# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=303

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 304

---

## [Disk usage/shard allocation problems during snapshot creation](https://discuss.elastic.co/t/disk-usage-shard-allocation-problems-during-snapshot-creation/342768)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 4\
**Last updated:** [September 16, 2023, 4:51am UTC](https://discuss.elastic.co/t/disk-usage-shard-allocation-problems-during-snapshot-creation/342768 "2023-09-16T04:51:22Z")

</div>

version 7.17.12 last night my cluster stoped ingesting data. One node ran out of disk after snapshot started. That node normally has plenty of headroom: 57% available: 1.85TB total: 4.30TB logs show: \[2023-09-12T00…

---

## [Mapping date in milliseconds to basic\_date\_time](https://discuss.elastic.co/t/mapping-date-in-milliseconds-to-basic-date-time/343160)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 2\
**Last updated:** [September 15, 2023, 11:19pm UTC](https://discuss.elastic.co/t/mapping-date-in-milliseconds-to-basic-date-time/343160 "2023-09-15T23:19:06Z")

</div>

I followed the instructions here: I ran this command as instructed: PUT /\_index\_template/itential\_jobs\_template { "index\_patterns": \["itential-jobs-\*"\], "template": { "mappings": { "properties": { "start\_ti…

---

## [Logstash container not receiving log files from Filebeats running on host](https://discuss.elastic.co/t/logstash-container-not-receiving-log-files-from-filebeats-running-on-host/343162)

<div class="topic-metadata">

**Author:** [@David\_Locarno](https://discuss.elastic.co/u/David_Locarno)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 10:48pm UTC](https://discuss.elastic.co/t/logstash-container-not-receiving-log-files-from-filebeats-running-on-host/343162 "2023-09-15T22:48:20Z")

</div>

I am running a RHEL VM with Filebeats installed and three Podman containers running Kibana, Elasticsearch, and Logstash. Almost everything works, except for sending files from Filebeats to my Logstash container's pipelin…

---

## [Cannot parse logs - problem with multiline parse failures](https://discuss.elastic.co/t/cannot-parse-logs-problem-with-multiline-parse-failures/343146)

<div class="topic-metadata">

**Author:** [@danmed](https://discuss.elastic.co/u/danmed)\
**Replies:** 4\
**Last updated:** [September 15, 2023, 10:27pm UTC](https://discuss.elastic.co/t/cannot-parse-logs-problem-with-multiline-parse-failures/343146 "2023-09-15T22:27:04Z")

</div>

Hi All, I am having a lot of problems parsing logs especially with different dates and logs having multiline tags. For example: A head (very first 10 lines) of one of my log files, specifically, catalina.out, could be…

---

## [Advice needed on making logs available to application developer](https://discuss.elastic.co/t/advice-needed-on-making-logs-available-to-application-developer/341599)

<div class="topic-metadata">

**Author:** [@mubashar.tariq](https://discuss.elastic.co/u/mubashar.tariq)\
**Replies:** 3\
**Last updated:** [September 15, 2023, 6:48pm UTC](https://discuss.elastic.co/t/advice-needed-on-making-logs-available-to-application-developer/341599 "2023-09-15T18:48:25Z")

</div>

Background: We have number of large web applications deployed to WebLogic servers that are running on RedHat Linux 8. Development Teams need access to different logs (e.g. WebLogic, application logs) on these Linux machi…

---

## [Drop filter in Logstash filter not working for the below event](https://discuss.elastic.co/t/drop-filter-in-logstash-filter-not-working-for-the-below-event/343120)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 6:31pm UTC](https://discuss.elastic.co/t/drop-filter-in-logstash-filter-not-working-for-the-below-event/343120 "2023-09-15T18:31:11Z")

</div>

Event in Logstash : { "timestamp" =\> "2023-09-13T05:10:52.527038098Z", "user" =\> "admin", "type" =\> "icd\_postgresql", "status" =\> "INSERT INTO t1 SELECT i/100, i/500 FROM generate\_series(1,1…

---

## [Srping data elasticsearch document count info using built in reactive client](https://discuss.elastic.co/t/srping-data-elasticsearch-document-count-info-using-built-in-reactive-client/343148)

<div class="topic-metadata">

**Author:** [@D1sturbance](https://discuss.elastic.co/u/D1sturbance)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 2:50pm UTC](https://discuss.elastic.co/t/srping-data-elasticsearch-document-count-info-using-built-in-reactive-client/343148 "2023-09-15T14:50:57Z")

</div>

My problem: I am trying to get indices information: IndexName IndexCreationDate IndexAlias IndexDocumentCount IndexSize I am able to get some of that information via GetIndexResponse mentioned below. Which holds alia…

---

## [Kibana Maps world countries does not have names](https://discuss.elastic.co/t/kibana-maps-world-countries-does-not-have-names/342872)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 3\
**Last updated:** [September 15, 2023, 1:08pm UTC](https://discuss.elastic.co/t/kibana-maps-world-countries-does-not-have-names/342872 "2023-09-15T13:08:27Z")

</div>

I chose Data source EMS Boundaries Layer \[world\_countries\] , when I added a new layer to the map. The map does not contain the country names. Please check the attachment. How do I display the names? Thanks.

---

## [One ELK Node is Down](https://discuss.elastic.co/t/one-elk-node-is-down/343041)

<div class="topic-metadata">

**Author:** [@linux\_admin](https://discuss.elastic.co/u/linux_admin)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 12:53pm UTC](https://discuss.elastic.co/t/one-elk-node-is-down/343041 "2023-09-15T12:53:30Z")

</div>

Dear All, I have ELK cluster consists of three nodes elk01, elk02, elk03. One node elk01 is suddenly down. When I check the logs /var/log/elasticsearch/elasticsearch.log of elk01, I found these errors: "\[elk01\] Authent…

---

## [Read-only URL Repository](https://discuss.elastic.co/t/read-only-url-repository/343104)

<div class="topic-metadata">

**Author:** [@frh](https://discuss.elastic.co/u/frh)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 10:17am UTC](https://discuss.elastic.co/t/read-only-url-repository/343104 "2023-09-15T10:17:45Z")

</div>

Hi, I just created read-only URL repository and give it a name as "test". I got this error when verify repository: { "error": { "root\_cause": \[ { "type": "repository\_exception", "reason": "\[…

---

## [Scores are inconsistent with data and query](https://discuss.elastic.co/t/scores-are-inconsistent-with-data-and-query/343121)

<div class="topic-metadata">

**Author:** [@appsol](https://discuss.elastic.co/u/appsol)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 9:03am UTC](https://discuss.elastic.co/t/scores-are-inconsistent-with-data-and-query/343121 "2023-09-15T09:03:05Z")

</div>

Hello, My document has a title field and an intro field. I have given greater importance to the title field over the intro field in my query, yet all other fields being equal, the intro field is getting a higher score t…

---

## [Not able to connect to elastic from kibana](https://discuss.elastic.co/t/not-able-to-connect-to-elastic-from-kibana/341652)

<div class="topic-metadata">

**Author:** [@chitra\_perumal](https://discuss.elastic.co/u/chitra_perumal)\
**Replies:** 16\
**Last updated:** [September 15, 2023, 8:00am UTC](https://discuss.elastic.co/t/not-able-to-connect-to-elastic-from-kibana/341652 "2023-09-15T08:00:12Z")

</div>

Hello, I am trying to set up the OIDC authentication for Kibana in SSO . I have followed the steps from elastic guide. The CA and HTTP certificates are created as per the details provided in above link. The elastic is…

---

## [Rally 2.9.1](https://discuss.elastic.co/t/rally-2-9-1/343112)

<div class="topic-metadata">

**Author:** [@Quentin\_Pradet](https://discuss.elastic.co/u/Quentin_Pradet)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 7:25am UTC](https://discuss.elastic.co/t/rally-2-9-1/343112 "2023-09-15T07:25:10Z")

</div>

Rally 2.9.1 has just been released. Rally is the macrobenchmarking framework for Elasticsearch. The new continues to improve support for the upcoming Elasticsearch Serverless offering and fixes a bug introduced in Rally …

---

## [Adding Documents via REST API in ElasticSearch](https://discuss.elastic.co/t/adding-documents-via-rest-api-in-elasticsearch/343102)

<div class="topic-metadata">

**Author:** [@sanyam](https://discuss.elastic.co/u/sanyam)\
**Replies:** 4\
**Last updated:** [September 15, 2023, 6:45am UTC](https://discuss.elastic.co/t/adding-documents-via-rest-api-in-elasticsearch/343102 "2023-09-15T06:45:18Z")

</div>

I am getting this error while trying to run this code to add data/document In Elasticsearch version 6.4.1 in windows curl -X POST "localhost:9200/clusters/\_doc" -H "Content-Type" : application/json -d "{ "field1":"valu…

---

## [Help elk stack](https://discuss.elastic.co/t/help-elk-stack/342595)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 6\
**Last updated:** [September 15, 2023, 6:05am UTC](https://discuss.elastic.co/t/help-elk-stack/342595 "2023-09-15T06:05:54Z")

</div>

Bonjour j'ai une question j ai un champs date\_le(qui contient le date exemple 20 tte date juillet 2022,13 aout 2023 etc je voulais faire le split de ca comme l annee , le mois et apres la date comment je peux faire ca …

---

## [Logstash Grok Pattern Watchguard Firewall](https://discuss.elastic.co/t/logstash-grok-pattern-watchguard-firewall/342317)

<div class="topic-metadata">

**Author:** [@Simon7](https://discuss.elastic.co/u/Simon7)\
**Replies:** 6\
**Last updated:** [September 15, 2023, 5:22am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-watchguard-firewall/342317 "2023-09-15T05:22:41Z")

</div>

Hey Guys, this is my first topic here in this forum. I have established an Elasticsearch log management in our company. I'm having a bit of trouble with the grok pattern. If I can't use integrations, I need to create m…

---

## [Elasticsearch error in running service JAVA error](https://discuss.elastic.co/t/elasticsearch-error-in-running-service-java-error/342782)

<div class="topic-metadata">

**Author:** [@1337](https://discuss.elastic.co/u/1337)\
**Replies:** 15\
**Last updated:** [September 15, 2023, 4:51am UTC](https://discuss.elastic.co/t/elasticsearch-error-in-running-service-java-error/342782 "2023-09-15T04:51:26Z")

</div>

systemctl status elasticsearch × elasticsearch.service - Elasticsearch Loaded: loaded (/lib/systemd/system/elasticsearch.service; enabled; vendor preset: enabled) Active: failed (Result: exit-code) since Tue 2…

---

## [URI too long with custom routing](https://discuss.elastic.co/t/uri-too-long-with-custom-routing/342993)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 7\
**Last updated:** [September 15, 2023, 2:55am UTC](https://discuss.elastic.co/t/uri-too-long-with-custom-routing/342993 "2023-09-15T02:55:25Z")

</div>

Hi Team, I'm experimenting with custom routing to bring down the latency of search requests in my cluster. The routing\_ids are assigned in groups of N. For ex. a key with 1000 associated documents will be mapped to 10 d…

---

## [Multiple filters when creating a Metric Threshold](https://discuss.elastic.co/t/multiple-filters-when-creating-a-metric-threshold/342989)

<div class="topic-metadata">

**Author:** [@vsabado](https://discuss.elastic.co/u/vsabado)\
**Replies:** 22\
**Last updated:** [September 14, 2023, 9:17pm UTC](https://discuss.elastic.co/t/multiple-filters-when-creating-a-metric-threshold/342989 "2023-09-14T21:17:24Z")

</div>

I'm trying to create a rule in ES using the metric threshold. If I used a single filter, it works fine. But when I use a group of filters strung together using "and", like filter1 and filter2 and filter3, then it the rul…

---

## [Termsuggester in new Elasticsearch client library](https://discuss.elastic.co/t/termsuggester-in-new-elasticsearch-client-library/343070)

<div class="topic-metadata">

**Author:** [@ramyogi](https://discuss.elastic.co/u/ramyogi)\
**Replies:** 1\
**Last updated:** [September 14, 2023, 8:38pm UTC](https://discuss.elastic.co/t/termsuggester-in-new-elasticsearch-client-library/343070 "2023-09-14T20:38:02Z")

</div>

We could not find any option to supply accuracy with term suggest. But Elasticsearch core lib provided that option. https://www.javadoc.io/doc/org.elasticsearch/elasticsearch/latest/org.elasticsearch.server/org/elastics…

---

## [MySQL Slow query log](https://discuss.elastic.co/t/mysql-slow-query-log/343003)

<div class="topic-metadata">

**Author:** [@ELK\_USR1](https://discuss.elastic.co/u/ELK_USR1)\
**Replies:** 1\
**Last updated:** [September 14, 2023, 8:02pm UTC](https://discuss.elastic.co/t/mysql-slow-query-log/343003 "2023-09-14T20:02:53Z")

</div>

Hi All, Version: Elasticserch:8.8.1 Filebeat:8.8.1 kibana:8.8.1 I am configuring the ELK stack for MySQL component. I referred the below URL for configuration. I have successfully implemented for error log and is…

---

## [Elasticsearch JNA unavailable / elastic no start](https://discuss.elastic.co/t/elasticsearch-jna-unavailable-elastic-no-start/343072)

<div class="topic-metadata">

**Author:** [@deepx](https://discuss.elastic.co/u/deepx)\
**Replies:** 3\
**Last updated:** [September 14, 2023, 8:02pm UTC](https://discuss.elastic.co/t/elasticsearch-jna-unavailable-elastic-no-start/343072 "2023-09-14T20:02:33Z")

</div>

Hello, I installed elasticsearch on ubuntu , but when i start elastic I always get an error. The log is showing me the following: JNA not available java.lang.UnsatisfiedLinkError: /tmp/elasticsearch-1125708853983863618…

---

## [Exiting: error importing Kibana dashboards: fail to import the dashboards in Kibana](https://discuss.elastic.co/t/exiting-error-importing-kibana-dashboards-fail-to-import-the-dashboards-in-kibana/342912)

<div class="topic-metadata">

**Author:** [@ELK\_USR1](https://discuss.elastic.co/u/ELK_USR1)\
**Replies:** 3\
**Last updated:** [September 14, 2023, 7:33pm UTC](https://discuss.elastic.co/t/exiting-error-importing-kibana-dashboards-fail-to-import-the-dashboards-in-kibana/342912 "2023-09-14T19:33:55Z")

</div>

While running ./kibana setup -e getting below error {"log.level":"error","@timestamp":"2023-09-13T12:47:44.064+0530","log.origin":{"file.name":"instance/beat.go","file.line":1274},"message":"Exiting: error importing Kib…

---

## [Joining and mapping](https://discuss.elastic.co/t/joining-and-mapping/343069)

<div class="topic-metadata">

**Author:** [@Hamed\_Ahmadi](https://discuss.elastic.co/u/Hamed_Ahmadi)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 5:25pm UTC](https://discuss.elastic.co/t/joining-and-mapping/343069 "2023-09-14T17:25:51Z")

</div>

Hi guys! I have a relational Database which I have synchronised with Elasticsearch over logstash. I have a work table, article table and comment table. One work has multiple comments and articles, basically work is pare…

---

## [\[search\_phase\_execution\_exception Caused by: es\_rejected\_execution\_exception: rejected execution](https://discuss.elastic.co/t/search-phase-execution-exception-caused-by-es-rejected-execution-exception-rejected-execution/342081)

<div class="topic-metadata">

**Author:** [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Replies:** 9\
**Last updated:** [September 14, 2023, 4:39pm UTC](https://discuss.elastic.co/t/search-phase-execution-exception-caused-by-es-rejected-execution-exception-rejected-execution/342081 "2023-09-14T16:39:55Z")

</div>

I am using grafana k6 stress tool to generate some load in elastic and sooner or later i always get this error es\_rejected\_execution\_exception. All are search operations to get 30 docs. On small indices of 20-30mb it …

---

## [Fuzzy\_terms\_exception when matching against keyword fields](https://discuss.elastic.co/t/fuzzy-terms-exception-when-matching-against-keyword-fields/343057)

<div class="topic-metadata">

**Author:** [@David\_Kolb](https://discuss.elastic.co/u/David_Kolb)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 2:19pm UTC](https://discuss.elastic.co/t/fuzzy-terms-exception-when-matching-against-keyword-fields/343057 "2023-09-14T14:19:52Z")

</div>

Hi, I'm getting a ElasticsearchException\[Elasticsearch exception \[type=fuzzy\_terms\_exception, reason=Term too complex when running a fuzzy (AUTO) multi match query with a query String that contains long terms against …

---

## [Transform and simplify long regex with dissect or grok?](https://discuss.elastic.co/t/transform-and-simplify-long-regex-with-dissect-or-grok/342973)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 4\
**Last updated:** [September 14, 2023, 2:09pm UTC](https://discuss.elastic.co/t/transform-and-simplify-long-regex-with-dissect-or-grok/342973 "2023-09-14T14:09:35Z")

</div>

Hello, I have some long and heavy regex and i wonder if i can simplify and gain in term of performances by using dissect here are some examples "^\<%{NONNEGINT:syslog\_priority:int}\>1 (?:-|%{TIMESTAMP\_ISO8601:syslog\_t…

---

## [A way to reduced needed storage space for Elastic Agent?](https://discuss.elastic.co/t/a-way-to-reduced-needed-storage-space-for-elastic-agent/343052)

<div class="topic-metadata">

**Author:** [@Amadeus](https://discuss.elastic.co/u/Amadeus)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 12:13pm UTC](https://discuss.elastic.co/t/a-way-to-reduced-needed-storage-space-for-elastic-agent/343052 "2023-09-14T12:13:51Z")

</div>

Hello everyone, I have two questions. When installing/enrolling a Fleet-managed Elastic Agent (as tar) I'm required to download the tar.gz, extract the files and execute the install/enroll command. By doing so the …

---

## [Transform "pipeline with id \[blah\] does not exist" & "user \[foo\] with effective roles \[\] (assigned roles \[bar\] were not found)"](https://discuss.elastic.co/t/transform-pipeline-with-id-blah-does-not-exist-user-foo-with-effective-roles-assigned-roles-bar-were-not-found/343046)

<div class="topic-metadata">

**Author:** [@Mark\_Duncan](https://discuss.elastic.co/u/Mark_Duncan)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 11:14am UTC](https://discuss.elastic.co/t/transform-pipeline-with-id-blah-does-not-exist-user-foo-with-effective-roles-assigned-roles-bar-were-not-found/343046 "2023-09-14T11:14:14Z")

</div>

We have updated to ELK 8.9.1, and have had a few transforms now stop with this error, "Transform "pipeline with id \[blah\] does not exist". The pipeline does indeed exist, and we can stop/start the transform again, after …

---

## [Disable fuzzy match ion matchquery on search and return only desired set of fields in response](https://discuss.elastic.co/t/disable-fuzzy-match-ion-matchquery-on-search-and-return-only-desired-set-of-fields-in-response/343030)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 4\
**Last updated:** [September 14, 2023, 11:04am UTC](https://discuss.elastic.co/t/disable-fuzzy-match-ion-matchquery-on-search-and-return-only-desired-set-of-fields-in-response/343030 "2023-09-14T11:04:42Z")

</div>

1- In elastic java rest client, How I can disable the fuzzy match? with below source builder, I need only properly matching records. if I give 456-ABC, it should not return anything. if I give just ABC or 123-ABC, it s…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=302)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=304)
