# Latest

**URL:** https://discuss.elastic.co/latest.md?page=737

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 738

---

## [Logstash MultiPipeline](https://discuss.elastic.co/t/logstash-multipipeline/328341)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 1:39pm UTC](https://discuss.elastic.co/t/logstash-multipipeline/328341 "2023-03-23T13:39:59Z")

</div>

Hello , I want to use several pipeline . I had put them in the logstash directory conf.d . I named the files like this 01\_Input 02\_Filter 03\_Output Must I do anything else for work with the pipelines ? Does it wo…

---

## [Elasticsearch NoShardAvailableActionException](https://discuss.elastic.co/t/elasticsearch-noshardavailableactionexception/328279)

<div class="topic-metadata">

**Author:** [@Lohanna\_Sarah](https://discuss.elastic.co/u/Lohanna_Sarah)\
**Replies:** 4\
**Last updated:** [March 23, 2023, 1:35pm UTC](https://discuss.elastic.co/t/elasticsearch-noshardavailableactionexception/328279 "2023-03-23T13:35:51Z")

</div>

Suppose a cluster is composed of three data nodes. If one of the nodes throws the exception "NoShardAvailableActionException", what is the impact on the cluster and how is the request handled? Specifically, is the reques…

---

## [How do I use Elastic Agent to send log data to Logstash?](https://discuss.elastic.co/t/how-do-i-use-elastic-agent-to-send-log-data-to-logstash/328269)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 7\
**Last updated:** [March 23, 2023, 12:57pm UTC](https://discuss.elastic.co/t/how-do-i-use-elastic-agent-to-send-log-data-to-logstash/328269 "2023-03-23T12:57:14Z")

</div>

Hello. Based on the documentation (Beats and Elastic Agent capabilities | Fleet and Elastic Agent Guide \[8.6\] | Elastic) I am under the impression that the Elastic Agent can send log data to Logstash. However, the only b…

---

## [How to search a piece of URI](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 8\
**Last updated:** [March 23, 2023, 12:36pm UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342 "2023-03-23T12:36:28Z")

</div>

I want to search a piece of URL. I am using the sample weblogs in elasticsearch. If I analyze the field: GET /\_analyze { "analyzer" : "standard", "text" : \["http://nytimes.com/success/kevin-Kregel"\] } I get: { "…

---

## [Elastic apm not show where clause of query](https://discuss.elastic.co/t/elastic-apm-not-show-where-clause-of-query/327936)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 12:18pm UTC](https://discuss.elastic.co/t/elastic-apm-not-show-where-clause-of-query/327936 "2023-03-23T12:18:10Z")

</div>

I’m using elastic apm agent on jboss, it show jdbc queries but put “question mark” for where conditions. What is the reason of this happen? How can i fix it? Thanks

---

## [Regex lookahead in painless](https://discuss.elastic.co/t/regex-lookahead-in-painless/328268)

<div class="topic-metadata">

**Author:** [@HansPeterSloot](https://discuss.elastic.co/u/HansPeterSloot)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 12:17pm UTC](https://discuss.elastic.co/t/regex-lookahead-in-painless/328268 "2023-03-23T12:17:25Z")

</div>

Is it possible to use regex with lookahead in Painless? I want to match a pattern in a string starting with a certain expression and ending before a certain expression.

---

## [Kibana login Issue due to space full](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153)

<div class="topic-metadata">

**Author:** [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Replies:** 11\
**Last updated:** [March 23, 2023, 12:15pm UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153 "2023-03-23T12:15:27Z")

</div>

Hello Expert, We have created the Kibana and Elasticsearch with filebeat. Below are the details. Kibana version: 7.14.1. running in Kubernetes. Issue: Not able to login to Kibana as Elasticsearch space is full. but …

---

## [Kibana dashboard issue - i have created a disk usage dashboard , it doesnot show up a straight line --but with dotted lines](https://discuss.elastic.co/t/kibana-dashboard-issue-i-have-created-a-disk-usage-dashboard-it-doesnot-show-up-a-straight-line-but-with-dotted-lines/328346)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 12:05pm UTC](https://discuss.elastic.co/t/kibana-dashboard-issue-i-have-created-a-disk-usage-dashboard-it-doesnot-show-up-a-straight-line-but-with-dotted-lines/328346 "2023-03-23T12:05:25Z")

</div>

ELK - 7.17.3 , KIBANA 7.17.3 I have a 3 node cluster and two logstash server and one kibana server I have created disk usage dashboard , but it shows the data in dotted line for 15 minutes or 30 minutes.. while for 1 h…

---

## [Cluster en elastic search; error: main process exited, failed with result 'exit-code'](https://discuss.elastic.co/t/cluster-en-elastic-search-error-main-process-exited-failed-with-result-exit-code/328337)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 11:37am UTC](https://discuss.elastic.co/t/cluster-en-elastic-search-error-main-process-exited-failed-with-result-exit-code/328337 "2023-03-23T11:37:24Z")

</div>

I am trying to create a cluster with two machines and I am trying to configure the /etc/elasticsearch/elasticsearch.yml file but I get an error. I am attaching code captures. The attached screenshot is from the ma…

---

## [How to add an inner field as a source field in ML inference pipeline?](https://discuss.elastic.co/t/how-to-add-an-inner-field-as-a-source-field-in-ml-inference-pipeline/328323)

<div class="topic-metadata">

**Author:** [@848bb15cf6e891bef7ba](https://discuss.elastic.co/u/848bb15cf6e891bef7ba)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-to-add-an-inner-field-as-a-source-field-in-ml-inference-pipeline/328323 "2023-03-23T11:21:18Z")

</div>

Hi, I am trying out vector search. While creating a Machine Learning Inference Pipeline, I see that some fields in the index are not recognised. Only the top level fields are shown. Consider the below example with fiel…

---

## [Kibana Server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/328232)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 9:17am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/328232 "2023-03-23T09:17:18Z")

</div>

Hi, I am not able to connect kibana with elasticsearch, if someone could offer me some help. Thank you.

---

## [Issue in kubernetes azure-new](https://discuss.elastic.co/t/issue-in-kubernetes-azure-new/328340)

<div class="topic-metadata">

**Author:** [@digital\_crankz](https://discuss.elastic.co/u/digital_crankz)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 10:16am UTC](https://discuss.elastic.co/t/issue-in-kubernetes-azure-new/328340 "2023-03-23T10:16:31Z")

</div>

have different 5 azureuser login ssh address for kubernetes setup and Ansible setup After deployment and updating file in kubernetes server i have to check the docker logs in server. Is it possible to complete this task …

---

## [Building Kibana from source code got "operation not permitted, rename" ERROR](https://discuss.elastic.co/t/building-kibana-from-source-code-got-operation-not-permitted-rename-error/328317)

<div class="topic-metadata">

**Author:** [@gnehcnij](https://discuss.elastic.co/u/gnehcnij)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 9:28am UTC](https://discuss.elastic.co/t/building-kibana-from-source-code-got-operation-not-permitted-rename-error/328317 "2023-03-23T09:28:50Z")

</div>

When I run yarn build --skip-os-packages, it got error below: ERROR Error: EPERM: operation not permitted, rename........

---

## [ElasticSearch - Java layered search BoolQueryBuilder](https://discuss.elastic.co/t/elasticsearch-java-layered-search-boolquerybuilder/328256)

<div class="topic-metadata">

**Author:** [@Sachin\_Sharma](https://discuss.elastic.co/u/Sachin_Sharma)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 9:21am UTC](https://discuss.elastic.co/t/elasticsearch-java-layered-search-boolquerybuilder/328256 "2023-03-23T09:21:50Z")

</div>

I have data in Elastic. Elastic data is as below. Name Parties Parties is array of objects that contains partyCode and displayCode { "query": { "bool": { "should": \[ { "bool": { "must": \[ …

---

## [Dashboard performance help](https://discuss.elastic.co/t/dashboard-performance-help/327582)

<div class="topic-metadata">

**Author:** [@tommycahir](https://discuss.elastic.co/u/tommycahir)\
**Replies:** 9\
**Last updated:** [March 23, 2023, 8:56am UTC](https://discuss.elastic.co/t/dashboard-performance-help/327582 "2023-03-23T08:56:57Z")

</div>

Hi All I am looking for some help in understanding how I can debug/find slow performance issues and then resolve them. We have a dashboard that is presenting some visualisations on an index with 29,369,877 documents an…

---

## [APM-Server /intake/v2/events http 404 page not found](https://discuss.elastic.co/t/apm-server-intake-v2-events-http-404-page-not-found/328244)

<div class="topic-metadata">

**Author:** [@niemimik](https://discuss.elastic.co/u/niemimik)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 8:40am UTC](https://discuss.elastic.co/t/apm-server-intake-v2-events-http-404-page-not-found/328244 "2023-03-23T08:40:13Z")

</div>

I'm running 7.17 APM server with Fleet and APM agent installed. APM server is responsing healthy status but intake/v2/events not found. I cannot see any errors in log files. Please, could you give some ideas how can I d…

---

## [co.elastic.clients.elasticsearch.\_types.ElasticsearchException: \[es/indices.create\] failed: \[resource\_already\_exists\_exception\] index \[\[test1111/OvwpReOdTNa-44HKedMUrw\]\]already exists](https://discuss.elastic.co/t/co-elastic-clients-elasticsearch-types-elasticsearchexception-es-indices-create-failed-resource-already-exists-exception-index-test1111-ovwpreodtna-44hkedmurw-already-exists/328321)

<div class="topic-metadata">

**Author:** [@chinaman](https://discuss.elastic.co/u/chinaman)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 8:25am UTC](https://discuss.elastic.co/t/co-elastic-clients-elasticsearch-types-elasticsearchexception-es-indices-create-failed-resource-already-exists-exception-index-test1111-ovwpreodtna-44hkedmurw-already-exists/328321 "2023-03-23T08:25:57Z")

</div>

Create index use elasticsearchClient.indices() , Executed Exception:co.elastic.clients.elasticsearch.\_types.ElasticsearchException: \[es/indices.create\] failed:\[resource\_already\_exists\_exception\] index \[test12345/OvwpReOd…

---

## [Snapshot Repository integration with GitHub](https://discuss.elastic.co/t/snapshot-repository-integration-with-github/328307)

<div class="topic-metadata">

**Author:** [@dadiasish](https://discuss.elastic.co/u/dadiasish)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 8:17am UTC](https://discuss.elastic.co/t/snapshot-repository-integration-with-github/328307 "2023-03-23T08:17:12Z")

</div>

Hi, We've currently enabled Snapshots in our cluster with Amazon S3 buckets and everything it going great. I'm just exploring on new repository connections which can be applied with Elasticsearch Snapshots enablement. …

---

## [Logstash error -"Could not load '.aprc' from ENV\['HOME'\]: couldn't find HOME environment -- expanding \`~"](https://discuss.elastic.co/t/logstash-error-could-not-load-aprc-from-env-home-couldnt-find-home-environment-expanding/328318)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 7:36am UTC](https://discuss.elastic.co/t/logstash-error-could-not-load-aprc-from-env-home-couldnt-find-home-environment-expanding/328318 "2023-03-23T07:36:38Z")

</div>

Hi Folks, I have a log file that logstash(8.6.2) is successfully parse, but has this error . i'm not sure whats causing it ? Could have a look ? , the data doesnt appear in kibana either Could not load '.aprc' from EN…

---

## [Filebeat processors](https://discuss.elastic.co/t/filebeat-processors/328275)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 7:34am UTC](https://discuss.elastic.co/t/filebeat-processors/328275 "2023-03-23T07:34:13Z")

</div>

Hi everyone, I have a question about the filebeat processors (extract\_array, drop\_event, drop\_fields). My filebeat agent collects about 2500 logs lines a second. Do you think that using these processors can lead to hug…

---

## [Split nested docs into a separate docs](https://discuss.elastic.co/t/split-nested-docs-into-a-separate-docs/328265)

<div class="topic-metadata">

**Author:** [@silverjoe](https://discuss.elastic.co/u/silverjoe)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 3:02pm UTC](https://discuss.elastic.co/t/split-nested-docs-into-a-separate-docs/328265 "2023-03-22T15:02:21Z")

</div>

Hi, I have a simple Logstash pipeline that reads all docs from an ES index using an ES input plugin, then I have a filter that splits one doc into several, and finally the output plugin to index docs in the ES. My probl…

---

## [Fleet Server Agent with Public URL can't be enrolled](https://discuss.elastic.co/t/fleet-server-agent-with-public-url-cant-be-enrolled/328306)

<div class="topic-metadata">

**Author:** [@johnkim](https://discuss.elastic.co/u/johnkim)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 5:51am UTC](https://discuss.elastic.co/t/fleet-server-agent-with-public-url-cant-be-enrolled/328306 "2023-03-23T05:51:04Z")

</div>

I essentially have the same issue as the person in this thread : The OP of that thread didn't really resolve the question for other people reading it. Similarly to that thread, I am trying to set up fleet-agent and ag…

---

## [Too much network data out in 8.4.3 elasticsearch](https://discuss.elastic.co/t/too-much-network-data-out-in-8-4-3-elasticsearch/328182)

<div class="topic-metadata">

**Author:** [@Dharampal\_Singh](https://discuss.elastic.co/u/Dharampal_Singh)\
**Replies:** 9\
**Last updated:** [March 23, 2023, 5:43am UTC](https://discuss.elastic.co/t/too-much-network-data-out-in-8-4-3-elasticsearch/328182 "2023-03-23T05:43:09Z")

</div>

HI We have migrated from elasticsearch 6.2.3 to 8.4.3 and seeing huge network data transfer cost.is anyone else also facing this issue or its suppose to be happen. in my configuration only 3 node cluster all are mater …

---

## [Two seprate log files to put in separate index](https://discuss.elastic.co/t/two-seprate-log-files-to-put-in-separate-index/327626)

<div class="topic-metadata">

**Author:** [@abhishek1111](https://discuss.elastic.co/u/abhishek1111)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 4:36am UTC](https://discuss.elastic.co/t/two-seprate-log-files-to-put-in-separate-index/327626 "2023-03-23T04:36:12Z")

</div>

Hello Experts :slight\_smile: Need your assistance on below use case of mine where filebeat is running as kubernetes daemon set. I have two log files under same folder in which i want to parse and push data to separate …

---

## [Why is the length of keyword array always 1?](https://discuss.elastic.co/t/why-is-the-length-of-keyword-array-always-1/328164)

<div class="topic-metadata">

**Author:** [@lyq2333](https://discuss.elastic.co/u/lyq2333)\
**Replies:** 6\
**Last updated:** [March 23, 2023, 12:56am UTC](https://discuss.elastic.co/t/why-is-the-length-of-keyword-array-always-1/328164 "2023-03-23T00:56:28Z")

</div>

I create an index by PUT my-index-000002 { "mappings": { "properties": { "content":{ "type": "keyword", "index\_options": "freqs" }, "id":{ "type": "integer" } } …

---

## [ORing a text field with a unique identifier keyword field leading to increased next\_doc count and poor performance](https://discuss.elastic.co/t/oring-a-text-field-with-a-unique-identifier-keyword-field-leading-to-increased-next-doc-count-and-poor-performance/328283)

<div class="topic-metadata">

**Author:** [@helderdias](https://discuss.elastic.co/u/helderdias)\
**Replies:** 8\
**Last updated:** [March 22, 2023, 11:24pm UTC](https://discuss.elastic.co/t/oring-a-text-field-with-a-unique-identifier-keyword-field-leading-to-increased-next-doc-count-and-poor-performance/328283 "2023-03-22T23:24:18Z")

</div>

TL;DR: I want to find documents that match a certain query (e.g. "my search") OR match the unique ID of a document. When I search for the text field alone, the search is super fast. However, when I or the text field wit…

---

## [K8s multiple replicas pq](https://discuss.elastic.co/t/k8s-multiple-replicas-pq/327887)

<div class="topic-metadata">

**Author:** [@liel\_bondy](https://discuss.elastic.co/u/liel_bondy)\
**Replies:** 3\
**Last updated:** [March 19, 2023, 1:10pm UTC](https://discuss.elastic.co/t/k8s-multiple-replicas-pq/327887 "2023-03-19T13:10:15Z")

</div>

Hey, quick question. If I want to scale my logstash (with PQ) horizontally in k8s, I would just increase the replica amount. Now that I have multiple nodes, I would like to understand how the PQ manages race conditions.…

---

## [Logstash TCP input pipeline performance issues](https://discuss.elastic.co/t/logstash-tcp-input-pipeline-performance-issues/328006)

<div class="topic-metadata">

**Author:** [@mread830](https://discuss.elastic.co/u/mread830)\
**Replies:** 9\
**Last updated:** [March 22, 2023, 9:44pm UTC](https://discuss.elastic.co/t/logstash-tcp-input-pipeline-performance-issues/328006 "2023-03-22T21:44:22Z")

</div>

I’m having an issue when a particular pipeline and i’m not sure how to track it down or trouble shoot it further.. First, I have multiple cloud environments, configured the same, sending to the same endpoints. 2 of the…

---

## [Bug in Cisco FTD Integration's Ingest Pipeline for Message ID's 302013, 302015](https://discuss.elastic.co/t/bug-in-cisco-ftd-integrations-ingest-pipeline-for-message-ids-302013-302015/328292)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 9:42pm UTC](https://discuss.elastic.co/t/bug-in-cisco-ftd-integrations-ingest-pipeline-for-message-ids-302013-302015/328292 "2023-03-22T21:42:06Z")

</div>

We have been getting quite a lot of "Network Traffic to Rare Destination Country" alerts based on the associated ML job, and after looking into each of these detections, the vast majority of them are false-positives for …

---

## [Ingesting Data from an API](https://discuss.elastic.co/t/ingesting-data-from-an-api/328186)

<div class="topic-metadata">

**Author:** [@mrodski](https://discuss.elastic.co/u/mrodski)\
**Replies:** 3\
**Last updated:** [March 22, 2023, 9:32pm UTC](https://discuss.elastic.co/t/ingesting-data-from-an-api/328186 "2023-03-22T21:32:09Z")

</div>

So I am pretty new to Elastic and have it installed on my servers. I do not have Elastic Cloud Services at this point in time. How do you take an API call from one server and have it ingested into Elastic so that I can v…

[Previous page](https://discuss.elastic.co/latest.md?page=736)

[Next page](https://discuss.elastic.co/latest.md?page=738)
