsearch/345931)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 19\
**Last updated:** [December 19, 2023, 2:14pm UTC](https://discuss.elastic.co/t/unstable-operation-of-elasticsearch/345931 "2023-12-19T14:14:15Z")

</div>

Hi Team! Recently I began to notice unstable operation of Logstash, I started looking at the logs (I have two Logstash nodes). Here is an example of logs: Oct 27 07:01:17 v-elk-lst01.my logstash\[42023\]: \[2023-10-27T07:…

---

## [Is indexing with HNSW required for kNN to work?](https://discuss.elastic.co/t/is-indexing-with-hnsw-required-for-knn-to-work/349598)

<div class="topic-metadata">

**Author:** [@mmaccou](https://discuss.elastic.co/u/mmaccou)\
**Replies:** 3\
**Last updated:** [December 19, 2023, 3:36pm UTC](https://discuss.elastic.co/t/is-indexing-with-hnsw-required-for-knn-to-work/349598 "2023-12-19T15:36:26Z")

</div>

While setting up some search templates for kNN, I discovered HNSW and the parameters for index options. "index\_options": { "type": "hnsw", "m": 32, "ef\_construction": 100 } When in…

---

## [Consolidate filebeats](https://discuss.elastic.co/t/consolidate-filebeats/349653)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 1:55pm UTC](https://discuss.elastic.co/t/consolidate-filebeats/349653 "2023-12-19T13:55:32Z")

</div>

Hi - we have a situation where different log files are being sent to diff logstash outputs and it's getting out of control with more than 7-8 instances running at the moment on a bunch of the key servers. I am trying to …

[Previous page](https://discuss.elastic.co/latest.md?page=448)

[Next page](https://discuss.elastic.co/latest.md?page=450)
