# Latest

**URL:** https://discuss.elastic.co/latest.md?page=767

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 768

---

## [Internal index process merging records into arrays of objects based on a parent common key](https://discuss.elastic.co/t/internal-index-process-merging-records-into-arrays-of-objects-based-on-a-parent-common-key/326451)

<div class="topic-metadata">

**Author:** [@MartinGarcia](https://discuss.elastic.co/u/MartinGarcia)\
**Replies:** 4\
**Last updated:** [February 27, 2023, 10:59am UTC](https://discuss.elastic.co/t/internal-index-process-merging-records-into-arrays-of-objects-based-on-a-parent-common-key/326451 "2023-02-27T10:59:41Z")

</div>

Hi, I have a doubt about a feature. I'm trying to run an internal process in Elastic where I create superseed objects based on an index that contains more flat and granular objects. For example: The source index contai…

---

## [How to Transpose Tabular Dashboard in Kibana](https://discuss.elastic.co/t/how-to-transpose-tabular-dashboard-in-kibana/326538)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 11:25am UTC](https://discuss.elastic.co/t/how-to-transpose-tabular-dashboard-in-kibana/326538 "2023-02-27T11:25:02Z")

</div>

Hello team, I wanted to transpose columns into row for better required visualization. Can you please suggest me how to do so. Note - I have used Lens for preparing Tabular dashboard Attaching screenshot for reference. …

---

## [Improve indexing performance speed by routing to a specific shard](https://discuss.elastic.co/t/improve-indexing-performance-speed-by-routing-to-a-specific-shard/326552)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 7\
**Last updated:** [February 27, 2023, 10:16am UTC](https://discuss.elastic.co/t/improve-indexing-performance-speed-by-routing-to-a-specific-shard/326552 "2023-02-27T10:16:47Z")

</div>

Hi, Let's say I have a 100GB of data that need to be indexed into a specific index with 5 shards. I don't have reads during indexing time and I want to speed up the process as much as possible. I have 5 (python) worke…

---

## [Logstash input elasticsearch](https://discuss.elastic.co/t/logstash-input-elasticsearch/326561)

<div class="topic-metadata">

**Author:** [@almteref](https://discuss.elastic.co/u/almteref)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 9:59am UTC](https://discuss.elastic.co/t/logstash-input-elasticsearch/326561 "2023-02-27T09:59:55Z")

</div>

Hi all I have question about the logstash in elasticsearch input plugin can I use the search template ID that I created in my cluster ? rether than pass query ?

---

## [Huge size for elastic endpoint (defend) integration indices?](https://discuss.elastic.co/t/huge-size-for-elastic-endpoint-defend-integration-indices/326344)

<div class="topic-metadata">

**Author:** [@rebug](https://discuss.elastic.co/u/rebug)\
**Replies:** 4\
**Last updated:** [February 27, 2023, 9:36am UTC](https://discuss.elastic.co/t/huge-size-for-elastic-endpoint-defend-integration-indices/326344 "2023-02-27T09:36:46Z")

</div>

Hello, Cluster information: 3 nodes with 1TB I have configured a fleet server with elastic defend integration to start using elastic security. Currently only 2 servers are enrolled with the agent. Here is the integra…

---

## [Question - Autoscaling on Kubernetes with ELK](https://discuss.elastic.co/t/question-autoscaling-on-kubernetes-with-elk/326421)

<div class="topic-metadata">

**Author:** [@dvp\_at](https://discuss.elastic.co/u/dvp_at)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 9:36am UTC](https://discuss.elastic.co/t/question-autoscaling-on-kubernetes-with-elk/326421 "2023-02-27T09:36:44Z")

</div>

Hello all, I am new in the ECK and Kubernetes environement usage and I am currently working on a school project. We need to autoscale our kubernetes pods on 3 nodes, depending the workload of the pods on the nodes. On…

---

## [An index that inflates](https://discuss.elastic.co/t/an-index-that-inflates/326517)

<div class="topic-metadata">

**Author:** [@boazBD](https://discuss.elastic.co/u/boazBD)\
**Replies:** 4\
**Last updated:** [February 27, 2023, 9:27am UTC](https://discuss.elastic.co/t/an-index-that-inflates/326517 "2023-02-27T09:27:23Z")

</div>

Hello, I have an index that inflates more until the node crashes with a full disk error. For now, I delete the index directly from the VM because Elastic is unhealthy when it happens. It is helpful for a short period,…

---

## [Add a csv input for every batch](https://discuss.elastic.co/t/add-a-csv-input-for-every-batch/326553)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 8:23am UTC](https://discuss.elastic.co/t/add-a-csv-input-for-every-batch/326553 "2023-02-27T08:23:19Z")

</div>

Hello, I am using http\_poller input plugin and elasticsearch output plugin.. I want to use CSV output plugin also for logging logstash success in a CSV file..But in my CSV all the events are noted but not only once. I …

---

## [Running \_forcemerge on an index that is being write on](https://discuss.elastic.co/t/running-forcemerge-on-an-index-that-is-being-write-on/326492)

<div class="topic-metadata">

**Author:** [@Tudor\_Plugaru](https://discuss.elastic.co/u/Tudor_Plugaru)\
**Replies:** 18\
**Last updated:** [February 27, 2023, 8:22am UTC](https://discuss.elastic.co/t/running-forcemerge-on-an-index-that-is-being-write-on/326492 "2023-02-27T08:22:27Z")

</div>

Hi, we are having an index with heavy updates on the documents. This leads us to having a lot of uncleaned deleted documents, for example, we can have around 400M searchable documents and around 150M of uncleaned docume…

---

## [How can I add field by a same field when across event](https://discuss.elastic.co/t/how-can-i-add-field-by-a-same-field-when-across-event/326551)

<div class="topic-metadata">

**Author:** [@OICAn](https://discuss.elastic.co/u/OICAn)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 8:09am UTC](https://discuss.elastic.co/t/how-can-i-add-field-by-a-same-field-when-across-event/326551 "2023-02-27T08:09:02Z")

</div>

A user access our system will trigger many transcations. A transaction will generate some log, which are serval event in es and they have a same field called "globalNo". One event will log the name of the transaction and…

---

## [Syslog to elastic stack on kubernetes/openshift](https://discuss.elastic.co/t/syslog-to-elastic-stack-on-kubernetes-openshift/326068)

<div class="topic-metadata">

**Author:** [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Replies:** 6\
**Last updated:** [February 27, 2023, 7:52am UTC](https://discuss.elastic.co/t/syslog-to-elastic-stack-on-kubernetes-openshift/326068 "2023-02-27T07:52:52Z")

</div>

Hi, We are almost in production and have one final function left, and it's fleet & elastic agent deployment so we can receive syslog from external source. For example CiscoFTD, Palo Alto etc. I have followed the docume…

---

## [Particular word count in particular file](https://discuss.elastic.co/t/particular-word-count-in-particular-file/326181)

<div class="topic-metadata">

**Author:** [@smitak](https://discuss.elastic.co/u/smitak)\
**Replies:** 5\
**Last updated:** [February 27, 2023, 7:10am UTC](https://discuss.elastic.co/t/particular-word-count-in-particular-file/326181 "2023-02-27T07:10:50Z")

</div>

Hello Sir, I want count of keyword occurance in a particular file in elaticsearch .

---

## [Interactive table in kibana with aggregation](https://discuss.elastic.co/t/interactive-table-in-kibana-with-aggregation/326505)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 7:03am UTC](https://discuss.elastic.co/t/interactive-table-in-kibana-with-aggregation/326505 "2023-02-27T07:03:29Z")

</div>

Hello, I'm using Kibana 8.6.1 . For a dashboard I want to create an interactive table in Kibana that contains a timestamd and a ID. The most of the loglines starts with the timestamp and the ID, but you have the simi…

---

## [Too many tcp connection established issue](https://discuss.elastic.co/t/too-many-tcp-connection-established-issue/326545)

<div class="topic-metadata">

**Author:** [@manzoor77](https://discuss.elastic.co/u/manzoor77)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 7:01am UTC](https://discuss.elastic.co/t/too-many-tcp-connection-established-issue/326545 "2023-02-27T07:01:56Z")

</div>

Hi, I have enable elasticsearch in my production chat application. There was total 500+ users that uses this application on daily bases for communication purpose. I have initialize ELS newclient once when server start …

---

## [Is my ILM policy stuck?](https://discuss.elastic.co/t/is-my-ilm-policy-stuck/326543)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 6:36am UTC](https://discuss.elastic.co/t/is-my-ilm-policy-stuck/326543 "2023-02-27T06:36:44Z")

</div>

Hi Team , I have set my ILM policy to move from hot to frozen node when it reach 45 GB size in primary shard. Howver it is not yet moved and not showing any errors. But if I do Preformatted textGET /metricbeat-\*/\_ilm/e…

---

## [Import kibana dashboard using ansible](https://discuss.elastic.co/t/import-kibana-dashboard-using-ansible/325685)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 6:04am UTC](https://discuss.elastic.co/t/import-kibana-dashboard-using-ansible/325685 "2023-02-27T06:04:01Z")

</div>

Hi, I have exported kibana dashboard in ndjson format. now i want to import it to another instance of kibana. I am doing this using ansible playbook. This is my command curl -X POST "\*Reverse\_PROXY\_IP/kibana\*/api/saved\_…

---

## [How to list all scripts/templates when GET \_cat/templates doesn't return them](https://discuss.elastic.co/t/how-to-list-all-scripts-templates-when-get-cat-templates-doesnt-return-them/326476)

<div class="topic-metadata">

**Author:** [@Cal\_L](https://discuss.elastic.co/u/Cal_L)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 3:44am UTC](https://discuss.elastic.co/t/how-to-list-all-scripts-templates-when-get-cat-templates-doesnt-return-them/326476 "2023-02-27T03:44:16Z")

</div>

I am new to ES ... I am looking at the existing codes which my team is using es.put\_script("my\_custom\_template\_1\_id", my\_custom\_template\_1\_query) I can retrieve the the template info by using the SPECIFIC template id li…

---

## [My ela cluster failed to load metadata when running, but I can't see the other problem. If there is the same problem, please help to take a look](https://discuss.elastic.co/t/my-ela-cluster-failed-to-load-metadata-when-running-but-i-cant-see-the-other-problem-if-there-is-the-same-problem-please-help-to-take-a-look/326286)

<div class="topic-metadata">

**Author:** [@limedong1](https://discuss.elastic.co/u/limedong1)\
**Replies:** 8\
**Last updated:** [February 27, 2023, 3:17am UTC](https://discuss.elastic.co/t/my-ela-cluster-failed-to-load-metadata-when-running-but-i-cant-see-the-other-problem-if-there-is-the-same-problem-please-help-to-take-a-look/326286 "2023-02-27T03:17:01Z")

</div>

Here is the error message： {"@timestamp":"2023-02-23T08:43:40.767Z", "log.level":"ERROR", "message":"fatal exception while booting Elasticsearch", "ecs.version": "1.2.0","service.name":"ES\_ECS","event.dataset":"elastic…

---

## [Monitoring postgres y sql server on AWS with an elastic on premises](https://discuss.elastic.co/t/monitoring-postgres-y-sql-server-on-aws-with-an-elastic-on-premises/325660)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 3:00am UTC](https://discuss.elastic.co/t/monitoring-postgres-y-sql-server-on-aws-with-an-elastic-on-premises/325660 "2023-02-27T03:00:33Z")

</div>

It is posible to monitor postgres y sql server on aws? if it is, with wich tool? our elastic is on premises. thanks.

---

## [Find: 'elasticsearch-translog': No such file or directory](https://discuss.elastic.co/t/find-elasticsearch-translog-no-such-file-or-directory/326518)

<div class="topic-metadata">

**Author:** [@ACoder](https://discuss.elastic.co/u/ACoder)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 2:10am UTC](https://discuss.elastic.co/t/find-elasticsearch-translog-no-such-file-or-directory/326518 "2023-02-27T02:10:39Z")

</div>

I think my translog is corrupted, so I'm trying to solve the problem by following this tutorial: But this tool doesn't exist in the docker image for elasticsearch at all: $ find / elasticsearch-translog ... find: 'ela…

---

## [Collect everything from a host](https://discuss.elastic.co/t/collect-everything-from-a-host/326532)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 1:16am UTC](https://discuss.elastic.co/t/collect-everything-from-a-host/326532 "2023-02-27T01:16:36Z")

</div>

Hi, It seems that there is no config which will allow winlogbeat to collect everything available on a given host. event.log: \* I want to deploy winlogbeat across my environment, but hosts have differing roles and ther…

---

## [The Kibana graph label of the date can't be changed in its format](https://discuss.elastic.co/t/the-kibana-graph-label-of-the-date-cant-be-changed-in-its-format/326409)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 12:34am UTC](https://discuss.elastic.co/t/the-kibana-graph-label-of-the-date-cant-be-changed-in-its-format/326409 "2023-02-27T00:34:45Z")

</div>

I use Elastic Cloud with v.8.6.2 of ES and Kibana. I used to change the Date format like this YYYY/MM/DD HH:mm:ss of the advanced settings at v.7 for the graph's date format of Kibana. After the version of Kibana grade…

---

## [Update existing record shuffles the data](https://discuss.elastic.co/t/update-existing-record-shuffles-the-data/326400)

<div class="topic-metadata">

**Author:** [@srb.saurabhjain](https://discuss.elastic.co/u/srb.saurabhjain)\
**Replies:** 3\
**Last updated:** [February 26, 2023, 9:42pm UTC](https://discuss.elastic.co/t/update-existing-record-shuffles-the-data/326400 "2023-02-26T21:42:11Z")

</div>

Hi team, I am trying to update a field in the below data B.B1 but the result data is randomly shuffled when I fetch again. Original { "A": { "A1": "test" }, "B": { "B1": "approved" }, …

---

## [Grep-like results on elasticsearch index](https://discuss.elastic.co/t/grep-like-results-on-elasticsearch-index/326524)

<div class="topic-metadata">

**Author:** [@John10](https://discuss.elastic.co/u/John10)\
**Replies:** 1\
**Last updated:** [February 26, 2023, 7:42pm UTC](https://discuss.elastic.co/t/grep-like-results-on-elasticsearch-index/326524 "2023-02-26T19:42:45Z")

</div>

If you have 5,000 pdf documents and you want to return every instance of the word "dog" across all of those documents (including the context where it occurs -- page number, the line before and after the match, etc.), you…

---

## [Elasticsearch filter to parse all date types in the logs?](https://discuss.elastic.co/t/elasticsearch-filter-to-parse-all-date-types-in-the-logs/326520)

<div class="topic-metadata">

**Author:** [@sid2014](https://discuss.elastic.co/u/sid2014)\
**Replies:** 1\
**Last updated:** [February 26, 2023, 3:41pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-to-parse-all-date-types-in-the-logs/326520 "2023-02-26T15:41:41Z")

</div>

I have to read multiple service logs which contain different time formats to the microseconds precision. Logstash is able to parse all the timestamps from "%{TIMESTAMP\_ISO8601:timestamp} filter but I get 400 for some log…

---

## [Nodes not syncing due to: master not discovered or elected yet](https://discuss.elastic.co/t/nodes-not-syncing-due-to-master-not-discovered-or-elected-yet/326434)

<div class="topic-metadata">

**Author:** [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Replies:** 1\
**Last updated:** [February 26, 2023, 6:28am UTC](https://discuss.elastic.co/t/nodes-not-syncing-due-to-master-not-discovered-or-elected-yet/326434 "2023-02-26T06:28:02Z")

</div>

Hello, I have a 3-node cluster with two nodes holding data and one as the voting node thastorees not hold any data. All virtual nodes run on ESXi 8.0 with Ubuntu 22.04.1 & Elasticsearch 8.6.2. OS and data are on…

---

## [Searchable Snapshot/Cold Nodes much slower to recover 8.5+?](https://discuss.elastic.co/t/searchable-snapshot-cold-nodes-much-slower-to-recover-8-5/326458)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 1\
**Last updated:** [February 25, 2023, 8:58pm UTC](https://discuss.elastic.co/t/searchable-snapshot-cold-nodes-much-slower-to-recover-8-5/326458 "2023-02-25T20:58:28Z")

</div>

Hi All, I was wondering if anyone else has noticed that since upgrading to 8.5.x (and 8.6.x), that the recovery of Searchable Snapshot/Cold nodes from a rolling restart is much slower than in lower versions? A cold nod…

---

## [Revert or cancel hardware profile change?](https://discuss.elastic.co/t/revert-or-cancel-hardware-profile-change/326460)

<div class="topic-metadata">

**Author:** [@GregoryJC](https://discuss.elastic.co/u/GregoryJC)\
**Replies:** 1\
**Last updated:** [February 25, 2023, 8:57pm UTC](https://discuss.elastic.co/t/revert-or-cancel-hardware-profile-change/326460 "2023-02-25T20:57:15Z")

</div>

When applying a hardware profile change to a cluster in elastic cloud is it possible to cancel or revert the process?

---

## [Should I be copying the \`/etc/elasticsearch/service\_tokens\` to several elastic nodes?](https://discuss.elastic.co/t/should-i-be-copying-the-etc-elasticsearch-service-tokens-to-several-elastic-nodes/326185)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [February 25, 2023, 8:37pm UTC](https://discuss.elastic.co/t/should-i-be-copying-the-etc-elasticsearch-service-tokens-to-several-elastic-nodes/326185 "2023-02-25T20:37:15Z")

</div>

I have an elastic cluster with three nodes: n1, n2 and n3. And I have a new kibana instance on a separate linux server. On n1, I ran this command /usr/share/elasticsearch/bin/elasticsearch-service-token elastic/kibana …

---

## [Logstash not shipping data to Elasticsearch](https://discuss.elastic.co/t/logstash-not-shipping-data-to-elasticsearch/326376)

<div class="topic-metadata">

**Author:** [@Technolust](https://discuss.elastic.co/u/Technolust)\
**Replies:** 2\
**Last updated:** [February 25, 2023, 7:50pm UTC](https://discuss.elastic.co/t/logstash-not-shipping-data-to-elasticsearch/326376 "2023-02-25T19:50:43Z")

</div>

How do I get logstash to ship data to Elasticsearch? I'm not sure what to change in the logstash.yml file or what section I should change for that matter. My pipelines.yml points to /etc/logstash/conf.d/syslog.conf... Th…

[Previous page](https://discuss.elastic.co/latest.md?page=766)

[Next page](https://discuss.elastic.co/latest.md?page=768)
