# Latest

**URL:** https://discuss.elastic.co/latest.md?page=743

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 744

---

## [Cannot suggest as I assume](https://discuss.elastic.co/t/cannot-suggest-as-i-assume/327604)

<div class="topic-metadata">

**Author:** [@Victor.Li](https://discuss.elastic.co/u/Victor.Li)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 7:19am UTC](https://discuss.elastic.co/t/cannot-suggest-as-i-assume/327604 "2023-03-14T07:19:27Z")

</div>

There's one field called 'table\_name' of which format is like 't\_data\_quality', 't\_data\_security'. Its mapping is "mappings": { "properties": { "table\_name": { "type": "text", "fields":{ "suggest":{ "type":"comp…

---

## [Exception "aggregation\_execution\_exception" after issues with not enough shards](https://discuss.elastic.co/t/exception-aggregation-execution-exception-after-issues-with-not-enough-shards/327907)

<div class="topic-metadata">

**Author:** [@Filisimus](https://discuss.elastic.co/u/Filisimus)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 6:43am UTC](https://discuss.elastic.co/t/exception-aggregation-execution-exception-after-issues-with-not-enough-shards/327907 "2023-03-20T06:43:51Z")

</div>

Hi guys, so we are using Graylog with Elasticsearch and when I tried to create additional indices we ran out of shards. I fixed the shard issue, created the new indices but if I use the new indices with existing indices…

---

## [Calculate disk space requirement for increasing replicas](https://discuss.elastic.co/t/calculate-disk-space-requirement-for-increasing-replicas/327552)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 6:29am UTC](https://discuss.elastic.co/t/calculate-disk-space-requirement-for-increasing-replicas/327552 "2023-03-20T06:29:52Z")

</div>

Im planning to increase replication of some of our indices and trying to understand the additional disk required for this. Looking at the test index below(1p:2r, store.size = 45mb, pri.store.size=15mb) would it be accura…

---

## [How is this hardware selection for 3 node cluster](https://discuss.elastic.co/t/how-is-this-hardware-selection-for-3-node-cluster/327715)

<div class="topic-metadata">

**Author:** [@jbates5873](https://discuss.elastic.co/u/jbates5873)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 6:23am UTC](https://discuss.elastic.co/t/how-is-this-hardware-selection-for-3-node-cluster/327715 "2023-03-20T06:23:48Z")

</div>

Hi All, We currently run a production 3 node cluster internally at our company on a VERY resource constrained server. We run it under a docker swarm, and have all or our services etc.. also within the swarm, so the 3 ho…

---

## [Kibana server is not ready yet and logstash 401 error](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-and-logstash-401-error/327247)

<div class="topic-metadata">

**Author:** [@Antony-m](https://discuss.elastic.co/u/Antony-m)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 4:52am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-and-logstash-401-error/327247 "2023-03-20T04:52:41Z")

</div>

@adityasinghal26 @renangenova I'm new to the ELK stack I watched a youtube tutorial and setup the ELK in my local using docker, here the youtube video link This is my docker-compose.yml file version: '3.6' services: …

---

## [Best practices for spot/preemptible instances](https://discuss.elastic.co/t/best-practices-for-spot-preemptible-instances/326812)

<div class="topic-metadata">

**Author:** [@marcoderama](https://discuss.elastic.co/u/marcoderama)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 4:43am UTC](https://discuss.elastic.co/t/best-practices-for-spot-preemptible-instances/326812 "2023-03-20T04:43:45Z")

</div>

I'm a noob with this stuff so looking for some guidance. Say I have a GCP cluster that uses preemptible instances, or an AWS cluster that uses spot instances. If I have an Agent policy with the "Google Cloud Platform" …

---

## [Elastic cloud on kubernetes - logstash question](https://discuss.elastic.co/t/elastic-cloud-on-kubernetes-logstash-question/326700)

<div class="topic-metadata">

**Author:** [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Replies:** 11\
**Last updated:** [March 20, 2023, 4:36am UTC](https://discuss.elastic.co/t/elastic-cloud-on-kubernetes-logstash-question/326700 "2023-03-20T04:36:03Z")

</div>

Hi, I'm trying to setup a logstash pipeline to receive tcp syslog from remote sources logstash on elastic cloud on kubernetes, Openshift 4.12. The sending source must send TCP port 6514 and use TLS to make the connectio…

---

## [Multi node cluster failing to connect](https://discuss.elastic.co/t/multi-node-cluster-failing-to-connect/326753)

<div class="topic-metadata">

**Author:** [@vanwoes](https://discuss.elastic.co/u/vanwoes)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 4:29am UTC](https://discuss.elastic.co/t/multi-node-cluster-failing-to-connect/326753 "2023-03-20T04:29:02Z")

</div>

Hi, I'm having an issue with a multi node elasticsearch cluster where the nodes are failing to join in a docker swarm. received join request from \[{es01}{SBn0YXX-RyuPcEsz3vgdjA}{0l0I2h0HRteijUgnwwmvqg}{es01}{10.0.0.69}…

---

## [Can i strip different values from "message" field](https://discuss.elastic.co/t/can-i-strip-different-values-from-message-field/328018)

<div class="topic-metadata">

**Author:** [@Hramoff](https://discuss.elastic.co/u/Hramoff)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 4:07am UTC](https://discuss.elastic.co/t/can-i-strip-different-values-from-message-field/328018 "2023-03-20T04:07:28Z")

</div>

I am using logstash with syslog plugin to collect logs from vsphere. The problem is that I get a lot of unnecessary entries, over 12,000 different rows per minute. I want to whitelist only the values ​​that I want in th…

---

## [Decompress a gzip compressed string in logstash and push to es](https://discuss.elastic.co/t/decompress-a-gzip-compressed-string-in-logstash-and-push-to-es/327720)

<div class="topic-metadata">

**Author:** [@shdasgupta](https://discuss.elastic.co/u/shdasgupta)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 2:18am UTC](https://discuss.elastic.co/t/decompress-a-gzip-compressed-string-in-logstash-and-push-to-es/327720 "2023-03-20T02:18:45Z")

</div>

Team, I am trying to decompress a gzip compressed data using logstash - am not able to figure out how to do this. Input json: (this is fed through a file in this example. In actual, it is consuming a kafka message whic…

---

## [Indices not getting an ILM policy applied after rollover](https://discuss.elastic.co/t/indices-not-getting-an-ilm-policy-applied-after-rollover/327997)

<div class="topic-metadata">

**Author:** [@jba](https://discuss.elastic.co/u/jba)\
**Replies:** 3\
**Last updated:** [March 19, 2023, 5:46pm UTC](https://discuss.elastic.co/t/indices-not-getting-an-ilm-policy-applied-after-rollover/327997 "2023-03-19T17:46:22Z")

</div>

I have a problem with indices not getting an ILM policy applied after rollover on a cluster (Elasticsearch, Logstash, and Kibana) that have recently been upgraded from 7.17 to 8.4 and have had our old legacy templates co…

---

## [Sending HTTPS requests to es01 running on docker-compose](https://discuss.elastic.co/t/sending-https-requests-to-es01-running-on-docker-compose/327728)

<div class="topic-metadata">

**Author:** [@anjankow](https://discuss.elastic.co/u/anjankow)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 12:38am UTC](https://discuss.elastic.co/t/sending-https-requests-to-es01-running-on-docker-compose/327728 "2023-03-20T00:38:51Z")

</div>

I'm using docker-compose setup as described here: And I'm able to send requests to e01 using curl passing a certificate and username with password. Now I want to send requests from my application to e01 node. I tried …

---

## [While searching how do I exclude only one object and include other object inside a nested object](https://discuss.elastic.co/t/while-searching-how-do-i-exclude-only-one-object-and-include-other-object-inside-a-nested-object/327322)

<div class="topic-metadata">

**Author:** [@Nabin\_Upreti](https://discuss.elastic.co/u/Nabin_Upreti)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 11:51pm UTC](https://discuss.elastic.co/t/while-searching-how-do-i-exclude-only-one-object-and-include-other-object-inside-a-nested-object/327322 "2023-03-19T23:51:49Z")

</div>

I want to search minimum of the negotiated\_rate where negotiated type is not percentage. I used must not query to filter out percentage but this results to excluding the whole document. Here I expect the minimum negotia…

---

## [Configure APM agent with System.Configuration](https://discuss.elastic.co/t/configure-apm-agent-with-system-configuration/326623)

<div class="topic-metadata">

**Author:** [@horato](https://discuss.elastic.co/u/horato)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 6:24pm UTC](https://discuss.elastic.co/t/configure-apm-agent-with-system-configuration/326623 "2023-02-27T18:24:03Z")

</div>

Hi, Is it possible to use System.Configuration instead of IConfiguration to configure APM agent on .NET Core? We still use App.config xml and System.Configuration to setup our ASP.Net Core apps. If not, are there any p…

---

## [How to configure Elastic stack with Fleet server and APM integration using docker compose?](https://discuss.elastic.co/t/how-to-configure-elastic-stack-with-fleet-server-and-apm-integration-using-docker-compose/326974)

<div class="topic-metadata">

**Author:** [@hexsorcerer](https://discuss.elastic.co/u/hexsorcerer)\
**Replies:** 0\
**Last updated:** [March 4, 2023, 1:51am UTC](https://discuss.elastic.co/t/how-to-configure-elastic-stack-with-fleet-server-and-apm-integration-using-docker-compose/326974 "2023-03-04T01:51:56Z")

</div>

I'm trying to setup an example project with the following functionality: Elasticsearch Logstash Kibana Fleet Server Elastic Agent with APM Integration OpenTelemetry from a .NET Application Getting the basic ELK setup …

---

## [Groks solution in filebeat](https://discuss.elastic.co/t/groks-solution-in-filebeat/327133)

<div class="topic-metadata">

**Author:** [@ingri.mahecha](https://discuss.elastic.co/u/ingri.mahecha)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 3:22am UTC](https://discuss.elastic.co/t/groks-solution-in-filebeat/327133 "2023-03-07T03:22:29Z")

</div>

Hello community, Having encountered the problem of how to apply groks in filebeat, I want to share with you the solution I found with the PROCESSORS section and the Dissect function, I hope it helps you, as well as havi…

---

## [Collecting logs via VMware vSphere integration](https://discuss.elastic.co/t/collecting-logs-via-vmware-vsphere-integration/327165)

<div class="topic-metadata">

**Author:** [@tumbl3w33d](https://discuss.elastic.co/u/tumbl3w33d)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 10:38am UTC](https://discuss.elastic.co/t/collecting-logs-via-vmware-vsphere-integration/327165 "2023-03-07T10:38:28Z")

</div>

Disclaimer: I don't know much about VMware, so I'd be glad if you enlighten me when necessary. Hello, I am trying to understand how to use this agent integration to collect logs and metrics from a vSphere setup. Metric…

---

## [How to use event.category intrusion\_detection](https://discuss.elastic.co/t/how-to-use-event-category-intrusion-detection/327316)

<div class="topic-metadata">

**Author:** [@jjacksonrkk](https://discuss.elastic.co/u/jjacksonrkk)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 1:52am UTC](https://discuss.elastic.co/t/how-to-use-event-category-intrusion-detection/327316 "2023-03-09T01:52:46Z")

</div>

How can I activate intrusion\_detection in auditbeat event.category? When debugging, log.logger occurs as a publisher and the event.category includes intrusion\_detection, but when the daemon service is run, the intrusion…

---

## [Filebeat logs stored in /tmp are causing pod eviction](https://discuss.elastic.co/t/filebeat-logs-stored-in-tmp-are-causing-pod-eviction/327221)

<div class="topic-metadata">

**Author:** [@Varun\_Sriram](https://discuss.elastic.co/u/Varun_Sriram)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 6:21pm UTC](https://discuss.elastic.co/t/filebeat-logs-stored-in-tmp-are-causing-pod-eviction/327221 "2023-03-07T18:21:21Z")

</div>

Hi all, i am seeing an issue on my environment which is using filebeat for logging and monitoring where files with large amounts of storage used are getting created. I presume these are log files created by filebeat and…

---

## [Options List Control Ignores Filters and Queries](https://discuss.elastic.co/t/options-list-control-ignores-filters-and-queries/317334)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 10\
**Last updated:** [March 19, 2023, 11:28pm UTC](https://discuss.elastic.co/t/options-list-control-ignores-filters-and-queries/317334 "2023-03-19T23:28:23Z")

</div>

Please see original thread Options List Control Ignores Filters and Queries - Elastic Stack / Kibana - Discuss the Elastic Stack. Why does no notification go out when a topic is about to close? @Teresa\_Alvarez , One …

---

## [Kibana degraded, available on Kubernetes](https://discuss.elastic.co/t/kibana-degraded-available-on-kubernetes/327059)

<div class="topic-metadata">

**Author:** [@PustyB](https://discuss.elastic.co/u/PustyB)\
**Replies:** 3\
**Last updated:** [March 19, 2023, 11:26pm UTC](https://discuss.elastic.co/t/kibana-degraded-available-on-kubernetes/327059 "2023-03-19T23:26:58Z")

</div>

Hey I've had a problem with Kibana for a while now. I installed Elastic Stack on kubernetes using the operator. At first everything was fine, however, since some time in the kibana logs it started throwing such errors: …

---

## [Receiving harvestor errors and invalid CRI log format on filebeat](https://discuss.elastic.co/t/receiving-harvestor-errors-and-invalid-cri-log-format-on-filebeat/327347)

<div class="topic-metadata">

**Author:** [@Narendra](https://discuss.elastic.co/u/Narendra)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 10:41am UTC](https://discuss.elastic.co/t/receiving-harvestor-errors-and-invalid-cri-log-format-on-filebeat/327347 "2023-03-09T10:41:06Z")

</div>

Hi, I have an ELK setup with deamonset filebeat(7.14) as input from 31 kubernetes nodes moved to logstash and then to ES. From couple of days we and are facing log drop and getting below logs in Filebeat. \<\<\<\<\<\<\<\<\<\< …

---

## [How to use Java api UpdateRequest for conditional write with optimistic locking control in place](https://discuss.elastic.co/t/how-to-use-java-api-updaterequest-for-conditional-write-with-optimistic-locking-control-in-place/327386)

<div class="topic-metadata">

**Author:** [@ted2349](https://discuss.elastic.co/u/ted2349)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 6:28pm UTC](https://discuss.elastic.co/t/how-to-use-java-api-updaterequest-for-conditional-write-with-optimistic-locking-control-in-place/327386 "2023-03-09T18:28:38Z")

</div>

Hi, My scenario is upsert the whole document with optimistic locking control (seqno/ primary term) I also want to do some conditional update meaning I want to update only when current doc's updatedAt is earlier than w…

---

## [Doing a lab](https://discuss.elastic.co/t/doing-a-lab/327388)

<div class="topic-metadata">

**Author:** [@kmuirur](https://discuss.elastic.co/u/kmuirur)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 6:49pm UTC](https://discuss.elastic.co/t/doing-a-lab/327388 "2023-03-09T18:49:54Z")

</div>

While creating a component template in Kibana and I am getting the following errors for the course "Configuring Elasticsearch Index to Time-Series Data On-Demand" "Unable to create component template unknown setting \[i…

---

## [How to get the Elastic search data running on my docker in my host](https://discuss.elastic.co/t/how-to-get-the-elastic-search-data-running-on-my-docker-in-my-host/327402)

<div class="topic-metadata">

**Author:** [@Anubhavg](https://discuss.elastic.co/u/Anubhavg)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 11:15pm UTC](https://discuss.elastic.co/t/how-to-get-the-elastic-search-data-running-on-my-docker-in-my-host/327402 "2023-03-19T23:15:09Z")

</div>

I am running the docker image of Elasticsearch and not able to bind the volume (/usr/share/elasticsearch/data) to my host volume (/home). I am using the following command: sudo docker run --name els6 --net elasticsearc…

---

## [Auditbeat vs elastic endpoint for collecting endpoint data](https://discuss.elastic.co/t/auditbeat-vs-elastic-endpoint-for-collecting-endpoint-data/327410)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 4:34am UTC](https://discuss.elastic.co/t/auditbeat-vs-elastic-endpoint-for-collecting-endpoint-data/327410 "2023-03-10T04:34:40Z")

</div>

Hi all, My elastic cluster is currently using both auditbeat and elastic endpoint to collect data from the endpoint server but due to limited space in the data node i have to cut off 1 type. I want to ask if which one …

---

## [Getting the latest transform trigger time in a continuous transform](https://discuss.elastic.co/t/getting-the-latest-transform-trigger-time-in-a-continuous-transform/327420)

<div class="topic-metadata">

**Author:** [@cwwongaz](https://discuss.elastic.co/u/cwwongaz)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 7:49am UTC](https://discuss.elastic.co/t/getting-the-latest-transform-trigger-time-in-a-continuous-transform/327420 "2023-03-10T07:49:03Z")

</div>

Hi, I am running a continuous transform at a 15-minute frequency to transform the data from index\_A to index\_B. In the transform, I have set a 120s sync delay time to avoid missing the latest data. However, in the aggre…

---

## [Creating a CURL POST query against an App Search Meta Engine](https://discuss.elastic.co/t/creating-a-curl-post-query-against-an-app-search-meta-engine/327462)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 3:37pm UTC](https://discuss.elastic.co/t/creating-a-curl-post-query-against-an-app-search-meta-engine/327462 "2023-03-10T15:37:01Z")

</div>

Hello, A little background of this topic. We are currently using SharePoint Search for crawling/indexing our web presence to create a website search experience on our site. Part of the functionality of SharePoint searc…

---

## [Elasticsearch function\_score not working inside nested aggregations](https://discuss.elastic.co/t/elasticsearch-function-score-not-working-inside-nested-aggregations/327479)

<div class="topic-metadata">

**Author:** [@frarafra](https://discuss.elastic.co/u/frarafra)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 11:28pm UTC](https://discuss.elastic.co/t/elasticsearch-function-score-not-working-inside-nested-aggregations/327479 "2023-03-10T23:28:36Z")

</div>

I have an Elasticsearch query with nested aggregations. It was working as expected but when I added a function\_score query it seems to not take it into account. This is my query: GET reviews/\_search { "size": 0, "a…

---

## [Field data type conflict](https://discuss.elastic.co/t/field-data-type-conflict/327507)

<div class="topic-metadata">

**Author:** [@Sara\_YB](https://discuss.elastic.co/u/Sara_YB)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 11:05pm UTC](https://discuss.elastic.co/t/field-data-type-conflict/327507 "2023-03-19T23:05:22Z")

</div>

I have nested field type (text, long). After upgrading to v 8.6, a conflict happened in this field. Below is the message I got: "The type of the (field name) field changes across indices and might not be available for s…

[Previous page](https://discuss.elastic.co/latest.md?page=742)

[Next page](https://discuss.elastic.co/latest.md?page=744)
