# Latest

**URL:** https://discuss.elastic.co/latest.md?page=555

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 556

---

## [Index is not creating in logstash through mule](https://discuss.elastic.co/t/index-is-not-creating-in-logstash-through-mule/342100)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 0\
**Last updated:** [September 1, 2023, 7:53am UTC](https://discuss.elastic.co/t/index-is-not-creating-in-logstash-through-mule/342100 "2023-09-01T07:53:06Z")

</div>

Hi I am not able to push the logs from my mule application to logstash which is running in ecs in aws and it is up . input { tcp { port =\> 4560 codec =\> json } } filter { date { match =\> \[ "timeMillis", "UNIX\_MS…

---

## [No uptime monitors found after upgrading to 8.8.2](https://discuss.elastic.co/t/no-uptime-monitors-found-after-upgrading-to-8-8-2/341998)

<div class="topic-metadata">

**Author:** [@tecbox41](https://discuss.elastic.co/u/tecbox41)\
**Replies:** 3\
**Last updated:** [September 1, 2023, 6:54am UTC](https://discuss.elastic.co/t/no-uptime-monitors-found-after-upgrading-to-8-8-2/341998 "2023-09-01T06:54:24Z")

</div>

Recently upgraded from Elasticsearch 7.16.2 to 8.8.2 and Uptime now shows "No uptime monitors found" for Monitors. I ran the setup for heartbeat once I upgraded it to 8.8.2 and the index template & data stream got create…

---

## [Filebeat pod continuously restarting : Liveness probe failed: rss\_mem 341245952](https://discuss.elastic.co/t/filebeat-pod-continuously-restarting-liveness-probe-failed-rss-mem-341245952/341980)

<div class="topic-metadata">

**Author:** [@Sam\_John](https://discuss.elastic.co/u/Sam_John)\
**Replies:** 2\
**Last updated:** [September 1, 2023, 6:28am UTC](https://discuss.elastic.co/t/filebeat-pod-continuously-restarting-liveness-probe-failed-rss-mem-341245952/341980 "2023-09-01T06:28:25Z")

</div>

filebeat pod in a k8s worker node is continuously restarting with following error message when the pods in the worker node increases: Error Message from filebeat pod: Warning Unhealthy 44m kubelet, k8s-worker-2 Livenes…

---

## [logstash Handling exception: io.netty.handler.codec.DecoderException:](https://discuss.elastic.co/t/logstash-handling-exception-io-netty-handler-codec-decoderexception/342054)

<div class="topic-metadata">

**Author:** [@zuoseven](https://discuss.elastic.co/u/zuoseven)\
**Replies:** 5\
**Last updated:** [September 1, 2023, 5:54am UTC](https://discuss.elastic.co/t/logstash-handling-exception-io-netty-handler-codec-decoderexception/342054 "2023-09-01T05:54:15Z")

</div>

Handling exception: io.netty.handler.codec.DecoderException: javax.net.ssl.SSLHandshakeException: Empty server certificate chain (caused by: javax.net.ssl.SSLHandshakeException: Empty server certificate chain) \[2023-08-3…

---

## [RAID 0, Replica 1, node 3 상태에서 서버 두대 더 추가 후 node 5로 변경 시 디스크 용량 변화 건](https://discuss.elastic.co/t/raid-0-replica-1-node-3-node-5/342094)

<div class="topic-metadata">

**Author:** [@2xploit](https://discuss.elastic.co/u/2xploit)\
**Replies:** 0\
**Last updated:** [September 1, 2023, 5:33am UTC](https://discuss.elastic.co/t/raid-0-replica-1-node-3-node-5/342094 "2023-09-01T05:33:18Z")

</div>

안녕하세요. 현재 저희 프로젝트에서는 ES 서버 3대에 node cluster 작업을 마친 상태입니다. 물리적 디스크는 SSD 4TB RAID 0 세팅으로 작업하고, Replica 1로 세팅을 한 상태 입니다. 이번에 추가로 서버 두대를 더 구매해서 5개에 node를 구성하려 하는데 조금 이해가 안가는 부분이 있어서 이렇게 문의 드립니다. 하드디스크가 늘어남에 따라 전체적인 용량도 …

---

## [Open SSL vulnerability in logstash directory](https://discuss.elastic.co/t/open-ssl-vulnerability-in-logstash-directory/341982)

<div class="topic-metadata">

**Author:** [@Supriyo](https://discuss.elastic.co/u/Supriyo)\
**Replies:** 4\
**Last updated:** [September 1, 2023, 5:01am UTC](https://discuss.elastic.co/t/open-ssl-vulnerability-in-logstash-directory/341982 "2023-09-01T05:01:56Z")

</div>

Security scans have found this open SSL vulnerability in logstash directory. We are trying to upgrade OpenSSL version 3.0.8 or later in the production server. The current version on the server is 3.0.3. Could you plea…

---

## [How to create boxes for particular field](https://discuss.elastic.co/t/how-to-create-boxes-for-particular-field/341075)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 2\
**Last updated:** [September 1, 2023, 3:52am UTC](https://discuss.elastic.co/t/how-to-create-boxes-for-particular-field/341075 "2023-09-01T03:52:05Z")

</div>

I want show some boxes which does not contain count for specific server. I am attach screenshot. In this picture i am trying too show that server but not their count,,, I want show only name for that particular serv…

---

## [Elasticsearch 2.2.4, issue with reindexing](https://discuss.elastic.co/t/elasticsearch-2-2-4-issue-with-reindexing/342089)

<div class="topic-metadata">

**Author:** [@Oeoeoey](https://discuss.elastic.co/u/Oeoeoey)\
**Replies:** 1\
**Last updated:** [September 1, 2023, 3:11am UTC](https://discuss.elastic.co/t/elasticsearch-2-2-4-issue-with-reindexing/342089 "2023-09-01T03:11:06Z")

</div>

I'm very new to elasticsearch and I just started working on some very old legacy code and the component I'm working on randomly stopped being able to reindex the indexes a couple of weeks ago. It used to be able to do a…

---

## [How can I creat the 'downloadable json file'?](https://discuss.elastic.co/t/how-can-i-creat-the-downloadable-json-file/340226)

<div class="topic-metadata">

**Author:** [@IANIAN](https://discuss.elastic.co/u/IANIAN)\
**Replies:** 1\
**Last updated:** [September 1, 2023, 12:20am UTC](https://discuss.elastic.co/t/how-can-i-creat-the-downloadable-json-file/340226 "2023-09-01T00:20:02Z")

</div>

Hi, I wanna demo this blog. How can I create the 'downlodable json file' ? It is at 'Step 4' from here

---

## [Is it possible to restore a single backing index for a data stream](https://discuss.elastic.co/t/is-it-possible-to-restore-a-single-backing-index-for-a-data-stream/341761)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 6\
**Last updated:** [August 31, 2023, 10:05pm UTC](https://discuss.elastic.co/t/is-it-possible-to-restore-a-single-backing-index-for-a-data-stream/341761 "2023-08-31T22:05:41Z")

</div>

we somehow lost both the a shard and its replica for the head of our datastream . I forced a rollover to get the datastream to accepting data again and removed the empty index (using api). I now want to restore that b…

---

## [Adding runtime fields referencing hash map elements to data view](https://discuss.elastic.co/t/adding-runtime-fields-referencing-hash-map-elements-to-data-view/342088)

<div class="topic-metadata">

**Author:** [@dstracha1](https://discuss.elastic.co/u/dstracha1)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 9:25pm UTC](https://discuss.elastic.co/t/adding-runtime-fields-referencing-hash-map-elements-to-data-view/342088 "2023-08-31T21:25:51Z")

</div>

Receiving painless script error when adding runtime field to a data view. The script references an element within a hash map in the document. I have a requirement to include a calculated field to a saved search that is …

---

## [After the group, the results were inconsistent](https://discuss.elastic.co/t/after-the-group-the-results-were-inconsistent/341897)

<div class="topic-metadata">

**Author:** [@ZE\_Share](https://discuss.elastic.co/u/ZE_Share)\
**Replies:** 7\
**Last updated:** [August 31, 2023, 8:45pm UTC](https://discuss.elastic.co/t/after-the-group-the-results-were-inconsistent/341897 "2023-08-31T20:45:09Z")

</div>

In low precision, I want to remove the fuzzy matching, so I will use search\_explain and elasticsearch/\_search to complete the group operation. I found a problem: Set params: query: 'tshirt', group: { 'field': 'company…

---

## [Curator advancing ILM phase due to disk usage](https://discuss.elastic.co/t/curator-advancing-ilm-phase-due-to-disk-usage/342070)

<div class="topic-metadata">

**Author:** [@Pete\_Nelson](https://discuss.elastic.co/u/Pete_Nelson)\
**Replies:** 2\
**Last updated:** [August 31, 2023, 7:11pm UTC](https://discuss.elastic.co/t/curator-advancing-ilm-phase-due-to-disk-usage/342070 "2023-08-31T19:11:47Z")

</div>

This is a feature request for Curator. I know that Elastic's official stance is that clusters should be sized for retention time requirements, and I know the answer to exhausting disk space is to enable automatic scalin…

---

## [How to set \`bulk\_max\_size\` and \`compression\_level\`?](https://discuss.elastic.co/t/how-to-set-bulk-max-size-and-compression-level/341387)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 8\
**Last updated:** [August 31, 2023, 6:34pm UTC](https://discuss.elastic.co/t/how-to-set-bulk-max-size-and-compression-level/341387 "2023-08-31T18:34:19Z")

</div>

I have about 2000 Elastic agents (version 8.9.0) connected to a system with 3 Fleet servers (version 8.9.0). We have about 20 different agent policies, because the various Elastic agents are sending slightly different …

---

## [Reindex from AWS Opensearch to Elasticsearch 7.17](https://discuss.elastic.co/t/reindex-from-aws-opensearch-to-elasticsearch-7-17/342067)

<div class="topic-metadata">

**Author:** [@Chuck\_Reynolds](https://discuss.elastic.co/u/Chuck_Reynolds)\
**Replies:** 3\
**Last updated:** [August 31, 2023, 4:00pm UTC](https://discuss.elastic.co/t/reindex-from-aws-opensearch-to-elasticsearch-7-17/342067 "2023-08-31T16:00:55Z")

</div>

I'm trying to reindex from AWS OPensearch to Elasticsearch 7.17 but I get the following error. { "error" : { "root\_cause" : \[ { "type" : "status\_exception", "reason" : "body={\\"error\\":{\\"roo…

---

## [Inconsistent behaviour of search\_after when used along with Point in time Id for large data sets](https://discuss.elastic.co/t/inconsistent-behaviour-of-search-after-when-used-along-with-point-in-time-id-for-large-data-sets/342074)

<div class="topic-metadata">

**Author:** [@Pravin\_Mourya](https://discuss.elastic.co/u/Pravin_Mourya)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 3:59pm UTC](https://discuss.elastic.co/t/inconsistent-behaviour-of-search-after-when-used-along-with-point-in-time-id-for-large-data-sets/342074 "2023-08-31T15:59:48Z")

</div>

Hello, We have a requirement in our project to extract all the data from the Elasticsearch index and dump it into a relational DB. The volume of data in the index is quite high around 100 million. Also there are process…

---

## [How to use Machine Learning to track thousands of different error codes?](https://discuss.elastic.co/t/how-to-use-machine-learning-to-track-thousands-of-different-error-codes/342065)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 3:10pm UTC](https://discuss.elastic.co/t/how-to-use-machine-learning-to-track-thousands-of-different-error-codes/342065 "2023-08-31T15:10:58Z")

</div>

Hi all. I'm working with around 1,500 different types of error codes. I'd like to use ML to know when any of them individually goes way up. That's too many for Multi-Metric to handle. Could anyone advise how to work …

---

## [Json codec vs. json\_lines codec for collecting mongoexport output JSON?](https://discuss.elastic.co/t/json-codec-vs-json-lines-codec-for-collecting-mongoexport-output-json/341616)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 18\
**Last updated:** [August 31, 2023, 2:59pm UTC](https://discuss.elastic.co/t/json-codec-vs-json-lines-codec-for-collecting-mongoexport-output-json/341616 "2023-08-31T14:59:47Z")

</div>

I'm trying to get Logstash to ingest a JSON file created by a mongoexport call. The file looks like this: { "\_id": "3c51d008add94422abf107f0", "name": "Pulse Get SVN By ID", "type": "automation", "tasks": { "53…

---

## [I want to use udp to output logs to logstash](https://discuss.elastic.co/t/i-want-to-use-udp-to-output-logs-to-logstash/342052)

<div class="topic-metadata">

**Author:** [@manymany](https://discuss.elastic.co/u/manymany)\
**Replies:** 1\
**Last updated:** [August 31, 2023, 2:04pm UTC](https://discuss.elastic.co/t/i-want-to-use-udp-to-output-logs-to-logstash/342052 "2023-08-31T14:04:11Z")

</div>

Filebeat Version: 8.4.3 ERROR: unsupported network type udp.

---

## [Failed to check for alias 'metricbeat-7.17.12': (status=403) : 403 Forbidden](https://discuss.elastic.co/t/failed-to-check-for-alias-metricbeat-7-17-12-status-403-403-forbidden/342046)

<div class="topic-metadata">

**Author:** [@BenKenobi](https://discuss.elastic.co/u/BenKenobi)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 12:11pm UTC](https://discuss.elastic.co/t/failed-to-check-for-alias-metricbeat-7-17-12-status-403-403-forbidden/342046 "2023-08-31T12:11:36Z")

</div>

Hi, We have Elastic and Kibana running on the same cluster and now I am trying to send system data from another host via metricbeat to elastic directly. For this I followed the 5 steps explained in the official documen…

---

## [Elasticsearch Reindexing error during upgrade in upgrade assistant](https://discuss.elastic.co/t/elasticsearch-reindexing-error-during-upgrade-in-upgrade-assistant/342044)

<div class="topic-metadata">

**Author:** [@agent47](https://discuss.elastic.co/u/agent47)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 12:04pm UTC](https://discuss.elastic.co/t/elasticsearch-reindexing-error-during-upgrade-in-upgrade-assistant/342044 "2023-08-31T12:04:11Z")

</div>

I am currently trying to upgrade my elasticsearch stack from 7.17.7 to 8.9 but I run in the error in the upgrade assistant while trying to fix the deprecation issues, I get the following error {"error":{"root\_cause":\[{"…

---

## [Unable to install 3rd party pluging using ES + Kibana 7.6.0](https://discuss.elastic.co/t/unable-to-install-3rd-party-pluging-using-es-kibana-7-6-0/341903)

<div class="topic-metadata">

**Author:** [@asad\_ali](https://discuss.elastic.co/u/asad_ali)\
**Replies:** 2\
**Last updated:** [August 31, 2023, 11:47am UTC](https://discuss.elastic.co/t/unable-to-install-3rd-party-pluging-using-es-kibana-7-6-0/341903 "2023-08-31T11:47:54Z")

</div>

Hello, I'm stuck in the situation where I'm to run a plugin which only support ES/Kibana 7.6.0 version, so I installed and run both services and they are working as expected. Problem comes when I attempt to install the …

---

## [How to enable certificate monitoring in synthetics](https://discuss.elastic.co/t/how-to-enable-certificate-monitoring-in-synthetics/342024)

<div class="topic-metadata">

**Author:** [@UweW](https://discuss.elastic.co/u/UweW)\
**Replies:** 2\
**Last updated:** [August 31, 2023, 11:37am UTC](https://discuss.elastic.co/t/how-to-enable-certificate-monitoring-in-synthetics/342024 "2023-08-31T11:37:33Z")

</div>

Hi, since i see the item "tls certificates" in the menu under synthetics, i assume that these can be read out by the tests accordingly. I have now already set up some tests, but the certificate of the website is not li…

---

## [Run arbitrary code at ingest that is too big for Painless script](https://discuss.elastic.co/t/run-arbitrary-code-at-ingest-that-is-too-big-for-painless-script/342032)

<div class="topic-metadata">

**Author:** [@jrihds](https://discuss.elastic.co/u/jrihds)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 10:08am UTC](https://discuss.elastic.co/t/run-arbitrary-code-at-ingest-that-is-too-big-for-painless-script/342032 "2023-08-31T10:08:16Z")

</div>

Hello, I have a simple algorithm I want to use as part of an ingest pipeline to derive a metric from a string field. For example: "this\_is\_my\_string" and from that we derive a new field for insertion into the index whic…

---

## [Active alert from a deleted rule](https://discuss.elastic.co/t/active-alert-from-a-deleted-rule/342019)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 0\
**Last updated:** [August 31, 2023, 7:14am UTC](https://discuss.elastic.co/t/active-alert-from-a-deleted-rule/342019 "2023-08-31T07:14:48Z")

</div>

Hello, I noticed 2 issues related to Kibana Alerts: In my Kibana, there are 2 active alerts for the same rule active all the time - even though one of them is from 3 months in the past and should be long recovered. A …

---

## [Snowflake to Elasticsearch Using Logtsash](https://discuss.elastic.co/t/snowflake-to-elasticsearch-using-logtsash/341785)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 3\
**Last updated:** [August 31, 2023, 7:01am UTC](https://discuss.elastic.co/t/snowflake-to-elasticsearch-using-logtsash/341785 "2023-08-31T07:01:17Z")

</div>

We are migrating data from Snowflake to Elasticsearch using the Logtsash driver. I took the logstash conf file template from \[Pull data from Snowflake with logstash | by Izek Chen | Medium\]. Below is the Logstash confi…

---

## [Selecting Required Fields in the Default Search UI After Crawling](https://discuss.elastic.co/t/selecting-required-fields-in-the-default-search-ui-after-crawling/341680)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 3\
**Last updated:** [August 31, 2023, 7:00am UTC](https://discuss.elastic.co/t/selecting-required-fields-in-the-default-search-ui-after-crawling/341680 "2023-08-31T07:00:04Z")

</div>

I am using Web Crawler within the app search. When the crawling was completed, I used the default search UI to search the results. Within the results, I am able to see all the fields. I just want to see a few fields in…

---

## [Table visualization in kibana](https://discuss.elastic.co/t/table-visualization-in-kibana/341946)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 3\
**Last updated:** [August 31, 2023, 5:31am UTC](https://discuss.elastic.co/t/table-visualization-in-kibana/341946 "2023-08-31T05:31:15Z")

</div>

I want to create a table visualization in kibana in which i want to display short\_date which is in date format for every entry the bytes and the duration as a separate row. If i select top values in the rows section it…

---

## [How to implement multi tenant environment in Elasticsearch](https://discuss.elastic.co/t/how-to-implement-multi-tenant-environment-in-elasticsearch/341606)

<div class="topic-metadata">

**Author:** [@HARSHAL\_CHAUDHARI](https://discuss.elastic.co/u/HARSHAL_CHAUDHARI)\
**Replies:** 18\
**Last updated:** [August 31, 2023, 4:38am UTC](https://discuss.elastic.co/t/how-to-implement-multi-tenant-environment-in-elasticsearch/341606 "2023-08-31T04:38:05Z")

</div>

What is the approach the Elasticsearch community recommends to use in a multi-tenant environment? Is one index Approach good? what are the pros and cons? Thanks, Harshal

---

## [Geoip log file](https://discuss.elastic.co/t/geoip-log-file/341901)

<div class="topic-metadata">

**Author:** [@AndyB](https://discuss.elastic.co/u/AndyB)\
**Replies:** 8\
**Last updated:** [August 31, 2023, 2:10am UTC](https://discuss.elastic.co/t/geoip-log-file/341901 "2023-08-31T02:10:50Z")

</div>

I would like to see if the geoip database is being downloaded. Getting information from Bard, it tells me that I need to create a file on my server here: /var/log/geoip/geoip.log I have done this but the geoip.log file…

[Previous page](https://discuss.elastic.co/latest.md?page=554)

[Next page](https://discuss.elastic.co/latest.md?page=556)
