# Latest

**URL:** https://discuss.elastic.co/latest.md?page=457

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 458

---

## [Save index-template in helm chart](https://discuss.elastic.co/t/save-index-template-in-helm-chart/349038)

<div class="topic-metadata">

**Author:** [@nkarthik](https://discuss.elastic.co/u/nkarthik)\
**Replies:** 2\
**Last updated:** [December 12, 2023, 1:02pm UTC](https://discuss.elastic.co/t/save-index-template-in-helm-chart/349038 "2023-12-12T13:02:05Z")

</div>

Hi, I am using the 7.17 elastic stack. I know that we can create the index template in the kibana UI. But is there a way to create index-template as a YAML of any Kubernetes resource, so that every time kibana gets deplo…

---

## [Can not create a document has mutlipolygon having hole](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/349133)

<div class="topic-metadata">

**Author:** [@Sai\_Suvam\_Patnaik](https://discuss.elastic.co/u/Sai_Suvam_Patnaik)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:47am UTC](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/349133 "2023-12-12T11:47:05Z")

</div>

Hi all , can anyone help me I am facing a following issue . Summary Can not create a document has multipolygon having hole. This is the screenshot of the shp file in qgis: Expected behavior The document is succe…

---

## [AWS lambda end of support for Go1.x runtime](https://discuss.elastic.co/t/aws-lambda-end-of-support-for-go1-x-runtime/349047)

<div class="topic-metadata">

**Author:** [@rsingh1](https://discuss.elastic.co/u/rsingh1)\
**Replies:** 3\
**Last updated:** [December 12, 2023, 11:37am UTC](https://discuss.elastic.co/t/aws-lambda-end-of-support-for-go1-x-runtime/349047 "2023-12-12T11:37:21Z")

</div>

Hi, My use case is to continue using the functionbeat itself, but since the go1.x runtime will not be supported in AWS lambda, can I create a new build with the gov2 version? On that, Will it be too much of effort doi…

---

## [Customize kibana image in ECK operator](https://discuss.elastic.co/t/customize-kibana-image-in-eck-operator/349130)

<div class="topic-metadata">

**Author:** [@expert1](https://discuss.elastic.co/u/expert1)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:26am UTC](https://discuss.elastic.co/t/customize-kibana-image-in-eck-operator/349130 "2023-12-12T11:26:24Z")

</div>

Hi, How to Customize kibana image in ECK operator ? Here is my kibana yaml apiVersion: kibana.k8s.elastic.co/v1 kind: Kibana metadata: name: elasticsearch spec: version: 7.17.14 count: 1 elasticsearchRef: n…

---

## [Create a rule for stopped log alert](https://discuss.elastic.co/t/create-a-rule-for-stopped-log-alert/349009)

<div class="topic-metadata">

**Author:** [@Bhavani90](https://discuss.elastic.co/u/Bhavani90)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:21am UTC](https://discuss.elastic.co/t/create-a-rule-for-stopped-log-alert/349009 "2023-12-12T11:21:29Z")

</div>

Hi, I'm trying to set up an alert for when my application logs haven't been updated in 1 hour. Could you please share the relevant query?

---

## [Does Cross Cluster Search Performance varies with number of clusters](https://discuss.elastic.co/t/does-cross-cluster-search-performance-varies-with-number-of-clusters/348954)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 3\
**Last updated:** [December 12, 2023, 11:19am UTC](https://discuss.elastic.co/t/does-cross-cluster-search-performance-varies-with-number-of-clusters/348954 "2023-12-12T11:19:08Z")

</div>

Hi Team, I have a query. We have around 5000 Nodes in our setup. If I distribute the Nodes across 30 different Clusters will the cross cluster search performance be significantly be faster as compared to if I have nod…

---

## [Field not found message](https://discuss.elastic.co/t/field-not-found-message/349040)

<div class="topic-metadata">

**Author:** [@vils](https://discuss.elastic.co/u/vils)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:17am UTC](https://discuss.elastic.co/t/field-not-found-message/349040 "2023-12-12T11:17:36Z")

</div>

Hi all, I received an error message for a metric, saying the field wasn't found. The field not being found is fine since it does not apply to all my users, but is there a way to remove the error message. Instead having …

---

## [Exact replacement of LIKE with MATCH() / QUERY() in SQL query](https://discuss.elastic.co/t/exact-replacement-of-like-with-match-query-in-sql-query/349134)

<div class="topic-metadata">

**Author:** [@Grzegorz\_Kolakowski](https://discuss.elastic.co/u/Grzegorz_Kolakowski)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:13am UTC](https://discuss.elastic.co/t/exact-replacement-of-like-with-match-query-in-sql-query/349134 "2023-12-12T11:13:21Z")

</div>

Hi! The documentation suggests to use MATCH()/QUERY() instead of LIKE for performance reasons. I am wondering if it is possible to translate expression from LIKE filter to either MATCH or QUERY in order to achieve exact…

---

## [Elastic Map Service : Unable to find EMS tile configuration for id:road\_map : Kibana 7.17.0](https://discuss.elastic.co/t/elastic-map-service-unable-to-find-ems-tile-configuration-for-id-road-map-kibana-7-17-0/349122)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 4\
**Last updated:** [December 12, 2023, 9:59am UTC](https://discuss.elastic.co/t/elastic-map-service-unable-to-find-ems-tile-configuration-for-id-road-map-kibana-7-17-0/349122 "2023-12-12T09:59:05Z")

</div>

We have done on premise Kibana deployment at client location on Windows Server VM. VM does not have public internet access. We are getting below error while loading map. Unable to load layer Unable to find EMS tile con…

---

## [Elastic's Tenable Vulnerability Management Integration - Re-injesting Lost Data](https://discuss.elastic.co/t/elastics-tenable-vulnerability-management-integration-re-injesting-lost-data/349131)

<div class="topic-metadata">

**Author:** [@longansoju](https://discuss.elastic.co/u/longansoju)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 9:55am UTC](https://discuss.elastic.co/t/elastics-tenable-vulnerability-management-integration-re-injesting-lost-data/349131 "2023-12-12T09:55:42Z")

</div>

TDLR: is there a way to force elastic to injest all existing data for the past month from my tenable source? For those that prefer an in-depth explaination: I was tasked with coming out with a Tenable Dashboard that sh…

---

## [Allow multi-line breaking using \\n in Discover Datatable](https://discuss.elastic.co/t/allow-multi-line-breaking-using-n-in-discover-datatable/348975)

<div class="topic-metadata">

**Author:** [@Saar\_Tamir](https://discuss.elastic.co/u/Saar_Tamir)\
**Replies:** 3\
**Last updated:** [December 12, 2023, 8:29am UTC](https://discuss.elastic.co/t/allow-multi-line-breaking-using-n-in-discover-datatable/348975 "2023-12-12T08:29:34Z")

</div>

Hello, I'm sending strings with \\n so I can see logs in multi-line formatting, but all I see is the literal '\\n'. For example: I found this previous issue and PR: and I see that it added on 8.4.0 but only for Lens…

---

## [Elasticsearch throws error 503 Server Unavailable](https://discuss.elastic.co/t/elasticsearch-throws-error-503-server-unavailable/348896)

<div class="topic-metadata">

**Author:** [@Kalidastate](https://discuss.elastic.co/u/Kalidastate)\
**Replies:** 7\
**Last updated:** [December 12, 2023, 8:13am UTC](https://discuss.elastic.co/t/elasticsearch-throws-error-503-server-unavailable/348896 "2023-12-12T08:13:24Z")

</div>

I am facing one issue with the Elasticsearch in the production environment. Elasticsearch stops responding to the API calls and it needs to be restarted. Logs collected from Elasticsearch are as follows When the issue…

---

## [Dec 12th, 2023: \[EN\] Retrieval Augmented Generation (RAG) for Improving Support](https://discuss.elastic.co/t/dec-12th-2023-en-retrieval-augmented-generation-rag-for-improving-support/347291)

<div class="topic-metadata">

**Author:** [@corymangini](https://discuss.elastic.co/u/corymangini)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-12th-2023-en-retrieval-augmented-generation-rag-for-improving-support/347291 "2023-12-12T08:00:39Z")

</div>

In previous articles on the Elastic blog and the December 7th Advent calendar, you have seen how to set up a simple semantic search to find topics without using the exact keyword. Elastic runs its own Support Hub on t…

---

## [Suggestion on elastic cluster requirement](https://discuss.elastic.co/t/suggestion-on-elastic-cluster-requirement/349109)

<div class="topic-metadata">

**Author:** [@Ishaque\_Mohammed](https://discuss.elastic.co/u/Ishaque_Mohammed)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 6:25am UTC](https://discuss.elastic.co/t/suggestion-on-elastic-cluster-requirement/349109 "2023-12-12T06:25:07Z")

</div>

I have GKE clusters in that I am getting total 50MB logs /second to elastic and for this I have setup a 6 node elastic cluster with 4core and 16GB RAM configuration still I am facing issue when a surge occurs however my…

---

## [Kibana visualization bar chart not as expected](https://discuss.elastic.co/t/kibana-visualization-bar-chart-not-as-expected/349099)

<div class="topic-metadata">

**Author:** [@Liam619](https://discuss.elastic.co/u/Liam619)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 4:05am UTC](https://discuss.elastic.co/t/kibana-visualization-bar-chart-not-as-expected/349099 "2023-12-12T04:05:31Z")

</div>

Hi, I'm new to Kibana / Elastic service and trying to create a bar chart. I have 2 fields that store the number of storage capacity. What I'm trying to achieve here is that I wanted to display the bar separately. But s…

---

## [Seeking advice on setting up the ELK Stack](https://discuss.elastic.co/t/seeking-advice-on-setting-up-the-elk-stack/348968)

<div class="topic-metadata">

**Author:** [@Carrier99](https://discuss.elastic.co/u/Carrier99)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 12:30am UTC](https://discuss.elastic.co/t/seeking-advice-on-setting-up-the-elk-stack/348968 "2023-12-12T00:30:36Z")

</div>

Hey there. I want to set up the ELK stack, and I'm wondering about a good way to set it up. I'm running Proxmox so I have the options of either VMs or LXCs (was thinking of going with LXCs). My main question is should…

---

## [Disk space measure for Elasticsearch service](https://discuss.elastic.co/t/disk-space-measure-for-elasticsearch-service/349076)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 12:11am UTC](https://discuss.elastic.co/t/disk-space-measure-for-elasticsearch-service/349076 "2023-12-12T00:11:07Z")

</div>

Hi, I have provisioned 300 GB of Hard disk storage to Elastic search stack. Is there a way to measure how much storage is consumed by ES service, as I need to work on Capacity planning. For example, how much memory and …

---

## [Problems with elasticsearch container](https://discuss.elastic.co/t/problems-with-elasticsearch-container/349080)

<div class="topic-metadata">

**Author:** [@Ergo\_Proxy](https://discuss.elastic.co/u/Ergo_Proxy)\
**Replies:** 1\
**Last updated:** [December 11, 2023, 6:06pm UTC](https://discuss.elastic.co/t/problems-with-elasticsearch-container/349080 "2023-12-11T18:06:39Z")

</div>

I have some trouble making a docker with elastic. Here is the .yaml and a fragment of the terminal log result that I think shows the problem. services: setup: image: docker.elastic.co/elasticsearc…

---

## [Migrate shards from one node set to another](https://discuss.elastic.co/t/migrate-shards-from-one-node-set-to-another/349065)

<div class="topic-metadata">

**Author:** [@hashworks](https://discuss.elastic.co/u/hashworks)\
**Replies:** 1\
**Last updated:** [December 11, 2023, 5:33pm UTC](https://discuss.elastic.co/t/migrate-shards-from-one-node-set-to-another/349065 "2023-12-11T17:33:54Z")

</div>

Hi, I have three sets of nodes: A, B and C. Over time, I want to migrate all shards on A and B to C (and remove A and B from the cluster). I could do that all at once by setting the cluster routing allocation setting: …

---

## [Elastic APM co.elastic.apm.agent.report.AbstractIntakeApiHandler ERROR](https://discuss.elastic.co/t/elastic-apm-co-elastic-apm-agent-report-abstractintakeapihandler-error/348814)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 12:49pm UTC](https://discuss.elastic.co/t/elastic-apm-co-elastic-apm-agent-report-abstractintakeapihandler-error/348814 "2023-12-07T12:49:26Z")

</div>

Hi we are using the APM Java agent to send some transaction monitoring data to APM. Recently we've started getting the below errors every 30s 2023-12-07 11:53:19,638 \[elastic-apm-server-reporter\] ERROR co.elastic.apm.ag…

---

## [Splitting an array of objects using Logstash](https://discuss.elastic.co/t/splitting-an-array-of-objects-using-logstash/349066)

<div class="topic-metadata">

**Author:** [@M0hsen](https://discuss.elastic.co/u/M0hsen)\
**Replies:** 2\
**Last updated:** [December 11, 2023, 4:21pm UTC](https://discuss.elastic.co/t/splitting-an-array-of-objects-using-logstash/349066 "2023-12-11T16:21:38Z")

</div>

Hello everyone, I'm trying to split the following array of objects into multiple log events: \[ { "time": "\*", "twkMessageId": "\*", "environmentName": "\*", "virtualhostName": "default", "apiproxyNa…

---

## [TLS and Metricbeat](https://discuss.elastic.co/t/tls-and-metricbeat/349064)

<div class="topic-metadata">

**Author:** [@Jame\_M](https://discuss.elastic.co/u/Jame_M)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 3:53pm UTC](https://discuss.elastic.co/t/tls-and-metricbeat/349064 "2023-12-11T15:53:12Z")

</div>

Hello, mostly new to the Elastic Search framework, but I have a question. I have successfully deployed Metricbeat onto a set of remote servers pointing back to our Elastic Search via a IP address, and those work perfectl…

---

## [Kibana Server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/349026)

<div class="topic-metadata">

**Author:** [@AbcDE](https://discuss.elastic.co/u/AbcDE)\
**Replies:** 1\
**Last updated:** [December 11, 2023, 3:55pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/349026 "2023-12-11T15:55:50Z")

</div>

Hi I'm a new user of Kibana&Ubuntu(and forum) and i'm trying to start Kibana service for view the log of Suricata with a graphical interface, so please if you give me help be clear and precise Thanks. ok so i'm on Ubun…

---

## [Passing context to another thread](https://discuss.elastic.co/t/passing-context-to-another-thread/349055)

<div class="topic-metadata">

**Author:** [@johngregg](https://discuss.elastic.co/u/johngregg)\
**Replies:** 3\
**Last updated:** [December 11, 2023, 3:52pm UTC](https://discuss.elastic.co/t/passing-context-to-another-thread/349055 "2023-12-11T15:52:09Z")

</div>

I am using the 1.42.0 java agent. I am working on an app that uses an unsupported threading library. Based on reading some posts here, we decided to use the OTel library like this: import io.opentelemetry.api.trace.Sp…

---

## [Grok with custom pattern works in debugger but not in pipline](https://discuss.elastic.co/t/grok-with-custom-pattern-works-in-debugger-but-not-in-pipline/348957)

<div class="topic-metadata">

**Author:** [@helldunkel](https://discuss.elastic.co/u/helldunkel)\
**Replies:** 5\
**Last updated:** [December 11, 2023, 3:48pm UTC](https://discuss.elastic.co/t/grok-with-custom-pattern-works-in-debugger-but-not-in-pipline/348957 "2023-12-11T15:48:22Z")

</div>

Hi, I´m have a lot of problems to get a dataset in elastic. In Debugger it works. Log \<30\>2023:12:08-12:59:39 fw-swr-2 ulogd\[32373\]: grock .\*\>%{SOPHOS\_TIMESTAMP:\_tmp.timestamp} %{TEST:firewall.name} custom pattern …

---

## [Scripted upsert is failing in Elasticsearch output](https://discuss.elastic.co/t/scripted-upsert-is-failing-in-elasticsearch-output/349057)

<div class="topic-metadata">

**Author:** [@gshankar-elastic](https://discuss.elastic.co/u/gshankar-elastic)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 3:02pm UTC](https://discuss.elastic.co/t/scripted-upsert-is-failing-in-elasticsearch-output/349057 "2023-12-11T15:02:26Z")

</div>

I am using an indexed script in the output to transform the event data like this: input { kafka { bootstrap\_servers =\> "kafka.localhost.com:9092" topics =\> \["enriched"\] } } filter { json { …

---

## [Memory spikes on ILM transition](https://discuss.elastic.co/t/memory-spikes-on-ilm-transition/349008)

<div class="topic-metadata">

**Author:** [@azhurbilo](https://discuss.elastic.co/u/azhurbilo)\
**Replies:** 7\
**Last updated:** [December 11, 2023, 11:38am UTC](https://discuss.elastic.co/t/memory-spikes-on-ilm-transition/349008 "2023-12-11T11:38:24Z")

</div>

We use hot-warm-cold architecture policy { "filebeat": { "version": 39128, "modified\_date": "2023-12-11T04:05:20.404Z", "policy": { "phases": { "hot": { "min\_age": "0ms", …

---

## [Expose Elasticsearch on GKE to Dataproc (Performantly )](https://discuss.elastic.co/t/expose-elasticsearch-on-gke-to-dataproc-performantly/349056)

<div class="topic-metadata">

**Author:** [@Pat\_Humphreys](https://discuss.elastic.co/u/Pat_Humphreys)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 2:42pm UTC](https://discuss.elastic.co/t/expose-elasticsearch-on-gke-to-dataproc-performantly/349056 "2023-12-11T14:42:19Z")

</div>

What is the recomended way of exposing an elasticsearch cluster outside of the GKE cluster e.g. to use by a spark job running in dataproc (Using ES Hadoop libary) within the same VPC, without enabling the wan.only option…

---

## [Upgrade Single Node Docker Instance](https://discuss.elastic.co/t/upgrade-single-node-docker-instance/349041)

<div class="topic-metadata">

**Author:** [@litronics](https://discuss.elastic.co/u/litronics)\
**Replies:** 2\
**Last updated:** [December 11, 2023, 2:24pm UTC](https://discuss.elastic.co/t/upgrade-single-node-docker-instance/349041 "2023-12-11T14:24:23Z")

</div>

Hi, I am trying to upgrade a single node docker instance from 8.6.0 to the latest version. My first try was to update the docker containers to the latest version and start them on the old data. Kibana upgraded well and…

---

## [Backup and restore procedure Appsearch](https://discuss.elastic.co/t/backup-and-restore-procedure-appsearch/349049)

<div class="topic-metadata">

**Author:** [@SanderP](https://discuss.elastic.co/u/SanderP)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 1:37pm UTC](https://discuss.elastic.co/t/backup-and-restore-procedure-appsearch/349049 "2023-12-11T13:37:06Z")

</div>

Hi, I was looking into the backup and restore processes for Appsearch. Based on How to backup and restore your engines? - Elastic Enterprise Search - Discuss the Elastic Stack I had a look at the out of the box snapshot…

[Previous page](https://discuss.elastic.co/latest.md?page=456)

[Next page](https://discuss.elastic.co/latest.md?page=458)
