# Latest

**URL:** https://discuss.elastic.co/latest.md?page=673

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 674

---

## [Is there a limit for number of routing values](https://discuss.elastic.co/t/is-there-a-limit-for-number-of-routing-values/333719)

<div class="topic-metadata">

**Author:** [@alper](https://discuss.elastic.co/u/alper)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 7:01am UTC](https://discuss.elastic.co/t/is-there-a-limit-for-number-of-routing-values/333719 "2023-05-18T07:01:14Z")

</div>

Hi, The index contains one routing field and has 50 shards. I use the routing field in search requests. I do, however, wonder if there would be a performance problem if I sent 1000 routing values in a single query. Sho…

---

## [Filebeat kubernetes autodiscovery per namespace & kibana missing beats](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscovery-per-namespace-kibana-missing-beats/333722)

<div class="topic-metadata">

**Author:** [@bdols](https://discuss.elastic.co/u/bdols)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 6:26am UTC](https://discuss.elastic.co/t/filebeat-kubernetes-autodiscovery-per-namespace-kibana-missing-beats/333722 "2023-05-18T06:26:44Z")

</div>

I've used this as a starting point to get ECK up and running: github/elastic/cloud-on-k8s/2.7/config/recipes/beats/stack\_monitoring.yaml I just want metrics and logs collected for elastic in one namespace, and the file…

---

## [Logstash date parse failure - ruby exception](https://discuss.elastic.co/t/logstash-date-parse-failure-ruby-exception/333710)

<div class="topic-metadata">

**Author:** [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Replies:** 2\
**Last updated:** [May 18, 2023, 6:11am UTC](https://discuss.elastic.co/t/logstash-date-parse-failure-ruby-exception/333710 "2023-05-18T06:11:49Z")

</div>

Hi, I am trying to use timestamp for each document by the value present in file name but i am getting Ruby exception occurred: wrong argument type DateTime (expected LogStash::Timestamp) when i run ruby code. it is wo…

---

## [Linux client data not visible on ELK server after](https://discuss.elastic.co/t/linux-client-data-not-visible-on-elk-server-after/333521)

<div class="topic-metadata">

**Author:** [@jg23](https://discuss.elastic.co/u/jg23)\
**Replies:** 4\
**Last updated:** [May 18, 2023, 6:07am UTC](https://discuss.elastic.co/t/linux-client-data-not-visible-on-elk-server-after/333521 "2023-05-18T06:07:13Z")

</div>

Hi, I recently installed the ELK stack on a Linux server running Ubuntu 22.04 using the following as a guide: After the initial installation and setup, I've also been able to successfully send logs from 4 other linux …

---

## [Elastic shard balancing / allocation](https://discuss.elastic.co/t/elastic-shard-balancing-allocation/333713)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 4:54am UTC](https://discuss.elastic.co/t/elastic-shard-balancing-allocation/333713 "2023-05-18T04:54:50Z")

</div>

Hi We are on Elastic 8.6 with 38 hot data nodes and ingesting about 140 different indices Top 10 indices have indexing rate about 15-50K events/sec. 20 indices has 1-20 K events/sec. And remaining 100 indices indexin…

---

## [New index es not being created after index 'reset' v7.17.9](https://discuss.elastic.co/t/new-index-es-not-being-created-after-index-reset-v7-17-9/333712)

<div class="topic-metadata">

**Author:** [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 4:33am UTC](https://discuss.elastic.co/t/new-index-es-not-being-created-after-index-reset-v7-17-9/333712 "2023-05-18T04:33:07Z")

</div>

I'm working on fixing our onsite elasticsearch 7.17.9 cluster. I've got a small 3 node cluster capturing our production data. Right now all of the logs get loaded into a single index that I use cron and curator to manu…

---

## [Add ILM to existing index 7.17.9](https://discuss.elastic.co/t/add-ilm-to-existing-index-7-17-9/333003)

<div class="topic-metadata">

**Author:** [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Replies:** 6\
**Last updated:** [May 18, 2023, 4:15am UTC](https://discuss.elastic.co/t/add-ilm-to-existing-index-7-17-9/333003 "2023-05-18T04:15:46Z")

</div>

I have an existing index I've applied the 30 day default lifecycle management policy to. But it doesn't seem to be working. I've read through the documentation and I/m obviously missing something. The index I'm attemp…

---

## [Elasticsearch Java Client 8.7 String List to FieldAndFormat List](https://discuss.elastic.co/t/elasticsearch-java-client-8-7-string-list-to-fieldandformat-list/333677)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 2\
**Last updated:** [May 18, 2023, 3:38am UTC](https://discuss.elastic.co/t/elasticsearch-java-client-8-7-string-list-to-fieldandformat-list/333677 "2023-05-18T03:38:43Z")

</div>

How do I pass Java String List to .fields as FieldAndFormat in search(req -\> req.index(index).fields())

---

## [Strigo Errors](https://discuss.elastic.co/t/strigo-errors/333705)

<div class="topic-metadata">

**Author:** [@rhink256](https://discuss.elastic.co/u/rhink256)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 3:06am UTC](https://discuss.elastic.co/t/strigo-errors/333705 "2023-05-18T03:06:10Z")

</div>

Course: Elasticsearch Engineer Version: On-demand Question: When I try to connect to the strigo lab environment for the first time, I get the following error: "Unfortunately, we cannot connect you to this training envi…

---

## [Filebeat on ELK not sending from configured paths](https://discuss.elastic.co/t/filebeat-on-elk-not-sending-from-configured-paths/333706)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 0\
**Last updated:** [May 18, 2023, 2:34am UTC](https://discuss.elastic.co/t/filebeat-on-elk-not-sending-from-configured-paths/333706 "2023-05-18T02:34:59Z")

</div>

In my /etc/filebeat/filebeat.yml I have this set: paths: - /var/log/audit/audit.log - /var/log/secure But in our Kibana we only seem to be receiving from this log.file.path : /var/log/messages Not sure why

---

## [Help with dissect in filter for logstash.conf to dynamically append filename to index patternNotFound Error](https://discuss.elastic.co/t/help-with-dissect-in-filter-for-logstash-conf-to-dynamically-append-filename-to-index-patternnotfound-error/333692)

<div class="topic-metadata">

**Author:** [@fsaa](https://discuss.elastic.co/u/fsaa)\
**Replies:** 2\
**Last updated:** [May 18, 2023, 1:43am UTC](https://discuss.elastic.co/t/help-with-dissect-in-filter-for-logstash-conf-to-dynamically-append-filename-to-index-patternnotfound-error/333692 "2023-05-18T01:43:40Z")

</div>

My folder structure is as follows: main\_directory. | .env | docker-compose.yml | +---elasticsearch | \\---config | elasticsearch.yml | \\---logstash +---config | | logstash.yml | | pipe…

---

## [Automatically balance Shard allocation](https://discuss.elastic.co/t/automatically-balance-shard-allocation/333682)

<div class="topic-metadata">

**Author:** [@NishuGoel](https://discuss.elastic.co/u/NishuGoel)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 1:11am UTC](https://discuss.elastic.co/t/automatically-balance-shard-allocation/333682 "2023-05-18T01:11:36Z")

</div>

A maintenance applied by "System" today caused a restart of a node in our production cluster The restarted node started reallocating shards, not receiving traffic after 2 hours and the remaining 2 nodes were under huge …

---

## [Is it possible to migrate data from one cluster to another using Snapshot and Restore](https://discuss.elastic.co/t/is-it-possible-to-migrate-data-from-one-cluster-to-another-using-snapshot-and-restore/333694)

<div class="topic-metadata">

**Author:** [@Abhilash\_B](https://discuss.elastic.co/u/Abhilash_B)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 1:06am UTC](https://discuss.elastic.co/t/is-it-possible-to-migrate-data-from-one-cluster-to-another-using-snapshot-and-restore/333694 "2023-05-18T01:06:00Z")

</div>

Hi Team, I am planning to migrate data from some indices using the snapshot and restore method. Is it possible to snapshot the indices from Cluster1 to one repository and then restore the same snapshot to Cluster2?

---

## [Logstash - Syslog Output - Custom message](https://discuss.elastic.co/t/logstash-syslog-output-custom-message/333588)

<div class="topic-metadata">

**Author:** [@Nandhini\_Viswanathan](https://discuss.elastic.co/u/Nandhini_Viswanathan)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 4:18pm UTC](https://discuss.elastic.co/t/logstash-syslog-output-custom-message/333588 "2023-05-16T16:18:03Z")

</div>

Logstash - Syslog Output - Custom message Hi, I'm I working with Logstash - Syslog Output and I've found out problem with setting custom field message. I'm using Elasticstack 7.8.0. I've installed logstash syslog-outp…

---

## [Normalizing Fields](https://discuss.elastic.co/t/normalizing-fields/333544)

<div class="topic-metadata">

**Author:** [@Felkio](https://discuss.elastic.co/u/Felkio)\
**Replies:** 1\
**Last updated:** [May 18, 2023, 12:02am UTC](https://discuss.elastic.co/t/normalizing-fields/333544 "2023-05-18T00:02:30Z")

</div>

Hello, we are currently using wazuh in conjunction with ELK stack 7.17.9, we would like to gradually switch to the full elastic stack, but to do this we would first like to normalize the fields that wazuh sends to elast…

---

## [Elastic Heap size calculation not correct with K8S 1.26](https://discuss.elastic.co/t/elastic-heap-size-calculation-not-correct-with-k8s-1-26/333528)

<div class="topic-metadata">

**Author:** [@lineconnect](https://discuss.elastic.co/u/lineconnect)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 11:58pm UTC](https://discuss.elastic.co/t/elastic-heap-size-calculation-not-correct-with-k8s-1-26/333528 "2023-05-17T23:58:03Z")

</div>

Hi, we run several elastic clusters(all with 3 nodes). And until now without any issues until we've upgraded vom k8s version 1.24.8. We don't have any JVM options set and the calculation from elastic was always fine. …

---

## [Get source of queries hitting indexes](https://discuss.elastic.co/t/get-source-of-queries-hitting-indexes/333250)

<div class="topic-metadata">

**Author:** [@callumdowling](https://discuss.elastic.co/u/callumdowling)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 11:52pm UTC](https://discuss.elastic.co/t/get-source-of-queries-hitting-indexes/333250 "2023-05-17T23:52:41Z")

</div>

Hi all, just wondering if this is possible. We have several tiers in elastic cloud, we would like to see when the frozen tier is being rules/dashboards/queries for our indexes so we can go through and optimise. Is there…

---

## [Not Getting Kubernetes related filters in Kibana when exporting logs from Logstash](https://discuss.elastic.co/t/not-getting-kubernetes-related-filters-in-kibana-when-exporting-logs-from-logstash/333400)

<div class="topic-metadata">

**Author:** [@Akshay04](https://discuss.elastic.co/u/Akshay04)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 11:44pm UTC](https://discuss.elastic.co/t/not-getting-kubernetes-related-filters-in-kibana-when-exporting-logs-from-logstash/333400 "2023-05-17T23:44:02Z")

</div>

Hello, I have configured Fluentbit in my k8s cluster to send logs to S3 and ELK stack to get logs from S3 and Visualise in Kibana. When I create Dataview in kibana for the Index, the kibana dashboard is not giving filte…

---

## [Can we connect to multiple clusters in JAVA using High level rest client](https://discuss.elastic.co/t/can-we-connect-to-multiple-clusters-in-java-using-high-level-rest-client/333310)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 11:13pm UTC](https://discuss.elastic.co/t/can-we-connect-to-multiple-clusters-in-java-using-high-level-rest-client/333310 "2023-05-17T23:13:32Z")

</div>

Hi team, I have a question about high level rest client lets suppose I have 2 clusters running on two different machines and those clusters have an index with the same name. I have a Java application which fetches dat…

---

## [Is there a way to recover kibana\_x file?](https://discuss.elastic.co/t/is-there-a-way-to-recover-kibana-x-file/333319)

<div class="topic-metadata">

**Author:** [@ardit](https://discuss.elastic.co/u/ardit)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 11:11pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-recover-kibana-x-file/333319 "2023-05-17T23:11:43Z")

</div>

Is there any possibility to recover from lost kibana\_x index? \[opc@elasticsearch-2 ~\]$ curl -XGET http://localhost:9200/\_cat/shards/.kibana\_7.12.0\_001 .kibana\_7.12.0\_001 0 p UNASSIGNED .kibana\_7.12.0\_001 0 r UNASSIG…

---

## [Elasticsearch Aggregations](https://discuss.elastic.co/t/elasticsearch-aggregations/333615)

<div class="topic-metadata">

**Author:** [@JulioAlbuquerque](https://discuss.elastic.co/u/JulioAlbuquerque)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 10:27pm UTC](https://discuss.elastic.co/t/elasticsearch-aggregations/333615 "2023-05-17T22:27:08Z")

</div>

I have a project in NodeJS with TypeScript that uses the library "@elastic/elasticsearch": "^8.7.0", to connect the server with Elastic Search 8.7.1. I'm trying to make a query where I retrieve the frequency of words fr…

---

## [How logstash jdbc plugin fetch data from database](https://discuss.elastic.co/t/how-logstash-jdbc-plugin-fetch-data-from-database/333103)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 14\
**Last updated:** [May 17, 2023, 9:09pm UTC](https://discuss.elastic.co/t/how-logstash-jdbc-plugin-fetch-data-from-database/333103 "2023-05-17T21:09:51Z")

</div>

Hi I have informix database that contain tons of tables and records that need to join some of them and send to elasticsearch. Result of this join are 70 columns and 100M records. Here is the requirements: 1-For first …

---

## [Looking for help enabling Metricbeat](https://discuss.elastic.co/t/looking-for-help-enabling-metricbeat/333570)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 5\
**Last updated:** [May 17, 2023, 8:45pm UTC](https://discuss.elastic.co/t/looking-for-help-enabling-metricbeat/333570 "2023-05-17T20:45:19Z")

</div>

Hello, I have a single node deploy of Elasticsearch Enterprise Search and Kibana all on version 8.6.2. In this node I enabled self-monitoring with xpack, but am trying to switch to using Metricbeat. While in 'Stack mon…

---

## [Elastic search practice exam reconnect to the lab](https://discuss.elastic.co/t/elastic-search-practice-exam-reconnect-to-the-lab/333601)

<div class="topic-metadata">

**Author:** [@Kimberly](https://discuss.elastic.co/u/Kimberly)\
**Replies:** 5\
**Last updated:** [May 17, 2023, 7:00pm UTC](https://discuss.elastic.co/t/elastic-search-practice-exam-reconnect-to-the-lab/333601 "2023-05-17T19:00:02Z")

</div>

I am trying to take a practice exam for Elasticsearch. I set it up a week ago and want to resume thru strigo. It is saying "your lab is reconnecting" over 30 minutes but still can't get in. Can some one help? Tx

---

## [Issue with Beats forwarding to logstash](https://discuss.elastic.co/t/issue-with-beats-forwarding-to-logstash/333689)

<div class="topic-metadata">

**Author:** [@vhaispdeaded](https://discuss.elastic.co/u/vhaispdeaded)\
**Replies:** 1\
**Last updated:** [May 17, 2023, 6:49pm UTC](https://discuss.elastic.co/t/issue-with-beats-forwarding-to-logstash/333689 "2023-05-17T18:49:16Z")

</div>

Our enterprise configures our AWS EC2 instances with Auditbeat, Filebeat, Journalbeat, Metricbeat, and Packetbeat to forward to a set of logstash servers. Our /var/log/messages, and /var/log/secure files are filled with …

---

## [Grok error in official Azure integration](https://discuss.elastic.co/t/grok-error-in-official-azure-integration/333585)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 3\
**Last updated:** [May 17, 2023, 6:22pm UTC](https://discuss.elastic.co/t/grok-error-in-official-azure-integration/333585 "2023-05-17T18:22:24Z")

</div>

Hey, the Azure integration currently (I'm using 8.7.0) fails to ingest some Azure Activity Logs with IPv6 source addresses. The reason is this processor: - grok: field: azure.activitylogs.callerIpAddress patter…

---

## [Which is better RAM allocation strategy?](https://discuss.elastic.co/t/which-is-better-ram-allocation-strategy/333497)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 4\
**Last updated:** [May 17, 2023, 6:07pm UTC](https://discuss.elastic.co/t/which-is-better-ram-allocation-strategy/333497 "2023-05-17T18:07:07Z")

</div>

If I have a data node with 128GB of RAM. Is it better to allocate 64GB to ES and 64GB to system? Or would it be ok (or even better) to allocate say 100GB to ES and leave 28GB to system? Our system is write heavy; ther…

---

## [Kibana and logstash can't run using docker-compose](https://discuss.elastic.co/t/kibana-and-logstash-cant-run-using-docker-compose/333498)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 2\
**Last updated:** [May 17, 2023, 5:52pm UTC](https://discuss.elastic.co/t/kibana-and-logstash-cant-run-using-docker-compose/333498 "2023-05-17T17:52:13Z")

</div>

hi ,hello everyone I run the elastic and logstash and kibana and mysql containers using docker-compose this the configuration that i use in my docker-compose file version: '3' services: mysql: container\_name: mysq…

---

## [Check if field from XML is object or array of objects?](https://discuss.elastic.co/t/check-if-field-from-xml-is-object-or-array-of-objects/333686)

<div class="topic-metadata">

**Author:** [@Meme-ento](https://discuss.elastic.co/u/Meme-ento)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 5:50pm UTC](https://discuss.elastic.co/t/check-if-field-from-xml-is-object-or-array-of-objects/333686 "2023-05-17T17:50:19Z")

</div>

I have the following case happening. I have an application that is configured to send data via a webhook like push method via HTTP rest api whenever data is inserted in the application database. Im using this functionali…

---

## [Winlogbeat yml file missing Elasticsearch output SSl Key](https://discuss.elastic.co/t/winlogbeat-yml-file-missing-elasticsearch-output-ssl-key/333679)

<div class="topic-metadata">

**Author:** [@geomandry](https://discuss.elastic.co/u/geomandry)\
**Replies:** 0\
**Last updated:** [May 17, 2023, 4:11pm UTC](https://discuss.elastic.co/t/winlogbeat-yml-file-missing-elasticsearch-output-ssl-key/333679 "2023-05-17T16:11:28Z")

</div>

Configured my stack to SSL and lost log forwarding from Winlogbeat. Everything looks well on yml file with the exception of the Elasticsearch output key path. I did not receive a key when Elasticsearch SSL was configured…

[Previous page](https://discuss.elastic.co/latest.md?page=672)

[Next page](https://discuss.elastic.co/latest.md?page=674)
