# Latest

**URL:** https://discuss.elastic.co/latest.md?page=720

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 721

---

## [Cluster Redundancy](https://discuss.elastic.co/t/cluster-redundancy/329415)

<div class="topic-metadata">

**Author:** [@George\_Smith](https://discuss.elastic.co/u/George_Smith)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 3:00pm UTC](https://discuss.elastic.co/t/cluster-redundancy/329415 "2023-04-05T15:00:46Z")

</div>

Hi all, I have a question regarding network redundancy with an Elasticsearch Cluster. I am attempting to add redundancy to my cluster so that if a network adapter a node is using fails, it can use another network adapt…

---

## [Similar configuration for multiple Filebeat inputs](https://discuss.elastic.co/t/similar-configuration-for-multiple-filebeat-inputs/329443)

<div class="topic-metadata">

**Author:** [@thibaut\_a](https://discuss.elastic.co/u/thibaut_a)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 2:34pm UTC](https://discuss.elastic.co/t/similar-configuration-for-multiple-filebeat-inputs/329443 "2023-04-05T14:34:46Z")

</div>

Hi, I am using Filebeat on about ten servers (almost all under Linux except 2 under Windows). I have edited a filebeat.yml file on each one and approximately 10 inputs inside both. Inputs are only 'filestream' type for t…

---

## [Char\_Filter pattern replace is not behaving correctly](https://discuss.elastic.co/t/char-filter-pattern-replace-is-not-behaving-correctly/329445)

<div class="topic-metadata">

**Author:** [@ahiggins](https://discuss.elastic.co/u/ahiggins)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 2:44pm UTC](https://discuss.elastic.co/t/char-filter-pattern-replace-is-not-behaving-correctly/329445 "2023-04-05T14:44:42Z")

</div>

Elasticsearch Version 7.178 I am trying to work on a custom analyzer that would fix problematic texts in our database that contain unsearchable texts that are being obscured by existing '\\u200c' characters, or half-spac…

---

## [Either white space or a %{WORD:\_\_\_\_\_}](https://discuss.elastic.co/t/either-white-space-or-a-word/329357)

<div class="topic-metadata">

**Author:** [@Jim\_Thunder](https://discuss.elastic.co/u/Jim_Thunder)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 2:35pm UTC](https://discuss.elastic.co/t/either-white-space-or-a-word/329357 "2023-04-05T14:35:12Z")

</div>

I have two different kinds of messages that are very similar: "Rec": " 10:33:38 +HCXPCTA-E CW83 ISMDAYS ASRA"} "Rec": " 10:31:56 +HCXPCTA-E IS60 RX1 ISMDAYS ASRA"} In the REC field one message has RX1 while …

---

## [Meraki not parsing sport and saddr correctly](https://discuss.elastic.co/t/meraki-not-parsing-sport-and-saddr-correctly/329440)

<div class="topic-metadata">

**Author:** [@pozniako16](https://discuss.elastic.co/u/pozniako16)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 2:26pm UTC](https://discuss.elastic.co/t/meraki-not-parsing-sport-and-saddr-correctly/329440 "2023-04-05T14:26:17Z")

</div>

Currently in the parsing pipeline for meraki. The sport and saddr are inverted. Address should be in Address:Port format not the opposite.

---

## [Bulk via Python to Kubernetes cluster](https://discuss.elastic.co/t/bulk-via-python-to-kubernetes-cluster/329065)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 1:46pm UTC](https://discuss.elastic.co/t/bulk-via-python-to-kubernetes-cluster/329065 "2023-04-05T13:46:38Z")

</div>

Hi! We are heavily indexing to Elasticsearch 8.6.1 via Python code using bulk API. Our cluster runs on Kubernetes with the elastic operator which creates the following services: my-cluster-es-data my-cluster-es-http m…

---

## [Kibana data](https://discuss.elastic.co/t/kibana-data/329329)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 1:19pm UTC](https://discuss.elastic.co/t/kibana-data/329329 "2023-04-05T13:19:42Z")

</div>

hello i use filebeat to load data from a virtual machine to Elasticsearch and i found it in discover as data stream i just have a question why the number of hits decrease everytime and not still the same thank u

---

## [Prevent filebeat-version-yyyy-mm-dd index from ingesting](https://discuss.elastic.co/t/prevent-filebeat-version-yyyy-mm-dd-index-from-ingesting/329152)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 5\
**Last updated:** [April 5, 2023, 12:37pm UTC](https://discuss.elastic.co/t/prevent-filebeat-version-yyyy-mm-dd-index-from-ingesting/329152 "2023-04-05T12:37:09Z")

</div>

On daily basis i am seeing indexes with name filebeat-7.17.7-yyyy-mm-dd are creating. This is eating lot of space i have to delete them manually. I Have seen options like to create entry in ES which will not allow aut…

---

## [What happened to composite runtime fields in Elasticsearch client?](https://discuss.elastic.co/t/what-happened-to-composite-runtime-fields-in-elasticsearch-client/329430)

<div class="topic-metadata">

**Author:** [@MichaelOpitz](https://discuss.elastic.co/u/MichaelOpitz)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 12:33pm UTC](https://discuss.elastic.co/t/what-happened-to-composite-runtime-fields-in-elasticsearch-client/329430 "2023-04-05T12:33:43Z")

</div>

Hi community, We used composite runtime fields in the Elasticsearch java client. But since we moved to the new Elasticsearch client, composite runtime fields are not longer supported. Are these runtime fields deprecate…

---

## [Index and search multiple indices and fields](https://discuss.elastic.co/t/index-and-search-multiple-indices-and-fields/329324)

<div class="topic-metadata">

**Author:** [@Adarsh\_R\_K](https://discuss.elastic.co/u/Adarsh_R_K)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 12:14pm UTC](https://discuss.elastic.co/t/index-and-search-multiple-indices-and-fields/329324 "2023-04-05T12:14:45Z")

</div>

I am new to elasticsearch I am using elasticsearch java-client library to in spring boot application for a global search functionality.I have 5 entity classes with multiple fileds to search for , how can I do that ? I …

---

## [How can I identify the root cause and fix a query in Elasticsearch cluster that never returns a response](https://discuss.elastic.co/t/how-can-i-identify-the-root-cause-and-fix-a-query-in-elasticsearch-cluster-that-never-returns-a-response/329424)

<div class="topic-metadata">

**Author:** [@Sagar\_Gulabani1](https://discuss.elastic.co/u/Sagar_Gulabani1)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 11:35am UTC](https://discuss.elastic.co/t/how-can-i-identify-the-root-cause-and-fix-a-query-in-elasticsearch-cluster-that-never-returns-a-response/329424 "2023-04-05T11:35:11Z")

</div>

How can I identify the root cause and fix a query in Elasticsearch cluster that never returns a response. I have an Elasticsearch cluster with Elasticsearch, Logstash, and Kibana running on the same machine using Docker…

---

## [How to visualize color change depending on the counts on a bar vertical graph?](https://discuss.elastic.co/t/how-to-visualize-color-change-depending-on-the-counts-on-a-bar-vertical-graph/329413)

<div class="topic-metadata">

**Author:** [@OlegG](https://discuss.elastic.co/u/OlegG)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 11:39am UTC](https://discuss.elastic.co/t/how-to-visualize-color-change-depending-on-the-counts-on-a-bar-vertical-graph/329413 "2023-04-05T11:39:43Z")

</div>

The question seems to be clear enough. The picture should look like this.

---

## [App Search Accuracy Match Results](https://discuss.elastic.co/t/app-search-accuracy-match-results/329139)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 10:57am UTC](https://discuss.elastic.co/t/app-search-accuracy-match-results/329139 "2023-04-05T10:57:17Z")

</div>

Hello, I would like to ask can the Search UI be configured the searching results component to display the accuracy match of the result? Probably something like above image from Relevance Tuning in App Search, but it…

---

## [How to transfer users from an Elastic Cluster to another one](https://discuss.elastic.co/t/how-to-transfer-users-from-an-elastic-cluster-to-another-one/329366)

<div class="topic-metadata">

**Author:** [@Leonardo\_Henrique](https://discuss.elastic.co/u/Leonardo_Henrique)\
**Replies:** 3\
**Last updated:** [April 5, 2023, 10:54am UTC](https://discuss.elastic.co/t/how-to-transfer-users-from-an-elastic-cluster-to-another-one/329366 "2023-04-05T10:54:54Z")

</div>

Hey everyone! I need to copy the users and roles from an Elastic cluster 7.9 to a new 8.3.2 cluster. Is there a way to do that? Recreating manually is not possible since we have hundreds of users configured and most of…

---

## [Problem with data streams date after rollover](https://discuss.elastic.co/t/problem-with-data-streams-date-after-rollover/329410)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 9:59am UTC](https://discuss.elastic.co/t/problem-with-data-streams-date-after-rollover/329410 "2023-04-05T09:59:27Z")

</div>

Hi. I configured ES to rollover my indexes every day. I noticed that today my index rolled at Current action time 2023-04-05 00:34:31. Despite that, the index name created was .ds-suricata-ids-8.6.2-2023.04.04-000010 w…

---

## [Unable to add empty field with Logstash](https://discuss.elastic.co/t/unable-to-add-empty-field-with-logstash/329306)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 9:34am UTC](https://discuss.elastic.co/t/unable-to-add-empty-field-with-logstash/329306 "2023-04-05T09:34:39Z")

</div>

Hello community! I'm trying to add empty field into Logstash parsers like this: mutate { add\_field =\> {"comments" =\> {} } } this is my mapping in Kibana: { "\_meta": { "documentation": "https://www.elastic.co/gu…

---

## [New Filebeat Module - ECS not supports email fields](https://discuss.elastic.co/t/new-filebeat-module-ecs-not-supports-email-fields/329339)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 2:59pm UTC](https://discuss.elastic.co/t/new-filebeat-module-ecs-not-supports-email-fields/329339 "2023-04-04T14:59:46Z")

</div>

Hi I'm trying to contribute several new filebeat modules (Postfix and Exchange) and can't use email fields. Seems filebeat tests use old ECS schema. I've tried to change ecs version to the last one but it's not working. …

---

## [Issue with elasticsearch](https://discuss.elastic.co/t/issue-with-elasticsearch/329333)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 6\
**Last updated:** [April 5, 2023, 9:11am UTC](https://discuss.elastic.co/t/issue-with-elasticsearch/329333 "2023-04-05T09:11:25Z")

</div>

\[logstash.outputs.elasticsearch\]\[main\] Attempted to resurrect connection to dead ES instance, but got an error {:url=\>"http://newadmin:xxxxxx@localhost:9200/", :exception=\>LogStash::Outputs::Elasticsearch::HttpClient::Po…

---

## [Ingest @timestamp](https://discuss.elastic.co/t/ingest-timestamp/329400)

<div class="topic-metadata">

**Author:** [@sta](https://discuss.elastic.co/u/sta)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 8:51am UTC](https://discuss.elastic.co/t/ingest-timestamp/329400 "2023-04-05T08:51:01Z")

</div>

Hello. I have a log file where timestamp is \[2023-04-05 07:42:35\]. I made a ingest pipeline PUT \_ingest/pipeline/fe-logs-json { "processors": \[ { "grok": { "field": "message", "patterns": \[ …

---

## [Latency reporting and rate limitting in logging-indexing-querying track](https://discuss.elastic.co/t/latency-reporting-and-rate-limitting-in-logging-indexing-querying-track/329135)

<div class="topic-metadata">

**Author:** [@Jiri\_Holusa](https://discuss.elastic.co/u/Jiri_Holusa)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 8:48am UTC](https://discuss.elastic.co/t/latency-reporting-and-rate-limitting-in-logging-indexing-querying-track/329135 "2023-04-05T08:48:02Z")

</div>

Hi, we're using rally for performance evaluation. In our case, it's about the effect of a JVM to Elasticsearch's performance (disclaimer: I work for Azul). We would like to use challenge "elastic/logs", track "logging-…

---

## [Is it possible to recover logs that failed to transfer to ElasticSearch?](https://discuss.elastic.co/t/is-it-possible-to-recover-logs-that-failed-to-transfer-to-elasticsearch/329401)

<div class="topic-metadata">

**Author:** [@r.fujii](https://discuss.elastic.co/u/r.fujii)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 8:35am UTC](https://discuss.elastic.co/t/is-it-possible-to-recover-logs-that-failed-to-transfer-to-elasticsearch/329401 "2023-04-05T08:35:20Z")

</div>

The following configuration is used to obtain the server's audit logs and forward them to Elasticsearch. AuditBeat -\> Logstash -\> Elasticsearch However, on Elasticsearch, the number of shards exceeded max\_shards\_per\_no…

---

## [Script Exception on Elasticsearch function score script query](https://discuss.elastic.co/t/script-exception-on-elasticsearch-function-score-script-query/329387)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 8:07am UTC](https://discuss.elastic.co/t/script-exception-on-elasticsearch-function-score-script-query/329387 "2023-04-05T08:07:46Z")

</div>

Hello, I have used function score for a query and my script is: "doc\['Field1\_score'\].value != null && doc\['Field2\_score'\].value !=null ? (doc\['Field1\_score'\].value \* 100000) + (doc\['Field2\_score'\].value \* 100000) : 1", …

---

## [Rally eventdata-track & support for Elastic Stack 8.x](https://discuss.elastic.co/t/rally-eventdata-track-support-for-elastic-stack-8-x/329312)

<div class="topic-metadata">

**Author:** [@jan.stap](https://discuss.elastic.co/u/jan.stap)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 7:53am UTC](https://discuss.elastic.co/t/rally-eventdata-track-support-for-elastic-stack-8-x/329312 "2023-04-05T07:53:44Z")

</div>

Hi, In this post I read that the rally-eventdata-track is not supported for Elasticsearch 8.x, but I find no further info on that. The README.md says it is compatible with the latest development version of Elasticsearch…

---

## [High Number of indices affect on performance](https://discuss.elastic.co/t/high-number-of-indices-affect-on-performance/329355)

<div class="topic-metadata">

**Author:** [@sukur55](https://discuss.elastic.co/u/sukur55)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 7:46am UTC](https://discuss.elastic.co/t/high-number-of-indices-affect-on-performance/329355 "2023-04-05T07:46:24Z")

</div>

Does, number of indices has considerable affect on running/startup performance? like image having 100GB of data in 50 indices or having 100GB data on 300+ indices, how they differ from performance perspective? imagine I …

---

## [Several types as values to same key](https://discuss.elastic.co/t/several-types-as-values-to-same-key/329194)

<div class="topic-metadata">

**Author:** [@yael\_shifman](https://discuss.elastic.co/u/yael_shifman)\
**Replies:** 4\
**Last updated:** [April 5, 2023, 7:34am UTC](https://discuss.elastic.co/t/several-types-as-values-to-same-key/329194 "2023-04-05T07:34:56Z")

</div>

I have jenkins logs in a json format. (taken with the API) the logs have different types of value to the same key: ''' { "\_class":"hudson.model.StringParameterValue", "name":"MANIFEST\_REVISION", "value":"master" }…

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/329375)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 1\
**Last updated:** [April 5, 2023, 7:34am UTC](https://discuss.elastic.co/t/elasticsearch/329375 "2023-04-05T07:34:48Z")

</div>

Hi Team, How to deploy metric beats through ECK. Is there any document fot this.

---

## [Custom service monitoring and autodiscovery](https://discuss.elastic.co/t/custom-service-monitoring-and-autodiscovery/329323)

<div class="topic-metadata">

**Author:** [@denisk](https://discuss.elastic.co/u/denisk)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 1:02pm UTC](https://discuss.elastic.co/t/custom-service-monitoring-and-autodiscovery/329323 "2023-04-04T13:02:49Z")

</div>

Hi, I have set up metric collection of a number of custom microservices using the http module. Per microservice I've create a separate yaml file, and in each yaml file looks something like this: # Each service has its …

---

## [Remove traceparent header from http request](https://discuss.elastic.co/t/remove-traceparent-header-from-http-request/329005)

<div class="topic-metadata">

**Author:** [@SleepyF0X](https://discuss.elastic.co/u/SleepyF0X)\
**Replies:** 1\
**Last updated:** [April 5, 2023, 7:32am UTC](https://discuss.elastic.co/t/remove-traceparent-header-from-http-request/329005 "2023-04-05T07:32:57Z")

</div>

Hello, I have a need in one place where I create an HttpClient and send requests, remove the "traceparent", "tracestate" headers, in other places I want to keep them. I tried removing them via DefaultRequestHeaders and …

---

## [Enterprise Search configuration parameters in YAML not applied by ECK](https://discuss.elastic.co/t/enterprise-search-configuration-parameters-in-yaml-not-applied-by-eck/328314)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 2\
**Last updated:** [April 5, 2023, 7:31am UTC](https://discuss.elastic.co/t/enterprise-search-configuration-parameters-in-yaml-not-applied-by-eck/328314 "2023-04-05T07:31:15Z")

</div>

Hi, I am trying to define configuration parametes in the config: section in the YAML file for Enterprise Search and they seem not to be applied by ECK. I am running my own on-premise Kubernetes Cluster and Enterprise Se…

---

## [Error running synthetics](https://discuss.elastic.co/t/error-running-synthetics/327823)

<div class="topic-metadata">

**Author:** [@jasonwhetton](https://discuss.elastic.co/u/jasonwhetton)\
**Replies:** 5\
**Last updated:** [April 5, 2023, 6:14am UTC](https://discuss.elastic.co/t/error-running-synthetics/327823 "2023-04-05T06:14:33Z")

</div>

Hi, Sometimes we are seeing errors running synthetics where the test appears to have succeeded but some internal operation fails and subsequently fails the test.

[Previous page](https://discuss.elastic.co/latest.md?page=719)

[Next page](https://discuss.elastic.co/latest.md?page=721)
