# Latest

**URL:** https://discuss.elastic.co/latest.md?page=734

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 735

---

## [Tasks are stuck for hours for index creation & setting update](https://discuss.elastic.co/t/tasks-are-stuck-for-hours-for-index-creation-setting-update/328523)

<div class="topic-metadata">

**Author:** [@sanders\_2345](https://discuss.elastic.co/u/sanders_2345)\
**Replies:** 8\
**Last updated:** [March 26, 2023, 3:28pm UTC](https://discuss.elastic.co/t/tasks-are-stuck-for-hours-for-index-creation-setting-update/328523 "2023-03-26T15:28:51Z")

</div>

Our cluster has 4k+ indices, 36 data nodes(8c & 32g). ,3 mn (4c & 16g) Write is on 10k+ & read is very less No of primary shards - 4k+, replica 1 Es version: 5.x All tasks are running for hrs. Logs throwing RemoteTr…

---

## [Grok pattern for timestamp with month short name](https://discuss.elastic.co/t/grok-pattern-for-timestamp-with-month-short-name/328119)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 4\
**Last updated:** [March 26, 2023, 9:15am UTC](https://discuss.elastic.co/t/grok-pattern-for-timestamp-with-month-short-name/328119 "2023-03-26T09:15:55Z")

</div>

Wondering how to convert timestamps given like: 2023-mar.-20 23:44:44 PM to @timestamp and adding a default timezone info

---

## [Why when i build data back to es config max\_buckets it back to default](https://discuss.elastic.co/t/why-when-i-build-data-back-to-es-config-max-buckets-it-back-to-default/328545)

<div class="topic-metadata">

**Author:** [@xuan\_do](https://discuss.elastic.co/u/xuan_do)\
**Replies:** 0\
**Last updated:** [March 26, 2023, 8:41am UTC](https://discuss.elastic.co/t/why-when-i-build-data-back-to-es-config-max-buckets-it-back-to-default/328545 "2023-03-26T08:41:28Z")

</div>

when I upload data to es, config max\_buckets sometimes resets its value default. Why is that

---

## [Using new elasticsearch client 8.0.8, creating a index , add a record and update the existing record](https://discuss.elastic.co/t/using-new-elasticsearch-client-8-0-8-creating-a-index-add-a-record-and-update-the-existing-record/328522)

<div class="topic-metadata">

**Author:** [@sudhakarvaradharaj](https://discuss.elastic.co/u/sudhakarvaradharaj)\
**Replies:** 1\
**Last updated:** [March 26, 2023, 7:46am UTC](https://discuss.elastic.co/t/using-new-elasticsearch-client-8-0-8-creating-a-index-add-a-record-and-update-the-existing-record/328522 "2023-03-26T07:46:03Z")

</div>

I am using client 8.0.8 Elastic.Clients.Elasticsearch to create index, add a record and update the existing record to the index. What is the appropriate method to add and update the index. Here is the code snippet I us…

---

## [Kibana Security Analyst Course - Access lab](https://discuss.elastic.co/t/kibana-security-analyst-course-access-lab/328540)

<div class="topic-metadata">

**Author:** [@Gal\_Baron](https://discuss.elastic.co/u/Gal_Baron)\
**Replies:** 0\
**Last updated:** [March 26, 2023, 7:28am UTC](https://discuss.elastic.co/t/kibana-security-analyst-course-access-lab/328540 "2023-03-26T07:28:05Z")

</div>

Course: Kibana Security Analyst Version: Image version: 3.2.4, CTFd version: 3.3.0 Question: I'm currently learning the Kibana Security Analyst course. For some reason I can't setting up my lab. The URL from the CTF…

---

## [LRU cache in the Jdbc streaming filter plugin](https://discuss.elastic.co/t/lru-cache-in-the-jdbc-streaming-filter-plugin/328538)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [March 26, 2023, 7:05am UTC](https://discuss.elastic.co/t/lru-cache-in-the-jdbc-streaming-filter-plugin/328538 "2023-03-26T07:05:08Z")

</div>

Hi All, when I parse the value to Jdbc streaming filter plugin to run the query for extract the results in the target, this values existing in the other input plugin, but the amount of values more than the time of quer…

---

## [Dashboards and index patterns lost after upgrade from 7 to 8](https://discuss.elastic.co/t/dashboards-and-index-patterns-lost-after-upgrade-from-7-to-8/328531)

<div class="topic-metadata">

**Author:** [@SANDEEP\_SOMAPANGU](https://discuss.elastic.co/u/SANDEEP_SOMAPANGU)\
**Replies:** 2\
**Last updated:** [March 26, 2023, 3:40am UTC](https://discuss.elastic.co/t/dashboards-and-index-patterns-lost-after-upgrade-from-7-to-8/328531 "2023-03-26T03:40:53Z")

</div>

Hello, we recently upgraded from kibana version 7 to 8. In the previous version, we stored our configuration in the index named .kibana-abc\_7.17.9\_001. However, it appears that version 8 no longer supports this kind of i…

---

## [Java low level client example](https://discuss.elastic.co/t/java-low-level-client-example/328526)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 1\
**Last updated:** [March 26, 2023, 12:15am UTC](https://discuss.elastic.co/t/java-low-level-client-example/328526 "2023-03-26T00:15:44Z")

</div>

I am trying to find a good example of a low level Elasticsearch client (with plain java/non spring) but no luck. Can anyone please point the right direction?

---

## [Logstash - rabbitmq config to get multiple queues data to multiple elastic indeces](https://discuss.elastic.co/t/logstash-rabbitmq-config-to-get-multiple-queues-data-to-multiple-elastic-indeces/328520)

<div class="topic-metadata">

**Author:** [@qrshat](https://discuss.elastic.co/u/qrshat)\
**Replies:** 5\
**Last updated:** [March 25, 2023, 10:20pm UTC](https://discuss.elastic.co/t/logstash-rabbitmq-config-to-get-multiple-queues-data-to-multiple-elastic-indeces/328520 "2023-03-25T22:20:13Z")

</div>

scenario: rabbitmq have different queues more than three. I want to make logstash configuration to get data from the rabbitmq queue and index this data to Elasticsearch. In order to that I have created logstash conf fi…

---

## [Elasticsearch Cluster Multi Node Shared File System Repository SMB Issue](https://discuss.elastic.co/t/elasticsearch-cluster-multi-node-shared-file-system-repository-smb-issue/328472)

<div class="topic-metadata">

**Author:** [@ali.sharjeel](https://discuss.elastic.co/u/ali.sharjeel)\
**Replies:** 3\
**Last updated:** [March 25, 2023, 3:33pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-multi-node-shared-file-system-repository-smb-issue/328472 "2023-03-25T15:33:01Z")

</div>

Hi Team! I am trying to register shared file system repository in elasticsearch 8.6.2. I have windows server where i have created a directory and have shared it using smb and have mounted that directory using NFS CIFS on…

---

## [Elastic Search was not loaded](https://discuss.elastic.co/t/elastic-search-was-not-loaded/328504)

<div class="topic-metadata">

**Author:** [@Alex\_David\_Hurtado\_Y](https://discuss.elastic.co/u/Alex_David_Hurtado_Y)\
**Replies:** 1\
**Last updated:** [March 25, 2023, 11:23am UTC](https://discuss.elastic.co/t/elastic-search-was-not-loaded/328504 "2023-03-25T11:23:08Z")

</div>

HI, i´m using laradock with laravel, on the laravel project is integrte elasticsearch and inatalled the imgae the elasticsearch. The project get a command to fill a table using elasticsearch, buy trow the error: Elastic…

---

## [ECK operator](https://discuss.elastic.co/t/eck-operator/328516)

<div class="topic-metadata">

**Author:** [@abdul90082](https://discuss.elastic.co/u/abdul90082)\
**Replies:** 0\
**Last updated:** [March 25, 2023, 10:20am UTC](https://discuss.elastic.co/t/eck-operator/328516 "2023-03-25T10:20:56Z")

</div>

Hi everyone! we would like to use ES operator in all our cluster to monitor kubernetes logs. We have tried to get fleet and the agents working based on our scenario that looks the following: We are trying to send the l…

---

## [Is it normal for my ElasticSearch process to consume 10% of the CPU even when there are no read or write requests?](https://discuss.elastic.co/t/is-it-normal-for-my-elasticsearch-process-to-consume-10-of-the-cpu-even-when-there-are-no-read-or-write-requests/328507)

<div class="topic-metadata">

**Author:** [@zzzzer91](https://discuss.elastic.co/u/zzzzer91)\
**Replies:** 2\
**Last updated:** [March 25, 2023, 6:50am UTC](https://discuss.elastic.co/t/is-it-normal-for-my-elasticsearch-process-to-consume-10-of-the-cpu-even-when-there-are-no-read-or-write-requests/328507 "2023-03-25T06:50:33Z")

</div>

Elasticsearch Version elasticsearch-8.5.3 Installed Plugins No response Java Version bundled OS Version 4.19.188-10.el7 Problem Description Is it normal for Elasticsearch to consume 10% CPU even without requests afte…

---

## [Monitor multiple directories in monitors.d using heartbeat](https://discuss.elastic.co/t/monitor-multiple-directories-in-monitors-d-using-heartbeat/328053)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 2\
**Last updated:** [March 25, 2023, 4:10am UTC](https://discuss.elastic.co/t/monitor-multiple-directories-in-monitors-d-using-heartbeat/328053 "2023-03-25T04:10:47Z")

</div>

Hi All, wanted to know do we able to manager directories in monitors.d directories in heartbeat. I wanted to monitor some service and wanted to manage the yml file in directors i.e. each yml files should be under machin…

---

## [Condicional if with Regex](https://discuss.elastic.co/t/condicional-if-with-regex/328417)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 4\
**Last updated:** [March 25, 2023, 1:21am UTC](https://discuss.elastic.co/t/condicional-if-with-regex/328417 "2023-03-25T01:21:46Z")

</div>

Hi everybody, Does anyone know how can I build a "if" condicional that logstash change de number "1" to string "Worked" ? As example, the input are lines like: hello,ola,1hi,1 1,red1,1,green 1 ... and the output…

---

## [Parsing JSON Array In Event](https://discuss.elastic.co/t/parsing-json-array-in-event/328393)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 9\
**Last updated:** [March 24, 2023, 9:54pm UTC](https://discuss.elastic.co/t/parsing-json-array-in-event/328393 "2023-03-24T21:54:24Z")

</div>

I am using the jdbc\_streaming filter to pull additional data for an event from a database, the result looks like below. Any ideas on how I could have this parsed out so that I don't lose any of the data and keep it all …

---

## [How can I change timefield to have browser timezone using script?](https://discuss.elastic.co/t/how-can-i-change-timefield-to-have-browser-timezone-using-script/328502)

<div class="topic-metadata">

**Author:** [@karlanakamura](https://discuss.elastic.co/u/karlanakamura)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 9:45pm UTC](https://discuss.elastic.co/t/how-can-i-change-timefield-to-have-browser-timezone-using-script/328502 "2023-03-24T21:45:48Z")

</div>

Hello, I'm using version 8.6.0 in elastic cloud. I need to separate a timefield according to the day of the week. The way I'm doing it considers the UTC +00.00, but I would like it to be split according to the browser'…

---

## [Index life cycle policy not deleting the index when reached the defined size](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475)

<div class="topic-metadata">

**Author:** [@breakandfix](https://discuss.elastic.co/u/breakandfix)\
**Replies:** 7\
**Last updated:** [March 24, 2023, 8:56pm UTC](https://discuss.elastic.co/t/index-life-cycle-policy-not-deleting-the-index-when-reached-the-defined-size/328475 "2023-03-24T20:56:08Z")

</div>

Hello I have vector agent running on a k8s. it creates a data stream and indexes. I created ILM with only hot and delete phase. It should keep the index in hot phase until it reaches the defined size \[100MB\] and then r…

---

## [Browse and Navigate functionality](https://discuss.elastic.co/t/browse-and-navigate-functionality/328427)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 8:46pm UTC](https://discuss.elastic.co/t/browse-and-navigate-functionality/328427 "2023-03-24T20:46:16Z")

</div>

Checking if any of the elastisearch features supports browse and navigate functionality.

---

## [Rollup Job when one of the Terms field is array of objects](https://discuss.elastic.co/t/rollup-job-when-one-of-the-terms-field-is-array-of-objects/328451)

<div class="topic-metadata">

**Author:** [@jiri\_whale](https://discuss.elastic.co/u/jiri_whale)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 8:30pm UTC](https://discuss.elastic.co/t/rollup-job-when-one-of-the-terms-field-is-array-of-objects/328451 "2023-03-24T20:30:56Z")

</div>

I am trying to create a RollUp job from Kibana. In the Terms field where I have given multiple fields, in which one of the fields is of an array type (actually array of objects). How can I define which item/object of the…

---

## [Graph is showing more traffic for one day](https://discuss.elastic.co/t/graph-is-showing-more-traffic-for-one-day/328478)

<div class="topic-metadata">

**Author:** [@ranganathp08](https://discuss.elastic.co/u/ranganathp08)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 8:19pm UTC](https://discuss.elastic.co/t/graph-is-showing-more-traffic-for-one-day/328478 "2023-03-24T20:19:55Z")

</div>

Hi team, could you help me on below issue; issue: across 3 months , one day Graph is showing unusual spikes with more traffic . but count is showing accurate . previous days and next days looking good (graph and c…

---

## [Plugin generator generates a plugin that causes an error](https://discuss.elastic.co/t/plugin-generator-generates-a-plugin-that-causes-an-error/325492)

<div class="topic-metadata">

**Author:** [@przemek\_ironcode](https://discuss.elastic.co/u/przemek_ironcode)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 8:01pm UTC](https://discuss.elastic.co/t/plugin-generator-generates-a-plugin-that-causes-an-error/325492 "2023-03-24T20:01:36Z")

</div>

Hi, I am trying to create a plugin for the latest version of Kibana \[8.6\]. I have used the plugin generator for this purpose. Unfortunately, after generating the plug-in and starting the server, I see this error: Elas…

---

## [Change Nil values to set default value](https://discuss.elastic.co/t/change-nil-values-to-set-default-value/328369)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 7:29pm UTC](https://discuss.elastic.co/t/change-nil-values-to-set-default-value/328369 "2023-03-24T19:29:14Z")

</div>

Logstash is dropping fields which has "nil" values, but I don't want those fields to be drop, but at least we can set it to default values if the field is nil, else it has it's original value. I tried with this code fou…

---

## [Elasticsearch combining Filter with Bool by a Must](https://discuss.elastic.co/t/elasticsearch-combining-filter-with-bool-by-a-must/327863)

<div class="topic-metadata">

**Author:** [@MonikaJ](https://discuss.elastic.co/u/MonikaJ)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 4:45pm UTC](https://discuss.elastic.co/t/elasticsearch-combining-filter-with-bool-by-a-must/327863 "2023-03-24T16:45:15Z")

</div>

I am trying to combine a "filter" with a "bool"/"should" inside a "must". The following query is automatically generated by an application (hence the nesting). How must the query look like to have an AND condition betwee…

---

## [Haystack US 2023 - The Search Relevance Conference](https://discuss.elastic.co/t/haystack-us-2023-the-search-relevance-conference/328479)

<div class="topic-metadata">

**Author:** [@flaxsearch](https://discuss.elastic.co/u/flaxsearch)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 4:36pm UTC](https://discuss.elastic.co/t/haystack-us-2023-the-search-relevance-conference/328479 "2023-03-24T16:36:07Z")

</div>

We've published the talk schedule for Haystack US 2023, The Search Relevance Conference - and I don't think we've ever had such an amazing list of speakers from organisations like Amazon, Reddit, Elsevier; from authors o…

---

## [Logstash Kafka input - converting date to string format](https://discuss.elastic.co/t/logstash-kafka-input-converting-date-to-string-format/327967)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 6\
**Last updated:** [March 24, 2023, 4:20pm UTC](https://discuss.elastic.co/t/logstash-kafka-input-converting-date-to-string-format/327967 "2023-03-24T16:20:27Z")

</div>

Hello, We are using Kafka plugin to get feed into Logstash. One of the fields that come with the message is in date format. I need to convert that date into string format. Please guide. My config file looks as follo…

---

## [What is the ratio between raw data and ingested data that is stored in Elastic cluster](https://discuss.elastic.co/t/what-is-the-ratio-between-raw-data-and-ingested-data-that-is-stored-in-elastic-cluster/327945)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 4:20pm UTC](https://discuss.elastic.co/t/what-is-the-ratio-between-raw-data-and-ingested-data-that-is-stored-in-elastic-cluster/327945 "2023-03-24T16:20:41Z")

</div>

Hi, I want to know what the ratio is between raw data and ingested data that is stored in Elastic cluster. I know raw logs and ingested logs are not same in size. Also is there any way to find the incoming raw log vol…

---

## [High availability with two servers](https://discuss.elastic.co/t/high-availability-with-two-servers/328467)

<div class="topic-metadata">

**Author:** [@amiraliw](https://discuss.elastic.co/u/amiraliw)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 2:43pm UTC](https://discuss.elastic.co/t/high-availability-with-two-servers/328467 "2023-03-24T14:43:53Z")

</div>

I have only two servers, how I should configure elasticsearch nodes to get high availability and avoid split-brain? should I only have one node on each server?

---

## [How variable width histogram with nested aggregations works](https://discuss.elastic.co/t/how-variable-width-histogram-with-nested-aggregations-works/328219)

<div class="topic-metadata">

**Author:** [@rym](https://discuss.elastic.co/u/rym)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 1:24pm UTC](https://discuss.elastic.co/t/how-variable-width-histogram-with-nested-aggregations-works/328219 "2023-03-24T13:24:56Z")

</div>

Hi, I want to use the variable\_width\_histogram combined with other aggregations, such as min or max Here is an example of combinated aggregations on a numeric field: "aggs": { "aggregated-items": { …

---

## [Filebeat and Metricbeat get Error 401 Unauthorized](https://discuss.elastic.co/t/filebeat-and-metricbeat-get-error-401-unauthorized/328200)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 7\
**Last updated:** [March 24, 2023, 1:10pm UTC](https://discuss.elastic.co/t/filebeat-and-metricbeat-get-error-401-unauthorized/328200 "2023-03-24T13:10:20Z")

</div>

I recently upgraded from ELK Stack 7.9.3 to 7.17.9. Everything is working great except that Filebeat and Metricbeat will not connect to Elasticsearch anymore unless they are installed on the same server. I get errors lik…

[Previous page](https://discuss.elastic.co/latest.md?page=733)

[Next page](https://discuss.elastic.co/latest.md?page=735)
