# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=257

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 258

---

## [Support for CloudWatch Metric Streams](https://discuss.elastic.co/t/support-for-cloudwatch-metric-streams/349399)

<div class="topic-metadata">

**Author:** [@RichiCoder](https://discuss.elastic.co/u/RichiCoder)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 11:24pm UTC](https://discuss.elastic.co/t/support-for-cloudwatch-metric-streams/349399 "2023-12-14T23:24:35Z")

</div>

Elastic recently added the ability to receive CloudWatch logs via Kinesis Data Firehouse, which offers and excellent (and cheaper) way to forward log data into Elastic. I'd love to see a similar capability like that for…

---

## [Behaviour of match\_phrase\_prefix in ES ES 8.9.0 is different from that in 7.17.7](https://discuss.elastic.co/t/behaviour-of-match-phrase-prefix-in-es-es-8-9-0-is-different-from-that-in-7-17-7/348283)

<div class="topic-metadata">

**Author:** [@elastic-a](https://discuss.elastic.co/u/elastic-a)\
**Replies:** 1\
**Last updated:** [December 14, 2023, 10:06pm UTC](https://discuss.elastic.co/t/behaviour-of-match-phrase-prefix-in-es-es-8-9-0-is-different-from-that-in-7-17-7/348283 "2023-12-14T22:06:45Z")

</div>

ES 8.9.0 With a query having match\_phrase\_prefix of just one term, the search returns expected match; with the same query, percolate by id does not return expected match. The same (both search and percolate) work as ex…

---

## [Please point me to a good article on how to "Optimally size Elasticsearch Thread Pools"](https://discuss.elastic.co/t/please-point-me-to-a-good-article-on-how-to-optimally-size-elasticsearch-thread-pools/349397)

<div class="topic-metadata">

**Author:** [@andrew3](https://discuss.elastic.co/u/andrew3)\
**Replies:** 2\
**Last updated:** [December 14, 2023, 9:38pm UTC](https://discuss.elastic.co/t/please-point-me-to-a-good-article-on-how-to-optimally-size-elasticsearch-thread-pools/349397 "2023-12-14T21:38:33Z")

</div>

We're pushing a lot of data in the form of bulk indexing requests and saturating the available thread pools. Can you point me to a good article on optimally sizing ES thread pools? Thanks.

---

## [Logstash runs on the linux container and extremely slow](https://discuss.elastic.co/t/logstash-runs-on-the-linux-container-and-extremely-slow/349249)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 3\
**Last updated:** [December 14, 2023, 6:22pm UTC](https://discuss.elastic.co/t/logstash-runs-on-the-linux-container-and-extremely-slow/349249 "2023-12-14T18:22:56Z")

</div>

logstash runs on linux container. Below is my configuration. It is very slow. Sharing my configuration for reference. This is my service configuration. file { path =\> "/common/logs/\*\*/\*.log" start\_posit…

---

## [Help for configuring index and query for autocomplete full\_text\_search on addresses](https://discuss.elastic.co/t/help-for-configuring-index-and-query-for-autocomplete-full-text-search-on-addresses/349386)

<div class="topic-metadata">

**Author:** [@Queepyl](https://discuss.elastic.co/u/Queepyl)\
**Replies:** 1\
**Last updated:** [December 14, 2023, 4:30pm UTC](https://discuss.elastic.co/t/help-for-configuring-index-and-query-for-autocomplete-full-text-search-on-addresses/349386 "2023-12-14T16:30:15Z")

</div>

Hello, I am creating an index to search existing addresses. Unfortunately I don't have some good results at all and I would like to ask for advices on how to improove these results. So the aim is to let a user enter i…

---

## [ElasticSearch in WordPress headless setup](https://discuss.elastic.co/t/elasticsearch-in-wordpress-headless-setup/349237)

<div class="topic-metadata">

**Author:** [@andreasdiehl](https://discuss.elastic.co/u/andreasdiehl)\
**Replies:** 2\
**Last updated:** [December 14, 2023, 3:34pm UTC](https://discuss.elastic.co/t/elasticsearch-in-wordpress-headless-setup/349237 "2023-12-14T15:34:24Z")

</div>

We are setting up a headless frontend (Nuxt, Vue) for our WordPress site. We pull data via GraphQL. Now we explore if / hot to make use of Elasticsearch. Any experiences / recommendations how to do the setup? So far we…

---

## [Correct way of mapping some structure to Elasticsearch document](https://discuss.elastic.co/t/correct-way-of-mapping-some-structure-to-elasticsearch-document/349379)

<div class="topic-metadata">

**Author:** [@Vadym\_Romanenko](https://discuss.elastic.co/u/Vadym_Romanenko)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 2:54pm UTC](https://discuss.elastic.co/t/correct-way-of-mapping-some-structure-to-elasticsearch-document/349379 "2023-12-14T14:54:18Z")

</div>

Good day, community! At this moment we're posting some items from our solution to the ES index. Everything works fine. But we want to enlarge our decision. Our project gives ability to categorize items. We want to have …

---

## ["Multiple mapping types and custom mapping types in index templates" issue when upgrading to v8](https://discuss.elastic.co/t/multiple-mapping-types-and-custom-mapping-types-in-index-templates-issue-when-upgrading-to-v8/349185)

<div class="topic-metadata">

**Author:** [@preetish\_P](https://discuss.elastic.co/u/preetish_P)\
**Replies:** 1\
**Last updated:** [December 14, 2023, 2:46pm UTC](https://discuss.elastic.co/t/multiple-mapping-types-and-custom-mapping-types-in-index-templates-issue-when-upgrading-to-v8/349185 "2023-12-14T14:46:36Z")

</div>

Hi folks, We are in the process of upgrading ELK stack from version 7.17.2 to 8.9.2. When going through the list of Elasticsearch deprecation issues I spotted the below in Prod: (not seen in non-prod) Multiple mapping …

---

## [Access Elasticsearch Data as a Remote Oracle Database](https://discuss.elastic.co/t/access-elasticsearch-data-as-a-remote-oracle-database/349350)

<div class="topic-metadata">

**Author:** [@onr1onr1](https://discuss.elastic.co/u/onr1onr1)\
**Replies:** 11\
**Last updated:** [December 14, 2023, 2:38pm UTC](https://discuss.elastic.co/t/access-elasticsearch-data-as-a-remote-oracle-database/349350 "2023-12-14T14:38:03Z")

</div>

We want to set up a dblink from the Oracle database to eleastic search and pull information, but we get the following error in the dblink. We could not find a source on this site, so we did it by following the steps in …

---

## [Not able to read the data from external json file in logstash config](https://discuss.elastic.co/t/not-able-to-read-the-data-from-external-json-file-in-logstash-config/349257)

<div class="topic-metadata">

**Author:** [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Replies:** 10\
**Last updated:** [December 14, 2023, 1:26pm UTC](https://discuss.elastic.co/t/not-able-to-read-the-data-from-external-json-file-in-logstash-config/349257 "2023-12-14T13:26:32Z")

</div>

I'm trying to search the host value from current event and looking for same value in json file. If Json block has the host value I'm just converting the block into struct value and inserting as a new column in index. ou…

---

## [Advanced Watcher to send alert of condition has been met for more than 1 hour](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247)

<div class="topic-metadata">

**Author:** [@ChrisKelly](https://discuss.elastic.co/u/ChrisKelly)\
**Replies:** 9\
**Last updated:** [December 14, 2023, 1:08pm UTC](https://discuss.elastic.co/t/advanced-watcher-to-send-alert-of-condition-has-been-met-for-more-than-1-hour/349247 "2023-12-14T13:08:02Z")

</div>

I want to create an advanced Watcher that will only send an alert email out if my conditions have been met more over an hour. Essentially, I am monitoring specific servers and watching if their CPU exceeds 50%. If it go…

---

## [Is there any recommended ratio between the number of master, data, coordinator and ingestion nodes?](https://discuss.elastic.co/t/is-there-any-recommended-ratio-between-the-number-of-master-data-coordinator-and-ingestion-nodes/349270)

<div class="topic-metadata">

**Author:** [@calin](https://discuss.elastic.co/u/calin)\
**Replies:** 13\
**Last updated:** [December 14, 2023, 1:05pm UTC](https://discuss.elastic.co/t/is-there-any-recommended-ratio-between-the-number-of-master-data-coordinator-and-ingestion-nodes/349270 "2023-12-14T13:05:23Z")

</div>

Currently working with equal number of master, data and coordinator nodes (10). Need to add some ingestion nodes. They all have 2 CPU/node, master and coordinator have 4 GB each, data has 16 GB. I haven't done the sizi…

---

## [Elasticsearch Upgrade issue](https://discuss.elastic.co/t/elasticsearch-upgrade-issue/349159)

<div class="topic-metadata">

**Author:** [@Ifteakhar\_ali](https://discuss.elastic.co/u/Ifteakhar_ali)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 2:23pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-issue/349159 "2023-12-12T14:23:43Z")

</div>

Hello Team, I am facing issue while upgrading elasticsearch from elasticsearch-6.8.11-1.noarch to elasticsearch-7.10.2-aarch64.rpm. Kindly advise Current ES Version : elasticsearch-6.8.11-1.noarch Current OS Version :…

---

## [Failed to reload inputs: 1 error: Error creating runner from config: log\_group\_arn, log\_group\_name and log\_group\_name\_prefix config parametercannot all be empty accessing config](https://discuss.elastic.co/t/failed-to-reload-inputs-1-error-error-creating-runner-from-config-log-group-arn-log-group-name-and-log-group-name-prefix-config-parametercannot-all-be-empty-accessing-config/349353)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 11:14am UTC](https://discuss.elastic.co/t/failed-to-reload-inputs-1-error-error-creating-runner-from-config-log-group-arn-log-group-name-and-log-group-name-prefix-config-parametercannot-all-be-empty-accessing-config/349353 "2023-12-14T11:14:21Z")

</div>

Hi Team, I was trying to integrate AWS cloudwatch and collect logs from specific log groups. I have configured below options Role ARN Default AWS Region Log Group ARN Log Group Name But I am facing below …

---

## [Filebeat & index patterns mapping issue](https://discuss.elastic.co/t/filebeat-index-patterns-mapping-issue/348162)

<div class="topic-metadata">

**Author:** [@Satsan](https://discuss.elastic.co/u/Satsan)\
**Replies:** 2\
**Last updated:** [December 14, 2023, 11:02am UTC](https://discuss.elastic.co/t/filebeat-index-patterns-mapping-issue/348162 "2023-12-14T11:02:17Z")

</div>

The data I recently entered in the Filebeat YAML file is not appearing in the index patterns. However, the old data is still visible, and I can successfully map it in the index patterns. Filebeat on win machine. Filebe…

---

## [How to combine 2 indexes in 1 graph](https://discuss.elastic.co/t/how-to-combine-2-indexes-in-1-graph/349335)

<div class="topic-metadata">

**Author:** [@remco\_zwaan](https://discuss.elastic.co/u/remco_zwaan)\
**Replies:** 3\
**Last updated:** [December 14, 2023, 10:22am UTC](https://discuss.elastic.co/t/how-to-combine-2-indexes-in-1-graph/349335 "2023-12-14T10:22:55Z")

</div>

0 We have 2 indexes called lodging\_index and price\_index. The relation is lodgings has many prices. In the price\_index there is a field called lodging\_id. We use this indexes in our api for frontend purpose. First call …

---

## [Create custom plugin to route](https://discuss.elastic.co/t/create-custom-plugin-to-route/349342)

<div class="topic-metadata">

**Author:** [@tung\_duong](https://discuss.elastic.co/u/tung_duong)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 9:33am UTC](https://discuss.elastic.co/t/create-custom-plugin-to-route/349342 "2023-12-14T09:33:14Z")

</div>

\-1 I am new to Elasticsearch. I currently need to design a plugin with the task of navigating my use of Elasticsearch. Specifically: I already have semantic search models, which can be used as an API, with output be…

---

## [Composite aggregation pagination](https://discuss.elastic.co/t/composite-aggregation-pagination/349340)

<div class="topic-metadata">

**Author:** [@Thishon](https://discuss.elastic.co/u/Thishon)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 9:28am UTC](https://discuss.elastic.co/t/composite-aggregation-pagination/349340 "2023-12-14T09:28:36Z")

</div>

I am using Elasticsearch and i want to show results by pagination so i choosed composite method. but i couldnt sort the result by outer source buckets.

---

## [Continuous transformation is not update](https://discuss.elastic.co/t/continuous-transformation-is-not-update/349212)

<div class="topic-metadata">

**Author:** [@Zosmex](https://discuss.elastic.co/u/Zosmex)\
**Replies:** 3\
**Last updated:** [December 14, 2023, 8:34am UTC](https://discuss.elastic.co/t/continuous-transformation-is-not-update/349212 "2023-12-14T08:34:29Z")

</div>

I created a pivot continuous transformation to automatically count the data in each location. Each document has an 'updated\_at' field which is a timestamp in epoch second format when each document was last modified. Aft…

---

## [Dec 14th, 2023: \[EN\] A Peak Inside Santa's Planning Meeting - Using ES|QL for Data Enrichment](https://discuss.elastic.co/t/dec-14th-2023-en-a-peak-inside-santas-planning-meeting-using-es-ql-for-data-enrichment/348131)

<div class="topic-metadata">

**Author:** [@Alexis\_Roberson](https://discuss.elastic.co/u/Alexis_Roberson)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-14th-2023-en-a-peak-inside-santas-planning-meeting-using-es-ql-for-data-enrichment/348131 "2023-12-14T08:00:53Z")

</div>

Often, we hear of Santa’s list, but what if the Elves had a list as well? With a little imagination, we could assume Santa’s list contains the names of children and whether they were naughty or nice and the Elves list…

---

## [Tenable Vulnerability Integration not producing Data Stream](https://discuss.elastic.co/t/tenable-vulnerability-integration-not-producing-data-stream/349332)

<div class="topic-metadata">

**Author:** [@longansoju](https://discuss.elastic.co/u/longansoju)\
**Replies:** 1\
**Last updated:** [December 14, 2023, 7:54am UTC](https://discuss.elastic.co/t/tenable-vulnerability-integration-not-producing-data-stream/349332 "2023-12-14T07:54:38Z")

</div>

I have a elastic fleet cluster set up and I've configured one of my agents to use the Tenable Vulnerability Management Integration. However, under Fleet \> Data Streams, there is no Tenable Data Stream being generated. M…

---

## [After upgrading macos to 14.x, the ElasticEndpoint authorization is automatically closed by the FDA](https://discuss.elastic.co/t/after-upgrading-macos-to-14-x-the-elasticendpoint-authorization-is-automatically-closed-by-the-fda/349328)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 7:14am UTC](https://discuss.elastic.co/t/after-upgrading-macos-to-14-x-the-elasticendpoint-authorization-is-automatically-closed-by-the-fda/349328 "2023-12-14T07:14:32Z")

</div>

After installing elastic agent version 8.4.1 and 8.9.1, I have clicked and checked in FDA to authorize ElasticEndpoint. However, after running on the computer for a period of time, the macos version is upgraded to 14.0, …

---

## [The Persistent Volume Claim (PVC) persists even after scaling in the Logstash deployment](https://discuss.elastic.co/t/the-persistent-volume-claim-pvc-persists-even-after-scaling-in-the-logstash-deployment/349323)

<div class="topic-metadata">

**Author:** [@Vignesh\_M](https://discuss.elastic.co/u/Vignesh_M)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 5:57am UTC](https://discuss.elastic.co/t/the-persistent-volume-claim-pvc-persists-even-after-scaling-in-the-logstash-deployment/349323 "2023-12-14T05:57:32Z")

</div>

Hi All, We are using the elastic/logstash Helm chart to deploy Logstash (StatefulSet) with persistent volume enabled in one of our Kubernetes clusters. While attempting to downscale the Logstash pod count, we observed t…

---

## [Cloudwatch input plugin configuration details for fetching AWS/ECS metrics](https://discuss.elastic.co/t/cloudwatch-input-plugin-configuration-details-for-fetching-aws-ecs-metrics/349321)

<div class="topic-metadata">

**Author:** [@mittal\_rawal1](https://discuss.elastic.co/u/mittal_rawal1)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 5:39am UTC](https://discuss.elastic.co/t/cloudwatch-input-plugin-configuration-details-for-fetching-aws-ecs-metrics/349321 "2023-12-14T05:39:30Z")

</div>

input { cloudwatch { namespace =\> "AWS/ECS" period =\> 6000 interval =\> 6000000 metrics =\> \["Average", "Minimum", "Maximum", "Sum", "Sample Count","CPUUtilization"\] filters =\> { "ClusterName" =\> "microservices" "S…

---

## [Unable to login using elastic](https://discuss.elastic.co/t/unable-to-login-using-elastic/349304)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 3\
**Last updated:** [December 14, 2023, 5:17am UTC](https://discuss.elastic.co/t/unable-to-login-using-elastic/349304 "2023-12-14T05:17:40Z")

</div>

Hi, I have upgraded elastic 6.8 to 7.17. and i have taken the .security-6 file backup as .security-6-reindexed. but. while performing upgrade to 8.x.x version. nodes are showing the following error java.lang.IllegalS…

---

## [Error connecting to package registry](https://discuss.elastic.co/t/error-connecting-to-package-registry/349299)

<div class="topic-metadata">

**Author:** [@A\_Niu](https://discuss.elastic.co/u/A_Niu)\
**Replies:** 2\
**Last updated:** [December 14, 2023, 1:17am UTC](https://discuss.elastic.co/t/error-connecting-to-package-registry/349299 "2023-12-14T01:17:04Z")

</div>

My Kibana is running behind corporate proxy, with curl, epr.elastic.co is reachable, but with Kibana service, I got below error, and added signer certificates into /etc/default/kibana NODE\_EXTRA\_CA\_CERTS="/etc/kibana/ce…

---

## [Files too big for Sentinel plugin](https://discuss.elastic.co/t/files-too-big-for-sentinel-plugin/348530)

<div class="topic-metadata">

**Author:** [@Joseph\_Leiber](https://discuss.elastic.co/u/Joseph_Leiber)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 11:41pm UTC](https://discuss.elastic.co/t/files-too-big-for-sentinel-plugin/348530 "2023-12-13T23:41:01Z")

</div>

Hi Logstash Experts - This is my first time dealing with Logstash, so I'm not quite sure why the logs are being formatted like this, whether this is expected/normal, or how to handle them. I'm hitting an issue with log…

---

## [How to know the Acknowledge of message on logstash](https://discuss.elastic.co/t/how-to-know-the-acknowledge-of-message-on-logstash/349225)

<div class="topic-metadata">

**Author:** [@pradeep.kumar](https://discuss.elastic.co/u/pradeep.kumar)\
**Replies:** 2\
**Last updated:** [December 13, 2023, 8:06pm UTC](https://discuss.elastic.co/t/how-to-know-the-acknowledge-of-message-on-logstash/349225 "2023-12-13T20:06:50Z")

</div>

Hi Team, we want to know whether the messages in the queue are acknowledged or not. We use a persistent queue on the logstash. Please let us know is there any way to get the status of it.

---

## [Elasticsearch server crashing with new version release](https://discuss.elastic.co/t/elasticsearch-server-crashing-with-new-version-release/349274)

<div class="topic-metadata">

**Author:** [@R7ST](https://discuss.elastic.co/u/R7ST)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 6:22pm UTC](https://discuss.elastic.co/t/elasticsearch-server-crashing-with-new-version-release/349274 "2023-12-13T18:22:49Z")

</div>

I have two ubuntu 22.04 servers with elasticsearch (two separate installations) and this is the second time both servers goes down at the same time. The same error message appears in both logs (below) The error occurs …

---

## [Logstash regex expression in conf xpath](https://discuss.elastic.co/t/logstash-regex-expression-in-conf-xpath/349252)

<div class="topic-metadata">

**Author:** [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Replies:** 2\
**Last updated:** [December 13, 2023, 5:48pm UTC](https://discuss.elastic.co/t/logstash-regex-expression-in-conf-xpath/349252 "2023-12-13T17:48:31Z")

</div>

Dears, Can we use regex expression in logstash configuration in case of filter and xpath? There is right now such to conditions: ... filter { if "xmlapps" in \[tags\] { xml { source =\> "message" store\_xml =\> …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=256)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=258)
