# Latest

**URL:** https://discuss.elastic.co/latest.md?page=591

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 592

---

## [No data Alert](https://discuss.elastic.co/t/no-data-alert/338315)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 18\
**Last updated:** [July 28, 2023, 9:27am UTC](https://discuss.elastic.co/t/no-data-alert/338315 "2023-07-28T09:27:40Z")

</div>

Hi Team, We want to create alert if no data is receiving is from last 15 minute. We have tried with the watcher it worked for us but we can't go as in watcher the alert status does not change like as in alert we have ac…

---

## [TSVB and interval issue](https://discuss.elastic.co/t/tsvb-and-interval-issue/339516)

<div class="topic-metadata">

**Author:** [@vincent2mots](https://discuss.elastic.co/u/vincent2mots)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 9:14am UTC](https://discuss.elastic.co/t/tsvb-and-interval-issue/339516 "2023-07-28T09:14:20Z")

</div>

Hi there! I'm using a 7.12 version of Elasticsearch Stack and I'm struggling with TSVB. I'm using the following formula : (params.bytes \* 8) / (params.\_interval / 1000) as shown bellow : However, when I see my area…

---

## [Time difference between a field and current time](https://discuss.elastic.co/t/time-difference-between-a-field-and-current-time/339494)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 2\
**Last updated:** [July 28, 2023, 8:37am UTC](https://discuss.elastic.co/t/time-difference-between-a-field-and-current-time/339494 "2023-07-28T08:37:49Z")

</div>

Hi Team, we have a field namely last\_modified\_date and we want to calculate aging time by noting the time difference between current time and last\_modified\_date. how can i achieve it via runtime field.

---

## [Rolling vs. Cluster Upgrades](https://discuss.elastic.co/t/rolling-vs-cluster-upgrades/339424)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 8:06am UTC](https://discuss.elastic.co/t/rolling-vs-cluster-upgrades/339424 "2023-07-28T08:06:30Z")

</div>

I'm wanting to better understand when to perform a full-cluster restart upgrade vs. a rolling upgrade of ES. I understand that a rolling upgrade has the benefit of minimizing impact to services during the upgrade (with t…

---

## [Memory consumption in io.netty.buffer.PoolThreadCache](https://discuss.elastic.co/t/memory-consumption-in-io-netty-buffer-poolthreadcache/339412)

<div class="topic-metadata">

**Author:** [@liguifa](https://discuss.elastic.co/u/liguifa)\
**Replies:** 10\
**Last updated:** [July 28, 2023, 8:02am UTC](https://discuss.elastic.co/t/memory-consumption-in-io-netty-buffer-poolthreadcache/339412 "2023-07-28T08:02:13Z")

</div>

Hi guys, I'm facing a large memory consumption in io.netty.buffer.PoolThreadCache. This portion of memory can reach up to 5GB. I think this is abnormal /usr/share/elasticsearch/jdk/bin/java -Xshare:auto -Des.networ…

---

## ["stacktrace": \["org.apache.lucene.index.CorruptIndexException: compound sub-files must have a valid codec header and footer: file is too small (0 bytes) (resource=BufferedChecksumIndexInput)](https://discuss.elastic.co/t/stacktrace-org-apache-lucene-index-corruptindexexception-compound-sub-files-must-have-a-valid-codec-header-and-footer-file-is-too-small-0-bytes-resource-bufferedchecksumindexinput/338323)

<div class="topic-metadata">

**Author:** [@Aravindh\_M](https://discuss.elastic.co/u/Aravindh_M)\
**Replies:** 21\
**Last updated:** [July 28, 2023, 8:00am UTC](https://discuss.elastic.co/t/stacktrace-org-apache-lucene-index-corruptindexexception-compound-sub-files-must-have-a-valid-codec-header-and-footer-file-is-too-small-0-bytes-resource-bufferedchecksumindexinput/338323 "2023-07-28T08:00:43Z")

</div>

Recently, we have been encountering the "CorruptIndexException" frequently, accompanied by the following stacktrace: "org.apache.lucene.index.CorruptIndexException: compound sub-files must have a valid codec header and f…

---

## [Total count of a field](https://discuss.elastic.co/t/total-count-of-a-field/339289)

<div class="topic-metadata">

**Author:** [@Dana\_Pavaday](https://discuss.elastic.co/u/Dana_Pavaday)\
**Replies:** 6\
**Last updated:** [July 28, 2023, 7:04am UTC](https://discuss.elastic.co/t/total-count-of-a-field/339289 "2023-07-28T07:04:43Z")

</div>

Hello everyone, I need to get the total count of a field in Elasticsearch (in my case, the number of clients in client field). How do I write the query in Dev tools?

---

## [Metrics don't send after some time to Elasticsearch - Temp. bulk send fail](https://discuss.elastic.co/t/metrics-dont-send-after-some-time-to-elasticsearch-temp-bulk-send-fail/339500)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 6:41am UTC](https://discuss.elastic.co/t/metrics-dont-send-after-some-time-to-elasticsearch-temp-bulk-send-fail/339500 "2023-07-28T06:41:58Z")

</div>

Hi, Few months ago I installed metricbeat in K8S cluster and everything was working fine. All of a sudden after 1-2 months I get error: Temporary bulk send failure - Drop batch INFO \[publisher\] pipeline/retry.go:223 …

---

## [I would like to know about the limit on the maximum number of documents per index](https://discuss.elastic.co/t/i-would-like-to-know-about-the-limit-on-the-maximum-number-of-documents-per-index/339497)

<div class="topic-metadata">

**Author:** [@bbasosuho](https://discuss.elastic.co/u/bbasosuho)\
**Replies:** 3\
**Last updated:** [July 28, 2023, 6:50am UTC](https://discuss.elastic.co/t/i-would-like-to-know-about-the-limit-on-the-maximum-number-of-documents-per-index/339497 "2023-07-28T06:50:17Z")

</div>

Hi We are going to use elasticsearch 8.7. I would like to know if there is a limit on the number of documents to be stored in one index. Is there a limit on the number of documents per index? Or is there a limit on th…

---

## [Can't see metricbeat logs](https://discuss.elastic.co/t/cant-see-metricbeat-logs/339407)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 2\
**Last updated:** [July 28, 2023, 6:35am UTC](https://discuss.elastic.co/t/cant-see-metricbeat-logs/339407 "2023-07-28T06:35:02Z")

</div>

Hi together Do you know why i can't see since creating of metricbeat any logfiles here ?

---

## [Logstash- How to parse formatted JSON arrays in log files](https://discuss.elastic.co/t/logstash-how-to-parse-formatted-json-arrays-in-log-files/339498)

<div class="topic-metadata">

**Author:** [@fisher\_he](https://discuss.elastic.co/u/fisher_he)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 6:15am UTC](https://discuss.elastic.co/t/logstash-how-to-parse-formatted-json-arrays-in-log-files/339498 "2023-07-28T06:15:33Z")

</div>

Logstash version: 7.17.10 Elasticsearch version:7.17.10 The logs are located in /var/logs directory and the format is as below: xxx.log \[ { "t": "SYS", "dt": "2023-04-17 19:46:40.147 GMT-04:00", "c": "M…

---

## [Elastic search not working](https://discuss.elastic.co/t/elastic-search-not-working/339423)

<div class="topic-metadata">

**Author:** [@gopikrish](https://discuss.elastic.co/u/gopikrish)\
**Replies:** 2\
**Last updated:** [July 28, 2023, 6:06am UTC](https://discuss.elastic.co/t/elastic-search-not-working/339423 "2023-07-28T06:06:52Z")

</div>

Hi Team, Suddenly, my Elasticsearch went down, and I'm not able to access it on remote systems or other systems with the same network band. I'm able to access it on my system only using my IP Address. For reference, I'…

---

## [Performance impact of upsert vs index with custom id](https://discuss.elastic.co/t/performance-impact-of-upsert-vs-index-with-custom-id/339492)

<div class="topic-metadata">

**Author:** [@sriapr98](https://discuss.elastic.co/u/sriapr98)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 4:49am UTC](https://discuss.elastic.co/t/performance-impact-of-upsert-vs-index-with-custom-id/339492 "2023-07-28T04:49:47Z")

</div>

We have a huge traffic coming out of kafka which we are continuously ingesting to es using Index api(with custom doc id). Due to some edge cases we are thinking of moving to update api(upsert with doc\_as\_upsert with upd…

---

## [Data relation using logstash conf file](https://discuss.elastic.co/t/data-relation-using-logstash-conf-file/338925)

<div class="topic-metadata">

**Author:** [@Vinod\_Kumar2](https://discuss.elastic.co/u/Vinod_Kumar2)\
**Replies:** 6\
**Last updated:** [July 28, 2023, 4:20am UTC](https://discuss.elastic.co/t/data-relation-using-logstash-conf-file/338925 "2023-07-28T04:20:37Z")

</div>

Multiple csv files in data folder and one column in common to relate the data between files. created logstash conf file and running manually and logstash gets shutdown. Sample data: File1:sample\_orders.csv id,product…

---

## [Failed to flush the buffer ||Data too large, data for|| could not push logs to Elasticsearch cluster](https://discuss.elastic.co/t/failed-to-flush-the-buffer-data-too-large-data-for-could-not-push-logs-to-elasticsearch-cluster/339489)

<div class="topic-metadata">

**Author:** [@Vikas1633](https://discuss.elastic.co/u/Vikas1633)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 4:08am UTC](https://discuss.elastic.co/t/failed-to-flush-the-buffer-data-too-large-data-for-could-not-push-logs-to-elasticsearch-cluster/339489 "2023-07-28T04:08:46Z")

</div>

Hi all i am facing this issue since long and not able to control the buffer file whenever large amount of data is ingested its get chocked any help would be apprecitated. 2023-05-24 17:34:11 +0300 \[warn\]: #0 failed to f…

---

## [Filebeat set add\_id: ~ does not take effect](https://discuss.elastic.co/t/filebeat-set-add-id-does-not-take-effect/336825)

<div class="topic-metadata">

**Author:** [@yt\_h](https://discuss.elastic.co/u/yt_h)\
**Replies:** 17\
**Last updated:** [July 28, 2023, 3:19am UTC](https://discuss.elastic.co/t/filebeat-set-add-id-does-not-take-effect/336825 "2023-07-28T03:19:49Z")

</div>

I have a filebeat 7.16.2 to extract messages in kafka 3.4. After setting add\_id: ~, restarting filebeat will repeatedly send data to elasticsearch. filebeat.yml: filebeat.yml: | filebeat.inputs: - type: kafka h…

---

## [Get logs from remote devices](https://discuss.elastic.co/t/get-logs-from-remote-devices/339292)

<div class="topic-metadata">

**Author:** [@Siddharth\_Jain1](https://discuss.elastic.co/u/Siddharth_Jain1)\
**Replies:** 3\
**Last updated:** [July 28, 2023, 12:54am UTC](https://discuss.elastic.co/t/get-logs-from-remote-devices/339292 "2023-07-28T00:54:10Z")

</div>

We have 1500+ remote hosts( MAC, ubuntu, Windows) laptops, which are not in our network 24x7. I want to fetch logs from these devices even if they are not connected to our VPN. Is there any way through which we can achie…

---

## [Logstash HTTP client](https://discuss.elastic.co/t/logstash-http-client/339483)

<div class="topic-metadata">

**Author:** [@Arjun\_Nambiar](https://discuss.elastic.co/u/Arjun_Nambiar)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 11:55pm UTC](https://discuss.elastic.co/t/logstash-http-client/339483 "2023-07-27T23:55:08Z")

</div>

I have an Elasticsearch cluster running on AWS which has an Elastic Load balancer(ELB) in front of it. I am scanning the ELB log file to find the clients writing to the Elasticsearch cluster. Logstash is also one of the …

---

## [Help with logstash output](https://discuss.elastic.co/t/help-with-logstash-output/339469)

<div class="topic-metadata">

**Author:** [@nach\_usal](https://discuss.elastic.co/u/nach_usal)\
**Replies:** 5\
**Last updated:** [July 27, 2023, 9:45pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/339469 "2023-07-27T21:45:28Z")

</div>

Hi guys, I am trying to capture login and logout events in programs such as TeamViewer and AnyDesk, installed in a Windows virtual machine. Then I send them to my Logstash server via the same Filebeat node, here is the …

---

## [Q: is it possible to send from filebeats/metricbeats via elasticagent to logstash or elastic?](https://discuss.elastic.co/t/q-is-it-possible-to-send-from-filebeats-metricbeats-via-elasticagent-to-logstash-or-elastic/339434)

<div class="topic-metadata">

**Author:** [@DrG](https://discuss.elastic.co/u/DrG)\
**Replies:** 2\
**Last updated:** [July 27, 2023, 7:29pm UTC](https://discuss.elastic.co/t/q-is-it-possible-to-send-from-filebeats-metricbeats-via-elasticagent-to-logstash-or-elastic/339434 "2023-07-27T19:29:42Z")

</div>

Hello everybody, Background: We have a setup of a set of computers, where "just one" of that is connected to the Companies Network - with a dedicated unique IP Adress etc. The other two systems (lets call them sysb, sy…

---

## [Controls showing incorrect document count](https://discuss.elastic.co/t/controls-showing-incorrect-document-count/339477)

<div class="topic-metadata">

**Author:** [@Matthew\_Salah](https://discuss.elastic.co/u/Matthew_Salah)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 7:11pm UTC](https://discuss.elastic.co/t/controls-showing-incorrect-document-count/339477 "2023-07-27T19:11:59Z")

</div>

I have a map on a Kibana dashboard and a series of controls. The controls have a count of documents associated with the filter value. However, the counts there don't line up with my global count of documents (see upper …

---

## [If index does not exists does not show error, return empty](https://discuss.elastic.co/t/if-index-does-not-exists-does-not-show-error-return-empty/339343)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 2\
**Last updated:** [July 27, 2023, 6:54pm UTC](https://discuss.elastic.co/t/if-index-does-not-exists-does-not-show-error-return-empty/339343 "2023-07-27T18:54:22Z")

</div>

hello , I have a search with many indexes here - GET index-0001, index-0002, index-0003/\_search { "size": 30, "query": { "match\_all": {} } } index-0001 exists index-0002 , does not exists . index-0003 exist…

---

## [Split filter and add\_field encoding object to a JSON string](https://discuss.elastic.co/t/split-filter-and-add-field-encoding-object-to-a-json-string/337590)

<div class="topic-metadata">

**Author:** [@MrOg](https://discuss.elastic.co/u/MrOg)\
**Replies:** 7\
**Last updated:** [July 27, 2023, 4:46pm UTC](https://discuss.elastic.co/t/split-filter-and-add-field-encoding-object-to-a-json-string/337590 "2023-07-27T16:46:34Z")

</div>

Hi, I have such a set of filters filter { json { source =\> "\[sql\_data\]\[response\]" } split { field =\> "docs" add\_field =\> { "id" =\> "%{\[docs\]\[id\]}" "names" =\> …

---

## [How to use pagination with new Java Client](https://discuss.elastic.co/t/how-to-use-pagination-with-new-java-client/339460)

<div class="topic-metadata">

**Author:** [@Andre\_Schmer](https://discuss.elastic.co/u/Andre_Schmer)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 4:42pm UTC](https://discuss.elastic.co/t/how-to-use-pagination-with-new-java-client/339460 "2023-07-27T16:42:24Z")

</div>

Trying to use a search\_after with the new Java API. That s what i did so far: SearchResponse\<PeriodInventory\> sr = newClient.search(searchRequest, PeriodInventory.class); List\<Hit\<PeriodInventory\>\> searchHits = sr.h…

---

## [Https backend call is not captured as transaction.type: http-request by RUM javascript agent](https://discuss.elastic.co/t/https-backend-call-is-not-captured-as-transaction-type-http-request-by-rum-javascript-agent/339458)

<div class="topic-metadata">

**Author:** [@dacothe](https://discuss.elastic.co/u/dacothe)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 4:26pm UTC](https://discuss.elastic.co/t/https-backend-call-is-not-captured-as-transaction-type-http-request-by-rum-javascript-agent/339458 "2023-07-27T16:26:11Z")

</div>

Kibana version: 7.16.3 Elasticsearch version: 7.16.3 APM Server version: 7.16.3 APM Agent language and version: @elastic/apm-rum:5.12 Browser version: Chrome 110.0.5481.100 Is there anything special in your setup? n…

---

## [Cannot access management console for any of our deployments](https://discuss.elastic.co/t/cannot-access-management-console-for-any-of-our-deployments/339360)

<div class="topic-metadata">

**Author:** [@Tommy\_Romano](https://discuss.elastic.co/u/Tommy_Romano)\
**Replies:** 2\
**Last updated:** [July 27, 2023, 4:08pm UTC](https://discuss.elastic.co/t/cannot-access-management-console-for-any-of-our-deployments/339360 "2023-07-27T16:08:17Z")

</div>

We are using Elastic Cloud on GCP and we cannot access the management console for any of our deployments. Each one results in a "connection reset" error in the web browser. Additionally, our terraform runner cannot acces…

---

## [How to Create a list of Buttons (with link) when specific selected button is clicked there is a new set of sub buttons (links) that user can click in Mardown Visualisation?](https://discuss.elastic.co/t/how-to-create-a-list-of-buttons-with-link-when-specific-selected-button-is-clicked-there-is-a-new-set-of-sub-buttons-links-that-user-can-click-in-mardown-visualisation/339275)

<div class="topic-metadata">

**Author:** [@SHAIK\_ASMA\_ZABI\_18BB](https://discuss.elastic.co/u/SHAIK_ASMA_ZABI_18BB)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 3:58pm UTC](https://discuss.elastic.co/t/how-to-create-a-list-of-buttons-with-link-when-specific-selected-button-is-clicked-there-is-a-new-set-of-sub-buttons-links-that-user-can-click-in-mardown-visualisation/339275 "2023-07-27T15:58:51Z")

</div>

I am using Markdown Visualization in which there are 5 buttons which have individual dashboard loading links. From those dashboard links there are sub buttons coming up which have their own dashboard loading links. How d…

---

## [Threshold Alerts with Delayed Logs - Verification](https://discuss.elastic.co/t/threshold-alerts-with-delayed-logs-verification/338362)

<div class="topic-metadata">

**Author:** [@kbratt](https://discuss.elastic.co/u/kbratt)\
**Replies:** 2\
**Last updated:** [July 27, 2023, 3:53pm UTC](https://discuss.elastic.co/t/threshold-alerts-with-delayed-logs-verification/338362 "2023-07-27T15:53:18Z")

</div>

I have set up Threshold Security Alerts that are running every 5 minutes and looking back an additional 1 minute.. We are working on fixing a performance issue where our Logs are delayed by up to 20 minutes at times. S…

---

## [Upgrading from 7.11.1 to 7.17 with only one node in the Cluster](https://discuss.elastic.co/t/upgrading-from-7-11-1-to-7-17-with-only-one-node-in-the-cluster/339455)

<div class="topic-metadata">

**Author:** [@getmoin](https://discuss.elastic.co/u/getmoin)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 2:51pm UTC](https://discuss.elastic.co/t/upgrading-from-7-11-1-to-7-17-with-only-one-node-in-the-cluster/339455 "2023-07-27T14:51:55Z")

</div>

Hi everyone, I have an Elastic search in prod, hosting on GCP. The present version of the Elastic search is 7.11.1 and its in yellow (EOL) in the dashboard.I want to upgrade it to the 7.17.12. And then to the 8.x I hav…

---

## [Kibana 8.9.0 plugin build failure](https://discuss.elastic.co/t/kibana-8-9-0-plugin-build-failure/339351)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 3\
**Last updated:** [July 27, 2023, 2:47pm UTC](https://discuss.elastic.co/t/kibana-8-9-0-plugin-build-failure/339351 "2023-07-27T14:47:36Z")

</div>

Hi we have updated our plugin from 8.8.1 to 8.9.0 and are hitting this error yarn bootstrap yarn run v1.22.19 $ yarn kbn bootstrap && yarn install $ node ../../scripts/kbn bootstrap \[bazel\] INFO: Invocation ID: 63a2c789…

[Previous page](https://discuss.elastic.co/latest.md?page=590)

[Next page](https://discuss.elastic.co/latest.md?page=592)
