# Latest

**URL:** https://discuss.elastic.co/latest.md?page=739

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 740

---

## [Restore indices on snapshots based on their alias](https://discuss.elastic.co/t/restore-indices-on-snapshots-based-on-their-alias/328237)

<div class="topic-metadata">

**Author:** [@Nuno\_Santos1](https://discuss.elastic.co/u/Nuno_Santos1)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 11:23am UTC](https://discuss.elastic.co/t/restore-indices-on-snapshots-based-on-their-alias/328237 "2023-03-22T11:23:43Z")

</div>

When restoring indices from a snapshot, is there a way to get from the snapshot the aliases associated with an index before starting to restore the index? Through the REST API I can get information about the indices that…

---

## [Too many properties: should we increase the property limit or use a nested approach and increase that limit?](https://discuss.elastic.co/t/too-many-properties-should-we-increase-the-property-limit-or-use-a-nested-approach-and-increase-that-limit/328179)

<div class="topic-metadata">

**Author:** [@obi-wan](https://discuss.elastic.co/u/obi-wan)\
**Replies:** 3\
**Last updated:** [March 22, 2023, 11:19am UTC](https://discuss.elastic.co/t/too-many-properties-should-we-increase-the-property-limit-or-use-a-nested-approach-and-increase-that-limit/328179 "2023-03-22T11:19:59Z")

</div>

Hi there, We have a situation with limits in the mapping, and I am not sure what is the way to go as there are multiple solutions. I will start by describing the use case: there are multiple tenants, which each have …

---

## [UPDATE existing index with reindex and pipeline](https://discuss.elastic.co/t/update-existing-index-with-reindex-and-pipeline/328227)

<div class="topic-metadata">

**Author:** [@hben](https://discuss.elastic.co/u/hben)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 9:51am UTC](https://discuss.elastic.co/t/update-existing-index-with-reindex-and-pipeline/328227 "2023-03-22T09:51:54Z")

</div>

Hi, I have an index that our application is working with like a Relational table, so we insert and update documents in it. now we want to make a structure change and add 3 fields and add data to those fields from a ta…

---

## [Kibana rollup for MAX values](https://discuss.elastic.co/t/kibana-rollup-for-max-values/328228)

<div class="topic-metadata">

**Author:** [@thirty2](https://discuss.elastic.co/u/thirty2)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 9:55am UTC](https://discuss.elastic.co/t/kibana-rollup-for-max-values/328228 "2023-03-22T09:55:19Z")

</div>

Hi, i have this problem with Kibana rollups: i have raw data each 5minutes, as you can see the MAX value from 19:00 till 20:00 is 155.775 When i configured rollup job with Interval 60m in the roollup index as MAX v…

---

## [Convert string to ip in painless processor](https://discuss.elastic.co/t/convert-string-to-ip-in-painless-processor/328189)

<div class="topic-metadata">

**Author:** [@HansPeterSloot](https://discuss.elastic.co/u/HansPeterSloot)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 9:39am UTC](https://discuss.elastic.co/t/convert-string-to-ip-in-painless-processor/328189 "2023-03-22T09:39:15Z")

</div>

Hello, Is there a way to convert a string to an ip address in a painless processor? Regards Hans

---

## [How to use user-defined plugin](https://discuss.elastic.co/t/how-to-use-user-defined-plugin/328224)

<div class="topic-metadata">

**Author:** [@wendywong0020](https://discuss.elastic.co/u/wendywong0020)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 9:24am UTC](https://discuss.elastic.co/t/how-to-use-user-defined-plugin/328224 "2023-03-22T09:24:06Z")

</div>

logstash.conf: input { file { type =\> "\_doc" path =\> "/data/mysql\_\*\_log/slow.log" codec =\> multiline { …

---

## [Edit Deployment Cloud without downtime](https://discuss.elastic.co/t/edit-deployment-cloud-without-downtime/328177)

<div class="topic-metadata">

**Author:** [@davide.lilliu](https://discuss.elastic.co/u/davide.lilliu)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 9:15am UTC](https://discuss.elastic.co/t/edit-deployment-cloud-without-downtime/328177 "2023-03-22T09:15:19Z")

</div>

Hi, i want to edit my deployment cloud from 3 server elastic server hot data to 1 hot data and 2 warm data. I read this document ec-customize-deployment and it seems that the old servers are not turned off before the n…

---

## [Mailenable server smtp activity logs using filebeat to elasticsearch](https://discuss.elastic.co/t/mailenable-server-smtp-activity-logs-using-filebeat-to-elasticsearch/327852)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 9:08am UTC](https://discuss.elastic.co/t/mailenable-server-smtp-activity-logs-using-filebeat-to-elasticsearch/327852 "2023-03-22T09:08:34Z")

</div>

Hello Every one I am using elasticsearch 7.10 and filebeat 7.10 I want to pars following logs using filebeat to direct elasticsearch I have no Idea how I can achive can you please suggest me from my sample logs. 03/15/…

---

## [Detected ambiguous Field Reference warning](https://discuss.elastic.co/t/detected-ambiguous-field-reference-warning/328218)

<div class="topic-metadata">

**Author:** [@parosio](https://discuss.elastic.co/u/parosio)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 8:29am UTC](https://discuss.elastic.co/t/detected-ambiguous-field-reference-warning/328218 "2023-03-22T08:29:58Z")

</div>

Hello, I've got to ingest (logstash 6.7) documents which are stages of a workflow (queue\_in, start\_work, end\_work, queue\_out, etc.). I need to add various fields with elapsed times (looking for initial times in previou…

---

## [Double values filebeat](https://discuss.elastic.co/t/double-values-filebeat/328217)

<div class="topic-metadata">

**Author:** [@chrispos](https://discuss.elastic.co/u/chrispos)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 8:09am UTC](https://discuss.elastic.co/t/double-values-filebeat/328217 "2023-03-22T08:09:16Z")

</div>

Hello, I'm trying to read my log server.json into logstash /kibana. Now I have opened a topic for this before, and I was advised to ask further questions in the filebeat forum. For the record. I've already gotten a lit…

---

## [Extract logs from a file that start with a line and end with a known line do this for the whole file using logstash](https://discuss.elastic.co/t/extract-logs-from-a-file-that-start-with-a-line-and-end-with-a-known-line-do-this-for-the-whole-file-using-logstash/328216)

<div class="topic-metadata">

**Author:** [@chikugerson](https://discuss.elastic.co/u/chikugerson)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 7:58am UTC](https://discuss.elastic.co/t/extract-logs-from-a-file-that-start-with-a-line-and-end-with-a-known-line-do-this-for-the-whole-file-using-logstash/328216 "2023-03-22T07:58:21Z")

</div>

input { file { path =\> "C:/Users/user/Documents/Logstash/mylogs/spa2.log" start\_position =\> "beginning" } } filter { if "SPAHGW:31 32 30 30 :004:: 1200" in \[message\] { …

---

## [Logstash ignores newly created template when importing index](https://discuss.elastic.co/t/logstash-ignores-newly-created-template-when-importing-index/328215)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 7:40am UTC](https://discuss.elastic.co/t/logstash-ignores-newly-created-template-when-importing-index/328215 "2023-03-22T07:40:43Z")

</div>

I am using the following pipeline to do an import of an index exported from Elastic: - pipeline.id: import-process pipeline.workers: 4 config.string: | input { file { path =\>…

---

## [Can Filebeat handle same load as Logstash while being a lightweight shipper](https://discuss.elastic.co/t/can-filebeat-handle-same-load-as-logstash-while-being-a-lightweight-shipper/328212)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 6:43am UTC](https://discuss.elastic.co/t/can-filebeat-handle-same-load-as-logstash-while-being-a-lightweight-shipper/328212 "2023-03-22T06:43:09Z")

</div>

if I am using Logstash / Filebeat as a Log server . in term of memory and other things . which tool is better to go with.

---

## [Metricbeat shows containers as host in APM UI](https://discuss.elastic.co/t/metricbeat-shows-containers-as-host-in-apm-ui/328154)

<div class="topic-metadata">

**Author:** [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 11:19am UTC](https://discuss.elastic.co/t/metricbeat-shows-containers-as-host-in-apm-ui/328154 "2023-03-21T11:19:01Z")

</div>

hi, I am trying to monitor a microservices application deployed in docker with APM on elastic cloud. When I start metricbeat with the system and docker modules enabled, it shows me the containers as if they were hosts. …

---

## [Databricks Spark SQL and Elasticsearch](https://discuss.elastic.co/t/databricks-spark-sql-and-elasticsearch/328028)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 6:19am UTC](https://discuss.elastic.co/t/databricks-spark-sql-and-elasticsearch/328028 "2023-03-22T06:19:45Z")

</div>

Is there any documentation related to Databricks Spark/Spark SQL integration with elasticsearch?

---

## [Query to find all the users with one role](https://discuss.elastic.co/t/query-to-find-all-the-users-with-one-role/328156)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 4:09am UTC](https://discuss.elastic.co/t/query-to-find-all-the-users-with-one-role/328156 "2023-03-22T04:09:14Z")

</div>

Hi Team, How can I find the user in ELK with one particular role. I can get all the users with following query: GET /\_security/user but when I try to find user with a role GET /\_security/user/ { "query":"select …

---

## [Logstash stop working priodicly!](https://discuss.elastic.co/t/logstash-stop-working-priodicly/328201)

<div class="topic-metadata">

**Author:** [@Siavash\_Fazli](https://discuss.elastic.co/u/Siavash_Fazli)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 1:38am UTC](https://discuss.elastic.co/t/logstash-stop-working-priodicly/328201 "2023-03-22T01:38:42Z")

</div>

hi guys. my logstash stopped working several times as you can see in the picture. I have 15 pipelines on one docker logstash node can anyone guess what happened?

---

## [Docker Logs keep getting dropped with tried to parse field \[image\] as object, but found a concrete value error](https://discuss.elastic.co/t/docker-logs-keep-getting-dropped-with-tried-to-parse-field-image-as-object-but-found-a-concrete-value-error/326245)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 49\
**Last updated:** [March 22, 2023, 1:15am UTC](https://discuss.elastic.co/t/docker-logs-keep-getting-dropped-with-tried-to-parse-field-image-as-object-but-found-a-concrete-value-error/326245 "2023-03-22T01:15:41Z")

</div>

When investigating why I couldn't find my docker logs in Elastic, I found that Elastic Agent has been dropping them. It keeps logging stuff like: {"log.level":"warn","@timestamp":"2023-02-22T18:48:50.007-0800","message"…

---

## [Migrating 7.17 to 8.0 (With Frozen Indices and Searchable Snapshots)](https://discuss.elastic.co/t/migrating-7-17-to-8-0-with-frozen-indices-and-searchable-snapshots/328106)

<div class="topic-metadata">

**Author:** [@pkward](https://discuss.elastic.co/u/pkward)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 1:15am UTC](https://discuss.elastic.co/t/migrating-7-17-to-8-0-with-frozen-indices-and-searchable-snapshots/328106 "2023-03-22T01:15:23Z")

</div>

Hello, I'm migrating a cluster from 7.17 to 8.0 and I have frozen indices. I read in the documentation that the frozen action was removed or deprecated in version 8, so I wanted to know I can I safely migrate to version…

---

## [Ingesting syslog from NetApp ONTAP](https://discuss.elastic.co/t/ingesting-syslog-from-netapp-ontap/328170)

<div class="topic-metadata">

**Author:** [@diselkgd7](https://discuss.elastic.co/u/diselkgd7)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 12:58am UTC](https://discuss.elastic.co/t/ingesting-syslog-from-netapp-ontap/328170 "2023-03-22T00:58:51Z")

</div>

I've configured our storage to send syslog to filebeat but when I examine what's been ingested in kibana - the whole syslog message is crammed in one "message" field while the rest of the 26 fields have values relating t…

---

## [Semantic Search API](https://discuss.elastic.co/t/semantic-search-api/328113)

<div class="topic-metadata">

**Author:** [@rpmansion](https://discuss.elastic.co/u/rpmansion)\
**Replies:** 7\
**Last updated:** [March 21, 2023, 8:52pm UTC](https://discuss.elastic.co/t/semantic-search-api/328113 "2023-03-21T20:52:25Z")

</div>

There is a semantic search API endpoint (/index\_name/\_semantic-search) that was released in the documentation, what is the reason this was removed?

---

## [Conflict fluent bit and elasticsearch](https://discuss.elastic.co/t/conflict-fluent-bit-and-elasticsearch/328198)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 7:54pm UTC](https://discuss.elastic.co/t/conflict-fluent-bit-and-elasticsearch/328198 "2023-03-21T19:54:54Z")

</div>

Hello everyone, I just migrated my cluster from version 7.9 to 8.5 everything went well but I have problems with fluent. For some reason Fluent is not able to ingest on ELK. Here are some data. \[SERVICE\] Flush …

---

## [Failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/failed-to-publish-events-temporary-bulk-send-failure/327681)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 1\
**Last updated:** [March 21, 2023, 7:45pm UTC](https://discuss.elastic.co/t/failed-to-publish-events-temporary-bulk-send-failure/327681 "2023-03-21T19:45:08Z")

</div>

Hello everyone. I am trying to modify some parameters of the logs that come from fleet with the "custom logs" integration. I have created the following pipeline: LOG LINE: 2023-02-28 09:04:01,937 ERROR \[org.jboss.rem…

---

## [Handle space in a field](https://discuss.elastic.co/t/handle-space-in-a-field/328190)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 7:43pm UTC](https://discuss.elastic.co/t/handle-space-in-a-field/328190 "2023-03-21T19:43:41Z")

</div>

I am trying to remove a space from a field in logstash but it's not working, because there is space in the field, I can't even rename the field or not able to do replacement is with gsub. Request ID to be renamed to Req…

---

## [Auditbeat Equivalent for Elastic Agent](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 6:08pm UTC](https://discuss.elastic.co/t/auditbeat-equivalent-for-elastic-agent/328171 "2023-03-21T18:08:27Z")

</div>

When will there be an Auditbeat-equivalent Integration for Elastic Agent? We are trying to move exclusively to Elastic Agent, but the same monitoring done by Auditbeat is still not yet available that I can see. Eric

---

## [Query Alert History in Elastic Cloud 8.6.2](https://discuss.elastic.co/t/query-alert-history-in-elastic-cloud-8-6-2/328105)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 3\
**Last updated:** [March 21, 2023, 5:38pm UTC](https://discuss.elastic.co/t/query-alert-history-in-elastic-cloud-8-6-2/328105 "2023-03-21T17:38:00Z")

</div>

As an Elastic Cloud user (v8.6.2), I would like to query my Observability Alert history for reporting purposes, and perhaps even to create a high-level dashboard showing open alerts across multiple workspaces in Elastic …

---

## [Ingest RESTAPI response into Elasticsearch as separate document through Logstash](https://discuss.elastic.co/t/ingest-restapi-response-into-elasticsearch-as-separate-document-through-logstash/328117)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 5:30pm UTC](https://discuss.elastic.co/t/ingest-restapi-response-into-elasticsearch-as-separate-document-through-logstash/328117 "2023-03-21T17:30:28Z")

</div>

I am working http\_poller and using http plugin to ingest RestApi Array response output into Elasticsearch. using Logstash , I need help to split the output and store each as a separate document in Elasticsearch. Below…

---

## [Creating Multiple Alert Documents when Alert is Triggered](https://discuss.elastic.co/t/creating-multiple-alert-documents-when-alert-is-triggered/327088)

<div class="topic-metadata">

**Author:** [@juliette.littlewood](https://discuss.elastic.co/u/juliette.littlewood)\
**Replies:** 3\
**Last updated:** [March 10, 2023, 11:46pm UTC](https://discuss.elastic.co/t/creating-multiple-alert-documents-when-alert-is-triggered/327088 "2023-03-10T23:46:47Z")

</div>

Hi all, I've got a bit of a unique issue. For the system I am developing, data records will be ingested and compared against thresholds to confirm if values are anomalous. To test out this functionality I've set up an …

---

## [Best approach to implement ILM on a large index and archive old data](https://discuss.elastic.co/t/best-approach-to-implement-ilm-on-a-large-index-and-archive-old-data/328045)

<div class="topic-metadata">

**Author:** [@Baygon](https://discuss.elastic.co/u/Baygon)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 4:43pm UTC](https://discuss.elastic.co/t/best-approach-to-implement-ilm-on-a-large-index-and-archive-old-data/328045 "2023-03-21T16:43:16Z")

</div>

Hi, We have a single node cluster where one index unfortunately grew very big (261Gb) as we had no ILM on it. This is a production cluster. We understand that above 50Gb there is performance degradation and I think we …

---

## [Maximum allowed string Issue](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076)

<div class="topic-metadata">

**Author:** [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 4:21pm UTC](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076 "2023-03-21T16:21:11Z")

</div>

I get this error: The content length (732630494) is bigger than the maximum allowed string (536870888) I added to kibana.yml: server.maxPayloadBytes: 888888888 savedObjects.maxImportPayloadBytes: 50485760 I added to…

[Previous page](https://discuss.elastic.co/latest.md?page=738)

[Next page](https://discuss.elastic.co/latest.md?page=740)
