# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=268

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 269

---

## [Cluster currently has \[1000\]/\[1000\] maximum normal shards open](https://discuss.elastic.co/t/cluster-currently-has-1000-1000-maximum-normal-shards-open/347719)

<div class="topic-metadata">

**Author:** [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Replies:** 4\
**Last updated:** [November 23, 2023, 1:32pm UTC](https://discuss.elastic.co/t/cluster-currently-has-1000-1000-maximum-normal-shards-open/347719 "2023-11-23T13:32:03Z")

</div>

Hi, From the title, this is an error I usually encounter with my Elastic Proof Of Concept. The workaround is easy, I simply close and delete some indices from time to time... But now I'm currently deploying Elastic in…

---

## [Syncing Huge DataSet From MySQL to Elasticsearch](https://discuss.elastic.co/t/syncing-huge-dataset-from-mysql-to-elasticsearch/347853)

<div class="topic-metadata">

**Author:** [@Aswini\_Kumar\_Rout](https://discuss.elastic.co/u/Aswini_Kumar_Rout)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 1:04pm UTC](https://discuss.elastic.co/t/syncing-huge-dataset-from-mysql-to-elasticsearch/347853 "2023-11-23T13:04:53Z")

</div>

Hi Team, We have one requirement to use Elasticsearch in our legacy application which has MySQL datbase and the size of the DB is around 300 GB and with 200 or more tables. So, here I am bit confused that - which would…

---

## [Editing a managed policy can break Kibana](https://discuss.elastic.co/t/editing-a-managed-policy-can-break-kibana/347828)

<div class="topic-metadata">

**Author:** [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Replies:** 2\
**Last updated:** [November 23, 2023, 1:19pm UTC](https://discuss.elastic.co/t/editing-a-managed-policy-can-break-kibana/347828 "2023-11-23T13:19:57Z")

</div>

Hi, After a successful Fleet Server and Elastic Agent deployment, I wanted to tweak the ILM called "logs" and "metrics" which are both "Managed". But when trying to do so, I encounter this well known warning : So af…

---

## [Search template based on list](https://discuss.elastic.co/t/search-template-based-on-list/347852)

<div class="topic-metadata">

**Author:** [@pszemesy](https://discuss.elastic.co/u/pszemesy)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 12:37pm UTC](https://discuss.elastic.co/t/search-template-based-on-list/347852 "2023-11-23T12:37:30Z")

</div>

Hi All, I have an index (contains translations) with the following mappings: document\_name: keyword, ... EN: { content: text, stored\_by: keyword, stored\_at: date, ... } \<\<lang code\>\>: { content: text, store…

---

## [Rollup then backup indices](https://discuss.elastic.co/t/rollup-then-backup-indices/346036)

<div class="topic-metadata">

**Author:** [@lstoneir](https://discuss.elastic.co/u/lstoneir)\
**Replies:** 1\
**Last updated:** [November 23, 2023, 12:09pm UTC](https://discuss.elastic.co/t/rollup-then-backup-indices/346036 "2023-11-23T12:09:57Z")

</div>

Hi there, I have a elastic cluster with 5 nodes (each node 1TB) I want to backup my indices, but I dont have enough resources to backup all indices. I want to rollup indices for example my main indices are hourly, I w…

---

## [Sync 2 indices diffrenet remote clusters](https://discuss.elastic.co/t/sync-2-indices-diffrenet-remote-clusters/347851)

<div class="topic-metadata">

**Author:** [@lstoneir](https://discuss.elastic.co/u/lstoneir)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 11:58am UTC](https://discuss.elastic.co/t/sync-2-indices-diffrenet-remote-clusters/347851 "2023-11-23T11:58:50Z")

</div>

Hi I have cluser A with index e.g. User\_info I have another cluster named B I want to sync User\_info (B) with User\_info (A) all time!! Can i do this with logstash? how?

---

## [Elasticsearch.yml configuration file is missing in linux](https://discuss.elastic.co/t/elasticsearch-yml-configuration-file-is-missing-in-linux/347839)

<div class="topic-metadata">

**Author:** [@krishnapro](https://discuss.elastic.co/u/krishnapro)\
**Replies:** 1\
**Last updated:** [November 23, 2023, 11:48am UTC](https://discuss.elastic.co/t/elasticsearch-yml-configuration-file-is-missing-in-linux/347839 "2023-11-23T11:48:47Z")

</div>

I have installed elasticsearch in linux mint but elasticsearch.yml file is missing. I have uninstall and reinstall it but same problem. I don't know what do please help me to fix it.

---

## [CSV::MalformedCSVError: Missing or stray quote in line 1](https://discuss.elastic.co/t/csv-missing-or-stray-quote-in-line-1/346726)

<div class="topic-metadata">

**Author:** [@parosio](https://discuss.elastic.co/u/parosio)\
**Replies:** 1\
**Last updated:** [November 23, 2023, 11:05am UTC](https://discuss.elastic.co/t/csv-missing-or-stray-quote-in-line-1/346726 "2023-11-23T11:05:25Z")

</div>

Hello, I've read the previuos posts on this topic (and related), but still have problems with csv files containing windows command lines... For example: 98792634295,https://falcon.eu-1.crowdstrike.com/activity/detecti…

---

## [Getting Timeout after sometime](https://discuss.elastic.co/t/getting-timeout-after-sometime/347494)

<div class="topic-metadata">

**Author:** [@deepak\_Bahuguna](https://discuss.elastic.co/u/deepak_Bahuguna)\
**Replies:** 4\
**Last updated:** [November 23, 2023, 10:55am UTC](https://discuss.elastic.co/t/getting-timeout-after-sometime/347494 "2023-11-23T10:55:53Z")

</div>

HI Guys, I am new to Elastic, Kibana. I have downloaded the Elastic and Kibana then I run both and it worked fine. What is problem is after installing I have kept it opened in evening and when I see it morning it has sh…

---

## [How to get a NodeClient inside a plugin?](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-plugin/347703)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 5\
**Last updated:** [November 23, 2023, 10:13am UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-plugin/347703 "2023-11-23T10:13:36Z")

</div>

I am currently working on developing a schedule plugin for Elasticsearch. The objective is to display only the index number every 5 minutes. However, I am encountering an issue where the NodeClient is consistently null. …

---

## [Multy-tenany elasticsearch](https://discuss.elastic.co/t/multy-tenany-elasticsearch/347832)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 10:05am UTC](https://discuss.elastic.co/t/multy-tenany-elasticsearch/347832 "2023-11-23T10:05:24Z")

</div>

I am currently working on implementing multi-tenancy in Elasticsearch and have come across two prominent approaches: using a shared index across multiple tenants and having a dedicated index per tenant. As part of my res…

---

## [\["org.elasticsearch.bootstrap.StartupException: ElasticsearchException\[failed to bind service\]; nested: CorruptIndexException\[codec footer mismatch (file truncated?)](https://discuss.elastic.co/t/org-elasticsearch-bootstrap-startupexception-elasticsearchexception-failed-to-bind-service-nested-corruptindexexception-codec-footer-mismatch-file-truncated/347642)

<div class="topic-metadata">

**Author:** [@lins](https://discuss.elastic.co/u/lins)\
**Replies:** 11\
**Last updated:** [November 23, 2023, 8:23am UTC](https://discuss.elastic.co/t/org-elasticsearch-bootstrap-startupexception-elasticsearchexception-failed-to-bind-service-nested-corruptindexexception-codec-footer-mismatch-file-truncated/347642 "2023-11-23T08:23:18Z")

</div>

{"type": "server", "timestamp": "2023-11-21T09:52:52,412Z", "level": "ERROR", "component": "o.e.b.ElasticsearchUncaughtExceptionHandler", "cluster.name": "elasticsearch", "node.name": "elasticsearch-es-master-1", "messag…

---

## [Snowflake to Elasticsearch](https://discuss.elastic.co/t/snowflake-to-elasticsearch/347543)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 8\
**Last updated:** [November 23, 2023, 8:14am UTC](https://discuss.elastic.co/t/snowflake-to-elasticsearch/347543 "2023-11-23T08:14:57Z")

</div>

Hi Team , We are trying to pull data from Snowflake database to Elasticsaerch via Logstash JDBC plugin Input Config: input { jdbc { jdbc\_driver\_library =\> "/usr/share/logstash/logstash-core/lib/jars/snowflake-jd…

---

## [SSL Certificate issues](https://discuss.elastic.co/t/ssl-certificate-issues/347390)

<div class="topic-metadata">

**Author:** [@nvanalphen](https://discuss.elastic.co/u/nvanalphen)\
**Replies:** 12\
**Last updated:** [November 23, 2023, 8:14am UTC](https://discuss.elastic.co/t/ssl-certificate-issues/347390 "2023-11-23T08:14:56Z")

</div>

I am trying to set up a server to evaluate and determine if/how we can use this solution. Unfortunately I am going mad trying to set it up. I have been trying, searching, reading and trying again for over a week now and…

---

## [How to debug http.max\_content\_length on elasticsearch](https://discuss.elastic.co/t/how-to-debug-http-max-content-length-on-elasticsearch/347754)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 3:03pm UTC](https://discuss.elastic.co/t/how-to-debug-http-max-content-length-on-elasticsearch/347754 "2023-11-22T15:03:21Z")

</div>

Hi Is it possible to trace a log on elasticsearch for http.max\_content\_length ? Thx!

---

## [Ingest Microsoft Intune Audit Logs to Elastic](https://discuss.elastic.co/t/ingest-microsoft-intune-audit-logs-to-elastic/346633)

<div class="topic-metadata">

**Author:** [@momher](https://discuss.elastic.co/u/momher)\
**Replies:** 2\
**Last updated:** [November 23, 2023, 6:14am UTC](https://discuss.elastic.co/t/ingest-microsoft-intune-audit-logs-to-elastic/346633 "2023-11-23T06:14:32Z")

</div>

Do any one have done ingesting their Microsoft Intune Audit Logs to elastic for alerting purposes? For example, if there's a specific Audit Logs on Intune it gets ingested to Elastic to create an alert ticket.

---

## [Send output socket tcp or udp in line protocol format](https://discuss.elastic.co/t/send-output-socket-tcp-or-udp-in-line-protocol-format/347810)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 4:37am UTC](https://discuss.elastic.co/t/send-output-socket-tcp-or-udp-in-line-protocol-format/347810 "2023-11-23T04:37:15Z")

</div>

Hi need to send data with tcp or udp in line protocol format instead on influx or http output plugin. Is it possible to create message format like http output plugin? Any idea? Thank

---

## [Logstash to influxdb2 aggregate datapoints issue](https://discuss.elastic.co/t/logstash-to-influxdb2-aggregate-datapoints-issue/347809)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 4:14am UTC](https://discuss.elastic.co/t/logstash-to-influxdb2-aggregate-datapoints-issue/347809 "2023-11-23T04:14:32Z")

</div>

Hi I have lots of log lines like this in exact same time, when i try to use logstash to pars and send to influxdb2, influx or ligstash aggregates some lines! e.g here is the sample lines that aggregate is I\[847676\] 20…

---

## [Reason: Setting "monitoring.enabled" doesn't exist](https://discuss.elastic.co/t/reason-setting-monitoring-enabled-doesnt-exist/347731)

<div class="topic-metadata">

**Author:** [@Vivi\_Allen](https://discuss.elastic.co/u/Vivi_Allen)\
**Replies:** 4\
**Last updated:** [November 23, 2023, 3:48am UTC](https://discuss.elastic.co/t/reason-setting-monitoring-enabled-doesnt-exist/347731 "2023-11-23T03:48:33Z")

</div>

I want to enable monitor for logstash with metricbeat. Following this guide Collect Logstash monitoring data with Metricbeat | Logstash Reference \[8.11\] | Elastic, I add monitoring.enabled: false to the logstash.yml. T…

---

## [ElasticsearchTemplate/client 8.7.1 with springboot 3.x Aggregation](https://discuss.elastic.co/t/elasticsearchtemplate-client-8-7-1-with-springboot-3-x-aggregation/347740)

<div class="topic-metadata">

**Author:** [@Priyank07](https://discuss.elastic.co/u/Priyank07)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 1:33pm UTC](https://discuss.elastic.co/t/elasticsearchtemplate-client-8-7-1-with-springboot-3-x-aggregation/347740 "2023-11-22T13:33:02Z")

</div>

Hi, I want to query elasticsearch document with aggregation. My use case : I want to sum the amount based on term aggregation on a particular field. I am able to do it with elasticsearch 7.17.3. Now I have to update i…

---

## [Logstash / problem with windows index](https://discuss.elastic.co/t/logstash-problem-with-windows-index/347545)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 4\
**Last updated:** [November 23, 2023, 3:35am UTC](https://discuss.elastic.co/t/logstash-problem-with-windows-index/347545 "2023-11-23T03:35:21Z")

</div>

Hello, could you please help me? Im using Elastic version 8.11.1 Im trying to create new 2 indexes for windows and linux. This code below is working for linux (it is automaticaly creating indexes every day), but it i…

---

## [Can I convert epoch time via data views to be readable?](https://discuss.elastic.co/t/can-i-convert-epoch-time-via-data-views-to-be-readable/347677)

<div class="topic-metadata">

**Author:** [@geeboy1](https://discuss.elastic.co/u/geeboy1)\
**Replies:** 6\
**Last updated:** [November 23, 2023, 3:15am UTC](https://discuss.elastic.co/t/can-i-convert-epoch-time-via-data-views-to-be-readable/347677 "2023-11-23T03:15:45Z")

</div>

good day, my app log is in epoch time format (sample: 1700529701700), can I convert this using script in data views to be human readable format in discover menu? or any suggestion how to convert this? i saw this in goo…

---

## [AKAMAI SIEM Integration not working](https://discuss.elastic.co/t/akamai-siem-integration-not-working/347173)

<div class="topic-metadata">

**Author:** [@jvgarita](https://discuss.elastic.co/u/jvgarita)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 11:18pm UTC](https://discuss.elastic.co/t/akamai-siem-integration-not-working/347173 "2023-11-14T23:18:20Z")

</div>

Hi all, I have deployed an ELK server using version 8.11.0 ad used the option for AKAMAI SIEM integration but the visualization pane is giving me an error "Could not locate field: akamai.siem.rules.ruleTags" and is not s…

---

## [Importing Index Patterns](https://discuss.elastic.co/t/importing-index-patterns/347275)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 10:28pm UTC](https://discuss.elastic.co/t/importing-index-patterns/347275 "2023-11-22T22:28:04Z")

</div>

Hello there, I have read it is possible to export index patterns from one elasticsearch cluster to another. Will this include all the fields and scripted fields and is this a viable way of insuring the mapping is the s…

---

## [How to parse a stringify sale on the label?](https://discuss.elastic.co/t/how-to-parse-a-stringify-sale-on-the-label/347794)

<div class="topic-metadata">

**Author:** [@thiagobr](https://discuss.elastic.co/u/thiagobr)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 10:25pm UTC](https://discuss.elastic.co/t/how-to-parse-a-stringify-sale-on-the-label/347794 "2023-11-22T22:25:52Z")

</div>

I'm using the library "@elastic/apm-rum-angular": "^2.1.7" for Angular 11, I'm already receiving the data through transaction + span + addLabels. However, the addLabel parameter only accepts string, boolean or number, a…

---

## [ALB health check failure while checking Elasticsearch cluster health](https://discuss.elastic.co/t/alb-health-check-failure-while-checking-elasticsearch-cluster-health/347018)

<div class="topic-metadata">

**Author:** [@siddharthavempa](https://discuss.elastic.co/u/siddharthavempa)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 1:33pm UTC](https://discuss.elastic.co/t/alb-health-check-failure-while-checking-elasticsearch-cluster-health/347018 "2023-11-13T13:33:35Z")

</div>

Hi Team, I am creating a two node Elasticsearch cluster in AWS using EC2 instances. I installed Elasticsearch in node-1 using rpm. Then I used the below commands to modify the elasticsearch.yaml file and started elasti…

---

## [Upgrading system indices to version 8](https://discuss.elastic.co/t/upgrading-system-indices-to-version-8/347364)

<div class="topic-metadata">

**Author:** [@bermanb](https://discuss.elastic.co/u/bermanb)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 10:07pm UTC](https://discuss.elastic.co/t/upgrading-system-indices-to-version-8/347364 "2023-11-22T22:07:23Z")

</div>

We recently updated Elasticsearch and Kibana from 7.17 to 8.10.2, and noticed that we can't find how to upgrade the system indices from 7 to 8 (like in the 7 to 8 upgrade assistant where we were able to upgrade our indic…

---

## [Cannot see custom transaction](https://discuss.elastic.co/t/cannot-see-custom-transaction/347500)

<div class="topic-metadata">

**Author:** [@sumitk](https://discuss.elastic.co/u/sumitk)\
**Replies:** 0\
**Last updated:** [November 20, 2023, 6:46am UTC](https://discuss.elastic.co/t/cannot-see-custom-transaction/347500 "2023-11-20T06:46:51Z")

</div>

Hi I am doing custom transaction for analytics, but not able to see them in the kibana dashboard , I can see the events are happening in the network tab with 202 but the payload is encrpted .Can some body help me? Dashb…

---

## [Color stops acting strange](https://discuss.elastic.co/t/color-stops-acting-strange/347701)

<div class="topic-metadata">

**Author:** [@Negan](https://discuss.elastic.co/u/Negan)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 9:57pm UTC](https://discuss.elastic.co/t/color-stops-acting-strange/347701 "2023-11-22T21:57:13Z")

</div>

Hi. The colour stops I am trying to use are not showing as they should be. See images: as you can see in this image for some reason it starts to be green at -60,21 while it needs to be green under 0. I tried changing…

---

## [Annotations @ Lens - query automatically derived annotations](https://discuss.elastic.co/t/annotations-lens-query-automatically-derived-annotations/347671)

<div class="topic-metadata">

**Author:** [@lodooowa](https://discuss.elastic.co/u/lodooowa)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 9:35pm UTC](https://discuss.elastic.co/t/annotations-lens-query-automatically-derived-annotations/347671 "2023-11-21T21:35:00Z")

</div>

Tracking application deployment with annotations seems to be very useful feature. However out of the box it is shown only on very few transaction charts. Is there any way to query those automatically derived annotations…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=267)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=269)
