# Latest

**URL:** https://discuss.elastic.co/latest.md?page=714

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 715

---

## [I need help to undertand "GET \<target\>/\_ilm/explain" output for ILM policy phases moving](https://discuss.elastic.co/t/i-need-help-to-undertand-get-target-ilm-explain-output-for-ilm-policy-phases-moving/327912)

<div class="topic-metadata">

**Author:** [@LizardNerd](https://discuss.elastic.co/u/LizardNerd)\
**Replies:** 0\
**Last updated:** [March 17, 2023, 9:22am UTC](https://discuss.elastic.co/t/i-need-help-to-undertand-get-target-ilm-explain-output-for-ilm-policy-phases-moving/327912 "2023-03-17T09:22:19Z")

</div>

Hi there, I'm fairly new to Elastic Stack. I created an ILM policy for my first data stream, then I ran: GET .ds-logs-pfsense.log-default-2023.01.26-000004/\_ilm/explain This is the output: { "indices": { ".ds-lo…

---

## [Log files getting accumulated in temporary\_directory path while reading logs from s3 buckets](https://discuss.elastic.co/t/log-files-getting-accumulated-in-temporary-directory-path-while-reading-logs-from-s3-buckets/329838)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 4:23pm UTC](https://discuss.elastic.co/t/log-files-getting-accumulated-in-temporary-directory-path-while-reading-logs-from-s3-buckets/329838 "2023-04-12T16:23:58Z")

</div>

Hi All, We have a logstash configuration to read logs from s3 bucket. Here is the configuration: input { s3 { access\_key\_id =\> "\*\*\*\*\*\*\*\*\*\*\*\*\*\*" secret\_access\_key =\> "hjiufaaaa" bucket =\> "test…

---

## [Elastic phrase suggester](https://discuss.elastic.co/t/elastic-phrase-suggester/329858)

<div class="topic-metadata">

**Author:** [@sujata1993](https://discuss.elastic.co/u/sujata1993)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 4:16pm UTC](https://discuss.elastic.co/t/elastic-phrase-suggester/329858 "2023-04-12T16:16:49Z")

</div>

Query: POST merchants\_phrase\_suggester\_29032023/\_search { "suggest": { "text" : "amazn,walmart", "simple\_phrase" : { "phrase" : { "field" : "mrch\_nm.trigram", "size" : 1, "confidence":0, "gram\_size":3, "max…

---

## [What triggers regular merges?](https://discuss.elastic.co/t/what-triggers-regular-merges/329773)

<div class="topic-metadata">

**Author:** [@Emma\_Vaiserfirov](https://discuss.elastic.co/u/Emma_Vaiserfirov)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 3:58pm UTC](https://discuss.elastic.co/t/what-triggers-regular-merges/329773 "2023-04-12T15:58:46Z")

</div>

Hi there, we're trying to decide if we need to trigger force merges on a regular basis. To do that, I was trying to understand how (and how often) merges are triggered by default. The piece of public documentation on mer…

---

## [Parse XML sub tags as a separate log](https://discuss.elastic.co/t/parse-xml-sub-tags-as-a-separate-log/329832)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 3:43pm UTC](https://discuss.elastic.co/t/parse-xml-sub-tags-as-a-separate-log/329832 "2023-04-12T15:43:17Z")

</div>

Hi Team, I have a XML formatted as below \<?xml version="1.0" encoding="UTF-8"?\> \<documents\> \<Document\>\<docID\>101074476\</docID\>\<Title\>End of Sale 1403 and 1416\</Title\>\<Author\>clark13\</Author\>\</Document\> \<Document\>\<docI…

---

## [Apply filters](https://discuss.elastic.co/t/apply-filters/329510)

<div class="topic-metadata">

**Author:** [@serjio](https://discuss.elastic.co/u/serjio)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 3:29pm UTC](https://discuss.elastic.co/t/apply-filters/329510 "2023-04-12T15:29:23Z")

</div>

good afternoon. Recently I started to get acquainted with ELK and aot what is my problem: I use such a filter filter { if \[type\] == "syslog" { grok { match =\> { "message" =\> "\<%{POSINT:syslog\_pri}\>%{SYSLO…

---

## [Data view - number of Index timeout issue](https://discuss.elastic.co/t/data-view-number-of-index-timeout-issue/329769)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 2:58pm UTC](https://discuss.elastic.co/t/data-view-number-of-index-timeout-issue/329769 "2023-04-12T14:58:34Z")

</div>

I have large index with high volume of data. one shard is 20gig, Lets say two index per day from six month = 360 index with billions of record combine. when I run following it timesout select x,y,z from myidex-\* wh…

---

## [Using \`Group by\` in Uptime Alerts](https://discuss.elastic.co/t/using-group-by-in-uptime-alerts/329523)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 2:41pm UTC](https://discuss.elastic.co/t/using-group-by-in-uptime-alerts/329523 "2023-04-12T14:41:26Z")

</div>

Use Case As a user, I am using Synthetics (beta) in Elastic Cloud 8.7.0 to monitor the availability of a service on multiple hosts in an agent policy with an Uptime Test using TCP Ping. Synthetics (beta) sees connection …

---

## [The documents JSON is not valid](https://discuss.elastic.co/t/the-documents-json-is-not-valid/329114)

<div class="topic-metadata">

**Author:** [@Hajar\_Lachhab](https://discuss.elastic.co/u/Hajar_Lachhab)\
**Replies:** 6\
**Last updated:** [April 12, 2023, 2:38pm UTC](https://discuss.elastic.co/t/the-documents-json-is-not-valid/329114 "2023-04-12T14:38:12Z")

</div>

Hi everyone, I just wanna ask for a solution of my problem when i try to test my pipeline i got an error "The documents JSON is not valid." That's the document that i try to test my pipeline with it \[ { "\_source…

---

## [Elastic Aggregations query](https://discuss.elastic.co/t/elastic-aggregations-query/329807)

<div class="topic-metadata">

**Author:** [@math1](https://discuss.elastic.co/u/math1)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 2:33pm UTC](https://discuss.elastic.co/t/elastic-aggregations-query/329807 "2023-04-12T14:33:39Z")

</div>

POST test/\_doc/ { "food": \[ { "food1": { "type": "Western food", "name": "hamburger" }, "food2": { "type": "Japanese food", "name": "sushi" } } \] } POS…

---

## [Bonnes pratiques concernant l'indexation de documents](https://discuss.elastic.co/t/bonnes-pratiques-concernant-lindexation-de-documents/329847)

<div class="topic-metadata">

**Author:** [@jarod51](https://discuss.elastic.co/u/jarod51)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 2:31pm UTC](https://discuss.elastic.co/t/bonnes-pratiques-concernant-lindexation-de-documents/329847 "2023-04-12T14:31:51Z")

</div>

Bonjour J'ai un petit projet de stockage de documents sous le coude. Dans mon idée je voulais séparer la problématique de stockage (multi drives; potentiellement gros fichiers) de la problématique d'indexation (beaucoup…

---

## [Licence: install Elastic 7.16.2 Free or Platinum on Kubernetes](https://discuss.elastic.co/t/licence-install-elastic-7-16-2-free-or-platinum-on-kubernetes/329576)

<div class="topic-metadata">

**Author:** [@SalvoDM91](https://discuss.elastic.co/u/SalvoDM91)\
**Replies:** 10\
**Last updated:** [April 12, 2023, 2:21pm UTC](https://discuss.elastic.co/t/licence-install-elastic-7-16-2-free-or-platinum-on-kubernetes/329576 "2023-04-12T14:21:31Z")

</div>

HI Guys, I would like to install all ELK stack (Elasticsearch, Logstash and Kibana) on Kubernets. I'm undecided if using the Free or Platinum version but before proceeding I would like to know if there are any limits on…

---

## [Search: Removing full stop if part of acronym / abbreviation with pattern\_replace character filter](https://discuss.elastic.co/t/search-removing-full-stop-if-part-of-acronym-abbreviation-with-pattern-replace-character-filter/329810)

<div class="topic-metadata">

**Author:** [@Marzipan](https://discuss.elastic.co/u/Marzipan)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 8:24am UTC](https://discuss.elastic.co/t/search-removing-full-stop-if-part-of-acronym-abbreviation-with-pattern-replace-character-filter/329810 "2023-04-12T08:24:05Z")

</div>

Hi! My input are author names and book titles. I try to delete full stops if they appear in acronyms and abbreviations. For example: S.O.S. should be replaced with SOS H.P. Lovecraft should be replaced with HP Lovec…

---

## [Can't create a cluster if node's domain points to the localhost in /etc/hosts](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738)

<div class="topic-metadata">

**Author:** [@panrobot](https://discuss.elastic.co/u/panrobot)\
**Replies:** 8\
**Last updated:** [April 12, 2023, 2:06pm UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738 "2023-04-12T14:06:37Z")

</div>

Hi, if /etc/hosts/ is configured as follows: 127.0.0.1 node01.com 127.0.0.1 localhost and if you set elasticsearch.yml to: network.host: \["\_enp1s0\_", "\_local\_"\] …

---

## [Unable to create dead letter queue writer](https://discuss.elastic.co/t/unable-to-create-dead-letter-queue-writer/329688)

<div class="topic-metadata">

**Author:** [@tcapp24](https://discuss.elastic.co/u/tcapp24)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 2:01pm UTC](https://discuss.elastic.co/t/unable-to-create-dead-letter-queue-writer/329688 "2023-04-12T14:01:10Z")

</div>

Logstash Version - 7.9.1 Currently we are unable to start Logstash properly without receiving error below: \[2023-04-10T20:18:52,978\]\[ERROR\]\[org.logstash.common.DeadLetterQueueFactory\] unable to create dead letter queue…

---

## [Winlogbeat wrong values](https://discuss.elastic.co/t/winlogbeat-wrong-values/326070)

<div class="topic-metadata">

**Author:** [@objectprogr](https://discuss.elastic.co/u/objectprogr)\
**Replies:** 7\
**Last updated:** [April 12, 2023, 1:36pm UTC](https://discuss.elastic.co/t/winlogbeat-wrong-values/326070 "2023-04-12T13:36:40Z")

</div>

I see the flows from my Windows computer, but I have for example: account name: %1 domain name: %2 logon type: %9 ect. For example, on Windows %1 is Computer1, domain name is testDomian ect.

---

## [Kibana web page does not open when virtual machine interface is host-only](https://discuss.elastic.co/t/kibana-web-page-does-not-open-when-virtual-machine-interface-is-host-only/329684)

<div class="topic-metadata">

**Author:** [@kh1971](https://discuss.elastic.co/u/kh1971)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 1:28pm UTC](https://discuss.elastic.co/t/kibana-web-page-does-not-open-when-virtual-machine-interface-is-host-only/329684 "2023-04-12T13:28:10Z")

</div>

I have recently installed elasticsearch on my Kali purple virtual machine with my VM interface setting set as network enabled. I used a vmnet which allowed me access to the internet via my regualr host machine. After in…

---

## [Aggregate secure/sshd syslog event based on selected events](https://discuss.elastic.co/t/aggregate-secure-sshd-syslog-event-based-on-selected-events/328249)

<div class="topic-metadata">

**Author:** [@jun.7.6](https://discuss.elastic.co/u/jun.7.6)\
**Replies:** 24\
**Last updated:** [April 12, 2023, 1:19pm UTC](https://discuss.elastic.co/t/aggregate-secure-sshd-syslog-event-based-on-selected-events/328249 "2023-04-12T13:19:55Z")

</div>

Hi I'm trying to filter out the login & logout events from linux ssh events send as syslog to Logstash and forward it to my firewall via syslog again. This setup is to allow my firewall to map the user-id to IP address i…

---

## [Elasticsearch how to correctly calculate the number of shards](https://discuss.elastic.co/t/elasticsearch-how-to-correctly-calculate-the-number-of-shards/329834)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 12:47pm UTC](https://discuss.elastic.co/t/elasticsearch-how-to-correctly-calculate-the-number-of-shards/329834 "2023-04-12T12:47:56Z")

</div>

the question is about the intricacies of configuration. Situation - there is one physical server. Two CPUs. 20 cores in total. The task is to load there a lot of text - about 250 millions of records. Each of which a coup…

---

## [Multiple bulk actions on the same document](https://discuss.elastic.co/t/multiple-bulk-actions-on-the-same-document/329650)

<div class="topic-metadata">

**Author:** [@Tudor\_Plugaru](https://discuss.elastic.co/u/Tudor_Plugaru)\
**Replies:** 6\
**Last updated:** [April 12, 2023, 12:44pm UTC](https://discuss.elastic.co/t/multiple-bulk-actions-on-the-same-document/329650 "2023-04-12T12:44:52Z")

</div>

Hi, To index data into Elasticsearch, we are using an Apache Flink pipeline that is consuming from Kafka topics. The index mapping looks something like below, a document with nested documents: { "name": "email documen…

---

## [Painless script to find the difference between two timestamp values](https://discuss.elastic.co/t/painless-script-to-find-the-difference-between-two-timestamp-values/329829)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 12:31pm UTC](https://discuss.elastic.co/t/painless-script-to-find-the-difference-between-two-timestamp-values/329829 "2023-04-12T12:31:31Z")

</div>

Hi All, I am trying to define a scripted field in ES 7.17 scope where the difference between two timestamp field values need to be defined. I did looked into the painless documentation, but could not exactly find some …

---

## [Query to Select Document based on only one object to be present under Node](https://discuss.elastic.co/t/query-to-select-document-based-on-only-one-object-to-be-present-under-node/329824)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 12:14pm UTC](https://discuss.elastic.co/t/query-to-select-document-based-on-only-one-object-to-be-present-under-node/329824 "2023-04-12T12:14:43Z")

</div>

Hi, We have data indexed as below { "tags": { "firstlevel": { "events": \[\], "promotions": \[\] } } } Data can be something like which has both events and promotions, just events or just promotion…

---

## [Controls in ES 8.6.2](https://discuss.elastic.co/t/controls-in-es-8-6-2/329828)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 11:38am UTC](https://discuss.elastic.co/t/controls-in-es-8-6-2/329828 "2023-04-12T11:38:27Z")

</div>

Hi I am migrating from ES 7.17 to ES 8.6.2 with predefined set of Kibana dashboards. Each dashboard has definition of user input panel with few Elasticsearch index fields. Now, with 8.6.2 introduced 'Controls' as repl…

---

## [Filebeat timestamp processor to parse from epoch/unix\_ms to readable format](https://discuss.elastic.co/t/filebeat-timestamp-processor-to-parse-from-epoch-unix-ms-to-readable-format/329712)

<div class="topic-metadata">

**Author:** [@rkelastic](https://discuss.elastic.co/u/rkelastic)\
**Replies:** 4\
**Last updated:** [April 12, 2023, 11:37am UTC](https://discuss.elastic.co/t/filebeat-timestamp-processor-to-parse-from-epoch-unix-ms-to-readable-format/329712 "2023-04-12T11:37:45Z")

</div>

I want to convert an epoch timestamp (ex: 1680940932415) to readable format (ex: '2006-01-02 15:04:05') using timestamp processor (Timestamp | Filebeat Reference \[8.7\] | Elastic), but am unable to achieve it. processor…

---

## [\[Elastic search\] wildcard (ignore case) query is not working](https://discuss.elastic.co/t/elastic-search-wildcard-ignore-case-query-is-not-working/329701)

<div class="topic-metadata">

**Author:** [@K\_Nam](https://discuss.elastic.co/u/K_Nam)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 11:37am UTC](https://discuss.elastic.co/t/elastic-search-wildcard-ignore-case-query-is-not-working/329701 "2023-04-12T11:37:01Z")

</div>

I have a problem when using wildcard (ignore case) query. I am using v7.10.2 Uppercase Lower case I have 2 query, the first is uppercase, the other is not. My expected output is both query will return the same r…

---

## [Esrally client option](https://discuss.elastic.co/t/esrally-client-option/329638)

<div class="topic-metadata">

**Author:** [@tmdgk490255](https://discuss.elastic.co/u/tmdgk490255)\
**Replies:** 6\
**Last updated:** [April 12, 2023, 9:32am UTC](https://discuss.elastic.co/t/esrally-client-option/329638 "2023-04-12T09:32:40Z")

</div>

there is some options to specify the number of clients for certain operation in rally track "schedule": \[ { "operation": "force-merge", "clients": 1 // here }, { "operation": "match-all-qu…

---

## [Search: Filter data after an aggregation](https://discuss.elastic.co/t/search-filter-data-after-an-aggregation/329760)

<div class="topic-metadata">

**Author:** [@gutierrezfj](https://discuss.elastic.co/u/gutierrezfj)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 10:25am UTC](https://discuss.elastic.co/t/search-filter-data-after-an-aggregation/329760 "2023-04-12T10:25:17Z")

</div>

Hi community. I have made a query to obtain the average number of bytes per browser type, but I require that only the data that has an average less than 5000 be displayed or retrieved. I have read a lot but nothing con…

---

## [How to create new field after subtracting 2 date time field](https://discuss.elastic.co/t/how-to-create-new-field-after-subtracting-2-date-time-field/329822)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 10:08am UTC](https://discuss.elastic.co/t/how-to-create-new-field-after-subtracting-2-date-time-field/329822 "2023-04-12T10:08:19Z")

</div>

I want to create one new field type String in existing index after subtracting two datetime (format - 2023-04-31 23:23:13). It should return 'Type-1' if seconds difference is more than or equal to 180 and should return '…

---

## [Multiple configuration or multiple codec](https://discuss.elastic.co/t/multiple-configuration-or-multiple-codec/329752)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 9:44am UTC](https://discuss.elastic.co/t/multiple-configuration-or-multiple-codec/329752 "2023-04-12T09:44:11Z")

</div>

Here is my logstash.conf file input { file { path =\> "/var/log/appslogs/\*\*/\*.log" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" codec =\> plain { charset =\> "UTF-8" } type =\> "…

---

## [Help with this grok](https://discuss.elastic.co/t/help-with-this-grok/329817)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 9:28am UTC](https://discuss.elastic.co/t/help-with-this-grok/329817 "2023-04-12T09:28:39Z")

</div>

Need a grok filter that parses out the account (the peacesat) from these two types of logs Case 1: Apr 11 14:26:55 mail saslauthd\[15405\]: auth\_zimbra: peacesat@uhtasi.org auth failed: authentication failed for \[peacesa…

[Previous page](https://discuss.elastic.co/latest.md?page=713)

[Next page](https://discuss.elastic.co/latest.md?page=715)
