# Latest

**URL:** https://discuss.elastic.co/latest.md?page=682

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 683

---

## [Поиск по ключу + 2 символа](https://discuss.elastic.co/t/topic/333177)

<div class="topic-metadata">

**Author:** [@cia](https://discuss.elastic.co/u/cia)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 9:18am UTC](https://discuss.elastic.co/t/topic/333177 "2023-05-11T09:18:28Z")

</div>

Добрый день. Мне нужно организовать поиск по началу слова, но не больше "ключ + 2 символа". То есть если проиндексировали фразу "Каждый охотник желает знать", то результат должен находиться по "охотн", но НЕ должен по "…

---

## [My index write api request blocked by status 403 after adding index lifecycle policy](https://discuss.elastic.co/t/my-index-write-api-request-blocked-by-status-403-after-adding-index-lifecycle-policy/333174)

<div class="topic-metadata">

**Author:** [@jeyong.oh](https://discuss.elastic.co/u/jeyong.oh)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 9:01am UTC](https://discuss.elastic.co/t/my-index-write-api-request-blocked-by-status-403-after-adding-index-lifecycle-policy/333174 "2023-05-11T09:01:46Z")

</div>

This is what happened today. I'm using index without life cycle management. The index name is "vehicle-iot-coordinate", it's size is about 280GB and it grow with rate of 1GB/day. I'm adding lifecycle management. (disab…

---

## [Logstash , multiple indexs using same ILM and index template and alias error](https://discuss.elastic.co/t/logstash-multiple-indexs-using-same-ilm-and-index-template-and-alias-error/333092)

<div class="topic-metadata">

**Author:** [@sankrithi43](https://discuss.elastic.co/u/sankrithi43)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 8:38am UTC](https://discuss.elastic.co/t/logstash-multiple-indexs-using-same-ilm-and-index-template-and-alias-error/333092 "2023-05-11T08:38:49Z")

</div>

Hi , below is my task to setup and struggling with ILM issue and looking forward if any help here. i setup and configured filebeat and logstash on kubernetes cluster successfully. since we had multiple application…

---

## [Some info does not get shipped with MetricsBeat from AWS EKS](https://discuss.elastic.co/t/some-info-does-not-get-shipped-with-metricsbeat-from-aws-eks/332528)

<div class="topic-metadata">

**Author:** [@jeffpang](https://discuss.elastic.co/u/jeffpang)\
**Replies:** 5\
**Last updated:** [May 11, 2023, 8:15am UTC](https://discuss.elastic.co/t/some-info-does-not-get-shipped-with-metricsbeat-from-aws-eks/332528 "2023-05-11T08:15:28Z")

</div>

Hello there, As we would have the EKS to be monitored by Elastic, we deploy DaemonSet following this url. Metricbeat However some of the metrics cannot be shipped nor displayed on dashboards. apiVersion: v1 kind: …

---

## [Elasticsearch high latency](https://discuss.elastic.co/t/elasticsearch-high-latency/328911)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 15\
**Last updated:** [May 11, 2023, 7:49am UTC](https://discuss.elastic.co/t/elasticsearch-high-latency/328911 "2023-05-11T07:49:47Z")

</div>

Hi all, We noticed some high request latency for searches on our elasticsearch cluster(7.17) and while checking the metrics, it was seen that there was spike in search\_fetch\_time for many indices which were configured 1…

---

## [Can we use kibana without ES?](https://discuss.elastic.co/t/can-we-use-kibana-without-es/333151)

<div class="topic-metadata">

**Author:** [@j\_lim](https://discuss.elastic.co/u/j_lim)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 6:53am UTC](https://discuss.elastic.co/t/can-we-use-kibana-without-es/333151 "2023-05-11T06:53:57Z")

</div>

is there any way use Kibana without ES?

---

## [Curriculum Vitae using ES](https://discuss.elastic.co/t/curriculum-vitae-using-es/333108)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 6:15am UTC](https://discuss.elastic.co/t/curriculum-vitae-using-es/333108 "2023-05-11T06:15:57Z")

</div>

Good morning, I would like use elastic to search in CV perfect matchings and I have this question. Is it possible that with the text of CV get a list of tags? Like a tag cloud. My idea is get this tags and simply sav…

---

## [Fetching filtered and unfiltered count in a single request](https://discuss.elastic.co/t/fetching-filtered-and-unfiltered-count-in-a-single-request/333160)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 6:11am UTC](https://discuss.elastic.co/t/fetching-filtered-and-unfiltered-count-in-a-single-request/333160 "2023-05-11T06:11:51Z")

</div>

Hi, I have a use case where a user\_id has multiple records in Elasticsearch. I'm using a bool query on user\_id and additional filters on top of it. I'm able to fetch the count of filtered records using track\_total\_hits…

---

## [Timestamp attribute mapping as text(this existing mapping not working for newly created indices )](https://discuss.elastic.co/t/timestamp-attribute-mapping-as-text-this-existing-mapping-not-working-for-newly-created-indices/333156)

<div class="topic-metadata">

**Author:** [@Dnyaneshwar\_Chavan](https://discuss.elastic.co/u/Dnyaneshwar_Chavan)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 5:46am UTC](https://discuss.elastic.co/t/timestamp-attribute-mapping-as-text-this-existing-mapping-not-working-for-newly-created-indices/333156 "2023-05-11T05:46:36Z")

</div>

I am using dynamic indices creation with template { "base\_index\_dev" : { "order" : 0, "index\_patterns" : \[ "dev\_shipments", "dev\_shipment\_legs\_", "dev\_transport\_orders\_\*" \], "settings" : { "index" : { "default…

---

## [Can we filter multiple values using kibanaAddFilter in Vega](https://discuss.elastic.co/t/can-we-filter-multiple-values-using-kibanaaddfilter-in-vega/332398)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 7\
**Last updated:** [May 11, 2023, 6:05am UTC](https://discuss.elastic.co/t/can-we-filter-multiple-values-using-kibanaaddfilter-in-vega/332398 "2023-05-11T06:05:27Z")

</div>

Hello @everyone, I am using Vega to create my Visualization. I want to put kibanaAddFilter so that on click it filter out a field's multiple selected values. Like a field XYZ contains values( a,b,c,d,e,f,g). The filter…

---

## [Logstash jdbc Illegal instant due to time zone offset transition (daylight savings time 'gap'): 1979-03-21](https://discuss.elastic.co/t/logstash-jdbc-illegal-instant-due-to-time-zone-offset-transition-daylight-savings-time-gap-1979-03-21/332902)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 5:59am UTC](https://discuss.elastic.co/t/logstash-jdbc-illegal-instant-due-to-time-zone-offset-transition-daylight-savings-time-gap-1979-03-21/332902 "2023-05-11T05:59:11Z")

</div>

Hi Here is the logstash jdbc input config: Logstash conf: input { jdbc { jdbc\_driver\_library =\> "/opt/jdbc/ifxjdbc.jar" jdbc\_driver\_class =\> "com.informix.jdbc.IfxDriver" jdbc\_connection\_string =\> "jdbc:…

---

## [ pipeline/output.go:180  failed to publish events: client is not connected](https://discuss.elastic.co/t/pipeline-output-go-180-failed-to-publish-events-client-is-not-connected/333154)

<div class="topic-metadata">

**Author:** [@sandhya\_131](https://discuss.elastic.co/u/sandhya_131)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 5:40am UTC](https://discuss.elastic.co/t/pipeline-output-go-180-failed-to-publish-events-client-is-not-connected/333154 "2023-05-11T05:40:59Z")

</div>

Hello Everyone, I have ELK setup in kubernetes 1.23 cluster, I have filebeat in one namespace in the cluster as daemonset. For the master nodes we have filebeat deployed on the nodes while building the ami. Earlier we h…

---

## [Custom dotproduct with long type field value](https://discuss.elastic.co/t/custom-dotproduct-with-long-type-field-value/333150)

<div class="topic-metadata">

**Author:** [@Akhilendra](https://discuss.elastic.co/u/Akhilendra)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 5:07am UTC](https://discuss.elastic.co/t/custom-dotproduct-with-long-type-field-value/333150 "2023-05-11T05:07:05Z")

</div>

An array long type field in document geting automatically sorted when calculating dotproduct via custom painless script. Index Mapping PUT /custom\_dot\_product { "settings": { "number\_of\_shards": 1, "number\_o…

---

## [How to apply Kubernetes metrics without adding the Elastic agent to Fleet?](https://discuss.elastic.co/t/how-to-apply-kubernetes-metrics-without-adding-the-elastic-agent-to-fleet/333116)

<div class="topic-metadata">

**Author:** [@dbstjdghks25](https://discuss.elastic.co/u/dbstjdghks25)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 4:42am UTC](https://discuss.elastic.co/t/how-to-apply-kubernetes-metrics-without-adding-the-elastic-agent-to-fleet/333116 "2023-05-11T04:42:57Z")

</div>

I want to monitor Kubernetes by adding kubernetes-metricbeat to an existing agent, but when I apply the following YAML file, the agent is additionally registered with Fleet. How can I configure the YAML file to avoid thi…

---

## [Split large json file](https://discuss.elastic.co/t/split-large-json-file/333145)

<div class="topic-metadata">

**Author:** [@sree3](https://discuss.elastic.co/u/sree3)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 4:09am UTC](https://discuss.elastic.co/t/split-large-json-file/333145 "2023-05-11T04:09:14Z")

</div>

Hi All, Trying to split a single json file into multiple one's and then to output those single files Could someone please help to get this done Input Data is json file { "Computer": "node2", "ContainerID": "cbcf", …

---

## [Displaying realtime video on Kibana](https://discuss.elastic.co/t/displaying-realtime-video-on-kibana/333055)

<div class="topic-metadata">

**Author:** [@huynv1407](https://discuss.elastic.co/u/huynv1407)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 3:13am UTC](https://discuss.elastic.co/t/displaying-realtime-video-on-kibana/333055 "2023-05-11T03:13:15Z")

</div>

I wants to know if displaying realtime video on kibana is possible or not. How can I do that?.

---

## [Can filebeat recognize .gz log files?](https://discuss.elastic.co/t/can-filebeat-recognize-gz-log-files/332961)

<div class="topic-metadata">

**Author:** [@talka](https://discuss.elastic.co/u/talka)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 2:49am UTC](https://discuss.elastic.co/t/can-filebeat-recognize-gz-log-files/332961 "2023-05-11T02:49:18Z")

</div>

Hi, I'm using filebeat version 8.7.0. /var/log list the following files: -rwxrwxrwx 1 1000 1000 244631 Mar 21 06:30 cron -rwxrwxrwx 1 1000 1000 48940 Feb 26 03:37 cron-20230226.gz -rwxrwxrwx 1 1000 1000 48766 Mar …

---

## [My lifecycle policy is not working](https://discuss.elastic.co/t/my-lifecycle-policy-is-not-working/332856)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 10\
**Last updated:** [May 11, 2023, 2:09am UTC](https://discuss.elastic.co/t/my-lifecycle-policy-is-not-working/332856 "2023-05-11T02:09:47Z")

</div>

I want to automatically delete indexes that are 60 days old and have set up the following lifecycle policy. # curl -XGET '\_ilm/policy/its\_index-policy?pretty' { "its\_index-policy" : { "version" : 1, "modified\_…

---

## [How to extract custom field value from first line and add it into later lines with Filebeat](https://discuss.elastic.co/t/how-to-extract-custom-field-value-from-first-line-and-add-it-into-later-lines-with-filebeat/333140)

<div class="topic-metadata">

**Author:** [@lma\_yb](https://discuss.elastic.co/u/lma_yb)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 1:21am UTC](https://discuss.elastic.co/t/how-to-extract-custom-field-value-from-first-line-and-add-it-into-later-lines-with-filebeat/333140 "2023-05-11T01:21:27Z")

</div>

I am using filebeat to import log file which has some meta data in the first few lines into ELK. The log file format looks like this: Hostname: xxx Created: \<time\> Format: XXX ----Actual logs--- I want to extract the …

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/332956)

<div class="topic-metadata">

**Author:** [@Ali\_Trache](https://discuss.elastic.co/u/Ali_Trache)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 1:13am UTC](https://discuss.elastic.co/t/elasticsearch/332956 "2023-05-11T01:13:16Z")

</div>

hello ; please i want somme repense for me . thank you 1-How to size ELk storage? 2-How to check storage status and detect possible saturation? Can it be integrated into an “ELK” Dashboard? 3- how can we expand the s…

---

## [Visualization of parts of URL](https://discuss.elastic.co/t/visualization-of-parts-of-url/332858)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 1:12am UTC](https://discuss.elastic.co/t/visualization-of-parts-of-url/332858 "2023-05-11T01:12:09Z")

</div>

How to reopen the closed issue Visualization of parts of URL ? @jughosta I just saw the reply. How to use the proposed solution to filter parts of the URL and show it in my pie chart? Thanks.

---

## [Verify snapshot repository 401 Unauthorized error](https://discuss.elastic.co/t/verify-snapshot-repository-401-unauthorized-error/332987)

<div class="topic-metadata">

**Author:** [@devops-chicago](https://discuss.elastic.co/u/devops-chicago)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 1:11am UTC](https://discuss.elastic.co/t/verify-snapshot-repository-401-unauthorized-error/332987 "2023-05-11T01:11:35Z")

</div>

I am running ES (3 master, 3 data, and 3 ingest nodes) and Kibana on EKS using the ECK operator. I am trying to setup an S3 based snapshot repository but I receive a 401 Unauthorized error when trying to verify the repos…

---

## [Read after write consistency (test refresh interval)](https://discuss.elastic.co/t/read-after-write-consistency-test-refresh-interval/332809)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 1:05am UTC](https://discuss.elastic.co/t/read-after-write-consistency-test-refresh-interval/332809 "2023-05-11T01:05:33Z")

</div>

I have a refresh interval of 1 s. I want to confirm that this is actually happening. Is there a test to validate the item getting indexed is getting searchable in a second? If so, How do I do that? I am ingesting documen…

---

## [Legend of a map](https://discuss.elastic.co/t/legend-of-a-map/332999)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 4\
**Last updated:** [May 11, 2023, 1:04am UTC](https://discuss.elastic.co/t/legend-of-a-map/332999 "2023-05-11T01:04:59Z")

</div>

Hi, Just a question : For the moment it's impossible to change the label in the legend of a map. Do you know if this feature is expected or not? t would be very useful because sometimes the legend is not very meaningfu…

---

## [With Java API Client, update by appending to field array of document](https://discuss.elastic.co/t/with-java-api-client-update-by-appending-to-field-array-of-document/332859)

<div class="topic-metadata">

**Author:** [@rrrrrr](https://discuss.elastic.co/u/rrrrrr)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 3:09am UTC](https://discuss.elastic.co/t/with-java-api-client-update-by-appending-to-field-array-of-document/332859 "2023-05-09T03:09:03Z")

</div>

Hello, Is there any examples to update a document partially ? I would like to append to a field array utilizing Java API Client. I would like to not use Scripts or Java High Level Client if possible. Thank you, Reza …

---

## [AWS S3 repo configuration](https://discuss.elastic.co/t/aws-s3-repo-configuration/332868)

<div class="topic-metadata">

**Author:** [@dj\_kill](https://discuss.elastic.co/u/dj_kill)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 6:14am UTC](https://discuss.elastic.co/t/aws-s3-repo-configuration/332868 "2023-05-09T06:14:48Z")

</div>

Hello. I'm using Elasticsearch (ECK) Operator 2.7 in OpenShift environment. All components are on 8.6.2 version. Configuration for the S3 is pretty simple: spec: version: 8.6.2 secureSettings: - secretName: c…

---

## [Search rate of index is too high in Kibana, but no query in actually](https://discuss.elastic.co/t/search-rate-of-index-is-too-high-in-kibana-but-no-query-in-actually/332883)

<div class="topic-metadata">

**Author:** [@hongbo](https://discuss.elastic.co/u/hongbo)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 12:57am UTC](https://discuss.elastic.co/t/search-rate-of-index-is-too-high-in-kibana-but-no-query-in-actually/332883 "2023-05-11T00:57:26Z")

</div>

search rate of index is too high in kibana stack-monitoring, but no query in actually. at the same time, with the primaries(number\_of\_shards) increase, the search rate value increase. for example, i have three index: m…

---

## [Aliases Error in Ingest pipeline Index](https://discuss.elastic.co/t/aliases-error-in-ingest-pipeline-index/332814)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 12:54am UTC](https://discuss.elastic.co/t/aliases-error-in-ingest-pipeline-index/332814 "2023-05-11T00:54:29Z")

</div>

Hi Team, We are processing the logs using API key from below path. C# -\> ingest pipeline -\> Elasticsearch -\> kibana We ran the below template but Aliases not working, it shows none. Please find the snapshot attached. …

---

## [BulkRequest with Java API Client missing document part](https://discuss.elastic.co/t/bulkrequest-with-java-api-client-missing-document-part/333077)

<div class="topic-metadata">

**Author:** [@DavJane](https://discuss.elastic.co/u/DavJane)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 11:00am UTC](https://discuss.elastic.co/t/bulkrequest-with-java-api-client-missing-document-part/333077 "2023-05-10T11:00:47Z")

</div>

Hi all, I am migrating from Elasticsearch high rest client 6.x to Java API client and have encountered an issue with the BulkRequest. I am creating a json string and sending that in as part of the document part of the …

---

## [Multisearch (bulk) knn searches](https://discuss.elastic.co/t/multisearch-bulk-knn-searches/333095)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 12:27am UTC](https://discuss.elastic.co/t/multisearch-bulk-knn-searches/333095 "2023-05-11T00:27:50Z")

</div>

Hello, I want to use knn searching on dense\_vectors for similarity searches, but I want to issue multiple requests at once using the Multisearch API. Is this possible? The Java client library (co.elastic.clients:elast…

[Previous page](https://discuss.elastic.co/latest.md?page=681)

[Next page](https://discuss.elastic.co/latest.md?page=683)
