# Latest

**URL:** https://discuss.elastic.co/latest.md?page=727

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 728

---

## [Set niofs as storage type in docker/k8s](https://discuss.elastic.co/t/set-niofs-as-storage-type-in-docker-k8s/328965)

<div class="topic-metadata">

**Author:** [@bade27](https://discuss.elastic.co/u/bade27)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 5:05pm UTC](https://discuss.elastic.co/t/set-niofs-as-storage-type-in-docker-k8s/328965 "2023-03-30T17:05:35Z")

</div>

Hi everyone. I'm trying to deploy an instance of Elasticsearch v. 8.5.1 on a Kubernetes cluster (using the official Helm Chart), but the cluster I'm working on doesn't allow me to use privileged containers. This is an is…

---

## [JVM Heap size larger than 32 GB](https://discuss.elastic.co/t/jvm-heap-size-larger-than-32-gb/328869)

<div class="topic-metadata">

**Author:** [@Milad\_Heydariaan](https://discuss.elastic.co/u/Milad_Heydariaan)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 9:35pm UTC](https://discuss.elastic.co/t/jvm-heap-size-larger-than-32-gb/328869 "2023-03-30T21:35:11Z")

</div>

We have several machines with 512 GB of RAM and I wanted to know if we can set JVM heap size for Elasticsearch larger than 32 GB (up to 256 GB). This page says we should keep the heap size below the threshold for compre…

---

## [Elasticsearch static settings - per node?](https://discuss.elastic.co/t/elasticsearch-static-settings-per-node/328691)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 7\
**Last updated:** [March 30, 2023, 9:30pm UTC](https://discuss.elastic.co/t/elasticsearch-static-settings-per-node/328691 "2023-03-30T21:30:21Z")

</div>

Hi, I am trying to understand the logic behind the static settings. I am trying to keep all nodes with the same configuration/settings where possible, but I'm curios and want to validate about the right way of doing it…

---

## [Configuration as Code for Elasticsearch](https://discuss.elastic.co/t/configuration-as-code-for-elasticsearch/328449)

<div class="topic-metadata">

**Author:** [@sonnenhund](https://discuss.elastic.co/u/sonnenhund)\
**Replies:** 14\
**Last updated:** [March 30, 2023, 9:17pm UTC](https://discuss.elastic.co/t/configuration-as-code-for-elasticsearch/328449 "2023-03-30T21:17:46Z")

</div>

Hi! We are attempting to stand up a full ELK stack and wish to have Elasticsearch fully configured, including ILM policies, Index Templates, and if necessary bootstrapping indices, such that when data begins flowing int…

---

## [Kibana Refused To connect on Browser after Installation (via RPM)](https://discuss.elastic.co/t/kibana-refused-to-connect-on-browser-after-installation-via-rpm/328873)

<div class="topic-metadata">

**Author:** [@abbyode](https://discuss.elastic.co/u/abbyode)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 8:49pm UTC](https://discuss.elastic.co/t/kibana-refused-to-connect-on-browser-after-installation-via-rpm/328873 "2023-03-30T20:49:43Z")

</div>

I am having issues connecting to kibana via browser. The service started successfully via cli but I'm unable to connect on port 5601 - "refused connection". Kibana.yml file: For more configuration options see the confi…

---

## [How to grok catalina log file](https://discuss.elastic.co/t/how-to-grok-catalina-log-file/328895)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 7:24am UTC](https://discuss.elastic.co/t/how-to-grok-catalina-log-file/328895 "2023-03-30T07:24:33Z")

</div>

I have context my config logstash for tomcat filtertomcat filter { if \[fileset\]\[module\] == "tomcat" { if \[fileset\]\[name\] == "tomcatcatalina" { grok { match =\> \[ "message", "(?m)%{TOMCAT\_DATESTAMP:timestamp} %{LOG…

---

## [Is logstash necessarily](https://discuss.elastic.co/t/is-logstash-necessarily/328833)

<div class="topic-metadata">

**Author:** [@LilBaloche](https://discuss.elastic.co/u/LilBaloche)\
**Replies:** 8\
**Last updated:** [March 30, 2023, 8:30pm UTC](https://discuss.elastic.co/t/is-logstash-necessarily/328833 "2023-03-30T20:30:36Z")

</div>

Hi everyone I'm testing ELK in a virtual environment (WinServer AD + DNS, Ubuntu Server 22.04, Ubuntu Client 22.04 and Win 10 Client) I've installed ELK stack on an Ubuntu Server 22.04 (I've been helped by a youtube vi…

---

## [Joining instances to form cluster](https://discuss.elastic.co/t/joining-instances-to-form-cluster/328860)

<div class="topic-metadata">

**Author:** [@DRW-ATCA](https://discuss.elastic.co/u/DRW-ATCA)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 6:23pm UTC](https://discuss.elastic.co/t/joining-instances-to-form-cluster/328860 "2023-03-30T18:23:46Z")

</div>

reference:ERROR: Failed to determine the health of the cluster - #7 by DRW-ATCA My goal is to create a 6-instance cluster in a private VPC (AWS), 1 master, 5 data nodes, with additional instances hosting Kibana and rela…

---

## ['More Like This' Query For App Search Engine](https://discuss.elastic.co/t/more-like-this-query-for-app-search-engine/328381)

<div class="topic-metadata">

**Author:** [@tchocky](https://discuss.elastic.co/u/tchocky)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 6:01pm UTC](https://discuss.elastic.co/t/more-like-this-query-for-app-search-engine/328381 "2023-03-30T18:01:28Z")

</div>

Hi all - I am using App Search on Elastic Cloud and would like to implement "More Like This" queries to show related content on our site. As you can see in the attachment I can run the query from the dev console. Howeve…

---

## [ERROR: Failed to determine the health of the cluster](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster/328746)

<div class="topic-metadata">

**Author:** [@DRW-ATCA](https://discuss.elastic.co/u/DRW-ATCA)\
**Replies:** 11\
**Last updated:** [March 30, 2023, 5:20pm UTC](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster/328746 "2023-03-30T17:20:52Z")

</div>

I am trying to add nodes to a cluster for ES 8.6.2 in an AWS EC2 environment. After creating a master node and the first of several data nodes, the two instances give healthy responses to the following commands but do n…

---

## [Logstash not reading my config](https://discuss.elastic.co/t/logstash-not-reading-my-config/328958)

<div class="topic-metadata">

**Author:** [@M\_D](https://discuss.elastic.co/u/M_D)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 5:13pm UTC](https://discuss.elastic.co/t/logstash-not-reading-my-config/328958 "2023-03-30T17:13:32Z")

</div>

I have my config under /etc/logstash/conf.d/myconfig.conf. Below is my simple config input { file { path =\> "/home/foo/logs/\*.log" start\_position =\> "beginning" # stat\_interval =\> 1 # discover\_interval =\>…

---

## [Elastic document\_id](https://discuss.elastic.co/t/elastic-document-id/328738)

<div class="topic-metadata">

**Author:** [@bmagistro1](https://discuss.elastic.co/u/bmagistro1)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 4:08pm UTC](https://discuss.elastic.co/t/elastic-document-id/328738 "2023-03-30T16:08:51Z")

</div>

Is there any defined behavior for document\_id (Elasticsearch output plugin | Logstash Reference \[8.6\] | Elastic) similar to pipeline (Elasticsearch output plugin | Logstash Reference \[8.6\] | Elastic)? We have at least o…

---

## [Date Histogram doesn't work with calendar\_interval month](https://discuss.elastic.co/t/date-histogram-doesnt-work-with-calendar-interval-month/328848)

<div class="topic-metadata">

**Author:** [@Tobse](https://discuss.elastic.co/u/Tobse)\
**Replies:** 8\
**Last updated:** [March 30, 2023, 3:24pm UTC](https://discuss.elastic.co/t/date-histogram-doesnt-work-with-calendar-interval-month/328848 "2023-03-30T15:24:01Z")

</div>

I have tried to use a group\_by with a date\_histogram by month. Our example works like expected with "calendar\_interval": "day" but returns nothing with "calendar\_interval": "month". In fact it seems wo work with day, wee…

---

## [Dataview with some columns excluded](https://discuss.elastic.co/t/dataview-with-some-columns-excluded/328942)

<div class="topic-metadata">

**Author:** [@joerg55](https://discuss.elastic.co/u/joerg55)\
**Replies:** 9\
**Last updated:** [March 30, 2023, 3:16pm UTC](https://discuss.elastic.co/t/dataview-with-some-columns-excluded/328942 "2023-03-30T15:16:35Z")

</div>

Hi community, I want to create a data view of an index without some columns. The background is that these columns lead to the display of 'no results' with certain filters. I only have this one index and I don't have the…

---

## [Trying to create tranform job which would not go through all documents](https://discuss.elastic.co/t/trying-to-create-tranform-job-which-would-not-go-through-all-documents/328905)

<div class="topic-metadata">

**Author:** [@Kiril\_Karamanolev](https://discuss.elastic.co/u/Kiril_Karamanolev)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 3:14pm UTC](https://discuss.elastic.co/t/trying-to-create-tranform-job-which-would-not-go-through-all-documents/328905 "2023-03-30T15:14:14Z")

</div>

Hello, Started using transform but I am struggling to find how to look at only recent documents not from the beginning (because I have 1-year historical data) The JSON of the job is: { "id": "ops\_authrate\_1m", "au…

---

## [How to distribute Primary & Replica shards equally across the nodes](https://discuss.elastic.co/t/how-to-distribute-primary-replica-shards-equally-across-the-nodes/328950)

<div class="topic-metadata">

**Author:** [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 3:03pm UTC](https://discuss.elastic.co/t/how-to-distribute-primary-replica-shards-equally-across-the-nodes/328950 "2023-03-30T15:03:05Z")

</div>

Hi Team, I have Elastic cluster with 3 Master, 5 Data & 2 Client nodes. I have created index called my-index with 5 Primary and 1 Replica also i used setting called number of shards per node is 2. But i could see at f…

---

## [Match query with specific order of terms](https://discuss.elastic.co/t/match-query-with-specific-order-of-terms/328936)

<div class="topic-metadata">

**Author:** [@Rafael\_Kubina](https://discuss.elastic.co/u/Rafael_Kubina)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 2:09pm UTC](https://discuss.elastic.co/t/match-query-with-specific-order-of-terms/328936 "2023-03-30T14:09:14Z")

</div>

We need to match a set of terms in a field while taking the order into account. Example: The document: { "my\_field": "foo bar" } It should match when the user search for foo bar, foo bar baz or baz foo bar but no…

---

## [Sharing Case ID value using Elastic Case Management webhook](https://discuss.elastic.co/t/sharing-case-id-value-using-elastic-case-management-webhook/328641)

<div class="topic-metadata">

**Author:** [@yzaritskyi](https://discuss.elastic.co/u/yzaritskyi)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 2:05pm UTC](https://discuss.elastic.co/t/sharing-case-id-value-using-elastic-case-management-webhook/328641 "2023-03-30T14:05:45Z")

</div>

Greetings! I'm on the way to implementing the automation solution for our Elastic Security Cases. While working on some automation scripts, I got a problem with the response to Cases. For example, when the Case is crea…

---

## [Correct way to do tiebreaking with search\_after query without PIT](https://discuss.elastic.co/t/correct-way-to-do-tiebreaking-with-search-after-query-without-pit/328941)

<div class="topic-metadata">

**Author:** [@martsraits](https://discuss.elastic.co/u/martsraits)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 1:05pm UTC](https://discuss.elastic.co/t/correct-way-to-do-tiebreaking-with-search-after-query-without-pit/328941 "2023-03-30T13:05:03Z")

</div>

Hi We use search\_after queries to support infinite scroll in the front end. Previously we used \_id field for sorting to keep consistent order. In newer versions of Elasticsearch it's not possible to use \_id field for so…

---

## [Icmp not responding as expected in Elastic](https://discuss.elastic.co/t/icmp-not-responding-as-expected-in-elastic/328900)

<div class="topic-metadata">

**Author:** [@TheNewGuy123](https://discuss.elastic.co/u/TheNewGuy123)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 1:03pm UTC](https://discuss.elastic.co/t/icmp-not-responding-as-expected-in-elastic/328900 "2023-03-30T13:03:26Z")

</div>

Hey, I setup my heartbeat monitoring and I have configured all three kind of monitors: http, tcp and icmp. So I got tcp and http to work correctly, but no luck with icmp (which is the one I actually need). So I am checki…

---

## [Collecting SHA256 checksum of container images using Metricbeat Kubernetes configuration](https://discuss.elastic.co/t/collecting-sha256-checksum-of-container-images-using-metricbeat-kubernetes-configuration/328940)

<div class="topic-metadata">

**Author:** [@kkushal0588](https://discuss.elastic.co/u/kkushal0588)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 12:57pm UTC](https://discuss.elastic.co/t/collecting-sha256-checksum-of-container-images-using-metricbeat-kubernetes-configuration/328940 "2023-03-30T12:57:18Z")

</div>

Hi, I have gone through the documentation link below to understand the fields exported by metricbeat for Kubernetes, but I do not see any field to get the SHA256 checksum of the container image being used for a running …

---

## [Scripted field for date + 12 months](https://discuss.elastic.co/t/scripted-field-for-date-12-months/328715)

<div class="topic-metadata">

**Author:** [@redfox](https://discuss.elastic.co/u/redfox)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 12:30pm UTC](https://discuss.elastic.co/t/scripted-field-for-date-12-months/328715 "2023-03-30T12:30:44Z")

</div>

How would I create a scripted field in Kibana that adds 12 months to the value in existing date field in the index?

---

## [Unable to communicate between 2 master nodes creating cluster issue](https://discuss.elastic.co/t/unable-to-communicate-between-2-master-nodes-creating-cluster-issue/328931)

<div class="topic-metadata">

**Author:** [@devarajsit](https://discuss.elastic.co/u/devarajsit)\
**Replies:** 4\
**Last updated:** [March 30, 2023, 12:31pm UTC](https://discuss.elastic.co/t/unable-to-communicate-between-2-master-nodes-creating-cluster-issue/328931 "2023-03-30T12:31:54Z")

</div>

I tried creating a new Elasticsearch cluster with 3 master nodes, 3 data nodes and 2 clients. All the 3 master nodes status is in Running but when i verified the logs of the third node, it says time out connecting to 1st…

---

## [I have created a Kibana dashboard for Top 10 Process by CPU Usage , the data is not coming up for 15 or 30 minutes or even for 1 hour](https://discuss.elastic.co/t/i-have-created-a-kibana-dashboard-for-top-10-process-by-cpu-usage-the-data-is-not-coming-up-for-15-or-30-minutes-or-even-for-1-hour/328760)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 12:30pm UTC](https://discuss.elastic.co/t/i-have-created-a-kibana-dashboard-for-top-10-process-by-cpu-usage-the-data-is-not-coming-up-for-15-or-30-minutes-or-even-for-1-hour/328760 "2023-03-30T12:30:41Z")

</div>

Kibana version -7.17.3, elk version 7.17.3 I have used the field - system.process.cpu.total.pct and aggregation is average... i dont see data coming up for 15 or 30 mints or even 1 hour interval time . I only get it f…

---

## [Elasticsearch 7.3.2 witjh Java 17](https://discuss.elastic.co/t/elasticsearch-7-3-2-witjh-java-17/328932)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 12:29pm UTC](https://discuss.elastic.co/t/elasticsearch-7-3-2-witjh-java-17/328932 "2023-03-30T12:29:57Z")

</div>

Hi Team, We need run the elasticsearch 7.3.2 with java 17 version ,myself able to run the elasticsearch with java17 version, is this casue any issues in future.

---

## [Java agent: Change span name for out of the box db span](https://discuss.elastic.co/t/java-agent-change-span-name-for-out-of-the-box-db-span/328888)

<div class="topic-metadata">

**Author:** [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 12:02pm UTC](https://discuss.elastic.co/t/java-agent-change-span-name-for-out-of-the-box-db-span/328888 "2023-03-30T12:02:58Z")

</div>

Hi, i'm experimenting with apm java client. I can see that APM automatically detect calls to my mssql database and shows the span inside the transactio. But if i'm trying to change the span's name using the API (code be…

---

## [Vector functions are not available in Sort Context? \[painless\] \[painful\]](https://discuss.elastic.co/t/vector-functions-are-not-available-in-sort-context-painless-painful/328737)

<div class="topic-metadata">

**Author:** [@MarynaCherniavska](https://discuss.elastic.co/u/MarynaCherniavska)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 11:58am UTC](https://discuss.elastic.co/t/vector-functions-are-not-available-in-sort-context-painless-painful/328737 "2023-03-30T11:58:17Z")

</div>

Dear team, I am trying to use dotProduct() in a script sort and failing. The simplified case looks like this: Setting up the data PUT test\_index { "mappings": { "properties": { "v": { "type": "dens…

---

## [Connect elastic search to external react plugin](https://discuss.elastic.co/t/connect-elastic-search-to-external-react-plugin/328929)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 11:56am UTC](https://discuss.elastic.co/t/connect-elastic-search-to-external-react-plugin/328929 "2023-03-30T11:56:29Z")

</div>

Hello there ! Is it possible to connect Elasticsearch to the external plugin created in react and use the data stored in indices without using node.js ?

---

## [External plugin connectivity with Elastic search](https://discuss.elastic.co/t/external-plugin-connectivity-with-elastic-search/328552)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 4\
**Last updated:** [March 30, 2023, 11:41am UTC](https://discuss.elastic.co/t/external-plugin-connectivity-with-elastic-search/328552 "2023-03-30T11:41:38Z")

</div>

Hello there ! I have created an external plugin using React in Kibana Now I want to connect that to the Elastic search and use the data stored in one of the index. What are the possible options to achieve this ?

---

## [Elasticsearch Python Client's LicenseClient.post fails](https://discuss.elastic.co/t/elasticsearch-python-clients-licenseclient-post-fails/328850)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 11:33am UTC](https://discuss.elastic.co/t/elasticsearch-python-clients-licenseclient-post-fails/328850 "2023-03-30T11:33:32Z")

</div>

Hi, We have upgrade from 7.17.1 to 8.6.2. We are using the Elasticsearch Python Client. We are using LicenseClient.post which was working in 7.17.1 but now is failing with 8.6.2. I get this error from the client ApiEr…

[Previous page](https://discuss.elastic.co/latest.md?page=726)

[Next page](https://discuss.elastic.co/latest.md?page=728)
